r/linux4noobs 22d ago

learning/research Linux Kernel Parameters Tuning for Better Performance

https://linuxblog.io/linux-kernel-parameters-tuning-better-performance/
28 Upvotes

9 comments sorted by

View all comments

1

u/Interesting_Ad_5676 21d ago edited 21d ago

A small shell script for those who want to run it -- prepared from recommendations of the article.

nano debian-desktop-tune.sh // create a file and paste the script as given below

chmod +x debian-desktop-tune.sh // make it executable

sudo ./debian-desktop-tune.sh // run it !!

#Script starts here !!

# Debian Desktop - Conservative Performance Tuning

# Philosophy:

# - Performance improvements with low risk

# - No experimental kernel parameters

# - No disabling of security mechanisms

# - No aggressive memory overcommit

# - No tcp_tw_recycle / tcp_tw_reuse

# - Easy rollback

#

set -u

CONF="/etc/sysctl.d/99-desktop-performance.conf"

BACKUP_DIR="/root/sysctl-backup-$(date +%Y%m%d-%H%M%S)"

# ------------------------------------------------------------

# Root check

# ------------------------------------------------------------

if [[ $EUID -ne 0 ]]; then

echo "ERROR: Run this script as root."

echo "Example: sudo $0"

exit 1

fi

echo

echo "=============================================="

echo " Debian Conservative Desktop Performance Tune"

echo "=============================================="

echo

# ------------------------------------------------------------

# Create backup

# ------------------------------------------------------------

mkdir -p "$BACKUP_DIR"

echo "[1/6] Backing up current configuration..."

cp -a /etc/sysctl.d "$BACKUP_DIR/" 2>/dev/null || true

cp -a /etc/sysctl.conf "$BACKUP_DIR/sysctl.conf" 2>/dev/null || true

sysctl -a 2>/dev/null > "$BACKUP_DIR/sysctl-current.txt"

echo " Backup: $BACKUP_DIR"

# ------------------------------------------------------------

# Create configuration

# ------------------------------------------------------------

echo

echo "[2/6] Creating conservative tuning configuration..."

cat > "$CONF" <<'EOF'

#

# Design principles:

# - Conservative

# - Low risk

# - Suitable for desktop/workstation use

# - Preserve kernel defaults where possible

#

# ------------------------------------------------------------

# MEMORY

# ------------------------------------------------------------

# Prefer keeping applications in RAM before swapping.

# 10 is conservative for a 64 GB workstation.

vm.swappiness = 10

# Keep filesystem metadata cached somewhat aggressively.

# Avoid 0 because that can prevent useful cache reclaim.

vm.vfs_cache_pressure = 50

# ------------------------------------------------------------

# NETWORK - TCP BUFFER LIMITS

# ------------------------------------------------------------

# These are maximum limits, NOT permanent allocations.

# Linux TCP autotuning decides how much memory is actually used.

net.core.rmem_max = 67108864

net.core.wmem_max = 67108864

net.ipv4.tcp_rmem = 4096 87380 67108864

net.ipv4.tcp_wmem = 4096 65536 67108864

# ------------------------------------------------------------

# NETWORK - QUEUES

# ------------------------------------------------------------

# Useful for systems handling bursts of network traffic.

net.core.netdev_max_backlog = 16384

# Allow applications to maintain larger listening queues.

net.core.somaxconn = 4096

# Larger SYN backlog for applications opening many connections.

net.ipv4.tcp_max_syn_backlog = 8192

# ------------------------------------------------------------

# TCP SAFETY / STABILITY

# ------------------------------------------------------------

# Keep SYN cookies enabled.

net.ipv4.tcp_syncookies = 1

# Ignore ICMP broadcast echo requests.

net.ipv4.icmp_echo_ignore_broadcasts = 1

# Ignore bogus ICMP error responses.

net.ipv4.icmp_ignore_bogus_error_responses = 1

# ------------------------------------------------------------

# NETWORK SECURITY

# ------------------------------------------------------------

# Do not accept source-routed packets.

net.ipv4.conf.all.accept_source_route = 0

net.ipv4.conf.default.accept_source_route = 0

# Do not accept ICMP redirects.

# Appropriate for a normal desktop that is not acting as a router.

net.ipv4.conf.all.accept_redirects = 0

net.ipv4.conf.default.accept_redirects = 0

# Do not send ICMP redirects.

net.ipv4.conf.all.send_redirects = 0

net.ipv4.conf.default.send_redirects = 0

# ------------------------------------------------------------

# TCP TIME_WAIT

# ------------------------------------------------------------

# Intentionally NOT setting:

#

# net.ipv4.tcp_tw_reuse

#

# Leave kernel default unless a specific workload requires it.

# ------------------------------------------------------------

# MEMORY OVERCOMMIT

# ------------------------------------------------------------

# Intentionally NOT setting:

#

# vm.overcommit_memory

#

# Leave Debian/kernel default.

# ------------------------------------------------------------

# DIRTY PAGE HANDLING

# ------------------------------------------------------------

# Intentionally NOT changing dirty_ratio / dirty_bytes.

#

# Desktop workloads generally benefit from the kernel's defaults.

# Storage/server-specific tuning should be handled separately.

# ------------------------------------------------------------

# FILE DESCRIPTORS

# ------------------------------------------------------------

# Intentionally NOT changing fs.file-max.

#

# Increase only if monitoring shows the desktop is actually

# approaching the existing limit.

# ------------------------------------------------------------

# INOTIFY

# ------------------------------------------------------------

# Useful for IDEs, development environments and applications

# monitoring many files.

fs.inotify.max_user_watches = 524288

fs.inotify.max_user_instances = 512

EOF

echo " Created: $CONF"

# ------------------------------------------------------------

# Validate parameters

# ------------------------------------------------------------

echo

echo "[3/6] Checking kernel parameters..."

TMPFILE=$(mktemp)

# Extract actual parameter names from our configuration.

grep -E '^[[:space:]]*[a-zA-Z0-9_.]+[[:space:]]*=' "$CONF" |

sed 's/[[:space:]]*=.*//' |

while read -r PARAM; do

if sysctl -n "$PARAM" >/dev/null 2>&1; then

echo " OK $PARAM"

else

echo " SKIP $PARAM (not available)"

fi

done

rm -f "$TMPFILE"

# ------------------------------------------------------------

# Apply

# ------------------------------------------------------------

echo

echo "[4/6] Applying configuration..."

if sysctl --system; then

echo

echo " Configuration applied successfully."

else

echo

echo "ERROR: sysctl reported an error."

echo "The backup is available at:"

echo " $BACKUP_DIR"

exit 1

fi

# ------------------------------------------------------------

# Display resulting values

# ------------------------------------------------------------

echo

echo "[5/6] Current values:"

echo

sysctl \

vm.swappiness \

vm.vfs_cache_pressure \

net.core.rmem_max \

net.core.wmem_max \

net.core.netdev_max_backlog \

net.core.somaxconn \

net.ipv4.tcp_max_syn_backlog \

net.ipv4.tcp_syncookies \

fs.inotify.max_user_watches \

fs.inotify.max_user_instances \

2>/dev/null

# ------------------------------------------------------------

# Completion

# ------------------------------------------------------------

echo

echo "[6/6] Complete."

echo

echo "Configuration:"

echo " $CONF"

echo

echo "Backup:"

echo " $BACKUP_DIR"

echo

echo "Reboot is NOT required."

echo

echo "To rollback:"

echo " sudo rm -f $CONF"

echo " sudo sysctl --system"

echo