CHROOT(2) | System Calls Manual | CHROOT(2) |
chroot
— change
root directory
#include
<unistd.h>
int
chroot
(const
char *dirname);
Dirname is the address of the pathname of a
directory, terminated by an ASCII NUL.
chroot
()
causes dirname to become the root directory, that is,
the starting point for path searches of pathnames beginning with
‘/
’.
In order for a directory to become the root directory a process must have execute (search) access for that directory.
If the program is not currently running with an
altered root directory, it should be noted that
chroot
()
has no effect on the process's current directory.
If the program is already running with an altered root directory, the process's current directory is changed to the same new root directory. This prevents the current directory from being further up the directory tree than the altered root directory.
This call is restricted to the super-user.
Upon successful completion, a value of 0 is returned. Otherwise, a value of -1 is returned and errno is set to indicate an error.
chroot
() will fail and the root directory
will be unchanged if:
ENOTDIR
]ENAMETOOLONG
]{NAME_MAX}
characters, or an entire path name exceeded
{PATH_MAX}
characters.ENOENT
]EACCES
]ELOOP
]EFAULT
]EIO
]There are ways for a root process to escape from the chroot jail.
The chroot
() function call appeared in
4.2BSD.
June 4, 1993 | BSD 4.2 |