kernel.rst 39.0 KB
Newer Older
1 2 3
===================================
Documentation for /proc/sys/kernel/
===================================
L
Linus Torvalds 已提交
4

5 6 7 8
Copyright (c) 1998, 1999,  Rik van Riel <riel@nl.linux.org>

Copyright (c) 2009,        Shen Feng<shen@cn.fujitsu.com>

S
Stephen Kitt 已提交
9
For general info and legal blurb, please look in :doc:`index`.
10 11

------------------------------------------------------------------------------
L
Linus Torvalds 已提交
12 13

This file contains documentation for the sysctl files in
S
Stephen Kitt 已提交
14
``/proc/sys/kernel/`` and is valid for Linux kernel version 2.2.
L
Linus Torvalds 已提交
15 16 17

The files in this directory can be used to tune and monitor
miscellaneous and general things in the operation of the Linux
S
Stephen Kitt 已提交
18
kernel. Since some of the files *can* be used to screw up your
L
Linus Torvalds 已提交
19 20 21 22
system, it is advisable to read both documentation and source
before actually making adjustments.

Currently, these files might (depending on your configuration)
S
Stephen Kitt 已提交
23 24 25 26 27 28 29 30 31
show up in ``/proc/sys/kernel``:

.. contents:: :local:


acct
====

::
L
Linus Torvalds 已提交
32

S
Stephen Kitt 已提交
33
    highwater lowwater frequency
L
Linus Torvalds 已提交
34 35 36

If BSD-style process accounting is enabled these values control
its behaviour. If free space on filesystem where the log lives
S
Stephen Kitt 已提交
37 38
goes below ``lowwater``% accounting suspends. If free space gets
above ``highwater``% accounting resumes. ``frequency`` determines
L
Linus Torvalds 已提交
39 40 41
how often do we check the amount of free space (value is in
seconds). Default:

S
Stephen Kitt 已提交
42
::
43

S
Stephen Kitt 已提交
44
    4 2 30
45

S
Stephen Kitt 已提交
46 47 48
That is, suspend accounting if free space drops below 2%; resume it
if it increases to at least 4%; consider information about amount of
free space valid for 30 seconds.
49 50


S
Stephen Kitt 已提交
51 52 53 54 55
acpi_video_flags
================

See Documentation/kernel/power/video.txt, it allows mode of video boot
to be set during run time.
56

S
Stephen Kitt 已提交
57 58 59

auto_msgmni
===========
60

61 62
This variable has no effect and may be removed in future kernel
releases. Reading it always returns 0.
S
Stephen Kitt 已提交
63 64 65
Up to Linux 3.17, it enabled/disabled automatic recomputing of
`msgmni`_
upon memory add/remove or upon IPC namespace creation/removal.
66
Echoing "1" into this file enabled msgmni automatic recomputing.
S
Stephen Kitt 已提交
67
Echoing "0" turned it off. The default value was 1.
68

69

S
Stephen Kitt 已提交
70 71
bootloader_type (x86 only)
==========================
72 73 74 75

This gives the bootloader type number as indicated by the bootloader,
shifted left by 4, and OR'd with the low four bits of the bootloader
version.  The reason for this encoding is that this used to match the
S
Stephen Kitt 已提交
76
``type_of_loader`` field in the kernel header; the encoding is kept for
77 78 79 80
backwards compatibility.  That is, if the full bootloader type number
is 0x15 and the full version number is 0x234, this file will contain
the value 340 = 0x154.

S
Stephen Kitt 已提交
81 82
See the ``type_of_loader`` and ``ext_loader_type`` fields in
:doc:`/x86/boot` for additional information.
83 84


S
Stephen Kitt 已提交
85 86
bootloader_version (x86 only)
=============================
87 88 89 90

The complete bootloader version number.  In the example above, this
file will contain the value 564 = 0x234.

S
Stephen Kitt 已提交
91 92
See the ``type_of_loader`` and ``ext_loader_ver`` fields in
:doc:`/x86/boot` for additional information.
93 94


S
Stephen Kitt 已提交
95 96
cap_last_cap
============
97 98

Highest valid capability of the running kernel.  Exports
S
Stephen Kitt 已提交
99
``CAP_LAST_CAP`` from the kernel.
100 101


S
Stephen Kitt 已提交
102 103
core_pattern
============
L
Linus Torvalds 已提交
104

S
Stephen Kitt 已提交
105
``core_pattern`` is used to specify a core dumpfile pattern name.
106 107

* max length 127 characters; default value is "core"
S
Stephen Kitt 已提交
108 109 110 111
* ``core_pattern`` is used as a pattern template for the output
  filename; certain string patterns (beginning with '%') are
  substituted with their actual values.
* backward compatibility with ``core_uses_pid``:
112

S
Stephen Kitt 已提交
113 114
	If ``core_pattern`` does not include "%p" (default does not)
	and ``core_uses_pid`` is set, then .PID will be appended to
L
Linus Torvalds 已提交
115
	the filename.
116

S
Stephen Kitt 已提交
117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137
* corename format specifiers

	========	==========================================
	%<NUL>		'%' is dropped
	%%		output one '%'
	%p		pid
	%P		global pid (init PID namespace)
	%i		tid
	%I		global tid (init PID namespace)
	%u		uid (in initial user namespace)
	%g		gid (in initial user namespace)
	%d		dump mode, matches ``PR_SET_DUMPABLE`` and
			``/proc/sys/fs/suid_dumpable``
	%s		signal number
	%t		UNIX time of dump
	%h		hostname
	%e		executable filename (may be shortened)
	%E		executable path
	%c		maximum size of core file by resource limit RLIMIT_CORE
	%<OTHER>	both are dropped
	========	==========================================
138 139

* If the first character of the pattern is a '|', the kernel will treat
140 141
  the rest of the pattern as a command to run.  The core dump will be
  written to the standard input of that program instead of to a file.
L
Linus Torvalds 已提交
142 143


S
Stephen Kitt 已提交
144 145
core_pipe_limit
===============
146

S
Stephen Kitt 已提交
147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172
This sysctl is only applicable when `core_pattern`_ is configured to
pipe core files to a user space helper (when the first character of
``core_pattern`` is a '|', see above).
When collecting cores via a pipe to an application, it is occasionally
useful for the collecting application to gather data about the
crashing process from its ``/proc/pid`` directory.
In order to do this safely, the kernel must wait for the collecting
process to exit, so as not to remove the crashing processes proc files
prematurely.
This in turn creates the possibility that a misbehaving userspace
collecting process can block the reaping of a crashed process simply
by never exiting.
This sysctl defends against that.
It defines how many concurrent crashing processes may be piped to user
space applications in parallel.
If this value is exceeded, then those crashing processes above that
value are noted via the kernel log and their cores are skipped.
0 is a special value, indicating that unlimited processes may be
captured in parallel, but that no waiting will take place (i.e. the
collecting process is not guaranteed access to ``/proc/<crashing
pid>/``).
This value defaults to 0.


core_uses_pid
=============
L
Linus Torvalds 已提交
173 174

The default coredump filename is "core".  By setting
S
Stephen Kitt 已提交
175 176 177
``core_uses_pid`` to 1, the coredump filename becomes core.PID.
If `core_pattern`_ does not include "%p" (default does not)
and ``core_uses_pid`` is set, then .PID will be appended to
L
Linus Torvalds 已提交
178 179 180
the filename.


S
Stephen Kitt 已提交
181 182
ctrl-alt-del
============
L
Linus Torvalds 已提交
183 184

When the value in this file is 0, ctrl-alt-del is trapped and
S
Stephen Kitt 已提交
185
sent to the ``init(1)`` program to handle a graceful restart.
L
Linus Torvalds 已提交
186 187 188 189
When, however, the value is > 0, Linux's reaction to a Vulcan
Nerve Pinch (tm) will be an immediate reboot, without even
syncing its dirty buffers.

190 191 192 193 194
Note:
  when a program (like dosemu) has the keyboard in 'raw'
  mode, the ctrl-alt-del is intercepted by the program before it
  ever reaches the kernel tty layer, and it's up to the program
  to decide what to do with it.
L
Linus Torvalds 已提交
195 196


S
Stephen Kitt 已提交
197 198
dmesg_restrict
==============
199

200
This toggle indicates whether unprivileged users are prevented
S
Stephen Kitt 已提交
201 202 203 204 205
from using ``dmesg(8)`` to view messages from the kernel's log
buffer.
When ``dmesg_restrict`` is set to 0 there are no restrictions.
When ``dmesg_restrict`` is set set to 1, users must have
``CAP_SYSLOG`` to use ``dmesg(8)``.
206

S
Stephen Kitt 已提交
207 208
The kernel config option ``CONFIG_SECURITY_DMESG_RESTRICT`` sets the
default value of ``dmesg_restrict``.
209 210


S
Stephen Kitt 已提交
211 212
domainname & hostname
=====================
L
Linus Torvalds 已提交
213 214 215

These files can be used to set the NIS/YP domainname and the
hostname of your box in exactly the same way as the commands
216 217 218 219 220 221 222 223 224
domainname and hostname, i.e.::

	# echo "darkstar" > /proc/sys/kernel/hostname
	# echo "mydomain" > /proc/sys/kernel/domainname

has the same effect as::

	# hostname "darkstar"
	# domainname "mydomain"
L
Linus Torvalds 已提交
225 226 227 228 229 230

Note, however, that the classic darkstar.frop.org has the
hostname "darkstar" and DNS (Internet Domain Name Server)
domainname "frop.org", not to be confused with the NIS (Network
Information Service) or YP (Yellow Pages) domainname. These two
domain names are in general different. For a detailed discussion
S
Stephen Kitt 已提交
231
see the ``hostname(1)`` man page.
L
Linus Torvalds 已提交
232

233

S
Stephen Kitt 已提交
234 235
hardlockup_all_cpu_backtrace
============================
236 237 238 239 240 241

This value controls the hard lockup detector behavior when a hard
lockup condition is detected as to whether or not to gather further
debug information. If enabled, arch-specific all-CPU stack dumping
will be initiated.

S
Stephen Kitt 已提交
242 243 244 245
= ============================================
0 Do nothing. This is the default behavior.
1 On detection capture more debug information.
= ============================================
246

L
Linus Torvalds 已提交
247

S
Stephen Kitt 已提交
248 249
hardlockup_panic
================
250 251 252 253

This parameter can be used to control whether the kernel panics
when a hard lockup is detected.

S
Stephen Kitt 已提交
254 255 256 257
= ===========================
0 Don't panic on hard lockup.
1 Panic on hard lockup.
= ===========================
258

S
Stephen Kitt 已提交
259 260
See :doc:`/admin-guide/lockup-watchdogs` for more information.
This can also be set using the nmi_watchdog kernel parameter.
261 262


S
Stephen Kitt 已提交
263 264
hotplug
=======
L
Linus Torvalds 已提交
265 266

Path for the hotplug policy agent.
S
Stephen Kitt 已提交
267
Default value is "``/sbin/hotplug``".
L
Linus Torvalds 已提交
268 269


S
Stephen Kitt 已提交
270 271
hung_task_panic
===============
272 273

Controls the kernel's behavior when a hung task is detected.
S
Stephen Kitt 已提交
274
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
275

S
Stephen Kitt 已提交
276 277 278 279
= =================================================
0 Continue operation. This is the default behavior.
1 Panic immediately.
= =================================================
280 281


S
Stephen Kitt 已提交
282 283
hung_task_check_count
=====================
284 285

The upper bound on the number of tasks that are checked.
S
Stephen Kitt 已提交
286
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
287 288


S
Stephen Kitt 已提交
289 290
hung_task_timeout_secs
======================
291

292
When a task in D state did not get scheduled
293
for more than this value report a warning.
S
Stephen Kitt 已提交
294
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
295

S
Stephen Kitt 已提交
296
0 means infinite timeout, no checking is done.
297

S
Stephen Kitt 已提交
298
Possible values to set are in range {0:``LONG_MAX``/``HZ``}.
299 300


S
Stephen Kitt 已提交
301 302
hung_task_check_interval_secs
=============================
303 304

Hung task check interval. If hung task checking is enabled
S
Stephen Kitt 已提交
305 306 307
(see `hung_task_timeout_secs`_), the check is done every
``hung_task_check_interval_secs`` seconds.
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
308

S
Stephen Kitt 已提交
309 310
0 (default) means use ``hung_task_timeout_secs`` as checking
interval.
311

S
Stephen Kitt 已提交
312
Possible values to set are in range {0:``LONG_MAX``/``HZ``}.
313

S
Stephen Kitt 已提交
314 315 316

hung_task_warnings
==================
317 318

The maximum number of warnings to report. During a check interval
319 320
if a hung task is detected, this value is decreased by 1.
When this value reaches 0, no more warnings will be reported.
S
Stephen Kitt 已提交
321
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
322 323 324 325

-1: report an infinite number of warnings.


S
Stephen Kitt 已提交
326 327
hyperv_record_panic_msg
=======================
328 329 330

Controls whether the panic kmsg data should be reported to Hyper-V.

S
Stephen Kitt 已提交
331 332 333 334
= =========================================================
0 Do not report panic kmsg data.
1 Report the panic kmsg data. This is the default behavior.
= =========================================================
335 336


S
Stephen Kitt 已提交
337 338
kexec_load_disabled
===================
339

S
Stephen Kitt 已提交
340 341 342 343 344 345 346 347 348
A toggle indicating if the ``kexec_load`` syscall has been disabled.
This value defaults to 0 (false: ``kexec_load`` enabled), but can be
set to 1 (true: ``kexec_load`` disabled).
Once true, kexec can no longer be used, and the toggle cannot be set
back to false.
This allows a kexec image to be loaded before disabling the syscall,
allowing a system to set up (and later use) an image without it being
altered.
Generally used together with the `modules_disabled`_ sysctl.
349 350


S
Stephen Kitt 已提交
351 352
kptr_restrict
=============
353 354

This toggle indicates whether restrictions are placed on
S
Stephen Kitt 已提交
355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381
exposing kernel addresses via ``/proc`` and other interfaces.

When ``kptr_restrict`` is set to 0 (the default) the address is hashed
before printing.
(This is the equivalent to %p.)

When ``kptr_restrict`` is set to 1, kernel pointers printed using the
%pK format specifier will be replaced with 0s unless the user has
``CAP_SYSLOG`` and effective user and group ids are equal to the real
ids.
This is because %pK checks are done at read() time rather than open()
time, so if permissions are elevated between the open() and the read()
(e.g via a setuid binary) then %pK will not leak kernel pointers to
unprivileged users.
Note, this is a temporary solution only.
The correct long-term solution is to do the permission checks at
open() time.
Consider removing world read permissions from files that use %pK, and
using `dmesg_restrict`_ to protect against uses of %pK in ``dmesg(8)``
if leaking kernel pointer values to unprivileged users is a concern.

When ``kptr_restrict`` is set to 2, kernel pointers printed using
%pK will be replaced with 0s regardless of privileges.


modprobe
========
382

383 384 385 386 387 388 389 390 391 392 393 394 395
This gives the full path of the modprobe command which the kernel will
use to load modules. This can be used to debug module loading
requests::

    echo '#! /bin/sh' > /tmp/modprobe
    echo 'echo "$@" >> /tmp/modprobe.log' >> /tmp/modprobe
    echo 'exec /sbin/modprobe "$@"' >> /tmp/modprobe
    chmod a+x /tmp/modprobe
    echo /tmp/modprobe > /proc/sys/kernel/modprobe

This only applies when the *kernel* is requesting that the module be
loaded; it won't have any effect if the module is being loaded
explicitly using ``modprobe`` from userspace.
396 397


S
Stephen Kitt 已提交
398 399
modules_disabled
================
400 401 402 403 404

A toggle value indicating if modules are allowed to be loaded
in an otherwise modular kernel.  This toggle defaults to off
(0), but can be set true (1).  Once true, modules can be
neither loaded nor unloaded, and the toggle cannot be set back
S
Stephen Kitt 已提交
405 406
to false.  Generally used with the `kexec_load_disabled`_ toggle.

407

S
Stephen Kitt 已提交
408
.. _msgmni:
409

S
Stephen Kitt 已提交
410 411 412
msgmax, msgmnb, and msgmni
==========================

413 414 415 416 417 418 419 420 421
``msgmax`` is the maximum size of an IPC message, in bytes. 8192 by
default (``MSGMAX``).

``msgmnb`` is the maximum size of an IPC queue, in bytes. 16384 by
default (``MSGMNB``).

``msgmni`` is the maximum number of IPC queues. 32000 by default
(``MSGMNI``).

S
Stephen Kitt 已提交
422 423 424

msg_next_id, sem_next_id, and shm_next_id (System V IPC)
========================================================
425 426 427 428 429

These three toggles allows to specify desired id for next allocated IPC
object: message, semaphore or shared memory respectively.

By default they are equal to -1, which means generic allocation logic.
S
Stephen Kitt 已提交
430
Possible values to set are in range {0:``INT_MAX``}.
431 432

Notes:
433 434 435 436 437
  1) kernel doesn't guarantee, that new object will have desired id. So,
     it's up to userspace, how to handle an object with "wrong" id.
  2) Toggle with non-default value will be set back to -1 by kernel after
     successful IPC object allocation. If an IPC object allocation syscall
     fails, it is undefined if the value remains unmodified or is reset to -1.
438 439


S
Stephen Kitt 已提交
440 441
nmi_watchdog
============
442

443 444
This parameter can be used to control the NMI watchdog
(i.e. the hard lockup detector) on x86 systems.
445

S
Stephen Kitt 已提交
446 447 448 449
= =================================
0 Disable the hard lockup detector.
1 Enable the hard lockup detector.
= =================================
450 451 452 453 454 455 456

The hard lockup detector monitors each CPU for its ability to respond to
timer interrupts. The mechanism utilizes CPU performance counter registers
that are programmed to generate Non-Maskable Interrupts (NMIs) periodically
while a CPU is busy. Hence, the alternative name 'NMI watchdog'.

The NMI watchdog is disabled by default if the kernel is running as a guest
457
in a KVM virtual machine. This default can be overridden by adding::
458 459 460

   nmi_watchdog=1

S
Stephen Kitt 已提交
461
to the guest kernel command line (see :doc:`/admin-guide/kernel-parameters`).
462 463


S
Stephen Kitt 已提交
464 465
numa_balancing
==============
466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482

Enables/disables automatic page fault based NUMA memory
balancing. Memory is moved automatically to nodes
that access it often.

Enables/disables automatic NUMA memory balancing. On NUMA machines, there
is a performance penalty if remote memory is accessed by a CPU. When this
feature is enabled the kernel samples what task thread is accessing memory
by periodically unmapping pages and later trapping a page fault. At the
time of the page fault, it is determined if the data being accessed should
be migrated to a local memory node.

The unmapping of pages and trapping faults incur additional overhead that
ideally is offset by improved memory locality but there is no universal
guarantee. If the target workload is already bound to NUMA nodes then this
feature should be disabled. Otherwise, if the system overhead from the
feature is too high then the rate the kernel samples for NUMA hinting
S
Stephen Kitt 已提交
483
faults may be controlled by the `numa_balancing_scan_period_min_ms,
484
numa_balancing_scan_delay_ms, numa_balancing_scan_period_max_ms,
S
Stephen Kitt 已提交
485 486
numa_balancing_scan_size_mb`_, and numa_balancing_settle_count sysctls.

487

488 489
numa_balancing_scan_period_min_ms, numa_balancing_scan_delay_ms, numa_balancing_scan_period_max_ms, numa_balancing_scan_size_mb
===============================================================================================================================
490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511


Automatic NUMA balancing scans tasks address space and unmaps pages to
detect if pages are properly placed or if the data should be migrated to a
memory node local to where the task is running.  Every "scan delay" the task
scans the next "scan size" number of pages in its address space. When the
end of the address space is reached the scanner restarts from the beginning.

In combination, the "scan delay" and "scan size" determine the scan rate.
When "scan delay" decreases, the scan rate increases.  The scan delay and
hence the scan rate of every task is adaptive and depends on historical
behaviour. If pages are properly placed then the scan delay increases,
otherwise the scan delay decreases.  The "scan size" is not adaptive but
the higher the "scan size", the higher the scan rate.

Higher scan rates incur higher system overhead as page faults must be
trapped and potentially data must be migrated. However, the higher the scan
rate, the more quickly a tasks memory is migrated to a local node if the
workload pattern changes and minimises performance impact due to remote
memory accesses. These sysctls control the thresholds for scan delays and
the number of pages scanned.

S
Stephen Kitt 已提交
512
``numa_balancing_scan_period_min_ms`` is the minimum time in milliseconds to
513 514
scan a tasks virtual memory. It effectively controls the maximum scanning
rate for each task.
515

S
Stephen Kitt 已提交
516
``numa_balancing_scan_delay_ms`` is the starting "scan delay" used for a task
517 518
when it initially forks.

S
Stephen Kitt 已提交
519
``numa_balancing_scan_period_max_ms`` is the maximum time in milliseconds to
520 521
scan a tasks virtual memory. It effectively controls the minimum scanning
rate for each task.
522

S
Stephen Kitt 已提交
523
``numa_balancing_scan_size_mb`` is how many megabytes worth of pages are
524 525 526
scanned for a given scan.


S
Stephen Kitt 已提交
527 528
osrelease, ostype & version
===========================
529 530

::
L
Linus Torvalds 已提交
531

532 533 534 535 536 537
  # cat osrelease
  2.1.88
  # cat ostype
  Linux
  # cat version
  #5 Wed Feb 25 21:49:24 MET 1998
L
Linus Torvalds 已提交
538

S
Stephen Kitt 已提交
539 540
The files ``osrelease`` and ``ostype`` should be clear enough.
``version``
L
Linus Torvalds 已提交
541 542 543 544 545 546
needs a little more clarification however. The '#5' means that
this is the fifth kernel built from this source base and the
date behind it indicates the time the kernel was built.
The only way to tune these values is to rebuild the kernel :-)


S
Stephen Kitt 已提交
547 548
overflowgid & overflowuid
=========================
L
Linus Torvalds 已提交
549

550 551 552 553
if your architecture did not always support 32-bit UIDs (i.e. arm,
i386, m68k, sh, and sparc32), a fixed UID and GID will be returned to
applications that use the old 16-bit UID/GID system calls, if the
actual UID or GID would exceed 65535.
L
Linus Torvalds 已提交
554 555 556 557 558

These sysctls allow you to change the value of the fixed UID and GID.
The default is 65534.


S
Stephen Kitt 已提交
559 560
panic
=====
L
Linus Torvalds 已提交
561

562 563 564 565 566 567 568 569 570
The value in this file determines the behaviour of the kernel on a
panic:

* if zero, the kernel will loop forever;
* if negative, the kernel will reboot immediately;
* if positive, the kernel will reboot after the corresponding number
  of seconds.

When you use the software watchdog, the recommended setting is 60.
571

572

S
Stephen Kitt 已提交
573 574
panic_on_io_nmi
===============
575 576 577 578

Controls the kernel's behavior when a CPU receives an NMI caused by
an IO error.

S
Stephen Kitt 已提交
579 580 581 582 583 584 585 586
= ==================================================================
0 Try to continue operation (default).
1 Panic immediately. The IO error triggered an NMI. This indicates a
  serious system condition which could result in IO data corruption.
  Rather than continuing, panicking might be a better choice. Some
  servers issue this sort of NMI when the dump button is pushed,
  and you can use this option to take a crash dump.
= ==================================================================
587

588

S
Stephen Kitt 已提交
589 590
panic_on_oops
=============
L
Linus Torvalds 已提交
591 592 593

Controls the kernel's behaviour when an oops or BUG is encountered.

S
Stephen Kitt 已提交
594 595 596 597 598
= ===================================================================
0 Try to continue operation.
1 Panic immediately.  If the `panic` sysctl is also non-zero then the
  machine will be rebooted.
= ===================================================================
L
Linus Torvalds 已提交
599 600


S
Stephen Kitt 已提交
601 602
panic_on_stackoverflow
======================
603 604 605

Controls the kernel's behavior when detecting the overflows of
kernel, IRQ and exception stacks except a user stack.
S
Stephen Kitt 已提交
606
This file shows up if ``CONFIG_DEBUG_STACKOVERFLOW`` is enabled.
607

S
Stephen Kitt 已提交
608 609 610 611
= ==========================
0 Try to continue operation.
1 Panic immediately.
= ==========================
612 613


S
Stephen Kitt 已提交
614 615
panic_on_unrecovered_nmi
========================
P
Prarit Bhargava 已提交
616 617 618 619 620 621

The default Linux behaviour on an NMI of either memory or unknown is
to continue operation. For many environments such as scientific
computing it is preferable that the box is taken out and the error
dealt with than an uncorrected parity/ECC error get propagated.

S
Stephen Kitt 已提交
622
A small number of systems do generate NMIs for bizarre random reasons
P
Prarit Bhargava 已提交
623 624 625 626
such as power management so the default is off. That sysctl works like
the existing panic controls already in that directory.


S
Stephen Kitt 已提交
627 628
panic_on_warn
=============
P
Prarit Bhargava 已提交
629 630 631 632

Calls panic() in the WARN() path when set to 1.  This is useful to avoid
a kernel rebuild when attempting to kdump at the location of a WARN().

S
Stephen Kitt 已提交
633 634 635 636
= ================================================
0 Only WARN(), default behaviour.
1 Call panic() after printing out WARN() location.
= ================================================
P
Prarit Bhargava 已提交
637 638


S
Stephen Kitt 已提交
639 640
panic_print
===========
641 642 643 644

Bitmask for printing system info when panic happens. User can chose
combination of the following bits:

S
Stephen Kitt 已提交
645
=====  ============================================
646 647 648
bit 0  print all tasks info
bit 1  print system memory info
bit 2  print timer info
S
Stephen Kitt 已提交
649
bit 3  print locks info if ``CONFIG_LOCKDEP`` is on
650
bit 4  print ftrace buffer
S
Stephen Kitt 已提交
651
=====  ============================================
652 653

So for example to print tasks and memory info on panic, user can::
654 655 656 657

  echo 3 > /proc/sys/kernel/panic_print


S
Stephen Kitt 已提交
658 659
panic_on_rcu_stall
==================
660 661 662 663

When set to 1, calls panic() after RCU stall detection messages. This
is useful to define the root cause of RCU stalls using a vmcore.

S
Stephen Kitt 已提交
664 665 666 667
= ============================================================
0 Do not panic() when RCU stall takes place, default behavior.
1 panic() after printing RCU stall messages.
= ============================================================
668 669


S
Stephen Kitt 已提交
670 671
perf_cpu_time_max_percent
=========================
672 673 674 675 676 677 678 679 680 681 682 683

Hints to the kernel how much CPU time it should be allowed to
use to handle perf sampling events.  If the perf subsystem
is informed that its samples are exceeding this limit, it
will drop its sampling frequency to attempt to reduce its CPU
usage.

Some perf sampling happens in NMIs.  If these samples
unexpectedly take too long to execute, the NMIs can become
stacked up next to each other so much that nothing else is
allowed to execute.

S
Stephen Kitt 已提交
684 685 686
===== ========================================================
0     Disable the mechanism.  Do not monitor or correct perf's
      sampling rate no matter how CPU time it takes.
687

S
Stephen Kitt 已提交
688 689 690 691 692 693 694 695
1-100 Attempt to throttle perf's sample rate to this
      percentage of CPU.  Note: the kernel calculates an
      "expected" length of each sample event.  100 here means
      100% of that expected length.  Even if this is set to
      100, you may still see sample throttling if this
      length is exceeded.  Set to 0 if you truly do not care
      how much CPU is consumed.
===== ========================================================
696 697


S
Stephen Kitt 已提交
698 699
perf_event_paranoid
===================
700 701

Controls use of the performance events system by unprivileged
702
users (without CAP_SYS_ADMIN).  The default value is 2.
703

704
===  ==================================================================
S
Stephen Kitt 已提交
705
 -1  Allow use of (almost) all events by all users.
706

S
Stephen Kitt 已提交
707 708
     Ignore mlock limit after perf_event_mlock_kb without
     ``CAP_IPC_LOCK``.
709

S
Stephen Kitt 已提交
710 711
>=0  Disallow ftrace function tracepoint by users without
     ``CAP_SYS_ADMIN``.
712

S
Stephen Kitt 已提交
713
     Disallow raw tracepoint access by users without ``CAP_SYS_ADMIN``.
714

S
Stephen Kitt 已提交
715
>=1  Disallow CPU event access by users without ``CAP_SYS_ADMIN``.
716

S
Stephen Kitt 已提交
717
>=2  Disallow kernel profiling by users without ``CAP_SYS_ADMIN``.
718 719
===  ==================================================================

720

S
Stephen Kitt 已提交
721 722
perf_event_max_stack
====================
723

S
Stephen Kitt 已提交
724 725 726
Controls maximum number of stack frames to copy for (``attr.sample_type &
PERF_SAMPLE_CALLCHAIN``) configured events, for instance, when using
'``perf record -g``' or '``perf trace --call-graph fp``'.
727 728

This can only be done when no events are in use that have callchains
S
Stephen Kitt 已提交
729
enabled, otherwise writing to this file will return ``-EBUSY``.
730 731 732 733

The default value is 127.


S
Stephen Kitt 已提交
734 735
perf_event_mlock_kb
===================
736 737 738 739 740 741

Control size of per-cpu ring buffer not counted agains mlock limit.

The default value is 512 + 1 page


S
Stephen Kitt 已提交
742 743
perf_event_max_contexts_per_stack
=================================
744 745

Controls maximum number of stack frame context entries for
S
Stephen Kitt 已提交
746 747
(``attr.sample_type & PERF_SAMPLE_CALLCHAIN``) configured events, for
instance, when using '``perf record -g``' or '``perf trace --call-graph fp``'.
748 749

This can only be done when no events are in use that have callchains
S
Stephen Kitt 已提交
750
enabled, otherwise writing to this file will return ``-EBUSY``.
751 752 753 754

The default value is 8.


S
Stephen Kitt 已提交
755 756
pid_max
=======
L
Linus Torvalds 已提交
757

758
PID allocation wrap value.  When the kernel's next PID value
L
Linus Torvalds 已提交
759
reaches this value, it wraps back to a minimum PID value.
S
Stephen Kitt 已提交
760
PIDs of value ``pid_max`` or larger are not allocated.
L
Linus Torvalds 已提交
761 762


S
Stephen Kitt 已提交
763 764
ns_last_pid
===========
765 766 767 768 769 770

The last pid allocated in the current (the one task using this sysctl
lives in) pid namespace. When selecting a pid for a next task on fork
kernel tries to allocate a number starting from this one.


S
Stephen Kitt 已提交
771 772
powersave-nap (PPC only)
========================
L
Linus Torvalds 已提交
773 774 775 776

If set, Linux-PPC will use the 'nap' mode of powersaving,
otherwise the 'doze' mode will be used.

S
Stephen Kitt 已提交
777

L
Linus Torvalds 已提交
778 779
==============================================================

S
Stephen Kitt 已提交
780 781
printk
======
L
Linus Torvalds 已提交
782

S
Stephen Kitt 已提交
783 784 785
The four values in printk denote: ``console_loglevel``,
``default_message_loglevel``, ``minimum_console_loglevel`` and
``default_console_loglevel`` respectively.
L
Linus Torvalds 已提交
786 787

These values influence printk() behavior when printing or
S
Stephen Kitt 已提交
788
logging error messages. See '``man 2 syslog``' for more info on
L
Linus Torvalds 已提交
789 790
the different loglevels.

S
Stephen Kitt 已提交
791 792 793 794 795 796 797 798 799
======================== =====================================
console_loglevel         messages with a higher priority than
                         this will be printed to the console
default_message_loglevel messages without an explicit priority
                         will be printed with this priority
minimum_console_loglevel minimum (highest) value to which
                         console_loglevel can be set
default_console_loglevel default value for console_loglevel
======================== =====================================
L
Linus Torvalds 已提交
800 801


S
Stephen Kitt 已提交
802 803
printk_delay
============
804

S
Stephen Kitt 已提交
805
Delay each printk message in ``printk_delay`` milliseconds
806 807 808 809

Value from 0 - 10000 is allowed.


S
Stephen Kitt 已提交
810 811
printk_ratelimit
================
L
Linus Torvalds 已提交
812

S
Stephen Kitt 已提交
813
Some warning messages are rate limited. ``printk_ratelimit`` specifies
814 815
the minimum length of time between these messages (in seconds).
The default value is 5 seconds.
L
Linus Torvalds 已提交
816 817 818 819

A value of 0 will disable rate limiting.


S
Stephen Kitt 已提交
820 821
printk_ratelimit_burst
======================
L
Linus Torvalds 已提交
822

S
Stephen Kitt 已提交
823
While long term we enforce one message per `printk_ratelimit`_
L
Linus Torvalds 已提交
824
seconds, we do allow a burst of messages to pass through.
S
Stephen Kitt 已提交
825
``printk_ratelimit_burst`` specifies the number of messages we can
L
Linus Torvalds 已提交
826 827
send before ratelimiting kicks in.

828 829
The default value is 10 messages.

L
Linus Torvalds 已提交
830

S
Stephen Kitt 已提交
831 832
printk_devkmsg
==============
833

S
Stephen Kitt 已提交
834
Control the logging to ``/dev/kmsg`` from userspace:
835

S
Stephen Kitt 已提交
836 837 838 839 840
========= =============================================
ratelimit default, ratelimited
on        unlimited logging to /dev/kmsg from userspace
off       logging to /dev/kmsg disabled
========= =============================================
841

S
Stephen Kitt 已提交
842
The kernel command line parameter ``printk.devkmsg=`` overrides this and is
843 844 845
a one-time setting until next reboot: once set, it cannot be changed by
this sysctl interface anymore.

S
Stephen Kitt 已提交
846
==============================================================
847

S
Stephen Kitt 已提交
848 849 850 851 852 853 854 855 856

pty
===

See Documentation/filesystems/devpts.txt.


randomize_va_space
==================
857 858 859 860 861

This option can be used to select the type of process address
space randomization that is used in the system, for architectures
that support this feature.

862 863
==  ===========================================================================
0   Turn the process address space randomization off.  This is the
864 865
    default for architectures that do not support this feature anyways,
    and kernels that are booted with the "norandmaps" parameter.
866

867
1   Make the addresses of mmap base, stack and VDSO page randomized.
868
    This, among other things, implies that shared libraries will be
869 870
    loaded to random addresses.  Also for PIE-linked binaries, the
    location of code start is randomized.  This is the default if the
S
Stephen Kitt 已提交
871
    ``CONFIG_COMPAT_BRK`` option is enabled.
872

873
2   Additionally enable heap randomization.  This is the default if
S
Stephen Kitt 已提交
874
    ``CONFIG_COMPAT_BRK`` is disabled.
875 876

    There are a few legacy applications out there (such as some ancient
877
    versions of libc.so.5 from 1996) that assume that brk area starts
878 879
    just after the end of the code+bss.  These applications break when
    start of the brk area is randomized.  There are however no known
880
    non-legacy applications that would be broken this way, so for most
881 882 883
    systems it is safe to choose full randomization.

    Systems with ancient and/or broken binaries should be configured
S
Stephen Kitt 已提交
884
    with ``CONFIG_COMPAT_BRK`` enabled, which excludes the heap from process
885
    address space randomization.
886
==  ===========================================================================
887 888


S
Stephen Kitt 已提交
889 890 891 892 893 894 895 896
real-root-dev
=============

See :doc:`/admin-guide/initrd`.


reboot-cmd (SPARC only)
=======================
L
Linus Torvalds 已提交
897 898 899 900 901 902

??? This seems to be a way to give an argument to the Sparc
ROM/Flash boot loader. Maybe to tell it what to do after
rebooting. ???


S
Stephen Kitt 已提交
903 904
sched_energy_aware
==================
905 906 907 908 909 910 911 912 913

Enables/disables Energy Aware Scheduling (EAS). EAS starts
automatically on platforms where it can run (that is,
platforms with asymmetric CPU topologies and having an Energy
Model available). If your platform happens to meet the
requirements for EAS but you do not want to use it, change
this value to 0.


S
Stephen Kitt 已提交
914 915
sched_schedstats
================
916 917 918 919 920 921

Enables/disables scheduler statistics. Enabling this feature
incurs a small amount of overhead in the scheduler but is
useful for debugging and performance tuning.


S
Stephen Kitt 已提交
922 923 924 925 926 927 928 929
seccomp
=======

See :doc:`/userspace-api/seccomp_filter`.


sg-big-buff
===========
L
Linus Torvalds 已提交
930 931 932

This file shows the size of the generic SCSI (sg) buffer.
You can't tune it just yet, but you could change it on
S
Stephen Kitt 已提交
933 934
compile time by editing ``include/scsi/sg.h`` and changing
the value of ``SG_BIG_BUFF``.
L
Linus Torvalds 已提交
935 936 937 938 939 940

There shouldn't be any reason to change this value. If
you can come up with one, you probably know what you
are doing anyway :)


S
Stephen Kitt 已提交
941 942
shmall
======
943 944

This parameter sets the total amount of shared memory pages that
S
Stephen Kitt 已提交
945 946
can be used system wide. Hence, ``shmall`` should always be at least
``ceil(shmmax/PAGE_SIZE)``.
947

S
Stephen Kitt 已提交
948 949
If you are not sure what the default ``PAGE_SIZE`` is on your Linux
system, you can run the following command::
950

951
	# getconf PAGE_SIZE
952 953


S
Stephen Kitt 已提交
954 955
shmmax
======
L
Linus Torvalds 已提交
956 957 958

This value can be used to query and set the run time limit
on the maximum shared memory segment size that can be created.
959
Shared memory segments up to 1Gb are now supported in the
S
Stephen Kitt 已提交
960
kernel.  This value defaults to ``SHMMAX``.
L
Linus Torvalds 已提交
961 962


S
Stephen Kitt 已提交
963 964 965
shmmni
======

966 967 968
This value determines the maximum number of shared memory segments.
4096 by default (``SHMMNI``).

S
Stephen Kitt 已提交
969 970 971

shm_rmid_forced
===============
972 973

Linux lets you set resource limits, including how much memory one
S
Stephen Kitt 已提交
974
process can consume, via ``setrlimit(2)``.  Unfortunately, shared memory
975 976 977 978 979
segments are allowed to exist without association with any process, and
thus might not be counted against any resource limits.  If enabled,
shared memory segments are automatically destroyed when their attach
count becomes zero after a detach or a process termination.  It will
also destroy segments that were created, but never attached to, on exit
S
Stephen Kitt 已提交
980
from the process.  The only use left for ``IPC_RMID`` is to immediately
981 982 983
destroy an unattached segment.  Of course, this breaks the way things are
defined, so some applications might stop working.  Note that this
feature will do you no good unless you also configure your resource
S
Stephen Kitt 已提交
984
limits (in particular, ``RLIMIT_AS`` and ``RLIMIT_NPROC``).  Most systems don't
985 986 987 988 989 990
need this.

Note that if you change this from 0 to 1, already created segments
without users and with a dead originative process will be destroyed.


S
Stephen Kitt 已提交
991 992
sysctl_writes_strict
====================
993 994

Control how file position affects the behavior of updating sysctl values
S
Stephen Kitt 已提交
995
via the ``/proc/sys`` interface:
996

997 998
  ==   ======================================================================
  -1   Legacy per-write sysctl value handling, with no printk warnings.
999 1000 1001
       Each write syscall must fully contain the sysctl value to be
       written, and multiple writes on the same sysctl file descriptor
       will rewrite the sysctl value, regardless of file position.
1002
   0   Same behavior as above, but warn about processes that perform writes
K
Kees Cook 已提交
1003
       to a sysctl file descriptor when the file position is not 0.
1004
   1   (default) Respect file position when writing sysctl strings. Multiple
K
Kees Cook 已提交
1005 1006 1007 1008
       writes will append to the sysctl value buffer. Anything past the max
       length of the sysctl value buffer will be ignored. Writes to numeric
       sysctl entries must always be at file position 0 and the value must
       be fully contained in the buffer sent in the write syscall.
1009
  ==   ======================================================================
1010 1011


S
Stephen Kitt 已提交
1012 1013
softlockup_all_cpu_backtrace
============================
1014 1015 1016 1017 1018 1019 1020 1021 1022

This value controls the soft lockup detector thread's behavior
when a soft lockup condition is detected as to whether or not
to gather further debug information. If enabled, each cpu will
be issued an NMI and instructed to capture stack trace.

This feature is only applicable for architectures which support
NMI.

S
Stephen Kitt 已提交
1023 1024 1025 1026
= ============================================
0 Do nothing. This is the default behavior.
1 On detection capture more debug information.
= ============================================
1027 1028


S
Stephen Kitt 已提交
1029 1030
soft_watchdog
=============
1031 1032 1033

This parameter can be used to control the soft lockup detector.

S
Stephen Kitt 已提交
1034 1035 1036 1037
= =================================
0 Disable the soft lockup detector.
1 Enable the soft lockup detector.
= =================================
1038 1039 1040 1041 1042

The soft lockup detector monitors CPUs for threads that are hogging the CPUs
without rescheduling voluntarily, and thus prevent the 'watchdog/N' threads
from running. The mechanism depends on the CPUs ability to respond to timer
interrupts which are needed for the 'watchdog/N' threads to be woken up by
S
Stephen Kitt 已提交
1043
the watchdog timer function, otherwise the NMI watchdog — if enabled — can
1044 1045 1046
detect a hard lockup condition.


S
Stephen Kitt 已提交
1047 1048
stack_erasing
=============
1049 1050

This parameter can be used to control kernel stack erasing at the end
S
Stephen Kitt 已提交
1051
of syscalls for kernels built with ``CONFIG_GCC_PLUGIN_STACKLEAK``.
1052 1053 1054 1055 1056 1057

That erasing reduces the information which kernel stack leak bugs
can reveal and blocks some uninitialized stack variable attacks.
The tradeoff is the performance impact: on a single CPU system kernel
compilation sees a 1% slowdown, other systems and workloads may vary.

S
Stephen Kitt 已提交
1058 1059 1060 1061 1062 1063 1064 1065 1066
= ====================================================================
0 Kernel stack erasing is disabled, STACKLEAK_METRICS are not updated.
1 Kernel stack erasing is enabled (default), it is performed before
  returning to the userspace at the end of syscalls.
= ====================================================================


stop-a (SPARC only)
===================
1067

1068 1069 1070 1071 1072 1073 1074 1075 1076 1077
Controls Stop-A:

= ====================================
0 Stop-A has no effect.
1 Stop-A breaks to the PROM (default).
= ====================================

Stop-A is always enabled on a panic, so that the user can return to
the boot PROM.

S
Stephen Kitt 已提交
1078 1079 1080 1081 1082

sysrq
=====

See :doc:`/admin-guide/sysrq`.
1083

1084

1085
tainted
1086
=======
L
Linus Torvalds 已提交
1087

K
Kees Cook 已提交
1088 1089 1090
Non-zero if the kernel has been tainted. Numeric values, which can be
ORed together. The letters are seen in "Tainted" line of Oops reports.

1091 1092 1093 1094 1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110
======  =====  ==============================================================
     1  `(P)`  proprietary module was loaded
     2  `(F)`  module was force loaded
     4  `(S)`  SMP kernel oops on an officially SMP incapable processor
     8  `(R)`  module was force unloaded
    16  `(M)`  processor reported a Machine Check Exception (MCE)
    32  `(B)`  bad page referenced or some unexpected page flags
    64  `(U)`  taint requested by userspace application
   128  `(D)`  kernel died recently, i.e. there was an OOPS or BUG
   256  `(A)`  an ACPI table was overridden by user
   512  `(W)`  kernel issued warning
  1024  `(C)`  staging driver was loaded
  2048  `(I)`  workaround for bug in platform firmware applied
  4096  `(O)`  externally-built ("out-of-tree") module was loaded
  8192  `(E)`  unsigned module was loaded
 16384  `(L)`  soft lockup occurred
 32768  `(K)`  kernel has been live patched
 65536  `(X)`  Auxiliary taint, defined and used by for distros
131072  `(T)`  The kernel was built with the struct randomization plugin
======  =====  ==============================================================
1111

S
Stephen Kitt 已提交
1112
See :doc:`/admin-guide/tainted-kernels` for more information.
L
Linus Torvalds 已提交
1113

1114

S
Stephen Kitt 已提交
1115 1116
threads-max
===========
1117 1118

This value controls the maximum number of threads that can be created
S
Stephen Kitt 已提交
1119
using ``fork()``.
1120 1121 1122 1123 1124

During initialization the kernel sets this value such that even if the
maximum number of threads is created, the thread structures occupy only
a part (1/8th) of the available RAM pages.

S
Stephen Kitt 已提交
1125
The minimum value that can be written to ``threads-max`` is 1.
1126

S
Stephen Kitt 已提交
1127 1128
The maximum value that can be written to ``threads-max`` is given by the
constant ``FUTEX_TID_MASK`` (0x3fffffff).
1129

S
Stephen Kitt 已提交
1130 1131
If a value outside of this range is written to ``threads-max`` an
``EINVAL`` error occurs.
1132 1133


S
Stephen Kitt 已提交
1134 1135
unknown_nmi_panic
=================
1136

1137 1138 1139
The value in this file affects behavior of handling NMI. When the
value is non-zero, unknown NMI is trapped and then panic occurs. At
that time, kernel debugging information is displayed on console.
1140

1141 1142
NMI switch that most IA32 servers have fires unknown NMI up, for
example.  If a system hangs up, try pressing the NMI switch.
1143 1144


S
Stephen Kitt 已提交
1145 1146
watchdog
========
1147 1148

This parameter can be used to disable or enable the soft lockup detector
S
Stephen Kitt 已提交
1149
*and* the NMI watchdog (i.e. the hard lockup detector) at the same time.
1150

S
Stephen Kitt 已提交
1151 1152 1153 1154
= ==============================
0 Disable both lockup detectors.
1 Enable both lockup detectors.
= ==============================
1155 1156

The soft lockup detector and the NMI watchdog can also be disabled or
S
Stephen Kitt 已提交
1157 1158 1159
enabled individually, using the ``soft_watchdog`` and ``nmi_watchdog``
parameters.
If the ``watchdog`` parameter is read, for example by executing::
1160 1161 1162

   cat /proc/sys/kernel/watchdog

S
Stephen Kitt 已提交
1163 1164
the output of this command (0 or 1) shows the logical OR of
``soft_watchdog`` and ``nmi_watchdog``.
1165 1166


S
Stephen Kitt 已提交
1167 1168
watchdog_cpumask
================
1169 1170

This value can be used to control on which cpus the watchdog may run.
S
Stephen Kitt 已提交
1171
The default cpumask is all possible cores, but if ``NO_HZ_FULL`` is
1172
enabled in the kernel config, and cores are specified with the
S
Stephen Kitt 已提交
1173
``nohz_full=`` boot argument, those cores are excluded by default.
1174 1175 1176
Offline cores can be included in this mask, and if the core is later
brought online, the watchdog will be started based on the mask value.

S
Stephen Kitt 已提交
1177
Typically this value would only be touched in the ``nohz_full`` case
1178 1179 1180 1181 1182
to re-enable cores that by default were not running the watchdog,
if a kernel lockup was suspected on those cores.

The argument value is the standard cpulist format for cpumasks,
so for example to enable the watchdog on cores 0, 2, 3, and 4 you
1183
might say::
1184 1185 1186 1187

  echo 0,2-4 > /proc/sys/kernel/watchdog_cpumask


S
Stephen Kitt 已提交
1188 1189
watchdog_thresh
===============
1190 1191 1192 1193 1194

This value can be used to control the frequency of hrtimer and NMI
events and the soft and hard lockup thresholds. The default threshold
is 10 seconds.

S
Stephen Kitt 已提交
1195
The softlockup threshold is (``2 * watchdog_thresh``). Setting this
1196
tunable to zero will disable lockup detection altogether.