|
@@ -33,6 +33,7 @@ show up in /proc/sys/kernel:
|
|
|
- domainname
|
|
|
- hostname
|
|
|
- hotplug
|
|
|
+- kexec_load_disabled
|
|
|
- kptr_restrict
|
|
|
- kstack_depth_to_print [ X86 only ]
|
|
|
- l2cr [ PPC only ]
|
|
@@ -287,6 +288,18 @@ Default value is "/sbin/hotplug".
|
|
|
|
|
|
==============================================================
|
|
|
|
|
|
+kexec_load_disabled:
|
|
|
+
|
|
|
+A toggle indicating if the kexec_load syscall has been disabled. This
|
|
|
+value defaults to 0 (false: kexec_load enabled), but can be set to 1
|
|
|
+(true: kexec_load disabled). Once true, kexec can no longer be used, and
|
|
|
+the toggle cannot be set back to false. This allows a kexec image to be
|
|
|
+loaded before disabling the syscall, allowing a system to set up (and
|
|
|
+later use) an image without it being altered. Generally used together
|
|
|
+with the "modules_disabled" sysctl.
|
|
|
+
|
|
|
+==============================================================
|
|
|
+
|
|
|
kptr_restrict:
|
|
|
|
|
|
This toggle indicates whether restrictions are placed on
|
|
@@ -331,7 +344,7 @@ A toggle value indicating if modules are allowed to be loaded
|
|
|
in an otherwise modular kernel. This toggle defaults to off
|
|
|
(0), but can be set true (1). Once true, modules can be
|
|
|
neither loaded nor unloaded, and the toggle cannot be set back
|
|
|
-to false.
|
|
|
+to false. Generally used with the "kexec_load_disabled" toggle.
|
|
|
|
|
|
==============================================================
|
|
|
|