Home / Alt manpages / proc_execdomains(5)

  • proc_execdomains(5)
  • File format
  • linux

Read Linux ABI Personality Compatibility Data Safely

You will identify what /proc/execdomains contains on a current Linux system, read it without elevated privileges, and decide whether software should treat the result as compatibility information. On the installed system, it is a read-only procfs interface that returns a constant compatibility string. It is not a list you can edit and it is not a switch for changing process behaviour.

Allow about five minutes. You need a shell and a Linux host with procfs mounted. The examples use Linux kernel 6.8.0-139-generic and the locally installed manpages package version 6.7-2. The manual page is from Linux man-pages 6.7 and describes the interface as obsolete, so keep the version boundary in mind when writing portable checks.

1. Confirm which manual page you are reading

Start with an ordinary, read-only lookup. This does not need sudo:

$ man --where proc_execdomains
/usr/share/man/man5/proc_execdomains.5.gz
$ dpkg-query -W -f='${Package} ${Version}\n' manpages
manpages 6.7-2

The section is 5, because this is documentation for a virtual file rather than a command. If man --where prints nothing, the documentation package may not be installed, but that does not by itself mean procfs lacks the file.

Checkpoint: the path should identify proc_execdomains.5.gz. On another distribution, use that system's package query instead of copying the Debian command above.

2. Read the interface as a normal user

Read the file directly and capture the status immediately:

$ cat /proc/execdomains
0-0	Linux           	[kernel]
$ printf 'exit status: %s\n' "$?"
exit status: 0

The precise spacing can differ, so scripts should not depend on columns lining up. The useful observation is that this current host reports one compatibility entry, 0-0 Linux [kernel]. The output is the constant string promised by the manual page for userspace compatibility. Older Linux releases used this path to list ABI personalities; the local manual says that use ended before Linux 4.1.

Do not interpret this line as a menu of personalities to enable. The file does not document a command syntax, and writing to it is not a supported operation. There is no configuration change to undo after this step.

3. Check readability without assuming root access

If a monitoring or diagnostic script needs to distinguish an absent interface from an unreadable one, test the path separately:

$ if test -r /proc/execdomains; then
    printf '%s\n' 'proc_execdomains is readable'
else
    printf '%s\n' 'proc_execdomains is absent or unreadable' >&2
    exit 1
fi
proc_execdomains is readable

Reading this procfs entry normally requires no elevated privilege. A failed read can instead indicate that procfs is not mounted, that the path is hidden by a container or restricted process view, or that the host's kernel no longer exposes the compatibility interface. Check the actual error before deciding which case applies.

For a second, descriptive check, inspect the procfs entry with stat:

$ stat -c '%F %a %U:%G %s bytes' /proc/execdomains
regular empty file 444 root:root 0 bytes

Procfs entries are kernel-generated views. A zero size from stat does not predict the bytes that a read will return, so do not reject the interface merely because it looks like an empty regular file. The mode and ownership also do not make it writable: the mode shown here is read-only for everyone.

4. Make a conservative compatibility check

For a one-off investigation, inspect the complete output with cat. For a script, first require a successful read, then match only the part of the contract you actually need. This example accepts the current kernel entry without relying on tabs or fixed column widths:

$ execdomains=$(cat /proc/execdomains) || {
    printf '%s\n' 'cannot read /proc/execdomains' >&2
    exit 1
}
$ case "$execdomains" in
    *Linux*'['kernel']'*) printf '%s\n' 'current kernel compatibility entry found' ;;
    *) printf '%s\n' 'unexpected execdomains content' >&2; exit 1 ;;
esac
current kernel compatibility entry found

This is a diagnostic example, not a promise that every future kernel will retain the same text. It avoids parsing the numeric range because the obsolete interface is not a stable configuration API. If your program merely needs to know whether it is running on Linux, use a suitable platform or kernel query instead of depending on this file's presentation.

Keep the command substitution quoted when you use its value. Do not feed the output to eval, generate shell code from it, or treat words from procfs as trusted options. Those precautions are ordinary shell hygiene even though this particular entry is currently a fixed kernel string.

5. Diagnose the common traps

If cat reports that the file does not exist, check the proc mount and the exact path:

$ test -d /proc && printf '%s\n' '/proc exists'
/proc exists
$ test -e /proc/execdomains && printf '%s\n' 'execdomains exists' || printf '%s\n' 'execdomains is absent'
execdomains exists

A process running in a container can see a deliberately limited procfs view. Compare the result from the relevant host context before changing mount configuration. Do not mount a new procfs, alter container permissions, or change service settings just to make an obsolete compatibility file appear; those are deployment changes, not fixes to the file.

If a script expects the historical multi-entry list, update the script rather than trying to reconstruct it from this constant string. A non-empty read proves only that the interface answered. It does not prove that an old ABI personality is available, selected, or required by a particular executable.

Done means

  • You confirmed the installed proc_execdomains(5) documentation and its package version.
  • You read /proc/execdomains successfully as an ordinary user.
  • You treated the current output as compatibility data, not editable configuration.
  • Your script checks read success and avoids brittle column parsing.
  • You know that a missing or restricted procfs view is an environment issue to investigate, not a reason to write to the file.