Linux Command: chroot
Run command or shell with a different root directory
chroot changes the root directory for a command or shell session. The process and its children see the specified directory as / and cannot access files outside of it (without special effort). chroot is used for system recovery (booting into a broken system), building packages in isolated environments, testing software in a minimal filesystem, and basic containerization. chroot provides filesystem isolation but is not a security boundary โ processes with root access can escape a chroot. For proper isolation, use containers (Docker, LXC) or namespaces.
Syntax
chroot NEWROOT [COMMAND]Key Options
NEWROOTโ New root directoryCOMMANDโ Command to run (default: /bin/sh)--userspecโ Run as specific user:group--groupsโ Set supplementary groups
Examples
System recovery
sudo mount /dev/sda1 /mnt && sudo chroot /mnt /bin/bashFix bootloader
sudo chroot /mnt /bin/bash -c 'grub-install /dev/sda && update-grub'Run in isolated env
sudo chroot /srv/build /bin/bashPro Tips
- chroot is NOT a security container. Root processes can escape chroot. Use proper containers (Docker, LXC) for security isolation.
- For full system recovery: mount /dev, /proc, /sys, and /dev/pts before chrooting. Otherwise many tools will not work.
- Use debootstrap to create a minimal Debian/Ubuntu filesystem for chroot: debootstrap focal /path/to/chroot
Learn more: Full chroot reference โ
Related Resources