Home / Alt manpages / prlimit(1)

  • prlimit(1)
  • User command
  • linux

Inspect and Set Linux Process Limits with prlimit

You will finish with a safe way to inspect resource limits, apply a temporary limit to a child process, and launch a command with a limit already in place. The examples use the installed prlimit binary from util-linux 2.41.3. The local manual page is from util-linux 2.39.3, so the version shown by your PATH may not match the version documented by the local manpage.

Allow about fifteen minutes. You need a shell and util-linux. The inspection commands are ordinary user commands. Changing another user's process, raising a hard limit, or changing a service's limits may require elevated privileges and can fail even with sudo if the kernel or service policy does not allow it.

1. Check the installed command

Start by checking which executable your shell will use and which util-linux release it reports:

$ command -v prlimit
/home/linuxbrew/.linuxbrew/bin/prlimit
$ prlimit --version
prlimit from util-linux 2.41.3

Your path and version can differ. Keep this check with a troubleshooting note or script, because two installations can expose different option details. The local manual describes the same main interface: choose a resource with an option such as --nofile, then either inspect it or attach a limit.

Checkpoint: ask the installed binary for its resource and output names before writing a script:

$ prlimit --help
Usage:
 prlimit [options] [--<resource>=<limit>] [-p PID]
 prlimit [options] [--<resource>=<limit>] COMMAND

Show or change the resource limits of a process.

The help output is the authority for the binary you are actually calling. In the examples below, nofile means the maximum number of open file descriptors and cpu means CPU time in seconds.

2. Inspect the current shell without changing it

Use --pid with the shell's process ID. This is read-only:

$ prlimit --pid $$ --noheadings --output RESOURCE,SOFT,HARD --nofile
NOFILE 1048576 1048576

The two numbers are the soft limit and the hard limit, also called the ceiling. The soft value is the limit normally enforced for the process. A process can usually lower its own limits, while raising a hard limit is more restricted. Your values may be different. If you omit --output, prlimit prints a broader, human-readable table.

To see every resource for the current shell, run:

$ prlimit --pid $$

Do not confuse the shell's limits with a system-wide setting. They belong to that process and are inherited by children it starts. A service launched by systemd, a container runtime or another supervisor can receive different limits.

3. Change a disposable child process

Changing a live process is a state change. For a first test, create a short-lived child that does no useful work, lower its open-file limit, inspect the result, then let it exit:

$ sleep 20 &
$ child=$!
$ prlimit --pid "$child" --nofile=128:256
$ prlimit --pid "$child" --noheadings --output RESOURCE,SOFT,HARD --nofile
NOFILE 128 256
$ kill "$child"
$ wait "$child" 2>/dev/null || true

The value 128:256 sets both parts of the range. The process must be one you own, and the soft limit cannot be higher than the hard limit. If prlimit reports permission denied, do not immediately add sudo: first confirm the PID and ownership. Applying a smaller limit to the wrong process can disrupt a service even though it is reversible in principle.

There is no persistent configuration to undo here. Killing the test process discards its changed limits. If you changed a real process, restore the previous pair explicitly, for example --nofile=OLD_SOFT:OLD_HARD, if you recorded it and still have permission.

4. Understand the limit syntax

prlimit accepts four useful forms. Use the form that matches the change you intend:

FormMeaning
soft:hardSet both values separately.
soft:Set only the soft value and keep the current hard value.
:hardSet only the hard value and keep the current soft value.
valueSet both values to the same value.

Use unlimited or -1 for the infinity value supported by the resource. Treat that as a deliberate security decision. Removing a limit can allow a process to consume more descriptors, memory, processes or CPU than its host was designed to tolerate. Check the result immediately after any change.

5. Launch a command under a limit

The safer operational pattern is to apply the limit while starting the command. The limit is inherited by the command and its descendants, rather than being attached later to an already-running service:

$ prlimit --cpu=1 /bin/sh -c 'printf "%s\n" child-ok'
child-ok

This sets both the soft and hard CPU-time limits to one second for the shell command. It does not reserve one second of CPU and it does not limit elapsed wall-clock time. A program that sleeps can run for longer while consuming little CPU. A command that exceeds its CPU limit can be terminated by the kernel, so do not trial this against a production workload without a recovery plan.

Arguments after the command belong to that command. Quote paths and arguments normally, and do not construct the option string from untrusted input. For a harmless file-descriptor check, you can start a shell with a lower open-file limit and inspect its inherited values:

$ prlimit --nofile=128:256 /bin/sh -c \
  'prlimit --pid $$ --noheadings --output RESOURCE,SOFT,HARD --nofile'
NOFILE 128 256

When this command exits, its temporary limit disappears with it. That makes command mode suitable for testing a worker or one-off job before changing the supervisor configuration.

6. Diagnose the common failures

A missing or invalid resource option is a syntax problem. Compare the option with prlimit --help; the installed command lists names such as core, data, fsize, nofile, nproc, stack and as. Do not substitute a similarly named setting from another tool.

A limit change can fail because the PID has exited, the process belongs to another user, the requested hard limit is too high, or the requested pair violates the soft-less-than-or-equal-to-hard rule. Re-run the inspection against the exact PID and capture the error status:

$ sleep 5 & child=$!
$ kill "$child"
$ wait "$child" 2>/dev/null || true
$ prlimit --pid "$child" --nofile=128:256
$ status=$?
$ printf 'prlimit status: %s\n' "$status"
prlimit: failed to set the NOFILE resource limit: No such process
prlimit status: 1

The exact diagnostic text and status can vary with the failure and util-linux version. A non-zero status means the requested operation did not complete; it is not evidence that a different resource was changed. Never treat a failed limit change as a successful safety control.

Remember that prlimit changes process state, not the service definition. For a long-running service, put the intended limit in the service manager or container configuration after testing, then restart through the normal change process. Keep the old configuration until the new limit has been observed under realistic load.

Done means

  • You confirmed which prlimit binary and util-linux version you are using.
  • You inspected a process with a selected output column and understood its soft and hard values.
  • You changed only a disposable child process, or recorded the old values before changing a real process.
  • You can distinguish a per-command limit from a persistent service configuration.
  • You verified every change and did not use unlimited without a clear capacity and security reason.