NOTE

chroot

Changing a process's filesystem root and understanding why chroot alone is not a security container.

Operating Systems / LinuxCreated Updated 1 min readhistorical

This is a historical learning note and may contain outdated or incomplete understanding.

chroot changes the root directory used for pathname resolution by a process and its descendants. It can create a restricted filesystem view for build/test/recovery workflows.

A chroot is not a complete security boundary. It does not isolate processes, users, networks, capabilities, devices, or resource usage by itself, and privileged code may escape poorly constructed environments.

Containers combine stronger mechanisms such as namespaces, cgroups, capabilities, seccomp, mount controls, and mandatory-access policies.

Loading helpful count