On Wed, 28 Sep 2022 18:51:01 +1000 (AEST) Michael Chapman <mike@xxxxxxxxxxxxxxxxx> wrote: > On Wed, 28 Sep 2022, Branko wrote: > > On Wed, 28 Sep 2022 18:11:14 +1000 (AEST) > > Michael Chapman <mike@xxxxxxxxxxxxxxxxx> wrote: > > > > Sure, but this example is kind of useless as it doesn't bind-mount > > anything into chroot. > > Sure, but you didn't mention anything about bind mounts. > > I added: > > BindReadOnlyPaths=/usr > > and my example still works for me. OK. You have bound one path. Is the executable within it or is it irrelevant for the case ( and the executable is in /tmp) ?