LINUX CORE · 84
Users / Groups / Permissions / sudo:Process 能不能讀這個檔,不只看檔案存在
Linux permission 是 execution boundary 的一部分。Service 用哪個 user 跑、檔案 owner/group 是誰、mode bits 如何設定,都會直接決定 process 能否 read/write/execute。
Learning outcomes
- 能讀 user/group/other permission bits。
- 能理解 process identity 與 file access。
- 能區分 chmod/chown/sudo。
- 能避免用 777 當萬用修復。
1. Permission string
-rw-r----- 1 app app 2048 config.envowner 可 read/write,group 可 read,others 無權限。第一個字元表示 file type。
2. rwx
r = read
w = write
x = execute / traverseDirectory 的 x 更接近「能 traverse 進入」,語意和普通 file execute 不完全一樣。
3. chmod / chown
chmod 640 config.env
chown app:app config.envchmod 改 permission mode;chown 改 owner/group。兩者解的是不同問題。
4. sudo 是權限提升,不是普通前綴
sudo systemctl restart course-apisudo 讓 command 以另一個高權限 identity 執行。只在必要操作使用,避免用 root 掩蓋 ownership/config 問題。
5. 為什麼 chmod 777 通常不是好解法
它把所有 user 都給 read/write/execute,blast radius 太大。正確方式是先找「哪個 process user 需要哪個最小權限」。
process user: app
needs:
read config
write logs
does not need:
modify executable codeProject checkpoint:Server Workspace v4
設定 app user 只能讀 config、寫 logs,但不能修改 release code。故意把 log directory owner 設錯,再從 service error 修到最小必要權限。
/srv/course-api/releases root:root 755
/srv/course-api/config app:app 640
/srv/course-api/logs app:app 750Debug evidence:Permission denied
- process 以誰執行?
- target path 每一層 directory 可 traverse 嗎?
- file owner/group/mode 是什麼?
- 是否其實是 SELinux/container mount 等另一層限制?
Knowledge check
- chmod 和 chown 差在哪?
- Directory x 代表什麼?
- 為什麼 777 是危險 shortcut?
- 替 app/config/logs 設計 least-privilege matrix。