Theory
અણગમતો Editor
કલ્પના કરો કે તમે આવનારા lab exam માટે LabOne પર તમારો Python script લખવામાં 3 કલાક વિતાવ્યા. તમે એક ચા લેવા તમારું terminal 5 મિનિટ માટે logged in છોડી દો છો. જ્યારે તમે પાછા આવો છો, એક classmate એ ભૂલથી તમારી file modify કરી દીધી છે, તમારા variables બદલતાં અને તમારા logic ને તોડતાં. 30 students વાળા એક વહેંચેલા server પર, operating system કેવી રીતે પાકું કરે છે કે તમારી private files ને તમારી પરવાનગી વગર કોઈ બીજું ભૂંસી કે વાંચી ન શકે?
Theory
Bank Locker System
file protection ને એક bank locker room ની જેમ વિચારો. ઓરડામાં સેંકડો અલગ લોકોના boxes છે. પણ તમે બસ કોઈ પણ box ખોલી શકતા નથી. તમને એક ખાસ key જોઈએ, અને bank manager પહેલાં તમારી ઓળખની ખાતરી કરે છે. એક operating system માં, દરેક file પાસે એક યાદી હોય છે કે એનો માલિક કોણ છે અને એ શું કરવાની પરવાનગી રાખે છે: એને read કરો, એમાં write કરો, કે એને execute કરો. OS guard ની જેમ કામ કરે છે, કોઈ પણ file ને સ્પર્શવા દેતાં પહેલાં તમારી ઓળખ તપાસતાં.
Theory
File Protection વ્યાખ્યાયિત કરવું
એક multi user system માં, file protection operating system દ્વારા નિયંત્રિત એક mechanism છે જે files ને અનધિકૃત access, modification, કે વિનાશ સામે સુરક્ષિત કરે છે. system ને guarantee કરવી પડશે કે માત્ર સ્પષ્ટ પરવાનગી વાળા users જ એક ખાસ file access કરી શકે. એ user identities track કરીને અને એક access control list કે protection bits લાગુ કરીને એને હાંસલ કરે છે જે અલગ categories ના users માટે મંજૂર કાર્યવાહીઓ નક્કી કરે છે.
At a glance
LabOne પર user categories સાથે કાર્યવાહીઓ map કરતું એક પ્રમાણભૂત protection bit layout.
| User Type | Read (r) | Write (w) | Execute (x) |
|---|---|---|---|
| Owner (તમે) | મંજૂર: content જોઈ શકો છો | મંજૂર: code modify કરી શકો છો | મંજૂર: program ચલાવી શકો છો |
| Group (Lab Batch) | મંજૂર: content જોઈ શકો છો | નિષિદ્ધ: files edit કરી શકતા નથી | મંજૂર: program ચલાવી શકો છો |
| Others (બાકીનું College) | નિષિદ્ધ: સંપૂર્ણપણે block | નિષિદ્ધ: સંપૂર્ણપણે block | નિષિદ્ધ: સંપૂર્ણપણે block |
Think first
Permission Bits ને Decode કરવા
LabOne terminal પર, તમે તમારી file permissions તપાસો છો અને rwxr-x--- તરીકે દર્શાવેલી એક setting જુઓ છો. જો તમારા lab group થી સંબંધિત એક student તમારી file edit કરવાનો પ્રયાસ કરે, વિશ્લેષણ કરો કે operating system શું કરશે. જવાબ પ્રગટ કરતાં પહેલાં permission categories નું મનમાં વિશ્લેષણ કરો.
Show the answer
Step 1: OS string ને 3 bits ના 3 groups માં તોડે છે: owner (rwx), group (r-x), અને others (---).
Step 2: system ઓળખે છે કે તમારો classmate તમારા lab group થી સંબંધિત છે, તો એ બીજો group તપાસે છે: r-x.
Step 3: r નો અર્થ read મંજૂર છે, અને x નો અર્થ execute મંજૂર છે. વચ્ચેનો hyphen દર્શાવે છે કે write permission નિષિદ્ધ છે.
Step 4: operating system write request ને block કરે છે અને એક Permission Denied error ફેંકે છે, student ને તમારી file edit કરવાથી અટકાવતાં.
Quiz
જો LabOne પર એક file ની permissions read અને write સક્રિય પણ execute disabled set છે, શું થશે જ્યારે તમે એને એક compiled C program તરીકે ચલાવવાનો પ્રયાસ કરશો?
- program ચાલે છે પણ disk માં કોઈ ફેરફાર save કરી શકતું નથી
- operating system file ને memory માં load કરવાનો ઇનકાર કરે છે અને execution block કરે છે
- program સામાન્ય રીતે ચાલે છે કારણ કે owner rights execute bits ને override કરે છે
- program terminal ની અંદર એક compilation error સાથે crash થાય છે
Show the answer
operating system file ને memory માં load કરવાનો ઇનકાર કરે છે અને execution block કરે છે
ભલે તમે file ના માલિક હો અને પૂરી read અને write access રાખો, એક operating system ને એક file ને એક runnable program તરીકે treat કરતાં પહેલાં સ્પષ્ટ execute bit (x) enabled જોઈએ. એના વગર, OS એને વિશુદ્ધ રીતે text કે data તરીકે treat કરે છે, execution block કરતાં.
Watch out
Owner Omnipotence નો ભ્રમ
semester exams માં એક classic ફાંદો એ માનવું છે કે તમે એક file ના સર્જક કે માલિક છો એટલે તમે એને કોઈ પણ સમયે આપોઆપ execute કરી શકો. આ ખોટું છે. જો તમે તમારી પોતાની file થી execute bit હટાવો, તમે પણ એને ત્યાં સુધી ચલાવી શકતા નથી જ્યાં સુધી તમે permissions પાછી ન બદલો. operating system સક્રિય protection bits ને આંખ મીંચીને અનુસરે છે, નિયમોને સખ્તાઈથી દરેક પર લાગુ કરતાં, file owner સહિત.
Quiz
આપણા LabOne server જેવા એક પ્રમાણભૂત Linux માહોલમાં, permissions ઘણી વાર એક 3 અંકોની સંખ્યા તરીકે દર્શાવાય છે જ્યાં r=4, w=2, અને x=1. એક 750 નો permission score શું અર્થ છે?
- Owner પાસે rwx, group પાસે r-x, others પાસે કોઈ access નહીં
- Owner પાસે r-x, group પાસે rwx, others પાસે માત્ર read
- Owner પાસે માત્ર read, group પાસે માત્ર write, others પાસે માત્ર execute
- Owner પાસે પૂરી access, group પાસે માત્ર write, others પાસે કોઈ access નહીં
Show the answer
Owner પાસે rwx, group પાસે r-x, others પાસે કોઈ access નહીં
score શોધવા, મૂલ્યો ઉમેરો: 7 = 4+2+1 (owner માટે rwx). 5 = 4+0+1 (group માટે r-x). 0 = કોઈ bits સક્રિય નહીં (others માટે ---). આ પહેલા વિકલ્પ સાથે perfectly મેળ ખાય છે.
Theory
LabOne થી આધુનિક Android સુધી
તમે આ બિલકુલ rwx bits ને Unit 4 માં ભારે વાપરશો જ્યારે આપણે LabOne પર chmod જેવી Linux administration commands શીખીએ છીએ. પણ ખરું આશ્ચર્ય Semester 3 માં આવે છે: આધુનિક Android operating systems પોતાના core પર આ બિલકુલ file protection mechanism વાપરે છે. તમે જે દરેક application install કરો છો એને એક અલગ user તરીકે treat કરાય છે. જો એક app તમારા photos વાંચવા માંગે, Android એને કોઈ બીજા user ની directory access કરવાનો પ્રયાસ કરતા એક બહારના user તરીકે treat કરે છે, એને ત્યાં સુધી block કરતાં જ્યાં સુધી તમે સ્પષ્ટ પરવાનગી ન આપો.
Summary
Key takeaways
- File protection વહેંચેલા systems પર user files ના અનધિકૃત reading, writing, કે execution ને અટકાવે છે.
- Operating systems users ને ત્રણ classes માં categorize કરે છે: owner, group, અને others.
- દરેક user class ત્રણ operational permissions સાથે map થાય છે: read (r), write (w), અને execute (x).
- Permissions ને strings ના triple groupings તરીકે દર્શાવી કે octal numeric scores વાપરીને calculate કરી શકાય છે.
- operating system દરેક એક file access request માટે આ નિયમો તપાસે છે, ઉલ્લંઘનોને તરત block કરતાં.
- Memory hook: Owner, group, અને other classes: અથડામણ અટકાવવા bits તપાસો!