Sysctl: Difference between revisions
No edit summary |
|||
| (3 intermediate revisions by the same user not shown) | |||
| Line 1: | Line 1: | ||
The sysctl file is somewhat similar to the registry on Windows, apart from it's just a simple text file to edit system settings, | |||
You can set any of the below options temporarily (until the next reboot), by running "sysctl -w kernel.yama.ptrace_scope=1". Use this to test options before you commit them to a permanent file. | |||
To permanently save any changes you make you can edit /etc/sysctl.conf and save the file, the file will be read on every boot, or you can load it instantly by running "sysctl -p" | |||
sudo [[nano]] /etc/sysctl.conf | sudo [[nano]] /etc/sysctl.conf | ||
== A note on EAC == | == A note on EAC (Easy Anti Cheat) == | ||
If you search for tips for sysctl tweaks/security improvements you will often find something a recommendation of | If you search for tips for sysctl tweaks/security improvements you will often find something a recommendation of | ||
kernel.yama.ptrace_scope=2 | kernel.yama.ptrace_scope=2 | ||
This will break EAC and stop any EAC game from starting on Linux, the highest you can set | This will break EAC and stop any EAC game from starting on Linux, the highest you can set this is 1 if you want EAC games to work. | ||
== Memory Tweaks == | == Memory Tweaks == | ||
| Line 23: | Line 27: | ||
Allow more connections to be queued on the system, good for programs that establish a lot of connections, such as P2P applications. | Allow more connections to be queued on the system, good for programs that establish a lot of connections, such as P2P applications. | ||
net.core.somaxconn=8192 | net.core.somaxconn=8192 | ||
Verify IP packet sources, this will potentially save you from very small DDoS attacks, but it wont save you if the traffic is more than your connection an handle. | |||
net.ipv4.conf.all.rp_filter=1 | |||
net.ipv4.conf.default.rp_filter=1 | |||
== Misc == | == Misc == | ||
Set a timer so the system will actually reboot once a kernel panic (BSOD/Bug Check) happens, this can be set as low as you like if you want to just reboot instantly, but 60 seconds allows the kernel watchdog to possibly recover the system if it's just something using all the CPU time. | Set a timer so the system will actually reboot once a kernel panic (BSOD/Bug Check) happens, this can be set as low as you like if you want to just reboot instantly, but 60 seconds allows the kernel watchdog to possibly recover the system if it's just something using all the CPU time. | ||
kernel.panic=60 | kernel.panic=60 | ||
Latest revision as of 18:49, 6 August 2026
The sysctl file is somewhat similar to the registry on Windows, apart from it's just a simple text file to edit system settings,
You can set any of the below options temporarily (until the next reboot), by running "sysctl -w kernel.yama.ptrace_scope=1". Use this to test options before you commit them to a permanent file.
To permanently save any changes you make you can edit /etc/sysctl.conf and save the file, the file will be read on every boot, or you can load it instantly by running "sysctl -p"
sudo nano /etc/sysctl.conf
A note on EAC (Easy Anti Cheat)
If you search for tips for sysctl tweaks/security improvements you will often find something a recommendation of
kernel.yama.ptrace_scope=2
This will break EAC and stop any EAC game from starting on Linux, the highest you can set this is 1 if you want EAC games to work.
Memory Tweaks
Keep more data in RAM instead of swapping to disk, make the system more responsive, especially if your swap (paging file in Windows terminology) file/partition is on a hard disk drive.
vm.swappiness=1
Network
Enable BBR (https://en.wikipedia.org/wiki/TCP_congestion_control#TCP_BBR) Greater top speeds and more reliable, especially for higher latency connections like 3/4/5G and satellite.
net.core.default_qdisc = cake net.ipv4.tcp_congestion_control = bbr
Allow more packets to be queued up before the system drops them, pretty much required for Gigabit+ connections
net.core.netdev_max_backlog=16384
Allow more connections to be queued on the system, good for programs that establish a lot of connections, such as P2P applications.
net.core.somaxconn=8192
Verify IP packet sources, this will potentially save you from very small DDoS attacks, but it wont save you if the traffic is more than your connection an handle.
net.ipv4.conf.all.rp_filter=1 net.ipv4.conf.default.rp_filter=1
Misc
Set a timer so the system will actually reboot once a kernel panic (BSOD/Bug Check) happens, this can be set as low as you like if you want to just reboot instantly, but 60 seconds allows the kernel watchdog to possibly recover the system if it's just something using all the CPU time.
kernel.panic=60