Working With Permissions, Users and Groups
Goal
You create users and groups, set the special bits a shared directory needs, and even build a script that checks by itself whether permissions are as expected.
Why it matters
Most permission incidents happen because people look only at "file permissions" and forget "directory permissions." What you need to delete a file is not write permission on that file but write permission on the directory that contains it. That is why even a read-only file can be deleted by someone else, and Unix added the sticky bit separately to close that hole. For the same reason, a directory used by several people needs setgid; without it, each person creates files with their own primary group and the situation where people cannot read each other's files keeps repeating.
Steps
- Create
/root/secret.txtand set its permissions to600. - Create the user
student1. - Create the group
devsand addstudent1to that group (keep the existing groups). - Create
/root/shared/report.txtand change its owner:group tostudent1:devs. - Set the group of the
/root/shareddirectory todevsand its permissions to2770. - Create the
/root/shared/incomingdirectory and set its permissions to1777. - Create
/root/shared/run.shand set its permissions to750. - Create
/root/shared/checkmode.sh <파일경로> <기대권한>(file path, expected permissions). It must be executable, and it must exit with code 0 when the permissions match and a non-zero code when they differ, printing the current permissions in that case. It must also exit with a non-zero code when the file does not exist.
Notes
stat -c %a 파일prints only the octal permissions. If a special bit is set, it comes out as four digits.- With
id -nG student1you can see the list of groups the user belongs to. - Common mistake 1: in step 3, if you write
usermod -G devs student1without-a, all existing supplementary groups disappear. - Common mistake 2: in step 5, if you only run
chmod 770, the leading setgid digit is missing. Specify four digits.
Lock down the secret file's permissions
Create /root/secret.txt and set its permissions to 600.
The three octal digits are owner, group, and others, in that order. What gives read and write access to the owner only?
Create a user
Create the user student1.
Create it with useradd. You can check it with the id command.
Create a group and add the user
Create the group devs and add student1 to that group (keep the existing groups).
Create the group with groupadd and add the user to a supplementary group with usermod. If you leave out -a, the existing groups are wiped out.
Change the owner and group
Create /root/shared/report.txt and change its owner:group to student1:devs.
chown accepts the owner:group format in one go. The file must exist first.
Set setgid on the shared directory
Set the group of the /root/shared directory to devs and its permissions to 2770.
In the four octal digits, the leading digit is the special bit. Find the value responsible for group inheritance.
Set sticky on the upload directory
Create the /root/shared/incoming directory and set its permissions to 1777.
Check the permissions of /tmp with ls -ld. Make yours the same form.
Organize the script's permissions
Create /root/shared/run.sh and set its permissions to 750.
It is the combination where the owner has read, write, and execute, the group has read and execute, and others have nothing.
Write a permission check script
Create /root/shared/checkmode.sh <파일경로> <기대권한> (file path, expected permissions). It must be executable, and it must exit with code 0 when the permissions match and a non-zero code when they differ, printing the current permissions in that case. It must also exit with a non-zero code when the file does not exist.
Read the current permissions with stat -c %a and compare them with the expected value. Report the result through the exit code, and on a mismatch also print the current permissions.