€•ÓEŒsphinx.addnodes”Œdocument”“”)”}”(Œ rawsource”Œ”Œchildren”]”(Œ translations”Œ LanguagesNode”“”)”}”(hhh]”(hŒ pending_xref”“”)”}”(hhh]”Œdocutils.nodes”ŒText”“”ŒChinese (Simplified)”…””}”Œparent”hsbaŒ attributes”}”(Œids”]”Œclasses”]”Œnames”]”Œdupnames”]”Œbackrefs”]”Œ refdomain”Œstd”Œreftype”Œdoc”Œ reftarget”Œ&/translations/zh_CN/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuŒtagname”hhh ubh)”}”(hhh]”hŒChinese (Traditional)”…””}”hh2sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ&/translations/zh_TW/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)”}”(hhh]”hŒItalian”…””}”hhFsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ&/translations/it_IT/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)”}”(hhh]”hŒJapanese”…””}”hhZsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ&/translations/ja_JP/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)”}”(hhh]”hŒKorean”…””}”hhnsbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ&/translations/ko_KR/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)”}”(hhh]”hŒPortuguese (Brazilian)”…””}”hh‚sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ&/translations/pt_BR/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubh)”}”(hhh]”hŒSpanish”…””}”hh–sbah}”(h]”h ]”h"]”h$]”h&]”Œ refdomain”h)Œreftype”h+Œ reftarget”Œ&/translations/sp_SP/filesystems/failfs”Œmodname”NŒ classname”NŒ refexplicit”ˆuh1hhh ubeh}”(h]”h ]”h"]”h$]”h&]”Œcurrent_language”ŒEnglish”uh1h hhŒ _document”hŒsource”NŒline”NubhŒcomment”“”)”}”(hŒ SPDX-License-Identifier: GPL-2.0”h]”hŒ SPDX-License-Identifier: GPL-2.0”…””}”hh·sbah}”(h]”h ]”h"]”h$]”h&]”Œ xml:space”Œpreserve”uh1hµhhh²hh³Œ@/var/lib/git/docbuild/linux/Documentation/filesystems/failfs.rst”h´KubhŒsection”“”)”}”(hhh]”(hŒtitle”“”)”}”(hŒfailfs”h]”hŒfailfs”…””}”(hhÏh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhhÊh²hh³hÇh´KubhŒ paragraph”“”)”}”(hX/failfs is a kernel-internal filesystem that fails every operation reaching it with ``EOPNOTSUPP``. It is the counterpart to nullfs. Where nullfs is permanently empty, failfs means "nothing is supported here". It cannot be mounted from userspace, nothing can be mounted on top of it. It cannot be cloned.”h]”(hŒSfailfs is a kernel-internal filesystem that fails every operation reaching it with ”…””}”(hhßh²hh³Nh´NubhŒliteral”“”)”}”(hŒ``EOPNOTSUPP``”h]”hŒ EOPNOTSUPP”…””}”(hhéh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhhßubhŒÒ. It is the counterpart to nullfs. Where nullfs is permanently empty, failfs means “nothing is supported hereâ€. It cannot be mounted from userspace, nothing can be mounted on top of it. It cannot be cloned.”…””}”(hhßh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhhÊh²hubhÞ)”}”(hŒ€The only way into it is the ``FD_FAILFS_ROOT`` file descriptor sentinel which is understood by ``fchdir(2)`` and ``fchroot(2)``.”h]”(hŒThe only way into it is the ”…””}”(hjh²hh³Nh´Nubhè)”}”(hŒ``FD_FAILFS_ROOT``”h]”hŒFD_FAILFS_ROOT”…””}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjubhŒ1 file descriptor sentinel which is understood by ”…””}”(hjh²hh³Nh´Nubhè)”}”(hŒ ``fchdir(2)``”h]”hŒ fchdir(2)”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjubhŒ and ”…””}”(hjh²hh³Nh´Nubhè)”}”(hŒ``fchroot(2)``”h]”hŒ fchroot(2)”…””}”(hj-h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjubhŒ.”…””}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K hhÊh²hubhÉ)”}”(hhh]”(hÎ)”}”(hŒ Semantics”h]”hŒ Semantics”…””}”(hjHh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhjEh²hh³hÇh´KubhÞ)”}”(hŒyEvery path walk of a component through failfs fails with ``EOPNOTSUPP`` before that component is parsed, including ``.``.”h]”(hŒ9Every path walk of a component through failfs fails with ”…””}”(hjVh²hh³Nh´Nubhè)”}”(hŒ``EOPNOTSUPP``”h]”hŒ EOPNOTSUPP”…””}”(hj^h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjVubhŒ, before that component is parsed, including ”…””}”(hjVh²hh³Nh´Nubhè)”}”(hŒ``.``”h]”hŒ.”…””}”(hjph²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjVubhŒ.”…””}”(hjVh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhjEh²hubhÞ)”}”(hŒ;No path lookup can open the root, not even with ``O_PATH``.”h]”(hŒ0No path lookup can open the root, not even with ”…””}”(hjˆh²hh³Nh´Nubhè)”}”(hŒ ``O_PATH``”h]”hŒO_PATH”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjˆubhŒ.”…””}”(hjˆh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhjEh²hubhÞ)”}”(hŒïA process with its working directory in failfs fails every ``AT_FDCWD``-relative lookup. As with any working directory that is unreachable from the process root, the ``getcwd(2)`` system call returns a path prefixed with ``(unreachable)``.”h]”(hŒ;A process with its working directory in failfs fails every ”…””}”(hj¨h²hh³Nh´Nubhè)”}”(hŒ ``AT_FDCWD``”h]”hŒAT_FDCWD”…””}”(hj°h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¨ubhŒ_-relative lookup. As with any working directory that is unreachable from the process root, the ”…””}”(hj¨h²hh³Nh´Nubhè)”}”(hŒ ``getcwd(2)``”h]”hŒ getcwd(2)”…””}”(hjÂh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¨ubhŒ* system call returns a path prefixed with ”…””}”(hj¨h²hh³Nh´Nubhè)”}”(hŒ``(unreachable)``”h]”hŒ (unreachable)”…””}”(hjÔh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¨ubhŒ.”…””}”(hj¨h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhjEh²hubhÞ)”}”(hŒ½A process with its root directory in failfs fails every absolute path lookup including absolute symlinks and the interpreter of dynamically linked binaries. In other words, this fails exec.”h]”hŒ½A process with its root directory in failfs fails every absolute path lookup including absolute symlinks and the interpreter of dynamically linked binaries. In other words, this fails exec.”…””}”(hjìh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´KhjEh²hubhÞ)”}”(hŒÏLookups anchored at explicit directory file descriptors keep working. It is the ``fs_struct`` equivalent of ``RESOLVE_BENEATH``. The process must anchor every lookup at a file descriptor it explicitly holds.”h]”(hŒPLookups anchored at explicit directory file descriptors keep working. It is the ”…””}”(hjúh²hh³Nh´Nubhè)”}”(hŒ ``fs_struct``”h]”hŒ fs_struct”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjúubhŒ equivalent of ”…””}”(hjúh²hh³Nh´Nubhè)”}”(hŒ``RESOLVE_BENEATH``”h]”hŒRESOLVE_BENEATH”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjúubhŒP. The process must anchor every lookup at a file descriptor it explicitly holds.”…””}”(hjúh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K!hjEh²hubeh}”(h]”Œ semantics”ah ]”h"]”Œ semantics”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´KubhÉ)”}”(hhh]”(hÎ)”}”(hŒEntering”h]”hŒEntering”…””}”(hj7h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhj4h²hh³hÇh´K&ubhÞ)”}”(hŒ°``fchroot(FD_FAILFS_ROOT, 0)`` requires ``CAP_SYS_CHROOT`` in the caller's user namespace, mirroring ``chroot(2)``. Unprivileged callers may enter if all of the following hold:”h]”(hè)”}”(hŒ``fchroot(FD_FAILFS_ROOT, 0)``”h]”hŒfchroot(FD_FAILFS_ROOT, 0)”…””}”(hjIh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjEubhŒ requires ”…””}”(hjEh²hh³Nh´Nubhè)”}”(hŒ``CAP_SYS_CHROOT``”h]”hŒCAP_SYS_CHROOT”…””}”(hj[h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjEubhŒ- in the caller’s user namespace, mirroring ”…””}”(hjEh²hh³Nh´Nubhè)”}”(hŒ ``chroot(2)``”h]”hŒ chroot(2)”…””}”(hjmh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjEubhŒ>. Unprivileged callers may enter if all of the following hold:”…””}”(hjEh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K(hj4h²hubhŒ bullet_list”“”)”}”(hhh]”(hŒ list_item”“”)”}”(hŒÈ``no_new_privs`` is set: setuid binaries on regular mounts remain reachable via inherited directory file descriptors and executing them with an unusable root directory is the classic confused deputy. ”h]”hÞ)”}”(hŒÇ``no_new_privs`` is set: setuid binaries on regular mounts remain reachable via inherited directory file descriptors and executing them with an unusable root directory is the classic confused deputy.”h]”(hè)”}”(hŒ``no_new_privs``”h]”hŒ no_new_privs”…””}”(hj”h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjubhŒ· is set: setuid binaries on regular mounts remain reachable via inherited directory file descriptors and executing them with an unusable root directory is the classic confused deputy.”…””}”(hjh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K,hjŒubah}”(h]”h ]”h"]”h$]”h&]”uh1jŠhj‡h²hh³hÇh´Nubj‹)”}”(hXThe caller is not already chrooted: the root directory is what confines ``..`` resolution and the failfs root can never be reached by walking up a real mount tree, so moving the root of a chrooted task to failfs would allow it to escape its chroot via ``openat(fd, "..")``. ”h]”hÞ)”}”(hXThe caller is not already chrooted: the root directory is what confines ``..`` resolution and the failfs root can never be reached by walking up a real mount tree, so moving the root of a chrooted task to failfs would allow it to escape its chroot via ``openat(fd, "..")``.”h]”(hŒHThe caller is not already chrooted: the root directory is what confines ”…””}”(hj¶h²hh³Nh´Nubhè)”}”(hŒ``..``”h]”hŒ..”…””}”(hj¾h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¶ubhŒ® resolution and the failfs root can never be reached by walking up a real mount tree, so moving the root of a chrooted task to failfs would allow it to escape its chroot via ”…””}”(hj¶h²hh³Nh´Nubhè)”}”(hŒ``openat(fd, "..")``”h]”hŒopenat(fd, "..")”…””}”(hjÐh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¶ubhŒ.”…””}”(hj¶h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K0hj²ubah}”(h]”h ]”h"]”h$]”h&]”uh1jŠhj‡h²hh³hÇh´Nubj‹)”}”(hXjThe caller does not share its ``fs_struct``: ``no_new_privs`` is checked on the calling thread, but the root lives in the ``fs_struct``. A ``CLONE_FS`` sibling without ``no_new_privs`` could otherwise execute a setuid binary with the failfs root, so entry requires ``fs->users == 1``, the same restriction ``setns(2)`` applies for the mount and user namespaces. ”h]”hÞ)”}”(hXiThe caller does not share its ``fs_struct``: ``no_new_privs`` is checked on the calling thread, but the root lives in the ``fs_struct``. A ``CLONE_FS`` sibling without ``no_new_privs`` could otherwise execute a setuid binary with the failfs root, so entry requires ``fs->users == 1``, the same restriction ``setns(2)`` applies for the mount and user namespaces.”h]”(hŒThe caller does not share its ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ ``fs_struct``”h]”hŒ fs_struct”…””}”(hjúh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒ: ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ``no_new_privs``”h]”hŒ no_new_privs”…””}”(hj h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒ= is checked on the calling thread, but the root lives in the ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ ``fs_struct``”h]”hŒ fs_struct”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒ. A ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ ``CLONE_FS``”h]”hŒCLONE_FS”…””}”(hj0h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒ sibling without ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ``no_new_privs``”h]”hŒ no_new_privs”…””}”(hjBh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒQ could otherwise execute a setuid binary with the failfs root, so entry requires ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ``fs->users == 1``”h]”hŒfs->users == 1”…””}”(hjTh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒ, the same restriction ”…””}”(hjòh²hh³Nh´Nubhè)”}”(hŒ ``setns(2)``”h]”hŒsetns(2)”…””}”(hjfh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhjòubhŒ+ applies for the mount and user namespaces.”…””}”(hjòh²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K5hjîubah}”(h]”h ]”h"]”h$]”h&]”uh1jŠhj‡h²hh³hÇh´Nubeh}”(h]”h ]”h"]”h$]”h&]”Œbullet”Œ*”uh1j…h³hÇh´K,hj4h²hubeh}”(h]”Œentering”ah ]”h"]”Œentering”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´K&ubhÉ)”}”(hhh]”(hÎ)”}”(hŒLeaving”h]”hŒLeaving”…””}”(hj—h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hÍhj”h²hh³hÇh´K=ubhÞ)”}”(hXñBacking out is currently hard, but this is a property of the current implementation, not a guaranteed interface, and may be loosened later. For now a process that entered failfs counts as chrooted, so it cannot create user namespaces to regain ``CAP_SYS_CHROOT``, and ``chroot(2)`` or ``fchroot(2)`` back out require ``CAP_SYS_CHROOT``. The remaining way out today is ``setns(2)`` with a mount namespace file descriptor, which requires ``CAP_SYS_ADMIN`` over the target mount namespace as well as ``CAP_SYS_CHROOT`` and ``CAP_SYS_ADMIN`` in the caller's user namespace and resets both root and working directory. A process that holds no such file descriptor and restricts ``*chdir()``/``*chroot()``/``setns()`` via seccomp cannot currently get back out.”h]”(hŒôBacking out is currently hard, but this is a property of the current implementation, not a guaranteed interface, and may be loosened later. For now a process that entered failfs counts as chrooted, so it cannot create user namespaces to regain ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ``CAP_SYS_CHROOT``”h]”hŒCAP_SYS_CHROOT”…””}”(hj­h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ, and ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ ``chroot(2)``”h]”hŒ chroot(2)”…””}”(hj¿h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ or ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ``fchroot(2)``”h]”hŒ fchroot(2)”…””}”(hjÑh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ back out require ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ``CAP_SYS_CHROOT``”h]”hŒCAP_SYS_CHROOT”…””}”(hjãh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ!. The remaining way out today is ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ ``setns(2)``”h]”hŒsetns(2)”…””}”(hjõh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ8 with a mount namespace file descriptor, which requires ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ``CAP_SYS_ADMIN``”h]”hŒ CAP_SYS_ADMIN”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ, over the target mount namespace as well as ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ``CAP_SYS_CHROOT``”h]”hŒCAP_SYS_CHROOT”…””}”(hjh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ and ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ``CAP_SYS_ADMIN``”h]”hŒ CAP_SYS_ADMIN”…””}”(hj+h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ‰ in the caller’s user namespace and resets both root and working directory. A process that holds no such file descriptor and restricts ”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ ``*chdir()``”h]”hŒ*chdir()”…””}”(hj=h²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ/”…””}”(hj¥h²hh³Nh´Nubhè)”}”(hŒ ``*chroot()``”h]”hŒ *chroot()”…””}”(hjOh²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ/”…””}”hj¥sbhè)”}”(hŒ ``setns()``”h]”hŒsetns()”…””}”(hjah²hh³Nh´Nubah}”(h]”h ]”h"]”h$]”h&]”uh1hçhj¥ubhŒ+ via seccomp cannot currently get back out.”…””}”(hj¥h²hh³Nh´Nubeh}”(h]”h ]”h"]”h$]”h&]”uh1hÝh³hÇh´K?hj”h²hubeh}”(h]”Œleaving”ah ]”h"]”Œleaving”ah$]”h&]”uh1hÈhhÊh²hh³hÇh´K=ubeh}”(h]”Œfailfs”ah ]”h"]”Œfailfs”ah$]”h&]”uh1hÈhhh²hh³hÇh´Kubeh}”(h]”h ]”h"]”h$]”h&]”Œsource”hÇuh1hŒcurrent_source”NŒ current_line”NŒsettings”Œdocutils.frontend”ŒValues”“”)”}”(hÍNŒ generator”NŒ datestamp”NŒ source_link”NŒ source_url”NŒ toc_backlinks”Œentry”Œfootnote_backlinks”KŒ sectnum_xform”KŒstrip_comments”NŒstrip_elements_with_classes”NŒ strip_classes”NŒ report_level”KŒ halt_level”KŒexit_status_level”KŒdebug”NŒwarning_stream”NŒ traceback”ˆŒinput_encoding”Œ utf-8-sig”Œinput_encoding_error_handler”Œstrict”Œoutput_encoding”Œutf-8”Œoutput_encoding_error_handler”j¬Œerror_encoding”Œutf-8”Œerror_encoding_error_handler”Œbackslashreplace”Œ language_code”Œen”Œrecord_dependencies”NŒconfig”NŒ id_prefix”hŒauto_id_prefix”Œid”Œ dump_settings”NŒdump_internals”NŒdump_transforms”NŒdump_pseudo_xml”NŒexpose_internals”NŒstrict_visitor”NŒ_disable_config”NŒ_source”hÇŒ _destination”NŒ _config_files”]”Œ7/var/lib/git/docbuild/linux/Documentation/docutils.conf”aŒfile_insertion_enabled”ˆŒ raw_enabled”KŒline_length_limit”M'Œpep_references”NŒ pep_base_url”Œhttps://peps.python.org/”Œpep_file_url_template”Œpep-%04d”Œrfc_references”NŒ rfc_base_url”Œ&https://datatracker.ietf.org/doc/html/”Œ tab_width”KŒtrim_footnote_reference_space”‰Œsyntax_highlight”Œlong”Œ smart_quotes”ˆŒsmartquotes_locales”]”Œcharacter_level_inline_markup”‰Œdoctitle_xform”‰Œ docinfo_xform”KŒsectsubtitle_xform”‰Œ image_loading”Œlink”Œembed_stylesheet”‰Œcloak_email_addresses”ˆŒsection_self_link”‰Œenv”NubŒreporter”NŒindirect_targets”]”Œsubstitution_defs”}”Œsubstitution_names”}”Œrefnames”}”Œrefids”}”Œnameids”}”(j†jƒj1j.j‘jŽj~j{uŒ nametypes”}”(j†‰j1‰j‘‰j~‰uh}”(jƒhÊj.jEjŽj4j{j”uŒ footnote_refs”}”Œ citation_refs”}”Œ autofootnotes”]”Œautofootnote_refs”]”Œsymbol_footnotes”]”Œsymbol_footnote_refs”]”Œ footnotes”]”Œ citations”]”Œautofootnote_start”KŒsymbol_footnote_start”KŒ id_counter”Œ collections”ŒCounter”“”}”…”R”Œparse_messages”]”Œtransform_messages”]”Œ transformer”NŒ include_log”]”Œ decoration”Nh²hub.