Theory
The Unwanted Editor
Imagine you spent 3 hours writing your Python script on LabOne for the upcoming lab exam. You leave your terminal logged in for 5 minutes to grab a tea. When you return, a classmate has accidentally modified your file, changing your variables and breaking your logic. On a shared server with 30 students, how does the operating system make sure your private files cannot be wiped out or read by anyone else without your permission?
Theory
The Bank Locker System
Think of file protection like a bank locker room. The room holds boxes belonging to hundreds of different people. But you cannot just open any box. You need a specific key, and the bank manager verifies your identity first. In an operating system, every file has a list of who owns it and what they are allowed to do: read it, write to it, or execute it. The OS acts as the guard, checking your identity before letting you touch any file.
Theory
Defining File Protection
In a multi user system, file protection is a mechanism controlled by the operating system to secure files against unauthorized access, modification, or destruction. The system must guarantee that only users with explicit permission can access a specific file. It achieves this by tracking user identities and enforcing an access control list or protection bits that dictate allowable actions for different categories of users.
At a glance
A standard protection bit layout mapping actions to user categories on LabOne.
| User Type | Read (r) | Write (w) | Execute (x) |
|---|---|---|---|
| Owner (You) | Allowed: Can view content | Allowed: Can modify code | Allowed: Can run program |
| Group (Lab Batch) | Allowed: Can view content | Denied: Cannot edit files | Allowed: Can run program |
| Others (Rest of College) | Denied: Blocked completely | Denied: Blocked completely | Denied: Blocked completely |
Think first
Decoding Permission Bits
On the LabOne terminal, you check your file permissions and see a setting represented as rwxr-x---. If a student belonging to your lab group attempts to edit your file, analyze what the operating system will do. Think through the permission categories mentally before revealing the answer.
Show the answer
Step 1: The OS breaks the string into 3 groups of 3 bits: owner (rwx), group (r-x), and others (---).
Step 2: The system identifies that your classmate belongs to your lab group, so it checks the second group: r-x.
Step 3: The r means read is allowed, and the x means execute is allowed. The hyphen in the middle indicates that write permission is denied.
Step 4: The operating system blocks the write request and throws a Permission Denied error, preventing the student from editing your file.
Quiz
If a file on LabOne has its permissions set to read and write active but execute disabled, what will happen when you try to run it as a compiled C program?
- The program runs but cannot save any changes to disk
- The operating system refuses to load the file into memory and blocks execution
- The program runs normally because owner rights override execute bits
- The program crashes with a compilation error inside the terminal
Show the answer
The operating system refuses to load the file into memory and blocks execution
Even if you own the file and have full read and write access, an operating system requires the explicit execute bit (x) to be enabled before it treats a file as a runnable program. Without it, the OS treats it purely as text or data, blocking execution.
Watch out
The Owner Omnipotence Fallacy
A classic trap in semester exams is assuming that because you are the creator or owner of a file, you can automatically execute it at any time. This is incorrect. If you remove the execute bit from your own file, even you cannot run it until you change the permissions back. The operating system follows the active protection bits blindly, applying the rules strictly to everyone, including the file owner.
Quiz
In a standard Linux environment like our LabOne server, permissions are often represented as a 3 digit number where r=4, w=2, and x=1. What does a permission score of 750 mean?
- Owner has rwx, group has r-x, others have no access
- Owner has r-x, group has rwx, others have read only
- Owner has read only, group has write only, others have execute only
- Owner has full access, group has write only, others have no access
Show the answer
Owner has rwx, group has r-x, others have no access
To find the score, add the values: 7 = 4+2+1 (rwx for owner). 5 = 4+0+1 (r-x for group). 0 = no bits active (--- for others). This matches the first option perfectly.
Theory
From LabOne to Modern Android
You will use these exact rwx bits heavily in Unit 4 when we learn Linux administration commands like chmod on LabOne. But the real surprise comes in Semester 3: modern Android operating systems use this exact file protection mechanism at their core. Every application you install is treated as a separate user. If an app wants to read your photos, Android treats it as an external user trying to access another user's directory, blocking it unless you grant explicit permission.
Summary
Key takeaways
- File protection prevents unauthorized reading, writing, or execution of user files on shared systems.
- Operating systems categorize users into three classes: owner, group, and others.
- Each user class is mapped to three operational permissions: read (r), write (w), and execute (x).
- Permissions can be represented as triple groupings of strings or calculated using octal numeric scores.
- The operating system checks these rules for every single file access request, blocking violations instantly.
- Memory hook: Owner, group, and other classes: check the bits to stop the clashes!