Jump to content

Sysctl

From SameTeem
Revision as of 18:49, 6 August 2026 by Admin (talk | contribs) (→A note on EAC)
(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)

The sysctl file is somewhat similar to the registry on Windows, apart from it's just a simple text file to edit system settings,

You can set any of the below options temporarily (until the next reboot), by running "sysctl -w kernel.yama.ptrace_scope=1". Use this to test options before you commit them to a permanent file.

To permanently save any changes you make you can edit /etc/sysctl.conf and save the file, the file will be read on every boot, or you can load it instantly by running "sysctl -p"

sudo nano /etc/sysctl.conf

A note on EAC (Easy Anti Cheat)

If you search for tips for sysctl tweaks/security improvements you will often find something a recommendation of

kernel.yama.ptrace_scope=2 

This will break EAC and stop any EAC game from starting on Linux, the highest you can set this is 1 if you want EAC games to work.

Memory Tweaks

Keep more data in RAM instead of swapping to disk, make the system more responsive, especially if your swap (paging file in Windows terminology) file/partition is on a hard disk drive.

vm.swappiness=1

Network

Enable BBR (https://en.wikipedia.org/wiki/TCP_congestion_control#TCP_BBR) Greater top speeds and more reliable, especially for higher latency connections like 3/4/5G and satellite.

net.core.default_qdisc = cake 
net.ipv4.tcp_congestion_control = bbr

Allow more packets to be queued up before the system drops them, pretty much required for Gigabit+ connections

net.core.netdev_max_backlog=16384

Allow more connections to be queued on the system, good for programs that establish a lot of connections, such as P2P applications.

net.core.somaxconn=8192

Verify IP packet sources, this will potentially save you from very small DDoS attacks, but it wont save you if the traffic is more than your connection an handle.

net.ipv4.conf.all.rp_filter=1 
net.ipv4.conf.default.rp_filter=1 

Misc

Set a timer so the system will actually reboot once a kernel panic (BSOD/Bug Check) happens, this can be set as low as you like if you want to just reboot instantly, but 60 seconds allows the kernel watchdog to possibly recover the system if it's just something using all the CPU time.

kernel.panic=60