3 ms·
> I once suggested "cgroup'ing" (loosely speaking) the entire system into two rough buckets: one for SSH, with enough dedicated RAM that ssh will never get swap
by secure 7y ago
> I once suggested "cgroup'ing" (loosely speaking) the entire system into two rough buckets: one for SSH, with enough dedicated RAM that ssh will never get swapped, and one for everything else.
You can use memlockd for that: https://manpages.debian.org/buster/memlockd/memlockd.8.en.html https://manpages.debian.org/buster/memlockd/memlockd.8.en.ht...
- aardvarklegend 7y agoSorry, but that’s not enough. You need more ram to actually make the ssh connection useful. You can lock sshd and then be blocked from running your shell or any commands in that shell. You really do need reserved unused memory.
- Godel_unicode 7y agoThis approaches understanding why this isn't done; it's not just reserved memory for SSH, it's reserved memory for SSH plus bash plus the vim, top, grep, kill, etc commands you'll be running once you SSH. How much RAM does top need? What about vim? Now realize you're imposing this penalty on every embedded, low-memory Linux device which might not ever have this problem.
- Dylan16807 7y agoBut for the actual goal you don't have to reserve it as empty, you just have to prioritize it.
- pixl97 7y agoWhy would you be imposing this on every device when I would assume it would be controlled by a settings file in /etc
- kevin_thibedeau 7y agoLinux was quite usable in 4MiB 25 years ago. Just give yourself a minimal busybox environment for rescue activities.