Re: [PATCH v5 2/4] man/man5/tunables.conf: Document system-wide tunables config

Alejandro Colomar <[email protected]>
Newsgroups org.kernel.vger.linux-man
Message-ID <anUAwb8lY_u7eU3F@devuan>
Hi DJ,

> Date: 2026-08-06 16:44:30-0400
> From: DJ Delorie <[email protected]>
>
> 
> ---

You forgot to sign.

>  man/man5/tunables.conf.5 | 145 +++++++++++++++++++++++++++++++++++++++
>  1 file changed, 145 insertions(+)
>  create mode 100644 man/man5/tunables.conf.5
> 
> diff --git a/man/man5/tunables.conf.5 b/man/man5/tunables.conf.5
> new file mode 100644
> index 000000000..29beeb8f8
> --- /dev/null
> +++ b/man/man5/tunables.conf.5
> @@ -0,0 +1,145 @@
> +.TH tunables.conf 5 (date) "Linux man-pages (unreleased)"
> +.SH NAME
> +tunables.conf \- tunables configuration file
> +.SH SYNOPSIS
> +.nf
> +.B /etc/tunables.conf
> +.fi
> +.SH DESCRIPTION
> +Tunables are a feature in the GNU C Library
> +that allows application authors and distribution maintainers
> +to alter the runtime library behavior to match their workload.
> +For a list of supported tunables,
> +please consult the glibc manual
> +that corresponds to your installed version of glibc,
> +or run the following command:
> +.P
> +.in +4n
> +.EX
> +ld.so \-\-list\-tunables
> +.EE
> +.P
> +The file is parsed by
> +.BR \%ldconfig (8)
> +and the results stored in
> +.IR /etc/ld.so.cache .
> +The resulting data is read when a new process is created by
> +.IR ld.so .

Sorry for noticing this in v4; I forgot about it.  I see this unresolved
issue from earlier versions remains.

ld.so(8) runs when a new program is executed --execve(2)--, not when
a new process is created --fork(2)--, AFAIK.

	alx@devuan:~$ MANWIDTH=64 man fork | grep ld.so
	alx@devuan:~$ MANWIDTH=64 man execve | grep -C2 ld.so
	     If the executable is an a.out  dynamically  linked  binary
	     executable  containing shared‐library stubs, the Linux dy‐
	     namic linker ld.so(8) is called at the start of  execution
	     to  bring  needed  shared objects into memory and link the
	     executable with them.
	--
	     ptrace(2), exec(3), fexecve(3),  getauxval(3),  getopt(3),
	     system(3),  capabilities(7),  credentials(7),  environ(7),
	     path_resolution(7), ld.so(8)

	Linux man‐pages 6.18‐18... 2026‐02‐08                 execve(2)

> +.P
> +Each line in the file
> +.I /etc/tunables.conf
> +specifies a tunable,
> +which is specified with a string of the form
> +.IB name = value \f[R].\f[]
> +.P
> +The syntax allows lines to start with the keyword
> +.I include

s/I/B/  (since it's a literal, not a variable)


Have a lovely night!
Alex

> +followed by a
> +.BR \%glob (7)
> +pattern.
> +Files matching that pattern will be processed
> +as if their contents were included at that point.
> +.P
> +Each line may include zero or more keywords or symbols at the beginning,
> +which affect how each tunable affects each processes.
> +The keywords must be separated by whitespace,
> +but the symbols need not be.
> +.TP
> +.B overridable
> +.TQ
> +.B +
> +Allow the tunable to be overridden by the
> +.B GLIBC_TUNABLES
> +environment variable when the process runs
> +(this is the default).
> +.TP
> +.B nonoverridable
> +.TQ
> +.B \-
> +Do not allow the tunable to be overridden by the environment variable.
> +.TP
> +.B onlysecure
> +.TQ
> +.B @
> +The tunable applies only to
> +.B AT_SECURE
> +processes,
> +such as one started from a set-user-ID program,
> +or one with elevated capabilities.
> +.TP
> +.B nonsecure
> +.TQ
> +.B $
> +The tunable applies only to
> +.RB non- AT_SECURE
> +processes (this is the default).
> +.TP
> +.B anysecure
> +.TQ
> +.B *
> +The tunable applies to both
> +.B AT_SECURE
> +and
> +.RB non- AT_SECURE
> +processes.
> +.P
> +The file may also contain
> +.IR filters ,
> +which limit the tunables following it.
> +The effects of a filter are terminated by
> +any of the following:
> +.IP \[bu] 3
> +The end of the file.
> +.PD 0
> +.IP \[bu]
> +The end of an included file.
> +.IP \[bu]
> +An
> +.B include
> +directive.
> +.IP \[bu]
> +A new (possibly empty) filter.
> +.PD
> +.P
> +The syntax is:
> +.P
> +.in +4n
> +.EX
> +.BI [ filter : pattern ]
> +.EE
> +.in
> +.TP
> +.B proc
> +The
> +.B proc
> +filter limits the following tunables to processes
> +whose name matches the pattern.
> +The pattern may be an absolute path
> +or just the base name.
> +.P
> +A filter can also be empty:
> +.BR [] .
> +Such a filter has no effects.
> +.SH FILES
> +.TP
> +.I /etc/tunables.conf
> +.TP
> +.I /etc/ld.so.cache
> +cached copy of tunables
> +.SH EXAMPLES
> +Example configuration file:
> +.P
> +.in +4n
> +.EX
> +glibc.malloc.arenas_max=5
> +onlysecure glibc.malloc.arenas_max=1
> +\-glibc.pthread.rseq=1
> +[proc:/bin/bad.program]
> +\-glibc.pthread.rseq=0
> +[proc:some.program]
> +\-glibc.malloc.mmap_threshold=65536
> +.EE
> +.in
> +.SH SEE ALSO
> +.BR ld.so (8),
> +.BR ldconfig (8)
> -- 
> 2.47.3

-- 
<https://www.alejandro-colomar.es>
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCgAdFiEES7Jt9u9GbmlWADAi64mZXMKQwqkFAmp1BIEACgkQ64mZXMKQ
wqmjAQ/+PRHpheeJAbEylyfzg2/v1rWUiaK08+uLjmXEMNsvw8rN1NbgGH22ABDH
YJZVpvgjY+LdUysJ3bhC09rteNq4+8850GAt9C5MAirI8WpvrZdXE2uvFXpEiwd7
bGI++dW9/In1Cpa8qkf61teYQPIkV7tOAFzSkBUFfiPDz1+H2akLwVYHTYrvpzbM
ysKle8K1pR7Y4kqMw+dhLl84AnTkNA3bn8rZWggoOSNxpUhkNMwdRvjqLwfeu7Ho
WiF4+9GdL3PbkjrgqVVVWqFOJQNIH+MrGYE1P2iPZghtA1wk2e3nvSELbXoQUdrF
T4RAK1OqygXQAqVToTGdAMCTzaOGsdpx5eBXmB8bN7Sw/SkRUUlD0yXdxDaIchbM
9/RSXY8uXF8B5cWOPN4MZeaiH2W1jcW26/bAwA7X/hoYdZ/ilAzTmtj4U9bV6f+m
y17fiU7aRxbxMHUC/GCIeX5Sz5Af8t7A5pbKlUIOKTATRxmbcRWmPCmYmere4UMG
DmdlV/e6JJgL4/8+vzf6RsK55gR5ehjYTbha0T0z6EvJRHk3Jv69r6hX1v67Ncc6
2vhW4ggmh3egFFX70o//3H1MlzZ4Qd6JRtnwuiVmfMRrN0AAN+ZwKGjVoUa7de5k
73VdQ/ajJH063nQpm3tVNclDptu+tgxoCHpwGQlqsmg0IaiWJUY=
=UCB5
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.