{
    "mode": "man",
    "parameter": "proc_sys_fs",
    "section": "5",
    "url": "https://www.chedong.com/phpMan.php/man/proc_sys_fs/5/json",
    "generated": "2026-10-07T21:09:46Z",
    "sections": {
        "NAME": {
            "content": "/proc/sys/fs/ - kernel variables related to filesystems\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "/proc/sys/fs/\nThis  directory  contains the files and subdirectories for kernel variables related to\nfilesystems.\n\n/proc/sys/fs/aio-max-nr and /proc/sys/fs/aio-nr (since Linux 2.6.4)\naio-nr is the running total of the number of events specified by iosetup(2) calls for\nall currently active AIO contexts.  If aio-nr  reaches  aio-max-nr,  then  iosetup(2)\nwill fail with the error EAGAIN.  Raising aio-max-nr does not result in the prealloca‐\ntion or resizing of any kernel data structures.\n\n/proc/sys/fs/binfmtmisc\nDocumentation  for  files in this directory can be found in the Linux kernel source in\nthe    file    Documentation/admin-guide/binfmt-misc.rst     (or     in     Documenta‐\ntion/binfmtmisc.txt on older kernels).\n\n/proc/sys/fs/dentry-state (since Linux 2.2)\nThis  file contains information about the status of the directory cache (dcache).  The\nfile  contains  six  numbers,  nrdentry,  nrunused,  agelimit  (age  in   seconds),\nwantpages (pages requested by system) and two dummy values.\n\n•  nrdentry  is the number of allocated dentries (dcache entries).  This field is un‐\nused in Linux 2.2.\n\n•  nrunused is the number of unused dentries.\n\n•  agelimit is the age in seconds after which dcache entries can  be  reclaimed  when\nmemory is short.\n\n•  wantpages  is  nonzero  when  the  kernel has called shrinkdcachepages() and the\ndcache isn't pruned yet.\n\n/proc/sys/fs/dir-notify-enable\nThis file can be used to disable or enable the dnotify interface described in fcntl(2)\non a system-wide basis.  A value of 0 in this file disables the interface, and a value\nof 1 enables it.\n\n/proc/sys/fs/dquot-max\nThis file shows the maximum number of cached disk quota entries.  On some  (2.4)  sys‐\ntems,  it is not present.  If the number of free cached disk quota entries is very low\nand you have some awesome number of simultaneous system users, you might want to raise\nthe limit.\n\n/proc/sys/fs/dquot-nr\nThis file shows the number of allocated disk quota entries and the number of free disk\nquota entries.\n\n/proc/sys/fs/epoll/ (since Linux 2.6.28)\nThis directory contains the file maxuserwatches, which can  be  used  to  limit  the\namount  of  kernel  memory  consumed by the epoll interface.  For further details, see\nepoll(7).\n\n/proc/sys/fs/file-max\nThis file defines a system-wide limit on the number of open files for  all  processes.\nSystem  calls that fail when encountering this limit fail with the error ENFILE.  (See\nalso setrlimit(2), which can be used by  a  process  to  set  the  per-process  limit,\nRLIMITNOFILE, on the number of files it may open.)  If you get lots of error messages\nin the kernel log about running out of file handles (open file descriptions) (look for\n\"VFS: file-max limit <number> reached\"), try increasing this value:\n\necho 100000 > /proc/sys/fs/file-max\n\nPrivileged processes (CAPSYSADMIN) can override the file-max limit.\n\n/proc/sys/fs/file-nr\nThis  (read-only)  file  contains  three numbers: the number of allocated file handles\n(i.e., the number of open file descriptions; see open(2)); the  number  of  free  file\nhandles;   and   the  maximum  number  of  file  handles  (i.e.,  the  same  value  as\n/proc/sys/fs/file-max).  If the number of allocated file handles is close to the maxi‐\nmum, you should consider increasing the maximum.  Before Linux 2.6, the  kernel  allo‐\ncated  file handles dynamically, but it didn't free them again.  Instead the free file\nhandles were kept in a list for reallocation; the \"free file handles\" value  indicates\nthe size of that list.  A large number of free file handles indicates that there was a\npast peak in the usage of open file handles.  Since Linux 2.6, the kernel does deallo‐\ncate freed file handles, and the \"free file handles\" value is always zero.\n\n/proc/sys/fs/inode-max (only present until Linux 2.2)\nThis  file  contains the maximum number of in-memory inodes.  This value should be 3–4\ntimes larger than the value in file-max, since stdin, stdout and network sockets  also\nneed  an  inode to handle them.  When you regularly run out of inodes, you need to in‐\ncrease this value.\n\nStarting with Linux 2.4, there is no longer a static limit on the  number  of  inodes,\nand this file is removed.\n\n/proc/sys/fs/inode-nr\nThis file contains the first two values from inode-state.\n\n/proc/sys/fs/inode-state\nThis file contains seven numbers: nrinodes, nrfreeinodes, preshrink, and four dummy\nvalues (always zero).\n\nnrinodes is the number of inodes the system has allocated.  nrfreeinodes represents\nthe number of free inodes.\n\npreshrink  is nonzero when the nrinodes > inode-max and the system needs to prune the\ninode list instead of allocating more; since Linux 2.4, this field is  a  dummy  value\n(always zero).\n\n/proc/sys/fs/inotify/ (since Linux 2.6.13)\nThis    directory    contains   files   maxqueuedevents,   maxuserinstances,   and\nmaxuserwatches, that can be used to limit the amount of kernel  memory  consumed  by\nthe inotify interface.  For further details, see inotify(7).\n\n/proc/sys/fs/lease-break-time\nThis  file  specifies  the  grace period that the kernel grants to a process holding a\nfile lease (fcntl(2)) after it has sent a signal to that process notifying it that an‐\nother process is waiting to open the file.  If the lease holder  does  not  remove  or\ndowngrade the lease within this grace period, the kernel forcibly breaks the lease.\n\n/proc/sys/fs/leases-enable\nThis file can be used to enable or disable file leases (fcntl(2)) on a system-wide ba‐\nsis.  If this file contains the value 0, leases are disabled.  A nonzero value enables\nleases.\n\n/proc/sys/fs/mount-max (since Linux 4.9)\nThe  value  in  this  file  specifies the maximum number of mounts that may exist in a\nmount namespace.  The default value in this file is 100,000.\n\n/proc/sys/fs/mqueue/ (since Linux 2.6.6)\nThis directory contains files msgmax, msgsizemax, and  queuesmax,  controlling  the\nresources used by POSIX message queues.  See mqoverview(7) for details.\n\n/proc/sys/fs/nropen (since Linux 2.6.25)\nThis file imposes a ceiling on the value to which the RLIMITNOFILE resource limit can\nbe  raised  (see  getrlimit(2)).   This  ceiling is enforced for both unprivileged and\nprivileged process.  The default value in this file is 1048576.  (Before Linux 2.6.25,\nthe ceiling for RLIMITNOFILE was hard-coded to the same value.)\n\n/proc/sys/fs/overflowgid and /proc/sys/fs/overflowuid\nThese files allow you to change the value of the fixed UID and GID.   The  default  is\n65534.  Some filesystems support only 16-bit UIDs and GIDs, although in Linux UIDs and\nGIDs  are  32 bits.  When one of these filesystems is mounted with writes enabled, any\nUID or GID that would exceed 65535 is translated to the overflow  value  before  being\nwritten to disk.\n\n/proc/sys/fs/pipe-max-size (since Linux 2.6.35)\nSee pipe(7).\n\n/proc/sys/fs/pipe-user-pages-hard (since Linux 4.5)\nSee pipe(7).\n\n/proc/sys/fs/pipe-user-pages-soft (since Linux 4.5)\nSee pipe(7).\n\n/proc/sys/fs/protectedfifos (since Linux 4.19)\nThe value in this file is/can be set to one of the following:\n\n0   Writing to FIFOs is unrestricted.\n\n1   Don't allow OCREAT open(2) on FIFOs that the caller doesn't own in world-writable\nsticky directories, unless the FIFO is owned by the owner of the directory.\n\n2   As  for the value 1, but the restriction also applies to group-writable sticky di‐\nrectories.\n\nThe intent of the above protections is to avoid unintentional writes to  an  attacker-\ncontrolled FIFO when a program expected to create a regular file.\n\n/proc/sys/fs/protectedhardlinks (since Linux 3.6)\nWhen  the  value in this file is 0, no restrictions are placed on the creation of hard\nlinks (i.e., this is the historical behavior before Linux 3.6).   When  the  value  in\nthis file is 1, a hard link can be created to a target file only if one of the follow‐\ning conditions is true:\n\n•  The  calling  process  has  the CAPFOWNER capability in its user namespace and the\nfile UID has a mapping in the namespace.\n\n•  The filesystem UID of the process creating the link matches the owner (UID) of  the\ntarget file (as described in credentials(7), a process's filesystem UID is normally\nthe same as its effective UID).\n\n•  All of the following conditions are true:\n\n•  the target is a regular file;\n\n•  the target file does not have its set-user-ID mode bit enabled;\n\n•  the  target  file does not have both its set-group-ID and group-executable mode\nbits enabled; and\n\n•  the caller has permission to read and write the target  file  (either  via  the\nfile's permissions mask or because it has suitable capabilities).\n\nThe  default  value in this file is 0.  Setting the value to 1 prevents a longstanding\nclass of security issues caused by hard-link-based time-of-check,  time-of-use  races,\nmost  commonly  seen in world-writable directories such as /tmp.  The common method of\nexploiting this flaw is to cross privilege boundaries when following a given hard link\n(i.e., a root process follows a hard link created by another user).  Additionally,  on\nsystems  without  separated  partitions,  this stops unauthorized users from \"pinning\"\nvulnerable set-user-ID and set-group-ID files against being upgraded by  the  adminis‐\ntrator, or linking to special files.\n\n/proc/sys/fs/protectedregular (since Linux 4.19)\nThe value in this file is/can be set to one of the following:\n\n0   Writing to regular files is unrestricted.\n\n1   Don't allow OCREAT open(2) on regular files that the caller doesn't own in world-\nwritable  sticky directories, unless the regular file is owned by the owner of the\ndirectory.\n\n2   As for the value 1, but the restriction also applies to group-writable sticky  di‐\nrectories.\n\nThe  intent  of the above protections is similar to protectedfifos, but allows an ap‐\nplication to avoid writes to an attacker-controlled regular file, where  the  applica‐\ntion expected to create one.\n\n/proc/sys/fs/protectedsymlinks (since Linux 3.6)\nWhen  the  value  in  this file is 0, no restrictions are placed on following symbolic\nlinks (i.e., this is the historical behavior before Linux 3.6).   When  the  value  in\nthis file is 1, symbolic links are followed only in the following circumstances:\n\n•  the filesystem UID of the process following the link matches the owner (UID) of the\nsymbolic  link  (as described in credentials(7), a process's filesystem UID is nor‐\nmally the same as its effective UID);\n\n•  the link is not in a sticky world-writable directory; or\n\n•  the symbolic link and its parent directory have the same owner (UID)\n\nA system call that fails to follow a symbolic link because of the  above  restrictions\nreturns the error EACCES in errno.\n\nThe  default  value  in  this file is 0.  Setting the value to 1 avoids a longstanding\nclass of security issues based on time-of-check, time-of-use races when accessing sym‐\nbolic links.\n\n/proc/sys/fs/suiddumpable (since Linux 2.6.13)\nThe value in this file is assigned to a process's \"dumpable\" flag in the circumstances\ndescribed in prctl(2).  In effect, the value in this file determines whether core dump\nfiles are produced for  set-user-ID  or  otherwise  protected/tainted  binaries.   The\n\"dumpable\" setting also affects the ownership of files in a process's /proc/pid direc‐\ntory, as described above.\n\nThree different integer values can be specified:\n\n0 (default)\nThis  provides  the  traditional (pre-Linux 2.6.13) behavior.  A core dump will\nnot be produced for a process which has changed  credentials  (by  calling  se‐\nteuid(2),  setgid(2), or similar, or by executing a set-user-ID or set-group-ID\nprogram) or whose binary does not have read permission enabled.\n\n1 (\"debug\")\nAll processes dump core when possible.  (Reasons why a process might  neverthe‐\nless  not  dump  core are described in core(5).)  The core dump is owned by the\nfilesystem user ID of the dumping process and no security is applied.  This  is\nintended for system debugging situations only: this mode is insecure because it\nallows  unprivileged  users  to  examine  the  memory  contents  of  privileged\nprocesses.\n\n2 (\"suidsafe\")\nAny binary which normally would not be dumped (see \"0\" above) is  dumped  read‐\nable  by  root only.  This allows the user to remove the core dump file but not\nto read it.  For security reasons core dumps in this mode  will  not  overwrite\none  another  or other files.  This mode is appropriate when administrators are\nattempting to debug problems in a normal environment.\n\nAdditionally, since Linux 3.6, /proc/sys/kernel/corepattern must either be  an\nabsolute  pathname or a pipe command, as detailed in core(5).  Warnings will be\nwritten to the kernel log if corepattern does not follow these rules,  and  no\ncore dump will be produced.\n\nFor  details  of  the  effect  of a process's \"dumpable\" setting on ptrace access mode\nchecking, see ptrace(2).\n\n/proc/sys/fs/super-max\nThis file controls the maximum number of superblocks, and thus the maximum  number  of\nmounted filesystems the kernel can have.  You need increase only super-max if you need\nto mount more filesystems than the current value in super-max allows you to.\n\n/proc/sys/fs/super-nr\nThis file contains the number of filesystems currently mounted.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "proc(5), procsys(5)\n\nLinux man-pages 6.7                          2023-09-30                               procsysfs(5)",
            "subsections": []
        }
    },
    "summary": "/proc/sys/fs/ - kernel variables related to filesystems",
    "flags": [],
    "examples": [],
    "see_also": [
        {
            "name": "proc",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/proc/5/json"
        },
        {
            "name": "procsys",
            "section": "5",
            "url": "https://www.chedong.com/phpMan.php/man/procsys/5/json"
        }
    ]
}