kernel.rst 39.1 KB
Newer Older
1 2 3
===================================
Documentation for /proc/sys/kernel/
===================================
L
Linus Torvalds 已提交
4

5 6 7 8
Copyright (c) 1998, 1999,  Rik van Riel <riel@nl.linux.org>

Copyright (c) 2009,        Shen Feng<shen@cn.fujitsu.com>

S
Stephen Kitt 已提交
9
For general info and legal blurb, please look in :doc:`index`.
10 11

------------------------------------------------------------------------------
L
Linus Torvalds 已提交
12 13

This file contains documentation for the sysctl files in
S
Stephen Kitt 已提交
14
``/proc/sys/kernel/`` and is valid for Linux kernel version 2.2.
L
Linus Torvalds 已提交
15 16 17

The files in this directory can be used to tune and monitor
miscellaneous and general things in the operation of the Linux
S
Stephen Kitt 已提交
18
kernel. Since some of the files *can* be used to screw up your
L
Linus Torvalds 已提交
19 20 21 22
system, it is advisable to read both documentation and source
before actually making adjustments.

Currently, these files might (depending on your configuration)
S
Stephen Kitt 已提交
23 24 25 26 27 28 29 30 31
show up in ``/proc/sys/kernel``:

.. contents:: :local:


acct
====

::
L
Linus Torvalds 已提交
32

S
Stephen Kitt 已提交
33
    highwater lowwater frequency
L
Linus Torvalds 已提交
34 35 36

If BSD-style process accounting is enabled these values control
its behaviour. If free space on filesystem where the log lives
S
Stephen Kitt 已提交
37 38
goes below ``lowwater``% accounting suspends. If free space gets
above ``highwater``% accounting resumes. ``frequency`` determines
L
Linus Torvalds 已提交
39 40 41
how often do we check the amount of free space (value is in
seconds). Default:

S
Stephen Kitt 已提交
42
::
43

S
Stephen Kitt 已提交
44
    4 2 30
45

S
Stephen Kitt 已提交
46 47 48
That is, suspend accounting if free space drops below 2%; resume it
if it increases to at least 4%; consider information about amount of
free space valid for 30 seconds.
49 50


S
Stephen Kitt 已提交
51 52 53 54 55
acpi_video_flags
================

See Documentation/kernel/power/video.txt, it allows mode of video boot
to be set during run time.
56

S
Stephen Kitt 已提交
57 58 59

auto_msgmni
===========
60

61 62
This variable has no effect and may be removed in future kernel
releases. Reading it always returns 0.
S
Stephen Kitt 已提交
63 64 65
Up to Linux 3.17, it enabled/disabled automatic recomputing of
`msgmni`_
upon memory add/remove or upon IPC namespace creation/removal.
66
Echoing "1" into this file enabled msgmni automatic recomputing.
S
Stephen Kitt 已提交
67
Echoing "0" turned it off. The default value was 1.
68

69

S
Stephen Kitt 已提交
70 71
bootloader_type (x86 only)
==========================
72 73 74 75

This gives the bootloader type number as indicated by the bootloader,
shifted left by 4, and OR'd with the low four bits of the bootloader
version.  The reason for this encoding is that this used to match the
S
Stephen Kitt 已提交
76
``type_of_loader`` field in the kernel header; the encoding is kept for
77 78 79 80
backwards compatibility.  That is, if the full bootloader type number
is 0x15 and the full version number is 0x234, this file will contain
the value 340 = 0x154.

S
Stephen Kitt 已提交
81 82
See the ``type_of_loader`` and ``ext_loader_type`` fields in
:doc:`/x86/boot` for additional information.
83 84


S
Stephen Kitt 已提交
85 86
bootloader_version (x86 only)
=============================
87 88 89 90

The complete bootloader version number.  In the example above, this
file will contain the value 564 = 0x234.

S
Stephen Kitt 已提交
91 92
See the ``type_of_loader`` and ``ext_loader_ver`` fields in
:doc:`/x86/boot` for additional information.
93 94


S
Stephen Kitt 已提交
95 96
cap_last_cap
============
97 98

Highest valid capability of the running kernel.  Exports
S
Stephen Kitt 已提交
99
``CAP_LAST_CAP`` from the kernel.
100 101


S
Stephen Kitt 已提交
102 103
core_pattern
============
L
Linus Torvalds 已提交
104

S
Stephen Kitt 已提交
105
``core_pattern`` is used to specify a core dumpfile pattern name.
106 107

* max length 127 characters; default value is "core"
S
Stephen Kitt 已提交
108 109 110 111
* ``core_pattern`` is used as a pattern template for the output
  filename; certain string patterns (beginning with '%') are
  substituted with their actual values.
* backward compatibility with ``core_uses_pid``:
112

S
Stephen Kitt 已提交
113 114
	If ``core_pattern`` does not include "%p" (default does not)
	and ``core_uses_pid`` is set, then .PID will be appended to
L
Linus Torvalds 已提交
115
	the filename.
116

S
Stephen Kitt 已提交
117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137
* corename format specifiers

	========	==========================================
	%<NUL>		'%' is dropped
	%%		output one '%'
	%p		pid
	%P		global pid (init PID namespace)
	%i		tid
	%I		global tid (init PID namespace)
	%u		uid (in initial user namespace)
	%g		gid (in initial user namespace)
	%d		dump mode, matches ``PR_SET_DUMPABLE`` and
			``/proc/sys/fs/suid_dumpable``
	%s		signal number
	%t		UNIX time of dump
	%h		hostname
	%e		executable filename (may be shortened)
	%E		executable path
	%c		maximum size of core file by resource limit RLIMIT_CORE
	%<OTHER>	both are dropped
	========	==========================================
138 139

* If the first character of the pattern is a '|', the kernel will treat
140 141
  the rest of the pattern as a command to run.  The core dump will be
  written to the standard input of that program instead of to a file.
L
Linus Torvalds 已提交
142 143


S
Stephen Kitt 已提交
144 145
core_pipe_limit
===============
146

S
Stephen Kitt 已提交
147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172
This sysctl is only applicable when `core_pattern`_ is configured to
pipe core files to a user space helper (when the first character of
``core_pattern`` is a '|', see above).
When collecting cores via a pipe to an application, it is occasionally
useful for the collecting application to gather data about the
crashing process from its ``/proc/pid`` directory.
In order to do this safely, the kernel must wait for the collecting
process to exit, so as not to remove the crashing processes proc files
prematurely.
This in turn creates the possibility that a misbehaving userspace
collecting process can block the reaping of a crashed process simply
by never exiting.
This sysctl defends against that.
It defines how many concurrent crashing processes may be piped to user
space applications in parallel.
If this value is exceeded, then those crashing processes above that
value are noted via the kernel log and their cores are skipped.
0 is a special value, indicating that unlimited processes may be
captured in parallel, but that no waiting will take place (i.e. the
collecting process is not guaranteed access to ``/proc/<crashing
pid>/``).
This value defaults to 0.


core_uses_pid
=============
L
Linus Torvalds 已提交
173 174

The default coredump filename is "core".  By setting
S
Stephen Kitt 已提交
175 176 177
``core_uses_pid`` to 1, the coredump filename becomes core.PID.
If `core_pattern`_ does not include "%p" (default does not)
and ``core_uses_pid`` is set, then .PID will be appended to
L
Linus Torvalds 已提交
178 179 180
the filename.


S
Stephen Kitt 已提交
181 182
ctrl-alt-del
============
L
Linus Torvalds 已提交
183 184

When the value in this file is 0, ctrl-alt-del is trapped and
S
Stephen Kitt 已提交
185
sent to the ``init(1)`` program to handle a graceful restart.
L
Linus Torvalds 已提交
186 187 188 189
When, however, the value is > 0, Linux's reaction to a Vulcan
Nerve Pinch (tm) will be an immediate reboot, without even
syncing its dirty buffers.

190 191 192 193 194
Note:
  when a program (like dosemu) has the keyboard in 'raw'
  mode, the ctrl-alt-del is intercepted by the program before it
  ever reaches the kernel tty layer, and it's up to the program
  to decide what to do with it.
L
Linus Torvalds 已提交
195 196


S
Stephen Kitt 已提交
197 198
dmesg_restrict
==============
199

200
This toggle indicates whether unprivileged users are prevented
S
Stephen Kitt 已提交
201 202 203 204 205
from using ``dmesg(8)`` to view messages from the kernel's log
buffer.
When ``dmesg_restrict`` is set to 0 there are no restrictions.
When ``dmesg_restrict`` is set set to 1, users must have
``CAP_SYSLOG`` to use ``dmesg(8)``.
206

S
Stephen Kitt 已提交
207 208
The kernel config option ``CONFIG_SECURITY_DMESG_RESTRICT`` sets the
default value of ``dmesg_restrict``.
209 210


S
Stephen Kitt 已提交
211 212
domainname & hostname
=====================
L
Linus Torvalds 已提交
213 214 215

These files can be used to set the NIS/YP domainname and the
hostname of your box in exactly the same way as the commands
216 217 218 219 220 221 222 223 224
domainname and hostname, i.e.::

	# echo "darkstar" > /proc/sys/kernel/hostname
	# echo "mydomain" > /proc/sys/kernel/domainname

has the same effect as::

	# hostname "darkstar"
	# domainname "mydomain"
L
Linus Torvalds 已提交
225 226 227 228 229 230

Note, however, that the classic darkstar.frop.org has the
hostname "darkstar" and DNS (Internet Domain Name Server)
domainname "frop.org", not to be confused with the NIS (Network
Information Service) or YP (Yellow Pages) domainname. These two
domain names are in general different. For a detailed discussion
S
Stephen Kitt 已提交
231
see the ``hostname(1)`` man page.
L
Linus Torvalds 已提交
232

233

S
Stephen Kitt 已提交
234 235
hardlockup_all_cpu_backtrace
============================
236 237 238 239 240 241

This value controls the hard lockup detector behavior when a hard
lockup condition is detected as to whether or not to gather further
debug information. If enabled, arch-specific all-CPU stack dumping
will be initiated.

S
Stephen Kitt 已提交
242 243 244 245
= ============================================
0 Do nothing. This is the default behavior.
1 On detection capture more debug information.
= ============================================
246

L
Linus Torvalds 已提交
247

S
Stephen Kitt 已提交
248 249
hardlockup_panic
================
250 251 252 253

This parameter can be used to control whether the kernel panics
when a hard lockup is detected.

S
Stephen Kitt 已提交
254 255 256 257
= ===========================
0 Don't panic on hard lockup.
1 Panic on hard lockup.
= ===========================
258

S
Stephen Kitt 已提交
259 260
See :doc:`/admin-guide/lockup-watchdogs` for more information.
This can also be set using the nmi_watchdog kernel parameter.
261 262


S
Stephen Kitt 已提交
263 264
hotplug
=======
L
Linus Torvalds 已提交
265 266

Path for the hotplug policy agent.
S
Stephen Kitt 已提交
267
Default value is "``/sbin/hotplug``".
L
Linus Torvalds 已提交
268 269


S
Stephen Kitt 已提交
270 271
hung_task_panic
===============
272 273

Controls the kernel's behavior when a hung task is detected.
S
Stephen Kitt 已提交
274
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
275

S
Stephen Kitt 已提交
276 277 278 279
= =================================================
0 Continue operation. This is the default behavior.
1 Panic immediately.
= =================================================
280 281


S
Stephen Kitt 已提交
282 283
hung_task_check_count
=====================
284 285

The upper bound on the number of tasks that are checked.
S
Stephen Kitt 已提交
286
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
287 288


S
Stephen Kitt 已提交
289 290
hung_task_timeout_secs
======================
291

292
When a task in D state did not get scheduled
293
for more than this value report a warning.
S
Stephen Kitt 已提交
294
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
295

S
Stephen Kitt 已提交
296
0 means infinite timeout, no checking is done.
297

S
Stephen Kitt 已提交
298
Possible values to set are in range {0:``LONG_MAX``/``HZ``}.
299 300


S
Stephen Kitt 已提交
301 302
hung_task_check_interval_secs
=============================
303 304

Hung task check interval. If hung task checking is enabled
S
Stephen Kitt 已提交
305 306 307
(see `hung_task_timeout_secs`_), the check is done every
``hung_task_check_interval_secs`` seconds.
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
308

S
Stephen Kitt 已提交
309 310
0 (default) means use ``hung_task_timeout_secs`` as checking
interval.
311

S
Stephen Kitt 已提交
312
Possible values to set are in range {0:``LONG_MAX``/``HZ``}.
313

S
Stephen Kitt 已提交
314 315 316

hung_task_warnings
==================
317 318

The maximum number of warnings to report. During a check interval
319 320
if a hung task is detected, this value is decreased by 1.
When this value reaches 0, no more warnings will be reported.
S
Stephen Kitt 已提交
321
This file shows up if ``CONFIG_DETECT_HUNG_TASK`` is enabled.
322 323 324 325

-1: report an infinite number of warnings.


S
Stephen Kitt 已提交
326 327
hyperv_record_panic_msg
=======================
328 329 330

Controls whether the panic kmsg data should be reported to Hyper-V.

S
Stephen Kitt 已提交
331 332 333 334
= =========================================================
0 Do not report panic kmsg data.
1 Report the panic kmsg data. This is the default behavior.
= =========================================================
335 336


S
Stephen Kitt 已提交
337 338
kexec_load_disabled
===================
339

S
Stephen Kitt 已提交
340 341 342 343 344 345 346 347 348
A toggle indicating if the ``kexec_load`` syscall has been disabled.
This value defaults to 0 (false: ``kexec_load`` enabled), but can be
set to 1 (true: ``kexec_load`` disabled).
Once true, kexec can no longer be used, and the toggle cannot be set
back to false.
This allows a kexec image to be loaded before disabling the syscall,
allowing a system to set up (and later use) an image without it being
altered.
Generally used together with the `modules_disabled`_ sysctl.
349 350


S
Stephen Kitt 已提交
351 352
kptr_restrict
=============
353 354

This toggle indicates whether restrictions are placed on
S
Stephen Kitt 已提交
355 356 357 358 359 360 361 362 363 364 365 366 367 368 369 370 371 372 373 374 375 376 377 378 379 380 381
exposing kernel addresses via ``/proc`` and other interfaces.

When ``kptr_restrict`` is set to 0 (the default) the address is hashed
before printing.
(This is the equivalent to %p.)

When ``kptr_restrict`` is set to 1, kernel pointers printed using the
%pK format specifier will be replaced with 0s unless the user has
``CAP_SYSLOG`` and effective user and group ids are equal to the real
ids.
This is because %pK checks are done at read() time rather than open()
time, so if permissions are elevated between the open() and the read()
(e.g via a setuid binary) then %pK will not leak kernel pointers to
unprivileged users.
Note, this is a temporary solution only.
The correct long-term solution is to do the permission checks at
open() time.
Consider removing world read permissions from files that use %pK, and
using `dmesg_restrict`_ to protect against uses of %pK in ``dmesg(8)``
if leaking kernel pointer values to unprivileged users is a concern.

When ``kptr_restrict`` is set to 2, kernel pointers printed using
%pK will be replaced with 0s regardless of privileges.


modprobe
========
382

383 384 385 386 387 388 389 390 391 392 393 394 395
This gives the full path of the modprobe command which the kernel will
use to load modules. This can be used to debug module loading
requests::

    echo '#! /bin/sh' > /tmp/modprobe
    echo 'echo "$@" >> /tmp/modprobe.log' >> /tmp/modprobe
    echo 'exec /sbin/modprobe "$@"' >> /tmp/modprobe
    chmod a+x /tmp/modprobe
    echo /tmp/modprobe > /proc/sys/kernel/modprobe

This only applies when the *kernel* is requesting that the module be
loaded; it won't have any effect if the module is being loaded
explicitly using ``modprobe`` from userspace.
396 397


S
Stephen Kitt 已提交
398 399
modules_disabled
================
400 401 402 403 404

A toggle value indicating if modules are allowed to be loaded
in an otherwise modular kernel.  This toggle defaults to off
(0), but can be set true (1).  Once true, modules can be
neither loaded nor unloaded, and the toggle cannot be set back
S
Stephen Kitt 已提交
405 406
to false.  Generally used with the `kexec_load_disabled`_ toggle.

407

S
Stephen Kitt 已提交
408
.. _msgmni:
409

S
Stephen Kitt 已提交
410 411 412
msgmax, msgmnb, and msgmni
==========================

413 414 415 416 417 418 419 420 421
``msgmax`` is the maximum size of an IPC message, in bytes. 8192 by
default (``MSGMAX``).

``msgmnb`` is the maximum size of an IPC queue, in bytes. 16384 by
default (``MSGMNB``).

``msgmni`` is the maximum number of IPC queues. 32000 by default
(``MSGMNI``).

S
Stephen Kitt 已提交
422 423 424

msg_next_id, sem_next_id, and shm_next_id (System V IPC)
========================================================
425 426 427 428 429

These three toggles allows to specify desired id for next allocated IPC
object: message, semaphore or shared memory respectively.

By default they are equal to -1, which means generic allocation logic.
S
Stephen Kitt 已提交
430
Possible values to set are in range {0:``INT_MAX``}.
431 432

Notes:
433 434 435 436 437
  1) kernel doesn't guarantee, that new object will have desired id. So,
     it's up to userspace, how to handle an object with "wrong" id.
  2) Toggle with non-default value will be set back to -1 by kernel after
     successful IPC object allocation. If an IPC object allocation syscall
     fails, it is undefined if the value remains unmodified or is reset to -1.
438 439


S
Stephen Kitt 已提交
440 441
nmi_watchdog
============
442

443 444
This parameter can be used to control the NMI watchdog
(i.e. the hard lockup detector) on x86 systems.
445

S
Stephen Kitt 已提交
446 447 448 449
= =================================
0 Disable the hard lockup detector.
1 Enable the hard lockup detector.
= =================================
450 451 452 453 454 455 456

The hard lockup detector monitors each CPU for its ability to respond to
timer interrupts. The mechanism utilizes CPU performance counter registers
that are programmed to generate Non-Maskable Interrupts (NMIs) periodically
while a CPU is busy. Hence, the alternative name 'NMI watchdog'.

The NMI watchdog is disabled by default if the kernel is running as a guest
457
in a KVM virtual machine. This default can be overridden by adding::
458 459 460

   nmi_watchdog=1

S
Stephen Kitt 已提交
461
to the guest kernel command line (see :doc:`/admin-guide/kernel-parameters`).
462 463


S
Stephen Kitt 已提交
464 465
numa_balancing
==============
466 467 468 469 470 471 472 473 474 475 476 477 478 479 480 481 482

Enables/disables automatic page fault based NUMA memory
balancing. Memory is moved automatically to nodes
that access it often.

Enables/disables automatic NUMA memory balancing. On NUMA machines, there
is a performance penalty if remote memory is accessed by a CPU. When this
feature is enabled the kernel samples what task thread is accessing memory
by periodically unmapping pages and later trapping a page fault. At the
time of the page fault, it is determined if the data being accessed should
be migrated to a local memory node.

The unmapping of pages and trapping faults incur additional overhead that
ideally is offset by improved memory locality but there is no universal
guarantee. If the target workload is already bound to NUMA nodes then this
feature should be disabled. Otherwise, if the system overhead from the
feature is too high then the rate the kernel samples for NUMA hinting
S
Stephen Kitt 已提交
483
faults may be controlled by the `numa_balancing_scan_period_min_ms,
484
numa_balancing_scan_delay_ms, numa_balancing_scan_period_max_ms,
S
Stephen Kitt 已提交
485 486
numa_balancing_scan_size_mb`_, and numa_balancing_settle_count sysctls.

487

488 489
numa_balancing_scan_period_min_ms, numa_balancing_scan_delay_ms, numa_balancing_scan_period_max_ms, numa_balancing_scan_size_mb
===============================================================================================================================
490 491 492 493 494 495 496 497 498 499 500 501 502 503 504 505 506 507 508 509 510 511


Automatic NUMA balancing scans tasks address space and unmaps pages to
detect if pages are properly placed or if the data should be migrated to a
memory node local to where the task is running.  Every "scan delay" the task
scans the next "scan size" number of pages in its address space. When the
end of the address space is reached the scanner restarts from the beginning.

In combination, the "scan delay" and "scan size" determine the scan rate.
When "scan delay" decreases, the scan rate increases.  The scan delay and
hence the scan rate of every task is adaptive and depends on historical
behaviour. If pages are properly placed then the scan delay increases,
otherwise the scan delay decreases.  The "scan size" is not adaptive but
the higher the "scan size", the higher the scan rate.

Higher scan rates incur higher system overhead as page faults must be
trapped and potentially data must be migrated. However, the higher the scan
rate, the more quickly a tasks memory is migrated to a local node if the
workload pattern changes and minimises performance impact due to remote
memory accesses. These sysctls control the thresholds for scan delays and
the number of pages scanned.

S
Stephen Kitt 已提交
512
``numa_balancing_scan_period_min_ms`` is the minimum time in milliseconds to
513 514
scan a tasks virtual memory. It effectively controls the maximum scanning
rate for each task.
515

S
Stephen Kitt 已提交
516
``numa_balancing_scan_delay_ms`` is the starting "scan delay" used for a task
517 518
when it initially forks.

S
Stephen Kitt 已提交
519
``numa_balancing_scan_period_max_ms`` is the maximum time in milliseconds to
520 521
scan a tasks virtual memory. It effectively controls the minimum scanning
rate for each task.
522

S
Stephen Kitt 已提交
523
``numa_balancing_scan_size_mb`` is how many megabytes worth of pages are
524 525 526
scanned for a given scan.


S
Stephen Kitt 已提交
527 528
osrelease, ostype & version
===========================
529 530

::
L
Linus Torvalds 已提交
531

532 533 534 535 536 537
  # cat osrelease
  2.1.88
  # cat ostype
  Linux
  # cat version
  #5 Wed Feb 25 21:49:24 MET 1998
L
Linus Torvalds 已提交
538

S
Stephen Kitt 已提交
539 540
The files ``osrelease`` and ``ostype`` should be clear enough.
``version``
L
Linus Torvalds 已提交
541 542 543 544 545 546
needs a little more clarification however. The '#5' means that
this is the fifth kernel built from this source base and the
date behind it indicates the time the kernel was built.
The only way to tune these values is to rebuild the kernel :-)


S
Stephen Kitt 已提交
547 548
overflowgid & overflowuid
=========================
L
Linus Torvalds 已提交
549

550 551 552 553
if your architecture did not always support 32-bit UIDs (i.e. arm,
i386, m68k, sh, and sparc32), a fixed UID and GID will be returned to
applications that use the old 16-bit UID/GID system calls, if the
actual UID or GID would exceed 65535.
L
Linus Torvalds 已提交
554 555 556 557 558

These sysctls allow you to change the value of the fixed UID and GID.
The default is 65534.


S
Stephen Kitt 已提交
559 560
panic
=====
L
Linus Torvalds 已提交
561

562 563 564 565
The value in this file represents the number of seconds the kernel
waits before rebooting on a panic. When you use the software watchdog,
the recommended setting is 60.

566

S
Stephen Kitt 已提交
567 568
panic_on_io_nmi
===============
569 570 571 572

Controls the kernel's behavior when a CPU receives an NMI caused by
an IO error.

S
Stephen Kitt 已提交
573 574 575 576 577 578 579 580
= ==================================================================
0 Try to continue operation (default).
1 Panic immediately. The IO error triggered an NMI. This indicates a
  serious system condition which could result in IO data corruption.
  Rather than continuing, panicking might be a better choice. Some
  servers issue this sort of NMI when the dump button is pushed,
  and you can use this option to take a crash dump.
= ==================================================================
581

582

S
Stephen Kitt 已提交
583 584
panic_on_oops
=============
L
Linus Torvalds 已提交
585 586 587

Controls the kernel's behaviour when an oops or BUG is encountered.

S
Stephen Kitt 已提交
588 589 590 591 592
= ===================================================================
0 Try to continue operation.
1 Panic immediately.  If the `panic` sysctl is also non-zero then the
  machine will be rebooted.
= ===================================================================
L
Linus Torvalds 已提交
593 594


S
Stephen Kitt 已提交
595 596
panic_on_stackoverflow
======================
597 598 599

Controls the kernel's behavior when detecting the overflows of
kernel, IRQ and exception stacks except a user stack.
S
Stephen Kitt 已提交
600
This file shows up if ``CONFIG_DEBUG_STACKOVERFLOW`` is enabled.
601

S
Stephen Kitt 已提交
602 603 604 605
= ==========================
0 Try to continue operation.
1 Panic immediately.
= ==========================
606 607


S
Stephen Kitt 已提交
608 609
panic_on_unrecovered_nmi
========================
P
Prarit Bhargava 已提交
610 611 612 613 614 615

The default Linux behaviour on an NMI of either memory or unknown is
to continue operation. For many environments such as scientific
computing it is preferable that the box is taken out and the error
dealt with than an uncorrected parity/ECC error get propagated.

S
Stephen Kitt 已提交
616
A small number of systems do generate NMIs for bizarre random reasons
P
Prarit Bhargava 已提交
617 618 619 620
such as power management so the default is off. That sysctl works like
the existing panic controls already in that directory.


S
Stephen Kitt 已提交
621 622
panic_on_warn
=============
P
Prarit Bhargava 已提交
623 624 625 626

Calls panic() in the WARN() path when set to 1.  This is useful to avoid
a kernel rebuild when attempting to kdump at the location of a WARN().

S
Stephen Kitt 已提交
627 628 629 630
= ================================================
0 Only WARN(), default behaviour.
1 Call panic() after printing out WARN() location.
= ================================================
P
Prarit Bhargava 已提交
631 632


S
Stephen Kitt 已提交
633 634
panic_print
===========
635 636 637 638

Bitmask for printing system info when panic happens. User can chose
combination of the following bits:

S
Stephen Kitt 已提交
639
=====  ============================================
640 641 642
bit 0  print all tasks info
bit 1  print system memory info
bit 2  print timer info
S
Stephen Kitt 已提交
643
bit 3  print locks info if ``CONFIG_LOCKDEP`` is on
644
bit 4  print ftrace buffer
S
Stephen Kitt 已提交
645
=====  ============================================
646 647

So for example to print tasks and memory info on panic, user can::
648 649 650 651

  echo 3 > /proc/sys/kernel/panic_print


S
Stephen Kitt 已提交
652 653
panic_on_rcu_stall
==================
654 655 656 657

When set to 1, calls panic() after RCU stall detection messages. This
is useful to define the root cause of RCU stalls using a vmcore.

S
Stephen Kitt 已提交
658 659 660 661
= ============================================================
0 Do not panic() when RCU stall takes place, default behavior.
1 panic() after printing RCU stall messages.
= ============================================================
662 663


S
Stephen Kitt 已提交
664 665
perf_cpu_time_max_percent
=========================
666 667 668 669 670 671 672 673 674 675 676 677

Hints to the kernel how much CPU time it should be allowed to
use to handle perf sampling events.  If the perf subsystem
is informed that its samples are exceeding this limit, it
will drop its sampling frequency to attempt to reduce its CPU
usage.

Some perf sampling happens in NMIs.  If these samples
unexpectedly take too long to execute, the NMIs can become
stacked up next to each other so much that nothing else is
allowed to execute.

S
Stephen Kitt 已提交
678 679 680
===== ========================================================
0     Disable the mechanism.  Do not monitor or correct perf's
      sampling rate no matter how CPU time it takes.
681

S
Stephen Kitt 已提交
682 683 684 685 686 687 688 689
1-100 Attempt to throttle perf's sample rate to this
      percentage of CPU.  Note: the kernel calculates an
      "expected" length of each sample event.  100 here means
      100% of that expected length.  Even if this is set to
      100, you may still see sample throttling if this
      length is exceeded.  Set to 0 if you truly do not care
      how much CPU is consumed.
===== ========================================================
690 691


S
Stephen Kitt 已提交
692 693
perf_event_paranoid
===================
694 695

Controls use of the performance events system by unprivileged
696
users (without CAP_SYS_ADMIN).  The default value is 2.
697

698
===  ==================================================================
S
Stephen Kitt 已提交
699
 -1  Allow use of (almost) all events by all users.
700

S
Stephen Kitt 已提交
701 702
     Ignore mlock limit after perf_event_mlock_kb without
     ``CAP_IPC_LOCK``.
703

S
Stephen Kitt 已提交
704 705
>=0  Disallow ftrace function tracepoint by users without
     ``CAP_SYS_ADMIN``.
706

S
Stephen Kitt 已提交
707
     Disallow raw tracepoint access by users without ``CAP_SYS_ADMIN``.
708

S
Stephen Kitt 已提交
709
>=1  Disallow CPU event access by users without ``CAP_SYS_ADMIN``.
710

S
Stephen Kitt 已提交
711
>=2  Disallow kernel profiling by users without ``CAP_SYS_ADMIN``.
712 713
===  ==================================================================

714

S
Stephen Kitt 已提交
715 716
perf_event_max_stack
====================
717

S
Stephen Kitt 已提交
718 719 720
Controls maximum number of stack frames to copy for (``attr.sample_type &
PERF_SAMPLE_CALLCHAIN``) configured events, for instance, when using
'``perf record -g``' or '``perf trace --call-graph fp``'.
721 722

This can only be done when no events are in use that have callchains
S
Stephen Kitt 已提交
723
enabled, otherwise writing to this file will return ``-EBUSY``.
724 725 726 727

The default value is 127.


S
Stephen Kitt 已提交
728 729
perf_event_mlock_kb
===================
730 731 732 733 734 735

Control size of per-cpu ring buffer not counted agains mlock limit.

The default value is 512 + 1 page


S
Stephen Kitt 已提交
736 737
perf_event_max_contexts_per_stack
=================================
738 739

Controls maximum number of stack frame context entries for
S
Stephen Kitt 已提交
740 741
(``attr.sample_type & PERF_SAMPLE_CALLCHAIN``) configured events, for
instance, when using '``perf record -g``' or '``perf trace --call-graph fp``'.
742 743

This can only be done when no events are in use that have callchains
S
Stephen Kitt 已提交
744
enabled, otherwise writing to this file will return ``-EBUSY``.
745 746 747 748

The default value is 8.


S
Stephen Kitt 已提交
749 750
pid_max
=======
L
Linus Torvalds 已提交
751

752
PID allocation wrap value.  When the kernel's next PID value
L
Linus Torvalds 已提交
753
reaches this value, it wraps back to a minimum PID value.
S
Stephen Kitt 已提交
754
PIDs of value ``pid_max`` or larger are not allocated.
L
Linus Torvalds 已提交
755 756


S
Stephen Kitt 已提交
757 758
ns_last_pid
===========
759 760 761 762 763 764

The last pid allocated in the current (the one task using this sysctl
lives in) pid namespace. When selecting a pid for a next task on fork
kernel tries to allocate a number starting from this one.


S
Stephen Kitt 已提交
765 766
powersave-nap (PPC only)
========================
L
Linus Torvalds 已提交
767 768 769 770

If set, Linux-PPC will use the 'nap' mode of powersaving,
otherwise the 'doze' mode will be used.

S
Stephen Kitt 已提交
771

L
Linus Torvalds 已提交
772 773
==============================================================

S
Stephen Kitt 已提交
774 775
printk
======
L
Linus Torvalds 已提交
776

S
Stephen Kitt 已提交
777 778 779
The four values in printk denote: ``console_loglevel``,
``default_message_loglevel``, ``minimum_console_loglevel`` and
``default_console_loglevel`` respectively.
L
Linus Torvalds 已提交
780 781

These values influence printk() behavior when printing or
S
Stephen Kitt 已提交
782
logging error messages. See '``man 2 syslog``' for more info on
L
Linus Torvalds 已提交
783 784
the different loglevels.

S
Stephen Kitt 已提交
785 786 787 788 789 790 791 792 793
======================== =====================================
console_loglevel         messages with a higher priority than
                         this will be printed to the console
default_message_loglevel messages without an explicit priority
                         will be printed with this priority
minimum_console_loglevel minimum (highest) value to which
                         console_loglevel can be set
default_console_loglevel default value for console_loglevel
======================== =====================================
L
Linus Torvalds 已提交
794 795


S
Stephen Kitt 已提交
796 797
printk_delay
============
798

S
Stephen Kitt 已提交
799
Delay each printk message in ``printk_delay`` milliseconds
800 801 802 803

Value from 0 - 10000 is allowed.


S
Stephen Kitt 已提交
804 805
printk_ratelimit
================
L
Linus Torvalds 已提交
806

S
Stephen Kitt 已提交
807
Some warning messages are rate limited. ``printk_ratelimit`` specifies
808 809
the minimum length of time between these messages (in seconds).
The default value is 5 seconds.
L
Linus Torvalds 已提交
810 811 812 813

A value of 0 will disable rate limiting.


S
Stephen Kitt 已提交
814 815
printk_ratelimit_burst
======================
L
Linus Torvalds 已提交
816

S
Stephen Kitt 已提交
817
While long term we enforce one message per `printk_ratelimit`_
L
Linus Torvalds 已提交
818
seconds, we do allow a burst of messages to pass through.
S
Stephen Kitt 已提交
819
``printk_ratelimit_burst`` specifies the number of messages we can
L
Linus Torvalds 已提交
820 821
send before ratelimiting kicks in.

822 823
The default value is 10 messages.

L
Linus Torvalds 已提交
824

S
Stephen Kitt 已提交
825 826
printk_devkmsg
==============
827

S
Stephen Kitt 已提交
828
Control the logging to ``/dev/kmsg`` from userspace:
829

S
Stephen Kitt 已提交
830 831 832 833 834
========= =============================================
ratelimit default, ratelimited
on        unlimited logging to /dev/kmsg from userspace
off       logging to /dev/kmsg disabled
========= =============================================
835

S
Stephen Kitt 已提交
836
The kernel command line parameter ``printk.devkmsg=`` overrides this and is
837 838 839
a one-time setting until next reboot: once set, it cannot be changed by
this sysctl interface anymore.

S
Stephen Kitt 已提交
840
==============================================================
841

S
Stephen Kitt 已提交
842 843 844 845 846 847 848 849 850

pty
===

See Documentation/filesystems/devpts.txt.


randomize_va_space
==================
851 852 853 854 855

This option can be used to select the type of process address
space randomization that is used in the system, for architectures
that support this feature.

856 857
==  ===========================================================================
0   Turn the process address space randomization off.  This is the
858 859
    default for architectures that do not support this feature anyways,
    and kernels that are booted with the "norandmaps" parameter.
860

861
1   Make the addresses of mmap base, stack and VDSO page randomized.
862
    This, among other things, implies that shared libraries will be
863 864
    loaded to random addresses.  Also for PIE-linked binaries, the
    location of code start is randomized.  This is the default if the
S
Stephen Kitt 已提交
865
    ``CONFIG_COMPAT_BRK`` option is enabled.
866

867
2   Additionally enable heap randomization.  This is the default if
S
Stephen Kitt 已提交
868
    ``CONFIG_COMPAT_BRK`` is disabled.
869 870

    There are a few legacy applications out there (such as some ancient
871
    versions of libc.so.5 from 1996) that assume that brk area starts
872 873
    just after the end of the code+bss.  These applications break when
    start of the brk area is randomized.  There are however no known
874
    non-legacy applications that would be broken this way, so for most
875 876 877
    systems it is safe to choose full randomization.

    Systems with ancient and/or broken binaries should be configured
S
Stephen Kitt 已提交
878
    with ``CONFIG_COMPAT_BRK`` enabled, which excludes the heap from process
879
    address space randomization.
880
==  ===========================================================================
881 882


S
Stephen Kitt 已提交
883 884 885 886 887 888 889 890
real-root-dev
=============

See :doc:`/admin-guide/initrd`.


reboot-cmd (SPARC only)
=======================
L
Linus Torvalds 已提交
891 892 893 894 895 896

??? This seems to be a way to give an argument to the Sparc
ROM/Flash boot loader. Maybe to tell it what to do after
rebooting. ???


S
Stephen Kitt 已提交
897 898
rtsig-max & rtsig-nr
====================
L
Linus Torvalds 已提交
899 900 901 902 903 904 905 906

The file rtsig-max can be used to tune the maximum number
of POSIX realtime (queued) signals that can be outstanding
in the system.

rtsig-nr shows the number of RT signals currently queued.


S
Stephen Kitt 已提交
907 908
sched_energy_aware
==================
909 910 911 912 913 914 915 916 917

Enables/disables Energy Aware Scheduling (EAS). EAS starts
automatically on platforms where it can run (that is,
platforms with asymmetric CPU topologies and having an Energy
Model available). If your platform happens to meet the
requirements for EAS but you do not want to use it, change
this value to 0.


S
Stephen Kitt 已提交
918 919
sched_schedstats
================
920 921 922 923 924 925

Enables/disables scheduler statistics. Enabling this feature
incurs a small amount of overhead in the scheduler but is
useful for debugging and performance tuning.


S
Stephen Kitt 已提交
926 927 928 929 930 931 932 933
seccomp
=======

See :doc:`/userspace-api/seccomp_filter`.


sg-big-buff
===========
L
Linus Torvalds 已提交
934 935 936

This file shows the size of the generic SCSI (sg) buffer.
You can't tune it just yet, but you could change it on
S
Stephen Kitt 已提交
937 938
compile time by editing ``include/scsi/sg.h`` and changing
the value of ``SG_BIG_BUFF``.
L
Linus Torvalds 已提交
939 940 941 942 943 944

There shouldn't be any reason to change this value. If
you can come up with one, you probably know what you
are doing anyway :)


S
Stephen Kitt 已提交
945 946
shmall
======
947 948

This parameter sets the total amount of shared memory pages that
S
Stephen Kitt 已提交
949 950
can be used system wide. Hence, ``shmall`` should always be at least
``ceil(shmmax/PAGE_SIZE)``.
951

S
Stephen Kitt 已提交
952 953
If you are not sure what the default ``PAGE_SIZE`` is on your Linux
system, you can run the following command::
954

955
	# getconf PAGE_SIZE
956 957


S
Stephen Kitt 已提交
958 959
shmmax
======
L
Linus Torvalds 已提交
960 961 962

This value can be used to query and set the run time limit
on the maximum shared memory segment size that can be created.
963
Shared memory segments up to 1Gb are now supported in the
S
Stephen Kitt 已提交
964
kernel.  This value defaults to ``SHMMAX``.
L
Linus Torvalds 已提交
965 966


S
Stephen Kitt 已提交
967 968 969
shmmni
======

970 971 972
This value determines the maximum number of shared memory segments.
4096 by default (``SHMMNI``).

S
Stephen Kitt 已提交
973 974 975

shm_rmid_forced
===============
976 977

Linux lets you set resource limits, including how much memory one
S
Stephen Kitt 已提交
978
process can consume, via ``setrlimit(2)``.  Unfortunately, shared memory
979 980 981 982 983
segments are allowed to exist without association with any process, and
thus might not be counted against any resource limits.  If enabled,
shared memory segments are automatically destroyed when their attach
count becomes zero after a detach or a process termination.  It will
also destroy segments that were created, but never attached to, on exit
S
Stephen Kitt 已提交
984
from the process.  The only use left for ``IPC_RMID`` is to immediately
985 986 987
destroy an unattached segment.  Of course, this breaks the way things are
defined, so some applications might stop working.  Note that this
feature will do you no good unless you also configure your resource
S
Stephen Kitt 已提交
988
limits (in particular, ``RLIMIT_AS`` and ``RLIMIT_NPROC``).  Most systems don't
989 990 991 992 993 994
need this.

Note that if you change this from 0 to 1, already created segments
without users and with a dead originative process will be destroyed.


S
Stephen Kitt 已提交
995 996
sysctl_writes_strict
====================
997 998

Control how file position affects the behavior of updating sysctl values
S
Stephen Kitt 已提交
999
via the ``/proc/sys`` interface:
1000

1001 1002
  ==   ======================================================================
  -1   Legacy per-write sysctl value handling, with no printk warnings.
1003 1004 1005
       Each write syscall must fully contain the sysctl value to be
       written, and multiple writes on the same sysctl file descriptor
       will rewrite the sysctl value, regardless of file position.
1006
   0   Same behavior as above, but warn about processes that perform writes
K
Kees Cook 已提交
1007
       to a sysctl file descriptor when the file position is not 0.
1008
   1   (default) Respect file position when writing sysctl strings. Multiple
K
Kees Cook 已提交
1009 1010 1011 1012
       writes will append to the sysctl value buffer. Anything past the max
       length of the sysctl value buffer will be ignored. Writes to numeric
       sysctl entries must always be at file position 0 and the value must
       be fully contained in the buffer sent in the write syscall.
1013
  ==   ======================================================================
1014 1015


S
Stephen Kitt 已提交
1016 1017
softlockup_all_cpu_backtrace
============================
1018 1019 1020 1021 1022 1023 1024 1025 1026

This value controls the soft lockup detector thread's behavior
when a soft lockup condition is detected as to whether or not
to gather further debug information. If enabled, each cpu will
be issued an NMI and instructed to capture stack trace.

This feature is only applicable for architectures which support
NMI.

S
Stephen Kitt 已提交
1027 1028 1029 1030
= ============================================
0 Do nothing. This is the default behavior.
1 On detection capture more debug information.
= ============================================
1031 1032


S
Stephen Kitt 已提交
1033 1034
soft_watchdog
=============
1035 1036 1037

This parameter can be used to control the soft lockup detector.

S
Stephen Kitt 已提交
1038 1039 1040 1041
= =================================
0 Disable the soft lockup detector.
1 Enable the soft lockup detector.
= =================================
1042 1043 1044 1045 1046

The soft lockup detector monitors CPUs for threads that are hogging the CPUs
without rescheduling voluntarily, and thus prevent the 'watchdog/N' threads
from running. The mechanism depends on the CPUs ability to respond to timer
interrupts which are needed for the 'watchdog/N' threads to be woken up by
S
Stephen Kitt 已提交
1047
the watchdog timer function, otherwise the NMI watchdog — if enabled — can
1048 1049 1050
detect a hard lockup condition.


S
Stephen Kitt 已提交
1051 1052
stack_erasing
=============
1053 1054

This parameter can be used to control kernel stack erasing at the end
S
Stephen Kitt 已提交
1055
of syscalls for kernels built with ``CONFIG_GCC_PLUGIN_STACKLEAK``.
1056 1057 1058 1059 1060 1061

That erasing reduces the information which kernel stack leak bugs
can reveal and blocks some uninitialized stack variable attacks.
The tradeoff is the performance impact: on a single CPU system kernel
compilation sees a 1% slowdown, other systems and workloads may vary.

S
Stephen Kitt 已提交
1062 1063 1064 1065 1066 1067 1068 1069 1070
= ====================================================================
0 Kernel stack erasing is disabled, STACKLEAK_METRICS are not updated.
1 Kernel stack erasing is enabled (default), it is performed before
  returning to the userspace at the end of syscalls.
= ====================================================================


stop-a (SPARC only)
===================
1071

1072 1073 1074 1075 1076 1077 1078 1079 1080 1081
Controls Stop-A:

= ====================================
0 Stop-A has no effect.
1 Stop-A breaks to the PROM (default).
= ====================================

Stop-A is always enabled on a panic, so that the user can return to
the boot PROM.

S
Stephen Kitt 已提交
1082 1083 1084 1085 1086

sysrq
=====

See :doc:`/admin-guide/sysrq`.
1087

1088

1089
tainted
1090
=======
L
Linus Torvalds 已提交
1091

K
Kees Cook 已提交
1092 1093 1094
Non-zero if the kernel has been tainted. Numeric values, which can be
ORed together. The letters are seen in "Tainted" line of Oops reports.

1095 1096 1097 1098 1099 1100 1101 1102 1103 1104 1105 1106 1107 1108 1109 1110 1111 1112 1113 1114
======  =====  ==============================================================
     1  `(P)`  proprietary module was loaded
     2  `(F)`  module was force loaded
     4  `(S)`  SMP kernel oops on an officially SMP incapable processor
     8  `(R)`  module was force unloaded
    16  `(M)`  processor reported a Machine Check Exception (MCE)
    32  `(B)`  bad page referenced or some unexpected page flags
    64  `(U)`  taint requested by userspace application
   128  `(D)`  kernel died recently, i.e. there was an OOPS or BUG
   256  `(A)`  an ACPI table was overridden by user
   512  `(W)`  kernel issued warning
  1024  `(C)`  staging driver was loaded
  2048  `(I)`  workaround for bug in platform firmware applied
  4096  `(O)`  externally-built ("out-of-tree") module was loaded
  8192  `(E)`  unsigned module was loaded
 16384  `(L)`  soft lockup occurred
 32768  `(K)`  kernel has been live patched
 65536  `(X)`  Auxiliary taint, defined and used by for distros
131072  `(T)`  The kernel was built with the struct randomization plugin
======  =====  ==============================================================
1115

S
Stephen Kitt 已提交
1116
See :doc:`/admin-guide/tainted-kernels` for more information.
L
Linus Torvalds 已提交
1117

1118

S
Stephen Kitt 已提交
1119 1120
threads-max
===========
1121 1122

This value controls the maximum number of threads that can be created
S
Stephen Kitt 已提交
1123
using ``fork()``.
1124 1125 1126 1127 1128

During initialization the kernel sets this value such that even if the
maximum number of threads is created, the thread structures occupy only
a part (1/8th) of the available RAM pages.

S
Stephen Kitt 已提交
1129
The minimum value that can be written to ``threads-max`` is 1.
1130

S
Stephen Kitt 已提交
1131 1132
The maximum value that can be written to ``threads-max`` is given by the
constant ``FUTEX_TID_MASK`` (0x3fffffff).
1133

S
Stephen Kitt 已提交
1134 1135
If a value outside of this range is written to ``threads-max`` an
``EINVAL`` error occurs.
1136 1137


S
Stephen Kitt 已提交
1138 1139
unknown_nmi_panic
=================
1140

1141 1142 1143
The value in this file affects behavior of handling NMI. When the
value is non-zero, unknown NMI is trapped and then panic occurs. At
that time, kernel debugging information is displayed on console.
1144

1145 1146
NMI switch that most IA32 servers have fires unknown NMI up, for
example.  If a system hangs up, try pressing the NMI switch.
1147 1148


S
Stephen Kitt 已提交
1149 1150
watchdog
========
1151 1152

This parameter can be used to disable or enable the soft lockup detector
S
Stephen Kitt 已提交
1153
*and* the NMI watchdog (i.e. the hard lockup detector) at the same time.
1154

S
Stephen Kitt 已提交
1155 1156 1157 1158
= ==============================
0 Disable both lockup detectors.
1 Enable both lockup detectors.
= ==============================
1159 1160

The soft lockup detector and the NMI watchdog can also be disabled or
S
Stephen Kitt 已提交
1161 1162 1163
enabled individually, using the ``soft_watchdog`` and ``nmi_watchdog``
parameters.
If the ``watchdog`` parameter is read, for example by executing::
1164 1165 1166

   cat /proc/sys/kernel/watchdog

S
Stephen Kitt 已提交
1167 1168
the output of this command (0 or 1) shows the logical OR of
``soft_watchdog`` and ``nmi_watchdog``.
1169 1170


S
Stephen Kitt 已提交
1171 1172
watchdog_cpumask
================
1173 1174

This value can be used to control on which cpus the watchdog may run.
S
Stephen Kitt 已提交
1175
The default cpumask is all possible cores, but if ``NO_HZ_FULL`` is
1176
enabled in the kernel config, and cores are specified with the
S
Stephen Kitt 已提交
1177
``nohz_full=`` boot argument, those cores are excluded by default.
1178 1179 1180
Offline cores can be included in this mask, and if the core is later
brought online, the watchdog will be started based on the mask value.

S
Stephen Kitt 已提交
1181
Typically this value would only be touched in the ``nohz_full`` case
1182 1183 1184 1185 1186
to re-enable cores that by default were not running the watchdog,
if a kernel lockup was suspected on those cores.

The argument value is the standard cpulist format for cpumasks,
so for example to enable the watchdog on cores 0, 2, 3, and 4 you
1187
might say::
1188 1189 1190 1191

  echo 0,2-4 > /proc/sys/kernel/watchdog_cpumask


S
Stephen Kitt 已提交
1192 1193
watchdog_thresh
===============
1194 1195 1196 1197 1198

This value can be used to control the frequency of hrtimer and NMI
events and the soft and hard lockup thresholds. The default threshold
is 10 seconds.

S
Stephen Kitt 已提交
1199
The softlockup threshold is (``2 * watchdog_thresh``). Setting this
1200
tunable to zero will disable lockup detection altogether.