[PATCH v2 2/4] man/man5/tunables.conf: Document system-wide tunables config
DJ Delorie <[email protected]> Tue, 14 Jul 2026 22:58:09 -0400
| Newsgroups | org.kernel.vger.linux-man |
|---|---|
| Message-ID | <fed61f93333ec0421dc9adc5af05d740a2e4bcd7.1784084289.git.dj@redhat.com> |
--- man/man5/tunables.conf.5 | 116 +++++++++++++++++++++++++++++++++++++++ 1 file changed, 116 insertions(+) create mode 100644 man/man5/tunables.conf.5 diff --git a/man/man5/tunables.conf.5 b/man/man5/tunables.conf.5 new file mode 100644 index 000000000..e2b31e351 --- /dev/null +++ b/man/man5/tunables.conf.5 @@ -0,0 +1,116 @@ +.TH tunables.conf 5 (date) "Linux man-pages (unreleased)" +.SH NAME +tunables.conf \- tunables configuration file +.SH SYNOPSIS +.nf +.B /etc/tunables.conf +.fi +.SH DESCRIPTION +Each line in the file +.I /etc/tunables.conf +specifies a tunable, +which is a name and value separated by an equals sign. +.P +For a list of valid tunables, +please consult the glibc manual. +.P +The syntax allows lines to start with the word +.I include +followed by a path wildcard, +and will include any files matching that wildcard. +The wildcard is a path specification in the +.BR \%glob (7) +format. +Files matching that wildcard will be processed +as if their contents were included in the main config file. +.P +The file is parsed by +.BR \%ldconfig (8) +and the results stored in +.IR /etc/ld.so.cache . +The resulting data is read when a new process starts. +.P +Each line may include zero or more words or symbols at the beginning, +which affect how each tunable affects each processes: +.TP +.B overridable +.TQ +.B + +Allow the tunable to be overridden by the +.B GLIBC_TUNABLES +environment variable when the process runs +(this is the default). +.TP +.B nonoverridable +.TQ +.B \- +Do not allow the tunable to be overridden by the environment variable. +.TP +.B onlysecure +.TQ +.B @ +The tunable only applies to +.B AT_SECURE +processes, +such as a set-user-ID process, +or one with elevated capabilities. +.TP +.B nonsecure +.TQ +.B $ +The tunable only applies to +.RB non- AT_SECURE +processes (this is the default). +.TP +.B anysecure +.TQ +.B * +The tunable only applies to both +.B AT_SECURE +and +.RB non- AT_SECURE +processes. +.P +The file may also contain +.IR filters , +which limit the tunables following it, +up to the end of the file +(or end of the included file, +or start of a new included file) +or a line with only +.B [] +on it. +The syntax is: +.IP +.in +4n +.EX +.RI [ filter : pattern ] +.EE +.in +.TP +.B proc +The +.I proc +filter limits the following tunables to processes +whose name matches the pattern. +The pattern may be an absolute path +or just the base name. +.P +Example config file: +.IP +.in +4n +.EX +glibc.malloc.arenas_max=5 +onlysecure glibc.malloc.arenas_max=1 +\-glibc.pthread.rseq=1 +[proc:/bin/bad.program] +\-glibc.pthread.rseq=0 +[proc:some.program] +\-glibc.malloc.mmap_threshold=65536 +.EE +.in +.SH FILES +.I /etc/ld.so.conf +.SH SEE ALSO +.BR ld.so (8), +.BR ldconfig (8) -- 2.47.3