Home / Alt manpages / proc_sys_kernel(5)

  • proc_sys_kernel(5)
  • File format
  • linux

Read and Safely Change Linux Kernel Settings in /proc/sys/kernel

You will finish with a small workflow for inspecting files under /proc/sys/kernel, making one reversible runtime change, and checking that the kernel accepted it. The examples are based on proc_sys_kernel(5) from the locally installed Linux man-pages package, version 6.7-2, and run against a Linux 6.8 kernel.

Allow about ten minutes. You need a shell for the read-only steps. The write step needs elevated privileges and changes live kernel behaviour, so use it on a test host or during a maintenance window. A value written to procfs is a runtime change; this guide does not claim that it survives a reboot or supplies a persistent configuration file.

Checkpoint: keep the original value before changing anything. That gives you an exact undo value rather than relying on memory or an assumed default.

1. Confirm the files and read their current values

Start by listing the directory and reading a few named entries. These commands only read state and do not need root:

$ printf '%s\n' /proc/sys/kernel/{randomize_va_space,dmesg_restrict,kptr_restrict,pid_max,threads-max}
/proc/sys/kernel/randomize_va_space
/proc/sys/kernel/dmesg_restrict
/proc/sys/kernel/kptr_restrict
/proc/sys/kernel/pid_max
/proc/sys/kernel/threads-max
$ for name in randomize_va_space dmesg_restrict kptr_restrict pid_max threads-max; do
    printf '%s = ' "$name"
    cat "/proc/sys/kernel/$name"
  done
randomize_va_space = 2
dmesg_restrict = 1
kptr_restrict = 1
pid_max = 4194304
threads-max = 254384

Your output will vary with the kernel configuration, available memory, boot parameters and other runtime changes. A missing file is not automatically an error in your command: some entries are conditional on kernel configuration, architecture or features. For example, modules_disabled is present only when the kernel has module support.

The directory is a collection of different controls, not one uniform settings file. Some entries are read-only, some accept numbers, and others contain several values or strings. Read the relevant entry in the manpage before writing it.

2. Choose a setting with a clear contract

For a controlled demonstration, use randomize_va_space. The manpage documents three values on architectures that support address space layout randomisation:

  • 0 disables ASLR.
  • 1 randomises mmap allocations, the stack, the VDSO page and suitable shared-library and PIE addresses.
  • 2 also randomises the heap and is the usual default when the kernel was not configured with CONFIG_COMPAT_BRK.

Do not use 0 as a casual test value. Disabling ASLR weakens a security mitigation and may affect programs that expect normal hardening. We will use the documented value 1, then restore the exact value captured from this machine.

Save the current value in a shell variable and check it is one of the documented values:

$ original_aslr=$(cat /proc/sys/kernel/randomize_va_space)
$ case "$original_aslr" in
    0|1|2) printf 'original randomize_va_space = %s\n' "$original_aslr" ;;
    *) printf 'unexpected value: %s\n' "$original_aslr" >&2; exit 1 ;;
  esac
original randomize_va_space = 2

Checkpoint: if the value is not 0, 1 or 2, stop. Do not guess what an undocumented value means.

3. Make the temporary runtime change

Writing directly to the procfs file requires elevated privileges. This command changes the live kernel setting until you restore it or the system is rebooted:

$ printf '%s\n' 1 | sudo tee /proc/sys/kernel/randomize_va_space
1

tee performs the write with root privileges supplied by sudo. A command such as sudo printf '%s\n' 1 > /proc/sys/kernel/randomize_va_space is a common trap: the shell opens the redirection before sudo runs, so the write can still fail with permission denied.

Do not continue if the command reports an error. A rejected write leaves the previous value in place, but the reason may be a read-only entry, an invalid value, missing privilege or a kernel-specific restriction.

4. Verify the value and restore it

Read the file again immediately after the write. The output should be the value you requested:

$ cat /proc/sys/kernel/randomize_va_space
1

Now restore the saved value. This is the recovery step and needs the same elevated privilege:

$ printf '%s\n' "$original_aslr" | sudo tee /proc/sys/kernel/randomize_va_space
2
$ test "$(cat /proc/sys/kernel/randomize_va_space)" = "$original_aslr" && printf '%s\n' 'ASLR setting restored'
ASLR setting restored

If your shell session no longer contains original_aslr, read the current value first and decide whether it is the value you intend to preserve. Do not blindly write 2; the machine may have been deliberately configured with another documented value.

The setting affects how new process address spaces are laid out. It is not a command to restart existing processes, and reading the file does not prove that every process has the same layout. Treat it as a kernel policy input, not as an application-level health check.

5. Handle the other common entries carefully

The same read, record, write and verify pattern applies to other entries, but their consequences differ:

  • dmesg_restrict controls access to kernel log contents. A value of 1 restricts reads to privileged users. Lowering it can disclose sensitive diagnostic information, so do not use that as a harmless connectivity test.
  • kptr_restrict controls exposure of kernel addresses printed with the %pK format. The manpage documents values 0, 1 and 2 with different capability rules. Keep the existing value unless you have a specific diagnostic reason.
  • pid_max sets the point at which process IDs wrap and also acts as a system-wide process and thread limit. Raising or lowering it is a capacity decision, not a cosmetic tweak.
  • threads-max limits the number of tasks. Linux bounds accepted values against a minimum, a maximum and available memory, so a write can be rejected or constrained by the kernel.
  • modules_disabled is deliberately one-way once set to 1. The manpage says modules can then be neither loaded nor unloaded and the toggle cannot return to 0. Never experiment with it on a working host.

Some files have special formats. printk contains four values, sem contains four System V semaphore limits, and sysrq uses either a special value or a bit mask. Do not apply a single-number command to those entries without reading their individual documentation.

6. Know what this workflow does not cover

This guide changes procfs state directly. It does not configure boot parameters, edit a service manager, or arrange for a value to be reapplied at boot. If you need persistence, choose a configuration mechanism supported by your distribution and document the desired value separately. Test the runtime write first, then verify persistence after a controlled reboot.

Also distinguish a missing path from a failed write. The manpage marks several entries as architecture-specific, version-specific or dependent on kernel configuration. For example, auto_msgmni is retained for compatibility but has had no effect since Linux 3.19, while cap-bound describes a system-wide interface only on much older kernels. Check the installed manpage and the running kernel before copying advice from an older host.

Done means

  • You read the exact file you intended to change.
  • You checked the documented value range and recorded the original value.
  • You used elevated privileges only for the write.
  • You verified the new runtime value.
  • You restored the original value, or recorded why the change is intentionally being kept.
  • You have not assumed that a procfs write is persistent across reboot.