Meta tags:
Headings (most frequently used words):
proot, equivalent, chroot, mount, bind, or, care, using, description, examples, downloads, ecosystem, support, su, binfmt_misc, rootfs, projects, third, party, packages, public, material, about, companies, internally,
Text of the page (most frequently used words):
the (83), proot (50), bin (40), linux (24), programs (24), and (23), guest (23), host (20), rootfs (18), that (16), for (16), mnt (16), qemu (15), this (15), user (14), can (14), bash (14), root (13), slackware (13), use (12), command (12), with (11), #system (11), file (11), bind (11), mode (10), execution (10), make (10), files (10), care (9), are (9), option (9), arm (9), etc (9), com (8), when (8), they (8), mount (8), one (7), access (7), cross (7), echo (7), just (7), not (7), dash (7), using (6), distribution (6), during (6), packages (6), without (6), https (6), typically (6), armslack (6), example (6), users (6), chroot (6), tmp (6), md5sum (6), google (6), presentation (5), debian (5), from (5), downloads (5), any (5), used (5), following (5), since (5), org (5), were (5), instance (5), its (5), cat (5), cpu (5), like (5), equivalent (5), tty (5), 089ed56cd74e63f461bef0fdfc2d159a (5), hosts (5), install (4), tools (4), ubuntu (4), execute (4), made (4), bound (4), build (4), native (4), built (4), over (4), hello (4), world (4), transparently (4), default (4), actually (4), foo (4), pts (4), proc (4), mechanism (4), list (3), support (3), another (3), essay (3), link (3), 2014 (3), bit (3), x86 (3), distros (3), create (3), which (3), compiler (3), ecosystem (3), has (3), available (3), tar (3), technically (3), releases (3), emulated (3), environment (3), gnu (3), opt (3), filesystem (3), most (3), compilation (3), mixed (3), useful (3), content (3), accessible (3), motd (3), welcome (3), architecture (3), binfmt_misc (3), recommended (3), some (3), directories (3), way (3), examples (3), kernel (3), your (2), but (2), reproducible (2), instrumentation (2), rémi (2), developers (2), material (2), about (2), gentoo (2), arch (2), binaries (2), portable (2), pypy (2), several (2), travis (2), contains (2), installation (2), android (2), archive (2), automatically (2), been (2), such (2), running (2), http (2), images (2), download (2), contain (2), archives (2), note (2), these (2), see (2), gitlab (2), chmod (2), version (2), source (2), same (2), repository (2), however (2), latest (2), found (2), x86_64 (2), binary (2), github (2), whether (2), worth (2), even (2), still (2), here (2), script (2), configure (2), usr (2), overlaid (2), program (2), export (2), gcc (2), may (2), want (2), elf (2), lsb (2), executable (2), mix (2), speed (2), time (2), feature (2), through (2), 1234 (2), enable (2), uses (2), incompatible (2), perl (2), installing (2), package (2), required (2), latter (2), enables (2), only (2), paths (2), bypass (2), permissions (2), bar (2), work (2), run (2), case (2), privileges (2), specified (2), specific (2), none (2), two (2), initially (2), part (2), possible (2), symbolic (2), distributions (2), resolveip (2), address (2), alternate_opt (2), prog (2), perform (2), all (2), cpus (2), resources (2), means (2), also (2), new (2), setup (2), description (2), top, feel, free, send, questions, bug, reports, suggestions, patches, chat, please, sure, answer, isn, first, manual, gitter, forum, mailing, infinite, omicron, llc, gogo, cisco, ericsson, sony, stmicroelectronics, companies, internally, tutorial, how, nix, home, quf, proceedings, step, forward, hipeac, csw, 2013, introduction, tool, dead, trust, comprehensive, archiver, linaro, connect, usa, testing, reproducing, lava, failures, locally, fosdem, software, engineering, based, syscall, articles, ivoire, blog, public, void, university, chicago, rcc, termux, nixos, alpine, section, likely, more, date, third, party, batch, long, term, computations, python, sio, workers, polysquare, container, distributed, computing, environments, openmole, fully, compiled, opam, opam2debian, junest, gnuroot, noroot, find, options, provide, best, optimizations, atos, projects, developed, around, publicly, gzip, my_rootfs, created, expected, alpinelinux, archlinuxarm, cdimage, core, distfiles, linuxcontainers, openvz, template, precreated, urls, freely, downloaded, errors, reported, extracting, safely, ignored, special, details, mknod, curl, code, hosted, previous, packaged, archived, builds, under, job, artifacts, each, commit, commands, convenience, pipelines, static, checking, mentioning, mixing, believe, demonstration, partial, output, typical, regular, where, cflags, sysroot, could, optional, indeed, both, deactivate, explicitly, configured, compile, target, allows, namespace, extend, significantly, enabled, emacs, parameter, whole, gdb, server, port, armedslack, point, view, handled, executed, have, specify, installpkg, tgz, into, try, update, instead, binds, known, updated, group, uid, gid, mkdir, rwx, will, correctly, managers, fake, identity, zero, there, bunch, why, provides, pre, defined, works, better, error, features, above, combined, confined, sometimes, rely, c229085928dc19e8d9bd29fe88268504, cases, shouldn, problem, strictly, dereferencing, specifying, character, end, because, whereas, points, consequence, tested, might, binding, set, non, disruptively, alternate_hosts, 675, mar, 2011, shown, owned, configuration, dns, setting, overlay, sources, 755, installed, relocate, trick, hard, coded, locations, scripts, thus, shortest, confine, interactive, shell, sub, inside, given, give, path, followed, desired, below, executes, print, respectively, noting, never, involved, regardless, translates, their, requests, before, sending, them, devices, network, normal, equivalents, missing, independent, interpreters, emulator, convenient, develop, validate, seamlessly, computer, issues, avoided, confines, actual, space, implementation, don, need, things, arbitrary, directory, making, somewhere, else, hierarchy, executing, generic, process, engine, thanks, extension, relies, unprivileged, call, every, ptrace, privilege,
Text of the page (random words):
proot chroot mount bind and binfmt_misc without privilege setup proot description examples source downloads ecosystem support description proot is a user space implementation of chroot mount bind and binfmt_misc this means that users don t need any privileges or setup to do things like using an arbitrary directory as the new root filesystem making files accessible somewhere else in the filesystem hierarchy or executing programs built for another cpu architecture transparently through qemu user mode also developers can use proot as a generic linux process instrumentation engine thanks to its extension mechanism see care for an example technically proot relies on ptrace an unprivileged system call available in every linux kernel the new root file system a k a guest rootfs typically contains a linux distribution by default proot confines the execution of programs to the guest rootfs only however users can use the built in mount bind mechanism to access files and directories from the actual root file system a k a host rootfs just as if they were part of the guest rootfs when the guest linux distribution is made for a cpu architecture incompatible with the host one proot uses the cpu emulator qemu user mode to execute transparently guest programs it s a convenient way to develop to build and to validate any guest linux packages seamlessly on users computer just as if they were in a native guest environment that way all of the cross compilation issues are avoided proot can also mix the execution of host programs and the execution of guest programs emulated by qemu user mode this is useful to use host equivalents of programs that are missing from the guest rootfs and to speed up build time by using cross compilation tools or cpu independent programs like interpreters it is worth noting that the guest kernel is never involved regardless of whether qemu user mode is used or not technically when guest programs perform access to system resources proot translates their requests before sending them to the host kernel this means that guest programs can use host resources devices network just as if they were normal host programs examples in the following examples the directories mnt slackware 8 0 and mnt armslack 12 2 contain a linux distribution respectively made for x86 cpus and arm cpus chroot equivalent to execute a command inside a given linux distribution just give proot the path to the guest rootfs followed by the desired command the example below executes the program cat to print the content of a file proot r mnt slackware 8 0 cat etc motd welcome to slackware linux 8 0 the default command is bin sh when none is specified thus the shortest way to confine an interactive shell and all its sub programs is proot r mnt slackware 8 0 cat etc motd welcome to slackware linux 8 0 mount bind equivalent the bind mechanism enables one to relocate files and directories this is typically useful to trick programs that perform access to hard coded locations like some installation scripts proot b tmp alternate_opt opt cd to sources make install install m 755 prog opt bin prog is installed in tmp alternate_opt bin actually as shown in this example it is possible to bind over files not even owned by the user this can be used to overlay system configuration files for instance the dns setting ls l etc hosts rw r r 1 root root 675 mar 4 2011 etc hosts proot b alternate_hosts etc hosts echo 1 2 3 4 google com etc hosts resolveip google com ip address of google com is 1 2 3 4 echo 5 6 7 8 google com etc hosts resolveip google com ip address of google com is 5 6 7 8 another example on most linux distributions bin sh is a symbolic link to bin bash whereas it points to bin dash on debian and ubuntu as a consequence a bin sh script tested with bash might not work with dash in this case the binding mechanism of proot can be used to set non disruptively bin bash as the default bin sh on these two linux distributions proot b bin bash bin sh because bin sh is initially a symbolic link to bin dash the content of bin bash is actually bound over this latter proot b bin bash bin sh md5sum bin sh 089ed56cd74e63f461bef0fdfc2d159a bin sh md5sum bin bash 089ed56cd74e63f461bef0fdfc2d159a bin bash md5sum bin dash 089ed56cd74e63f461bef0fdfc2d159a bin dash in most cases this shouldn t be a problem but it is still possible to strictly bind bin bash over bin sh without dereferencing it by specifying the character at the end proot b bin bash bin sh md5sum bin sh 089ed56cd74e63f461bef0fdfc2d159a bin sh md5sum bin bash 089ed56cd74e63f461bef0fdfc2d159a bin bash md5sum bin dash c229085928dc19e8d9bd29fe88268504 bin dash chroot mount bind equivalent the two features above can be combined to make any file from the host rootfs accessible in the confined environment just as if it were initially part of the guest rootfs it is sometimes required to run programs that rely on some specific files proot r mnt slackware 8 0 ps o tty command error do this mount t proc none proc works better with proot r mnt slackware 8 0 b proc ps o tty command tt command bash proot b proc mnt slackware 8 0 sh ps o tty command actually there s a bunch of such specific files that s why proot provides the option r to bind automatically a pre defined list of recommended paths proot r mnt slackware 8 0 ps o tty command tt command pts 6 bash pts 6 proot r mnt slackware 8 0 pts 6 sh pts 6 ps o tty command chroot mount bind su equivalent some programs will not work correctly if they are not run by the root user this is typically the case with package managers proot can fake the root identity and its privileges when the 0 zero option is specified proot r mnt slackware 8 0 0 id uid 0 root gid 0 root mkdir tmp foo chmod a rwx tmp foo echo i bypass file system permissions tmp foo bar cat tmp foo bar i bypass file system permissions this option is typically required to create or install packages into the guest rootfs note it is not recommended to use the r option when installing packages since they may try to update bound system files like etc group instead it is recommended to use the s option this latter enables the 0 option and binds only paths that are known to not be updated by packages proot s mnt slackware 8 0 installpkg perl tgz installing package perl chroot mount bind binfmt_misc equivalent proot uses qemu user mode to execute programs built for a cpu architecture incompatible with the host one from users point of view guest programs handled by qemu user mode are executed transparently that is just like host programs to enable this feature users just have to specify which instance of qemu user mode they want to use with the option q proot r mnt armslack 12 2 q qemu arm cat etc motd welcome to armedslack linux 12 2 the parameter of the q option is actually a whole qemu user mode command for instance to enable its gdb server on port 1234 proot r mnt armslack 12 2 q qemu arm g 1234 emacs proot allows one to mix transparently the emulated execution of guest programs and the native execution of host programs in the same file system namespace it s typically useful to extend the list of available programs and to speed up build time significantly this mixed execution feature is enabled by default when using qemu user mode and the content of the host rootfs is made accessible through host rootfs proot r mnt armslack 12 2 q qemu arm file bin echo elf 32 bit lsb executable arm bin echo hello world hello world file host rootfs bin echo elf 64 bit lsb executable x86 64 host rootfs bin echo hello mixed world hello mixed world since both host and guest programs use the guest rootfs as users may want to deactivate explicitly cross filesystem support found in most gnu cross compilation tools for example with gcc configured to cross compile to the arm target proot r mnt armslack 12 2 q qemu arm export cc host rootfs opt cross tools arm linux bin gcc export cflags sysroot could be optional indeed configure make as with regular files a host instance of a program can be bound over its guest instance here is an example where the guest binary of make is overlaid by the host one proot r mnt armslack 12 2 q qemu arm b usr bin make which make usr bin make make version overlaid gnu make 3 82 built for x86_64 slackware linux gnu it s worth mentioning that even when mixing the native execution of host programs and the emulated execution of guest programs they still believe they are running in a native guest environment as a demonstration here is a partial output of a typical configure script checking whether the c compiler is a cross compiler no downloads proot the source code for proot and care are hosted in the same repository on github previous proot releases were packaged at https github com proot me proot static build releases however that repository has since been archived the latest builds can be found under the job artifacts for the gitlab ci cd pipelines for each commit the following commands can be used to download the latest x86_64 binary for convenience curl lo https proot gitlab io proot bin proot chmod x proot proot version rootfs the following urls contain rootfs archives that can be freely downloaded note that mknod errors reported by tar when extracting these archives can be safely ignored since special files are typically bound see r option for details https download openvz org template precreated https images linuxcontainers org images http distfiles gentoo org releases http cdimage ubuntu com ubuntu core https archlinuxarm org about downloads https alpinelinux org downloads technically such rootfs archive can be created by running the following command on the expected linux distribution tar one file system create gzip file my_rootfs tar gz ecosystem the following ecosystem has developed around proot since it has been made publicly available projects using proot or care atos find automatically c c compiler options that provide best optimizations care archive material used during an execution to make it reproducible on any linux system debian noroot use debian linux on android without root access gnuroot use several linux distros on android without root access junest use arch linux on any linux distros without root access opam2debian create debian packages which contains a fully compiled opam installation openmole execute programs on distributed computing environments polysquare travis container use several linux distros on travis ci without root access portable pypy portable 32 and 64 bit x86 pypy binaries sio workers batch long term computations with python third party packages binaries from the downloads section are likely more up to date alpine linux arch linux debian gentoo nixos termux ubuntu university of chicago rcc void linux public material about proot or care articles on rémi s blog rémi a k a ivoire is one of the proot developers presentation software engineering tools based on syscall instrumentation during fosdem 2014 presentation sw testing reproducing a lava failures locally using care during linaro connect usa 2014 presentation and essay care the comprehensive archiver for reproducible execution essay during trust 2014 presentation an introduction to the care tool dead link during hipeac csw 2013 presentation and essay proot a step forward for qemu user mode proceedings during quf 11 tutorial how to install nix in home on another distribution companies using proot or care internally stmicroelectronics sony ericsson cisco gogo infinite omicron llc support feel free to send your questions bug reports suggestions and patches to the mailing list or to the forum or chat with us on gitter but please be sure that your answer isn t in the user manual first top
|