blob: 6d7ca5695b09f4851f48728459ed97ba5e1294fe [file] [log] [blame]
Linus Torvalds1da177e2005-04-16 15:20:36 -07001Documentation for /proc/sys/kernel/* kernel version 2.2.10
2 (c) 1998, 1999, Rik van Riel <riel@nl.linux.org>
Shen Feng760df932009-04-02 16:57:20 -07003 (c) 2009, Shen Feng<shen@cn.fujitsu.com>
Linus Torvalds1da177e2005-04-16 15:20:36 -07004
5For general info and legal blurb, please look in README.
6
7==============================================================
8
9This file contains documentation for the sysctl files in
10/proc/sys/kernel/ and is valid for Linux kernel version 2.2.
11
12The files in this directory can be used to tune and monitor
13miscellaneous and general things in the operation of the Linux
14kernel. Since some of the files _can_ be used to screw up your
15system, it is advisable to read both documentation and source
16before actually making adjustments.
17
18Currently, these files might (depending on your configuration)
19show up in /proc/sys/kernel:
Pavel Machekc255d842006-02-20 18:27:58 -080020- acpi_video_flags
Linus Torvalds1da177e2005-04-16 15:20:36 -070021- acct
H. Peter Anvind75757a2009-12-11 14:23:44 -080022- bootloader_type [ X86 only ]
23- bootloader_version [ X86 only ]
Bryan Huntsman3f2bc4d2011-08-16 17:27:22 -070024- boot_reason [ ARM only ]
Hans-Joachim Pichtc1147282009-09-11 10:28:47 +020025- callhome [ S390 only ]
Shen Feng760df932009-04-02 16:57:20 -070026- auto_msgmni
Linus Torvalds1da177e2005-04-16 15:20:36 -070027- core_pattern
Neil Hormana2939802009-09-23 15:56:56 -070028- core_pipe_limit
Linus Torvalds1da177e2005-04-16 15:20:36 -070029- core_uses_pid
30- ctrl-alt-del
31- dentry-state
Dan Rosenbergeaf06b22010-11-11 14:05:18 -080032- dmesg_restrict
Linus Torvalds1da177e2005-04-16 15:20:36 -070033- domainname
34- hostname
35- hotplug
36- java-appletviewer [ binfmt_java, obsolete ]
37- java-interpreter [ binfmt_java, obsolete ]
Dan Rosenberg455cd5a2011-01-12 16:59:41 -080038- kptr_restrict
Chuck Ebbert0741f4d2006-12-07 02:14:11 +010039- kstack_depth_to_print [ X86 only ]
Linus Torvalds1da177e2005-04-16 15:20:36 -070040- l2cr [ PPC only ]
Michael Opdenackerac76cff2008-02-13 15:03:32 -080041- modprobe ==> Documentation/debugging-modules.txt
Kees Cook3d433212009-04-02 15:49:29 -070042- modules_disabled
Linus Torvalds1da177e2005-04-16 15:20:36 -070043- msgmax
44- msgmnb
45- msgmni
Shen Feng760df932009-04-02 16:57:20 -070046- nmi_watchdog
Linus Torvalds1da177e2005-04-16 15:20:36 -070047- osrelease
48- ostype
49- overflowgid
50- overflowuid
51- panic
52- pid_max
53- powersave-nap [ PPC only ]
Shen Feng760df932009-04-02 16:57:20 -070054- panic_on_unrecovered_nmi
Linus Torvalds1da177e2005-04-16 15:20:36 -070055- printk
Jiri Kosina1ec7fd52008-02-09 23:24:08 +010056- randomize_va_space
Linus Torvalds1da177e2005-04-16 15:20:36 -070057- real-root-dev ==> Documentation/initrd.txt
58- reboot-cmd [ SPARC only ]
59- rtsig-max
60- rtsig-nr
61- sem
62- sg-big-buff [ generic SCSI device (sg) ]
63- shmall
64- shmmax [ sysv ipc ]
65- shmmni
66- stop-a [ SPARC only ]
67- sysrq ==> Documentation/sysrq.txt
68- tainted
69- threads-max
Shen Feng760df932009-04-02 16:57:20 -070070- unknown_nmi_panic
Linus Torvalds1da177e2005-04-16 15:20:36 -070071- version
72
73==============================================================
74
Pavel Machekc255d842006-02-20 18:27:58 -080075acpi_video_flags:
76
77flags
78
79See Doc*/kernel/power/video.txt, it allows mode of video boot to be
80set during run time.
81
82==============================================================
83
Linus Torvalds1da177e2005-04-16 15:20:36 -070084acct:
85
86highwater lowwater frequency
87
88If BSD-style process accounting is enabled these values control
89its behaviour. If free space on filesystem where the log lives
90goes below <lowwater>% accounting suspends. If free space gets
91above <highwater>% accounting resumes. <Frequency> determines
92how often do we check the amount of free space (value is in
93seconds). Default:
944 2 30
95That is, suspend accounting if there left <= 2% free; resume it
96if we got >=4%; consider information about amount of free space
97valid for 30 seconds.
98
99==============================================================
100
H. Peter Anvind75757a2009-12-11 14:23:44 -0800101bootloader_type:
102
103x86 bootloader identification
104
105This gives the bootloader type number as indicated by the bootloader,
106shifted left by 4, and OR'd with the low four bits of the bootloader
107version. The reason for this encoding is that this used to match the
108type_of_loader field in the kernel header; the encoding is kept for
109backwards compatibility. That is, if the full bootloader type number
110is 0x15 and the full version number is 0x234, this file will contain
111the value 340 = 0x154.
112
113See the type_of_loader and ext_loader_type fields in
114Documentation/x86/boot.txt for additional information.
115
116==============================================================
117
118bootloader_version:
119
120x86 bootloader version
121
122The complete bootloader version number. In the example above, this
123file will contain the value 564 = 0x234.
124
125See the type_of_loader and ext_loader_ver fields in
126Documentation/x86/boot.txt for additional information.
127
128==============================================================
129
Bryan Huntsman3f2bc4d2011-08-16 17:27:22 -0700130boot_reason:
131
132ARM -- reason for device boot
133
134A single bit will be set in the unsigned integer value to identify the
135reason the device was booted / powered on. The value will be zero if this
136feature is not supported on the ARM device being booted.
137
138See the power-on-status field definitions in
139Documentation/arm/msm/boot.txt for Qualcomm's family of devices.
140
141==============================================================
142
Hans-Joachim Pichtc1147282009-09-11 10:28:47 +0200143callhome:
144
145Controls the kernel's callhome behavior in case of a kernel panic.
146
147The s390 hardware allows an operating system to send a notification
148to a service organization (callhome) in case of an operating system panic.
149
150When the value in this file is 0 (which is the default behavior)
151nothing happens in case of a kernel panic. If this value is set to "1"
152the complete kernel oops message is send to the IBM customer service
153organization in case the mainframe the Linux operating system is running
154on has a service contract with IBM.
155
156==============================================================
157
Linus Torvalds1da177e2005-04-16 15:20:36 -0700158core_pattern:
159
160core_pattern is used to specify a core dumpfile pattern name.
Matthias Urlichscd081042006-10-11 01:21:57 -0700161. max length 128 characters; default value is "core"
Linus Torvalds1da177e2005-04-16 15:20:36 -0700162. core_pattern is used as a pattern template for the output filename;
163 certain string patterns (beginning with '%') are substituted with
164 their actual values.
165. backward compatibility with core_uses_pid:
166 If core_pattern does not include "%p" (default does not)
167 and core_uses_pid is set, then .PID will be appended to
168 the filename.
169. corename format specifiers:
170 %<NUL> '%' is dropped
171 %% output one '%'
172 %p pid
173 %u uid
174 %g gid
175 %s signal number
176 %t UNIX time of dump
177 %h hostname
Jiri Slaby57cc0832011-05-26 16:25:46 -0700178 %e executable filename (may be shortened)
179 %E executable path
Linus Torvalds1da177e2005-04-16 15:20:36 -0700180 %<OTHER> both are dropped
Matthias Urlichscd081042006-10-11 01:21:57 -0700181. If the first character of the pattern is a '|', the kernel will treat
182 the rest of the pattern as a command to run. The core dump will be
183 written to the standard input of that program instead of to a file.
Linus Torvalds1da177e2005-04-16 15:20:36 -0700184
185==============================================================
186
Neil Hormana2939802009-09-23 15:56:56 -0700187core_pipe_limit:
188
189This sysctl is only applicable when core_pattern is configured to pipe core
Randy Dunlap7beeec82009-10-04 19:23:13 -0700190files to a user space helper (when the first character of core_pattern is a '|',
Neil Hormana2939802009-09-23 15:56:56 -0700191see above). When collecting cores via a pipe to an application, it is
Randy Dunlap7beeec82009-10-04 19:23:13 -0700192occasionally useful for the collecting application to gather data about the
Neil Hormana2939802009-09-23 15:56:56 -0700193crashing process from its /proc/pid directory. In order to do this safely, the
194kernel must wait for the collecting process to exit, so as not to remove the
195crashing processes proc files prematurely. This in turn creates the possibility
196that a misbehaving userspace collecting process can block the reaping of a
197crashed process simply by never exiting. This sysctl defends against that. It
198defines how many concurrent crashing processes may be piped to user space
199applications in parallel. If this value is exceeded, then those crashing
200processes above that value are noted via the kernel log and their cores are
201skipped. 0 is a special value, indicating that unlimited processes may be
202captured in parallel, but that no waiting will take place (i.e. the collecting
Randy Dunlap7beeec82009-10-04 19:23:13 -0700203process is not guaranteed access to /proc/<crashing pid>/). This value defaults
Neil Hormana2939802009-09-23 15:56:56 -0700204to 0.
205
206==============================================================
207
Linus Torvalds1da177e2005-04-16 15:20:36 -0700208core_uses_pid:
209
210The default coredump filename is "core". By setting
211core_uses_pid to 1, the coredump filename becomes core.PID.
212If core_pattern does not include "%p" (default does not)
213and core_uses_pid is set, then .PID will be appended to
214the filename.
215
216==============================================================
217
218ctrl-alt-del:
219
220When the value in this file is 0, ctrl-alt-del is trapped and
221sent to the init(1) program to handle a graceful restart.
222When, however, the value is > 0, Linux's reaction to a Vulcan
223Nerve Pinch (tm) will be an immediate reboot, without even
224syncing its dirty buffers.
225
226Note: when a program (like dosemu) has the keyboard in 'raw'
227mode, the ctrl-alt-del is intercepted by the program before it
228ever reaches the kernel tty layer, and it's up to the program
229to decide what to do with it.
230
231==============================================================
232
Dan Rosenbergeaf06b22010-11-11 14:05:18 -0800233dmesg_restrict:
234
235This toggle indicates whether unprivileged users are prevented from using
236dmesg(8) to view messages from the kernel's log buffer. When
237dmesg_restrict is set to (0) there are no restrictions. When
Serge E. Hallyn38ef4c22010-12-08 15:19:01 +0000238dmesg_restrict is set set to (1), users must have CAP_SYSLOG to use
Dan Rosenbergeaf06b22010-11-11 14:05:18 -0800239dmesg(8).
240
241The kernel config option CONFIG_SECURITY_DMESG_RESTRICT sets the default
242value of dmesg_restrict.
243
244==============================================================
245
Linus Torvalds1da177e2005-04-16 15:20:36 -0700246domainname & hostname:
247
248These files can be used to set the NIS/YP domainname and the
249hostname of your box in exactly the same way as the commands
250domainname and hostname, i.e.:
251# echo "darkstar" > /proc/sys/kernel/hostname
252# echo "mydomain" > /proc/sys/kernel/domainname
253has the same effect as
254# hostname "darkstar"
255# domainname "mydomain"
256
257Note, however, that the classic darkstar.frop.org has the
258hostname "darkstar" and DNS (Internet Domain Name Server)
259domainname "frop.org", not to be confused with the NIS (Network
260Information Service) or YP (Yellow Pages) domainname. These two
261domain names are in general different. For a detailed discussion
262see the hostname(1) man page.
263
264==============================================================
265
266hotplug:
267
268Path for the hotplug policy agent.
269Default value is "/sbin/hotplug".
270
271==============================================================
272
273l2cr: (PPC only)
274
275This flag controls the L2 cache of G3 processor boards. If
2760, the cache is disabled. Enabled if nonzero.
277
278==============================================================
279
Dan Rosenberg455cd5a2011-01-12 16:59:41 -0800280kptr_restrict:
281
282This toggle indicates whether restrictions are placed on
283exposing kernel addresses via /proc and other interfaces. When
284kptr_restrict is set to (0), there are no restrictions. When
285kptr_restrict is set to (1), the default, kernel pointers
286printed using the %pK format specifier will be replaced with 0's
287unless the user has CAP_SYSLOG. When kptr_restrict is set to
288(2), kernel pointers printed using %pK will be replaced with 0's
289regardless of privileges.
290
291==============================================================
292
Chuck Ebbert0741f4d2006-12-07 02:14:11 +0100293kstack_depth_to_print: (X86 only)
294
295Controls the number of words to print when dumping the raw
296kernel stack.
297
298==============================================================
299
Kees Cook3d433212009-04-02 15:49:29 -0700300modules_disabled:
301
302A toggle value indicating if modules are allowed to be loaded
303in an otherwise modular kernel. This toggle defaults to off
304(0), but can be set true (1). Once true, modules can be
305neither loaded nor unloaded, and the toggle cannot be set back
306to false.
307
308==============================================================
309
Linus Torvalds1da177e2005-04-16 15:20:36 -0700310osrelease, ostype & version:
311
312# cat osrelease
3132.1.88
314# cat ostype
315Linux
316# cat version
317#5 Wed Feb 25 21:49:24 MET 1998
318
319The files osrelease and ostype should be clear enough. Version
320needs a little more clarification however. The '#5' means that
321this is the fifth kernel built from this source base and the
322date behind it indicates the time the kernel was built.
323The only way to tune these values is to rebuild the kernel :-)
324
325==============================================================
326
327overflowgid & overflowuid:
328
329if your architecture did not always support 32-bit UIDs (i.e. arm, i386,
330m68k, sh, and sparc32), a fixed UID and GID will be returned to
331applications that use the old 16-bit UID/GID system calls, if the actual
332UID or GID would exceed 65535.
333
334These sysctls allow you to change the value of the fixed UID and GID.
335The default is 65534.
336
337==============================================================
338
339panic:
340
341The value in this file represents the number of seconds the
342kernel waits before rebooting on a panic. When you use the
343software watchdog, the recommended setting is 60.
344
345==============================================================
346
347panic_on_oops:
348
349Controls the kernel's behaviour when an oops or BUG is encountered.
350
3510: try to continue operation
352
Matt LaPlantea982ac02007-05-09 07:35:06 +02003531: panic immediately. If the `panic' sysctl is also non-zero then the
Maxime Bizon8b23d042006-08-05 12:14:32 -0700354 machine will be rebooted.
Linus Torvalds1da177e2005-04-16 15:20:36 -0700355
356==============================================================
357
358pid_max:
359
Robert P. J. Daybeb7dd82007-05-09 07:14:03 +0200360PID allocation wrap value. When the kernel's next PID value
Linus Torvalds1da177e2005-04-16 15:20:36 -0700361reaches this value, it wraps back to a minimum PID value.
362PIDs of value pid_max or larger are not allocated.
363
364==============================================================
365
366powersave-nap: (PPC only)
367
368If set, Linux-PPC will use the 'nap' mode of powersaving,
369otherwise the 'doze' mode will be used.
370
371==============================================================
372
373printk:
374
375The four values in printk denote: console_loglevel,
376default_message_loglevel, minimum_console_loglevel and
377default_console_loglevel respectively.
378
379These values influence printk() behavior when printing or
380logging error messages. See 'man 2 syslog' for more info on
381the different loglevels.
382
383- console_loglevel: messages with a higher priority than
384 this will be printed to the console
Paul Bolle87889e12011-02-06 21:00:41 +0100385- default_message_loglevel: messages without an explicit priority
Linus Torvalds1da177e2005-04-16 15:20:36 -0700386 will be printed with this priority
387- minimum_console_loglevel: minimum (highest) value to which
388 console_loglevel can be set
389- default_console_loglevel: default value for console_loglevel
390
391==============================================================
392
393printk_ratelimit:
394
395Some warning messages are rate limited. printk_ratelimit specifies
396the minimum length of time between these messages (in jiffies), by
397default we allow one every 5 seconds.
398
399A value of 0 will disable rate limiting.
400
401==============================================================
402
403printk_ratelimit_burst:
404
405While long term we enforce one message per printk_ratelimit
406seconds, we do allow a burst of messages to pass through.
407printk_ratelimit_burst specifies the number of messages we can
408send before ratelimiting kicks in.
409
410==============================================================
411
Dave Youngaf913222009-09-22 16:43:33 -0700412printk_delay:
413
414Delay each printk message in printk_delay milliseconds
415
416Value from 0 - 10000 is allowed.
417
418==============================================================
419
Jiri Kosina1ec7fd52008-02-09 23:24:08 +0100420randomize-va-space:
421
422This option can be used to select the type of process address
423space randomization that is used in the system, for architectures
424that support this feature.
425
Horst Schirmeierb7f5ab62009-07-03 14:20:17 +02004260 - Turn the process address space randomization off. This is the
427 default for architectures that do not support this feature anyways,
428 and kernels that are booted with the "norandmaps" parameter.
Jiri Kosina1ec7fd52008-02-09 23:24:08 +0100429
4301 - Make the addresses of mmap base, stack and VDSO page randomized.
431 This, among other things, implies that shared libraries will be
Horst Schirmeierb7f5ab62009-07-03 14:20:17 +0200432 loaded to random addresses. Also for PIE-linked binaries, the
433 location of code start is randomized. This is the default if the
434 CONFIG_COMPAT_BRK option is enabled.
Jiri Kosina1ec7fd52008-02-09 23:24:08 +0100435
Horst Schirmeierb7f5ab62009-07-03 14:20:17 +02004362 - Additionally enable heap randomization. This is the default if
437 CONFIG_COMPAT_BRK is disabled.
438
439 There are a few legacy applications out there (such as some ancient
Jiri Kosina1ec7fd52008-02-09 23:24:08 +0100440 versions of libc.so.5 from 1996) that assume that brk area starts
Horst Schirmeierb7f5ab62009-07-03 14:20:17 +0200441 just after the end of the code+bss. These applications break when
442 start of the brk area is randomized. There are however no known
Jiri Kosina1ec7fd52008-02-09 23:24:08 +0100443 non-legacy applications that would be broken this way, so for most
Horst Schirmeierb7f5ab62009-07-03 14:20:17 +0200444 systems it is safe to choose full randomization.
445
446 Systems with ancient and/or broken binaries should be configured
447 with CONFIG_COMPAT_BRK enabled, which excludes the heap from process
448 address space randomization.
Jiri Kosina1ec7fd52008-02-09 23:24:08 +0100449
450==============================================================
451
Linus Torvalds1da177e2005-04-16 15:20:36 -0700452reboot-cmd: (Sparc only)
453
454??? This seems to be a way to give an argument to the Sparc
455ROM/Flash boot loader. Maybe to tell it what to do after
456rebooting. ???
457
458==============================================================
459
460rtsig-max & rtsig-nr:
461
462The file rtsig-max can be used to tune the maximum number
463of POSIX realtime (queued) signals that can be outstanding
464in the system.
465
466rtsig-nr shows the number of RT signals currently queued.
467
468==============================================================
469
470sg-big-buff:
471
472This file shows the size of the generic SCSI (sg) buffer.
473You can't tune it just yet, but you could change it on
474compile time by editing include/scsi/sg.h and changing
475the value of SG_BIG_BUFF.
476
477There shouldn't be any reason to change this value. If
478you can come up with one, you probably know what you
479are doing anyway :)
480
481==============================================================
482
483shmmax:
484
485This value can be used to query and set the run time limit
486on the maximum shared memory segment size that can be created.
487Shared memory segments up to 1Gb are now supported in the
488kernel. This value defaults to SHMMAX.
489
490==============================================================
491
Ravikiran G Thirumalaic4f3b632007-10-16 23:26:09 -0700492softlockup_thresh:
493
Andrew Mortonb4d19cc2008-09-22 13:57:51 -0700494This value can be used to lower the softlockup tolerance threshold. The
495default threshold is 60 seconds. If a cpu is locked up for 60 seconds,
496the kernel complains. Valid values are 1-60 seconds. Setting this
497tunable to zero will disable the softlockup detection altogether.
Ravikiran G Thirumalaic4f3b632007-10-16 23:26:09 -0700498
499==============================================================
500
Linus Torvalds1da177e2005-04-16 15:20:36 -0700501tainted:
502
503Non-zero if the kernel has been tainted. Numeric values, which
504can be ORed together:
505
Greg Kroah-Hartmanbb206982008-10-17 15:01:07 -0700506 1 - A module with a non-GPL license has been loaded, this
507 includes modules with no license.
508 Set by modutils >= 2.4.9 and module-init-tools.
509 2 - A module was force loaded by insmod -f.
510 Set by modutils >= 2.4.9 and module-init-tools.
511 4 - Unsafe SMP processors: SMP with CPUs not designed for SMP.
512 8 - A module was forcibly unloaded from the system by rmmod -f.
513 16 - A hardware machine check error occurred on the system.
514 32 - A bad page was discovered on the system.
515 64 - The user has asked that the system be marked "tainted". This
516 could be because they are running software that directly modifies
517 the hardware, or for other reasons.
518 128 - The system has died.
519 256 - The ACPI DSDT has been overridden with one supplied by the user
520 instead of using the one provided by the hardware.
521 512 - A kernel warning has occurred.
5221024 - A module from drivers/staging was loaded.
Linus Torvalds1da177e2005-04-16 15:20:36 -0700523
Shen Feng760df932009-04-02 16:57:20 -0700524==============================================================
525
526auto_msgmni:
527
528Enables/Disables automatic recomputing of msgmni upon memory add/remove or
529upon ipc namespace creation/removal (see the msgmni description above).
530Echoing "1" into this file enables msgmni automatic recomputing.
531Echoing "0" turns it off.
532auto_msgmni default value is 1.
533
534==============================================================
535
536nmi_watchdog:
537
538Enables/Disables the NMI watchdog on x86 systems. When the value is non-zero
539the NMI watchdog is enabled and will continuously test all online cpus to
540determine whether or not they are still functioning properly. Currently,
541passing "nmi_watchdog=" parameter at boot time is required for this function
542to work.
543
544If LAPIC NMI watchdog method is in use (nmi_watchdog=2 kernel parameter), the
545NMI watchdog shares registers with oprofile. By disabling the NMI watchdog,
546oprofile may have more registers to utilize.
547
548==============================================================
549
550unknown_nmi_panic:
551
552The value in this file affects behavior of handling NMI. When the value is
553non-zero, unknown NMI is trapped and then panic occurs. At that time, kernel
554debugging information is displayed on console.
555
556NMI switch that most IA32 servers have fires unknown NMI up, for example.
557If a system hangs up, try pressing the NMI switch.
558
559==============================================================
560
561panic_on_unrecovered_nmi:
562
563The default Linux behaviour on an NMI of either memory or unknown is to continue
564operation. For many environments such as scientific computing it is preferable
565that the box is taken out and the error dealt with than an uncorrected
566parity/ECC error get propogated.
567
568A small number of systems do generate NMI's for bizarre random reasons such as
569power management so the default is off. That sysctl works like the existing
570panic controls already in that directory.
571