Re: man/man8/ldconfig.8: document system-wide tunables
Alejandro Colomar <[email protected]> Fri, 10 Jul 2026 16:31:18 +0200
| Newsgroups | org.kernel.vger.linux-man |
|---|---|
| Message-ID | <alEAgbFxQi9oHME3@devuan> |
Hi DJ,
On 2026-07-09T14:53:09-0400, DJ Delorie wrote:
>
> diff --git a/man/man8/ldconfig.8 b/man/man8/ldconfig.8
I see some diagnostics after applying this patch:
$ make lint-man build-catman -R -k
make: warning: undefined variable 'GNUMAKEFLAGS'
MANDOC .tmp/man/man8/ldconfig.8.lint-man.mandoc.touch
mandoc: .tmp/man/man8/ldconfig.8:212:85: STYLE: input text line longer than 80 bytes: Allow the tunable to...
mandoc: .tmp/man/man8/ldconfig.8:250:2: WARNING: skipping paragraph macro: PP empty
mandoc: .tmp/man/man8/ldconfig.8:270:2: WARNING: skipping paragraph macro: PP empty
make: *** [/srv/alx/src/linux/man-pages/man-pages/contrib/share/mk/lint/man/mandoc.mk:30: .tmp/man/man8/ldconfig.8.lint-man.mandoc.touch] Error 1
PCRE2GREP .tmp/man/man8/ldconfig.8.lint-man.poems.touch
lint-man-poems: .tmp/man/man8/ldconfig.8: Use semantic newlines (see man-pages(7)):
222: The tunable only applies to AT_SECURE (i.e. setuid, or elevated
make: *** [/srv/alx/src/linux/man-pages/man-pages/contrib/share/mk/lint/man/poems.mk:30: .tmp/man/man8/ldconfig.8.lint-man.poems.touch] Error 1
make: Target 'lint-man' not remade because of errors.
TROFF .tmp/man/man8/ldconfig.8.cat.set
an.tmac:.tmp/man/man8/ldconfig.8:92: style: .IR expects at least 2 arguments, got 1
an.tmac:.tmp/man/man8/ldconfig.8:195: style: .IR expects at least 2 arguments, got 1
an.tmac:.tmp/man/man8/ldconfig.8:197: style: .IR expects at least 2 arguments, got 1
make: *** [/srv/alx/src/linux/man-pages/man-pages/contrib/share/mk/build/catman/troff.mk:33: .tmp/man/man8/ldconfig.8.cat.set] Error 1
make: *** Deleting file '.tmp/man/man8/ldconfig.8.cat.set'
make: Target 'build-catman' not remade because of errors.
> index ee024b8f6..8574eae24 100644
> --- a/man/man8/ldconfig.8
> +++ b/man/man8/ldconfig.8
> @@ -17,6 +17,8 @@ .SH SYNOPSIS
> .IR conf ]
> .RB [ \-r\~\c
> .IR root ]
> +.RB [ \-t\~\c
> +.IR tunconf ]
> .IR directory \~.\|.\|.
> .YS
> .SY /sbin/ldconfig
> @@ -85,6 +87,11 @@ .SH DESCRIPTION
> .P
> Failure to follow this pattern may result in compatibility issues
> after an upgrade.
> +.P
> +If the file
> +.IR /etc/tunables.conf
s/IR/I/
> +exists, it contains one tunable per line. These tunables are stored
Please use semantic newlines. See man-pages(7):
$ MANWIDTH=72 man man-pages | awk '/Use semantic newlines/,/^$/'
Use semantic newlines
In the source of a manual page, new sentences should be started on
new lines, long sentences should be split into lines at clause
breaks (commas, semicolons, colons, and so on), and long clauses
should be split at phrase boundaries. This convention, sometimes
known as "semantic newlines", makes it easier to see the effect of
patches, which often operate at the level of individual sentences,
clauses, or phrases.
> +in the cache and applied to every process at its startup.
> .SH OPTIONS
> .TP
> .BI \-\-format= fmt
> @@ -157,6 +164,12 @@ .SH OPTIONS
> .I root
> as the root directory.
> .TP
> +.BI \-t\~ tunconf
> +Use
> +.I tunconf
> +instead of
> +.IR /etc/tunables.conf .
> +.TP
> .B \-\-verbose
> .TQ
> .B \-v
> @@ -177,9 +190,85 @@ .SH OPTIONS
> .B \-N
> is also specified,
> the cache is still rebuilt.
> +.SH INCLUDES
I think this section belongs in new manual pages, ld.so.conf(5) and
tuinables.conf(5), which would describe the formats of those files.
> +The files
> +.IR /etc/ld.so.conf
s/IR/I/
> +and
> +.IR /etc/tunables.conf
s/IR/I/
> +allow lines to start with the word
> +.I include
> +followed by a path wildcard, and will include any files matching that
> +wildcard.
Please use semantic newlines.
> +.SH TUNABLES
Same here; I think this belongs in tunables.conf(5).
Have a lovely day!
Alex
> +Each line in the file
> +.I /etc/tunables.conf
> +specifies a tunable, which is a name and value
> +separated by an equals sign.
> +Each line may include zero or more words or symbols at the beginning:
> +.TP
> +.B overridable
> +.TQ
> +.B +
> +Allow the tunable to be overridden by the environment variable (this is the default).
> +.TP
> +.B nonoverridable
> +.TQ
> +.B \-
> +Do not allow the tunable to be overridden by the environment variable.
> +.TP
> +.B onlysecure
> +.TQ
> +.B @
> +The tunable only applies to AT_SECURE (i.e. setuid, or elevated
> +capabilities) processes.
> +.TP
> +.B nonsecure
> +.TQ
> +.B $
> +The tunable only applies to non-AT_SECURE processes (this is the default).
> +.TP
> +.B anysecure
> +.TQ
> +.B *
> +The tunable only applies to both AT_SECURE and non-AT_SECURE processes.
> +.P
> +The file may also contain
> +.I filters ,
> +which limit the tunables following it, up to the end of the file (or
> +end of the included file, or start of a new included file) or a line
> +with only
> +.B []
> +on it. The syntax is:
> +.RS
> +.P
> +[
> +.I filter
> +:
> +.I pattern
> +]
> +.RE
> +.P
> +.TP
> +.B proc
> +The
> +.I proc
> +filter limits the following tunables to processes starting from the
> +file matching the pattern. The file may be fully qualified or just
> +the basename.
> +.P
> +Example config file:
> +.P
> +.RS
> +.nf
> +glibc.malloc.arenas_max=5
> +onlysecure glibc.malloc.arenas_max=1
> +-glibc.pthread.rseq=1
> +[proc:/bin/bad.program]
> +-glibc.pthread.rseq=0
> +.fi
> +.RE
> +.P
> .SH FILES
> -.\" FIXME Since glibc-2.3.4, "include" directives are supported in ld.so.conf
> -.\"
> .\" FIXME Since glibc-2.4, "hwcap" directives are supported in ld.so.conf
> .PD 0
> .TP
> @@ -191,6 +280,11 @@ .SH FILES
> one per line,
> in which to search for libraries.
> .TP
> +.I /etc/tunables.conf
> +contains a list of tunables,
> +one per line,
> +to apply to all newly created processes.
> +.TP
> .I /etc/ld.so.cache
> contains an ordered list of libraries found in the directories
> specified in
>
>
--
<https://www.alejandro-colomar.es>
signature.asc
(application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEES7Jt9u9GbmlWADAi64mZXMKQwqkFAmpRAiYACgkQ64mZXMKQ wqlxfhAAqLXKO7DgoUURwzIcW2Ol9WmUY5Se5mGDfKNioIM2/ozAOhkMbsdlIhnc XMOiFUYJ843CYIsA/nwNPdvmh02OHwuukbApw/jVIhkMQUo+Bogmprn04iL+rwbA XCH+M7BMsBI2DyRh8+bY3OivclNPxotlHLJu47fZGr1N1H4h+um2ZoG+1NXUXDJh 72ef+wdH/TzT41YihLIuXocCzmqejfUp0GqodhrDBmq2TzkdWBTJIhqlhJdVvOeH moEooAM47hm9usEUZ04QUp+Y9jsXj2kpVFeX1TB0QQWdI5byKsU7vY5K8ZoLO1te RIPWFICdk+Ls1pcf5zxAk5BelXAXjX0aU9rUaMKG+x2i48yUTxibDe710AUcqe2l ifVA5awNnsl97BDmbMALWEcseqJWdSwEdJUAuUVgXvw1Sox4atczOSy7iv4pLTjc ocrDD3Ul6Ytl4UIcySGrLtD5zPn8IjoDGq83fILWtnzP4us6q4fwIqaDoqyssjZ1 86RJDDENsSbunW7175etZfxEYHatC7l5xEZAgCs0Yx5v+yggCxXwFGa9UbH078n9 YYdV13WjZUV69gTC5pozH/kG3TfISIweMO5zxuBmGMzJh8QCEqfApetugyWwwgix Fj3VaeUGefVMewZ9NzQpYexrroJtif3A2O9BkQivyPzzBiTVjYU= =fyW/ -----END PGP SIGNATURE-----