Steps from https://ubuntuforums.org/showthread.php?t=1874218&p=11421008#post11421008
The critical steps I took to get here here:
Create a directory for the chroot
Next a created a new home directory for the chrooted users in my case I called it files
Create the user account for a chrooted user in my case android under this chroot/files
Copy over mkchroot.sh and execute it, While this should have correctly setup the system it does not (but it makes things easier), so we need to manually copy over more files and configure things as well.
I started with etc, we also need: group, profile, resolv.conf, rssh.conf, nsswitch.conf, localtime
Remove unneeded entries from groups and password (such as none-chrooted users and the like, this is only for extra security).
Edit rssh.conf remove any references to chroot as we already have done that it is present it tries to do it twice.
Next I created a bin directory under the chroot and added dash, bash and ls to it (you can later once everything works remove them if you want)
For every executable to be under chrooted run ldd <executable> and ensure any linked library is present in chroot/lib I found that as I'm 64bit all files should be in lib64 and lib should be a symbolic link, so I moved the files place in lib by mkchroot.sh to lib64 and created a symbolic lic from lib64 to lib.
run "chmod u+s rssh_chroot_helper" for both the chrooted and root system executables (this was key to getting anything to work for me)
In /etc/default/rsyslog add update the line so that it looks like
RSYSLOGD_OPTIONS="-c4 -a /<chrooted dir>/dev/log" (this way you will have logging from the chroot, otherwise you will be working blind)
Now in theory this is a function chrooted directory you can test by running "chroot /<ch root directory> /bin/bash" (likely this will still fail, as we need more shared objects and I'm unsure why, see directory listing above for what I found required, your install may differ some however, sorry I can not fully explain why these are needed)
Assuming you have all the shared objects present run "chroot /<ch root directory> /bin/bash" again you should now be in the chroot and see a simple prompt "#"
manually execute all the executables now they should all function if any fails write down what shared object is missing so you can add it.
type "exit" to leave the chroot fix and libraries and repeat as needed.
Once every executable works, try scp and sftp (or whatever else you are using chrooted) they should work.
If any of them fail, go back and look at /var/log/syslog for some ideas, as for me everything at this point was operational.
If you want remove bash, dash and ls now, but I left them to use trouble shooting in the future.
Comments
0 B
|👍
/👎