❯ bwrap \
--ro-bind /usr /usr \
--symlink usr/lib64 /lib64 \
--proc /proc \
--dev /dev \
--unshare-pid \
--new-session \
bash
bash: cannot set terminal process group (1): Inappropriate ioctl for device
bash: no job control in this shell
bash-5.3$ ps
PID TTY TIME CMD
1 ? 00:00:00 bwrap
2 ? 00:00:00 bash
3 ? 00:00:00 ps
bash-5.3$ ls -al /
total 4
drwxr-xr-x 5 1000 1000 120 1. Jän 23:09 .
drwxr-xr-x 5 1000 1000 120 1. Jän 23:09 ..
drwxr-xr-x 4 1000 1000 340 1. Jän 23:09 dev
lrwxrwxrwx 1 1000 1000 9 1. Jän 23:09 lib64 -> usr/lib64
dr-xr-xr-x 350 65534 65534 0 1. Jän 23:09 proc
drwxr-xr-x 10 65534 65534 4096 31. Dez 11:57 usr
bash-5.3$
This is to show that is no need to copy files on by one (except someone paranoid).
The RAM consumed is 170KB for bwrap + 2,2MB for bash. I wander where is the size of /usr,
It seams this tmpfs (in RAM) is not seen by host... but is consumed.