简单来说:Debian 下 ulimit 本身不支持通配符,但在 PAM / systemd / limits.conf 层面是“支持匹配一类用户”的机制的,只是不是 shell 通配符意义上的 *,而是配置语义上的通配符。
下面分情况说明。
ulimit 命令本身:不支持通配符ulimit 是 shell 内建命令(bash/zsh 等),作用是设置当前 shell 进程及其子进程的资源限制。
例如:
ulimit -n 65535
特点:
*、? 这类通配符ulimit * -n 65535(语法错误)所以 ulimit 命令层面:❌ 不支持通配符
/etc/security/limits.conf:支持“通配符式”匹配这是 Debian 上最常见的资源限制配置方式(通过 PAM)。
文件路径:
/etc/security/limits.conf
这里支持的特殊“通配符”(其实是关键字):
| 符号 | 含义 |
|---|---|
* |
所有用户 |
root |
root 用户 |
@group |
用户组 |
% |
一般不用 |
示例:
* soft nofile 65535
* hard nofile 65535
@docker soft nproc 4096
✅ 这里的 * 可以理解为“对所有用户生效”
❌ 但不能写 user* 或 test? 这种 shell 通配符
所以:
如果你用 systemd 启动服务:
limits.conf 对 systemd service 不一定生效[Service]
LimitNOFILE=65535
或全局:
# /etc/systemd/system.conf
DefaultLimitNOFILE=65535
这里:
如果需求是:
给某一类用户(比如 test1, test2, test3)设置 ulimit
可选方案:
@testgroup soft nofile 65535
case "$USER" in
test*)
ulimit -n 65535
;;
esac
| 场景 | 是否支持通配符 |
|---|---|
ulimit 命令 |
❌ 不支持 |
limits.conf 的 * / @group |
✅ 语义级“通配” |
shell 通配符 (*, ?) |
❌ 不支持 |
| systemd Limit* | ❌ 不支持 |
如果你能说一下具体使用场景(比如:ssh 登录用户?某个服务?Docker?),我可以给你更精确的配置示例。