All of lore.kernel.org
 help / color / mirror / Atom feed
From: Alejandro Colomar <alx@kernel.org>
To: DJ Delorie <dj@redhat.com>
Cc: linux-man@vger.kernel.org
Subject: Re: [PATCH v5 2/4] man/man5/tunables.conf: Document system-wide tunables config
Date: Fri, 7 Aug 2026 00:02:47 +0200	[thread overview]
Message-ID: <anUAwb8lY_u7eU3F@devuan> (raw)
In-Reply-To: <xnzeyz2d3l.fsf@greed.delorie.com>

[-- Attachment #1: Type: text/plain, Size: 4944 bytes --]

Hi DJ,

> Date: 2026-08-06 16:44:30-0400
> From: DJ Delorie <dj@redhat.com>
>
> 
> ---

You forgot to sign.

>  man/man5/tunables.conf.5 | 145 +++++++++++++++++++++++++++++++++++++++
>  1 file changed, 145 insertions(+)
>  create mode 100644 man/man5/tunables.conf.5
> 
> diff --git a/man/man5/tunables.conf.5 b/man/man5/tunables.conf.5
> new file mode 100644
> index 000000000..29beeb8f8
> --- /dev/null
> +++ b/man/man5/tunables.conf.5
> @@ -0,0 +1,145 @@
> +.TH tunables.conf 5 (date) "Linux man-pages (unreleased)"
> +.SH NAME
> +tunables.conf \- tunables configuration file
> +.SH SYNOPSIS
> +.nf
> +.B /etc/tunables.conf
> +.fi
> +.SH DESCRIPTION
> +Tunables are a feature in the GNU C Library
> +that allows application authors and distribution maintainers
> +to alter the runtime library behavior to match their workload.
> +For a list of supported tunables,
> +please consult the glibc manual
> +that corresponds to your installed version of glibc,
> +or run the following command:
> +.P
> +.in +4n
> +.EX
> +ld.so \-\-list\-tunables
> +.EE
> +.P
> +The file is parsed by
> +.BR \%ldconfig (8)
> +and the results stored in
> +.IR /etc/ld.so.cache .
> +The resulting data is read when a new process is created by
> +.IR ld.so .

Sorry for noticing this in v4; I forgot about it.  I see this unresolved
issue from earlier versions remains.

ld.so(8) runs when a new program is executed --execve(2)--, not when
a new process is created --fork(2)--, AFAIK.

	alx@devuan:~$ MANWIDTH=64 man fork | grep ld.so
	alx@devuan:~$ MANWIDTH=64 man execve | grep -C2 ld.so
	     If the executable is an a.out  dynamically  linked  binary
	     executable  containing shared‐library stubs, the Linux dy‐
	     namic linker ld.so(8) is called at the start of  execution
	     to  bring  needed  shared objects into memory and link the
	     executable with them.
	--
	     ptrace(2), exec(3), fexecve(3),  getauxval(3),  getopt(3),
	     system(3),  capabilities(7),  credentials(7),  environ(7),
	     path_resolution(7), ld.so(8)

	Linux man‐pages 6.18‐18... 2026‐02‐08                 execve(2)

> +.P
> +Each line in the file
> +.I /etc/tunables.conf
> +specifies a tunable,
> +which is specified with a string of the form
> +.IB name = value \f[R].\f[]
> +.P
> +The syntax allows lines to start with the keyword
> +.I include

s/I/B/  (since it's a literal, not a variable)


Have a lovely night!
Alex

> +followed by a
> +.BR \%glob (7)
> +pattern.
> +Files matching that pattern will be processed
> +as if their contents were included at that point.
> +.P
> +Each line may include zero or more keywords or symbols at the beginning,
> +which affect how each tunable affects each processes.
> +The keywords must be separated by whitespace,
> +but the symbols need not be.
> +.TP
> +.B overridable
> +.TQ
> +.B +
> +Allow the tunable to be overridden by the
> +.B GLIBC_TUNABLES
> +environment variable when the process runs
> +(this is the default).
> +.TP
> +.B nonoverridable
> +.TQ
> +.B \-
> +Do not allow the tunable to be overridden by the environment variable.
> +.TP
> +.B onlysecure
> +.TQ
> +.B @
> +The tunable applies only to
> +.B AT_SECURE
> +processes,
> +such as one started from a set-user-ID program,
> +or one with elevated capabilities.
> +.TP
> +.B nonsecure
> +.TQ
> +.B $
> +The tunable applies only to
> +.RB non- AT_SECURE
> +processes (this is the default).
> +.TP
> +.B anysecure
> +.TQ
> +.B *
> +The tunable applies to both
> +.B AT_SECURE
> +and
> +.RB non- AT_SECURE
> +processes.
> +.P
> +The file may also contain
> +.IR filters ,
> +which limit the tunables following it.
> +The effects of a filter are terminated by
> +any of the following:
> +.IP \[bu] 3
> +The end of the file.
> +.PD 0
> +.IP \[bu]
> +The end of an included file.
> +.IP \[bu]
> +An
> +.B include
> +directive.
> +.IP \[bu]
> +A new (possibly empty) filter.
> +.PD
> +.P
> +The syntax is:
> +.P
> +.in +4n
> +.EX
> +.BI [ filter : pattern ]
> +.EE
> +.in
> +.TP
> +.B proc
> +The
> +.B proc
> +filter limits the following tunables to processes
> +whose name matches the pattern.
> +The pattern may be an absolute path
> +or just the base name.
> +.P
> +A filter can also be empty:
> +.BR [] .
> +Such a filter has no effects.
> +.SH FILES
> +.TP
> +.I /etc/tunables.conf
> +.TP
> +.I /etc/ld.so.cache
> +cached copy of tunables
> +.SH EXAMPLES
> +Example configuration file:
> +.P
> +.in +4n
> +.EX
> +glibc.malloc.arenas_max=5
> +onlysecure glibc.malloc.arenas_max=1
> +\-glibc.pthread.rseq=1
> +[proc:/bin/bad.program]
> +\-glibc.pthread.rseq=0
> +[proc:some.program]
> +\-glibc.malloc.mmap_threshold=65536
> +.EE
> +.in
> +.SH SEE ALSO
> +.BR ld.so (8),
> +.BR ldconfig (8)
> -- 
> 2.47.3

-- 
<https://www.alejandro-colomar.es>

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 833 bytes --]

  reply	other threads:[~2026-08-06 22:02 UTC|newest]

Thread overview: 9+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-06 20:44 [PATCH v5 2/4] man/man5/tunables.conf: Document system-wide tunables config DJ Delorie
2026-08-06 22:02 ` Alejandro Colomar [this message]
2026-08-06 22:15   ` DJ Delorie
2026-08-07  0:06     ` Alejandro Colomar
2026-08-07  0:11       ` Alejandro Colomar
2026-08-07  0:15         ` Alejandro Colomar
2026-08-07  3:25       ` DJ Delorie
2026-08-07 22:36         ` Alejandro Colomar
2026-08-08  3:08           ` DJ Delorie

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=anUAwb8lY_u7eU3F@devuan \
    --to=alx@kernel.org \
    --cc=dj@redhat.com \
    --cc=linux-man@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.