← Systems Foundations

LINUX CORE · 84

Users / Groups / Permissions / sudo:Process 能不能讀這個檔,不只看檔案存在

Linux permission 是 execution boundary 的一部分。Service 用哪個 user 跑、檔案 owner/group 是誰、mode bits 如何設定,都會直接決定 process 能否 read/write/execute。

Learning outcomes

1. Permission string

-rw-r----- 1 app app 2048 config.env

owner 可 read/write,group 可 read,others 無權限。第一個字元表示 file type。

2. rwx

r = read
w = write
x = execute / traverse

Directory 的 x 更接近「能 traverse 進入」,語意和普通 file execute 不完全一樣。

3. chmod / chown

chmod 640 config.env
chown app:app config.env

chmod 改 permission mode;chown 改 owner/group。兩者解的是不同問題。

4. sudo 是權限提升,不是普通前綴

sudo systemctl restart course-api

sudo 讓 command 以另一個高權限 identity 執行。只在必要操作使用,避免用 root 掩蓋 ownership/config 問題。

5. 為什麼 chmod 777 通常不是好解法

它把所有 user 都給 read/write/execute,blast radius 太大。正確方式是先找「哪個 process user 需要哪個最小權限」。

process user: app
needs:
  read config
  write logs
does not need:
  modify executable code

Project checkpoint:Server Workspace v4

設定 app user 只能讀 config、寫 logs,但不能修改 release code。故意把 log directory owner 設錯,再從 service error 修到最小必要權限。

/srv/course-api/releases  root:root  755
/srv/course-api/config    app:app    640
/srv/course-api/logs      app:app    750

Debug evidence:Permission denied

  1. process 以誰執行?
  2. target path 每一層 directory 可 traverse 嗎?
  3. file owner/group/mode 是什麼?
  4. 是否其實是 SELinux/container mount 等另一層限制?

Knowledge check

  1. chmod 和 chown 差在哪?
  2. Directory x 代表什麼?
  3. 為什麼 777 是危險 shortcut?
  4. 替 app/config/logs 設計 least-privilege matrix。