> For the complete documentation index, see [llms.txt](https://davidjosearaujo.gitbook.io/notes-mcs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://davidjosearaujo.gitbook.io/notes-mcs/secure-execution-environments/security-in-operating-systems/privilege-reduction.md).

# Privilege reduction

## `chroot` mechanism (or jail)

Used to **reduce the visibility of a file system**.

* Each process descriptor has a root *i*-node number.
  * From which absolute pathname resolution takes place.
* `chroot` changes it to an **arbitrary directory**.
  * The process **file system view gets reduced**.

Used to **protect the file system** from potentially problematic applications.

* e.g. public servers and downloaded applications.
* But it is not bulletproof!
