Complete chroot environment?
John Summerfield
debian at herakles.homelinux.org
Thu Dec 27 12:43:22 UTC 2007
Tom Horsley wrote:
> I've been experimenting with chroot to switch to an
> alternate root partition and "do stuff" without
> actually having to reboot to that alternate OS.
>
> I see that none of the special filesystems seem to
> be created as part of the ordinary chroot command, yet
> things like the bind-chroot rpm does manage to create
> a more complete environment for named to run in
> (with populated /dev and /proc and wot-not).
>
> Is there a handy tool somewhere to duplicate all the
> special filesystems in a chroot environment?
>
> Or should I just look at bind-chroot in more detail
> and steal what it does?
>
The general idea of chroot is to provide a slightly more secure
environment than the base system.
bind-chroot has what it needs; ordinarily one doesn't want devices in
the chroot environment (a few exceptions such as /dev/{null,zero} are
needed, but certainly not /dev/sda).
I would contemplate an alternative approach such as using xen or, if h/w
virtualisation is available. kvm.
--
Cheers
John
-- spambait
1aaaaaaa at coco.merseine.nu Z1aaaaaaa at coco.merseine.nu
-- Advice
http://webfoot.com/advice/email.top.php
http://www.catb.org/~esr/faqs/smart-questions.html
http://support.microsoft.com/kb/555375
You cannot reply off-list:-)
More information about the users
mailing list