Build, Inspect and Extract a Local ISO with xorriso
xorriso can build an ISO, look inside it and pull files back out, all without ever touching an optical drive. You will create an ISO 9660 image from a directory, inspect it without mounting it, and extract a selected tree into a separate directory, entirely with local regular files. It was tested with xorriso 1.5.6 from Ubuntu package version 1:1.5.6-1.1ubuntu3.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes. You need a shell, xorriso, a readable source directory, and enough space for the image and extracted copy. The examples write only under /tmp; replace the example paths with data you have deliberately chosen.
1. Check the installed command
Run these ordinary, read-only checks before anything else:
$ command -v xorriso
/usr/bin/xorriso
$ xorriso --version
xorriso 1.5.6 : RockRidge filesystem manipulator, libburnia project.
$ dpkg-query -W -f='${Package} ${Version}\n' xorriso
xorriso 1:1.5.6-1.1ubuntu3
The program is a session-based ISO tool. It can create or load an image, make changes in memory, and write a session when the run commits or ends normally. It treats a regular file as an overwriteable storage target, which is exactly what makes it a safe test bed before real media gets involved.
Checkpoint
If command -v prints nothing, stop here and install the package through your normal system administration process. Do not grab a binary from an unverified download just to keep the example moving.
2. Prepare a small source tree
Make a source directory with files that are safe to copy around. This only changes state under /tmp and needs no elevated privileges:
$ work=$(mktemp -d /tmp/xorriso-guide.XXXXXX)
$ mkdir -p "$work/source/docs" "$work/extract"
$ printf '%s\n' 'xorriso guide test' > "$work/source/README.txt"
$ printf '%s\n' 'safe example' > "$work/source/docs/example.txt"
$ printf 'working directory: %s\n' "$work"
working directory: /tmp/xorriso-guide.ABC123
The final directory name is generated, so your output will differ. Keep the value of work in the same shell; open a new one and you will need to set work again to the actual directory the previous command showed.
3. Create the ISO image
Use -outdev to pick a new image file, -map to copy a disk tree into an ISO path, and -volid to give the volume a recognisable label:
$ xorriso -outdev "$work/image.iso" \
-map "$work/source" /backup \
-volid GUIDE_TEST \
-commit
ISO image produced: 27 sectors
Writing to '/tmp/xorriso-guide.ABC123/image.iso' completed successfully.
In the image, the source directory contents land below /backup. The trailing -commit makes the write explicit; a normal end would commit pending changes too, but an explicit commit is easier to review in a script.
Destructive boundary: do not swap the regular file for /dev/sda, /dev/sdb, or another disk path while experimenting. xorriso really will write to storage targets. Move to optical media or a block device later, and verify the device identity and media state separately: blanking or committing is irreversible for that session.
Checkpoint
Confirm the image exists and is not empty:
$ stat -c '%n %s bytes' "$work/image.iso"
/tmp/xorriso-guide.ABC123/image.iso 55296 bytes
4. Inspect the image without mounting it
Load the image with -indev and list its ISO paths with -ls. This is read-only:
$ xorriso -indev "$work/image.iso" -ls / -ls /backup
'/':
'backup'
'/backup':
'README.txt'
'docs'
ISO paths start at /, even though the image itself is an ordinary file. Keep disk paths and ISO paths distinct: "$work/source/docs" is on the host, while /backup/docs is inside the image, and the two are not interchangeable.
Path not found? Check which namespace you used and whether the command actually got the expected image. Startup files can affect a run too: xorriso may read /etc/default/xorriso, /etc/opt/xorriso/rc, /etc/xorriso/xorriso.conf, and $HOME/.xorrisorc. Put -no_rc first for a controlled script:
$ xorriso -no_rc -indev "$work/image.iso" -ls /backup
'/backup':
'README.txt'
'docs'
Reach for -no_rc whenever you need predictable defaults and have checked your command does not rely on a site-wide policy. It stops startup files silently adding settings or actions behind your back.
5. Extract a tree with osirrox mode
Reading an ISO is not the same as copying files out of it. Enable the ISO-to-disk feature with -osirrox on, then use -extract:
$ xorriso -no_rc -osirrox on \
-indev "$work/image.iso" \
-extract /backup "$work/extract"
Copying of file objects from ISO image to disk filesystem is: Enabled
Extracted from ISO image: file '/backup'='/tmp/xorriso-guide.ABC123/extract'
The destination directory must be writable. The command builds the contents of extract from the ISO tree, so inspect the destination before pointing it at a real path. A protected destination may need elevated privileges, but reach for a directory you own first.
Check the recovered files and their content:
$ find "$work/extract" -type f -print -exec sed -n '1p' {} \;
/tmp/xorriso-guide.ABC123/extract/README.txt
xorriso guide test
/tmp/xorriso-guide.ABC123/extract/docs/example.txt
safe example
The osirrox alias starts xorriso with ISO-to-disk restoring already enabled. The explicit form used here is clearer in a guide and keeps the setting visible in a longer command, but the alias works fine when you specifically want that mode. Either way, still check the input image and destination.
6. Recover from a failed or unwanted operation
Before a commit, image changes just sit pending in xorriso's session state. -rollback discards those changes; -rollback_end discards them and exits. This pattern is safe for a run where you only meant to inspect:
$ xorriso -no_rc -indev "$work/image.iso" \
-rollback_end
xorriso : NOTE : -rollback_end done
That rollback will not undo files already extracted to disk. Remove or restore an extracted directory with your normal file recovery method, and verify the exact path before deleting anything. Wrote to an image file by mistake? Preserve it for inspection instead of overwriting it with another test.
For an optical drive or block device there is no general undo for a committed write or blank operation. Keep an independent copy of important data, use a disposable test image first, and keep an input device selected by -indev mentally separate from an output target selected by -outdev.
Done means
- Version confirmed:
xorriso --versionidentifies the installed implementation and version. - Image built: a regular file contains an ISO image with the expected volume ID.
- Paths verified:
-lsshows the intended ISO paths under/backup. - Extraction checked:
-osirrox on -extractrestored files to a separate, checked destination. - Reversibility understood:
-commit, blanking and device writes change storage, while-rollback_endonly discards pending in-memory changes.