thanks for all the help, finally get some idea of how this X security works.

By default, X clients access ~/.Xauthority to find cookies in order to talk to X server.

In order to make scenarios like "su" then run some root only programs "xhost +local:" is needed as this would allow anyone on the same machine(or access to the /tmp/.X11-unix sockets) to connect to the running display.

For a chrooted environment, /tmp in chroot is different from /tmp in hosting so the above won't work. "xhost +localhost" is needed as that means any X apps running on the local machine(not depending on the rootfs anymore) can access the X server.

The above should be good enough for a workstation used by only one person. If one wants more security, it has to resort to using the 'xauth' command to extract the cookies then import into the destination ~/.Xauthority. Though this is still not encrypted in anyway.

If one need to access X apps on another machine, just add "xhost +hostname" but that would mean any X apps from hostname can access the running X server.

hope this will help others.