Theory
"Permission Denied"
देर-सवेर campus server आपको 'Permission denied' बताता है। यही Linux का security model अपना job कर रहा होता है। एक shared multiuser machine पर, हर किसी को हर file पढ़ने, बदलने, या चलाने में सक्षम नहीं होना चाहिए, तो हर file permissions carry करती है यह बताते हुए कौन क्या कर सकता है।
यह पूरे course के सबसे important topics में से एक है, और वह जिस पर students सबसे ज़्यादा confused होते हैं, उस compact number code (755 जैसा) की वजह से जो chmod इस्तेमाल करता है। हम इसे carefully build करेंगे और arithmetic verify करेंगे, ताकि octal codes second nature बन जाएँ।
Theory
तीन Permissions, तीन Classes
हर file में तीन permissions होती हैं:
- r (read): file के contents देखना।
- w (write): file बदलना या delete करना।
- x (execute): file को एक program की तरह चलाना (या, एक directory के लिए, इसमें enter करना)।
और ये लोगों की तीन classes के लिए अलग-अलग set होती हैं:
- user (u): file का owner।
- group (g): file के group के members।
- others (o): बाकी सब।
तो ls -l नौ permission characters दिखाता है, हर class के लिए तीन: उदाहरण के लिए -rwxr-xr-x का मतलब है owner read, write, execute कर सकता है; group read और execute कर सकता है; others read और execute कर सकते हैं।
At a glance
| Permission | Letter | Value |
|---|---|---|
| Read | r | 4 |
| Write | w | 2 |
| Execute | x | 1 |
| (none) | - | 0 |
Theory
एक Octal Digit तक Add करना
यहाँ वह trick है जो chmod codes को काम करने लायक बनाती है। हर class के लिए, आप इसके पास मौजूद permissions की values add up करते हैं, 0 से 7 तक एक digit देते हुए:
- rwx = 4 + 2 + 1 = 7 (तीनों)
- r-x = 4 + 0 + 1 = 5 (read और execute)
- rw- = 4 + 2 + 0 = 6 (read और write)
- r-- = 4 = 4 (read only)
तीन classes तीन digits देती हैं। तो -rwxr-xr-x owner 7, group 5, others 5 बन जाता है, जो famous 755 है। और -rw-r--r-- 6, 4, 4 बन जाता है, जो 644 है। वे दोनों, 755 और 644, सबसे common settings हैं जो आप मिलेंगे।
Practical
chmod Action में (verified output)
$ chmod 755 script.sh # owner rwx=7, group r-x=5, others r-x=5
$ chmod 644 notes.txt # owner rw-=6, group r--=4, others r--=4
$ ls -l
-rwxr-xr-x 1 riya riya ... script.sh # 755
-rw-r--r-- 1 riya riya ... notes.txt # 644
# 755 is typical for scripts/programs (runnable);
# 644 is typical for ordinary data files (not runnable).Quiz
आप चाहते हैं एक file owner से readable, writable, और executable हो, और सिर्फ़ group और others से readable हो। वह chmod octal code क्या है?
- 777, क्योंकि यह full access है
- 744, क्योंकि owner rwx = 7, group r = 4, others r = 4
- 755, क्योंकि owner rwx = 7, group और others r = 5
- 644, क्योंकि owner rw = 6
Show the answer
744, क्योंकि owner rwx = 7, group r = 4, others r = 4
हर class को एक digit में काम कीजिए। Owner को rwx = 4 + 2 + 1 = 7 चाहिए। Group को read only = r-- = 4 चाहिए। Others को read only = r-- = 4 चाहिए। तो code 744 है। Option A (777) सबको rwx देता है (write और execute भी), group और others के लिए 'सिर्फ़ readable' से कहीं ज़्यादा। Option C (755) group और others को r-x = 5 देता है, इसमें EXECUTE शामिल है, पर हमें read only चाहिए था, तो उनके लिए 5 ग़लत है। Option D (644) owner को सिर्फ़ rw = 6 देता है, owner के लिए required execute miss करते हुए। हमेशा हर class अलग-अलग convert कीजिए: owner 7, group 4, others 4 -> 744।
Theory
Ownership और Default Permissions
Permissions decide करती हैं हर class क्या कर सकता है; ownership decide करता है कौन किस class में है।
- chown एक file के owner को बदलता है (chown riya file), और
chown user:group fileowner और group दोनों set करता है। - chgrp सिर्फ़ group बदलता है (chgrp students file)।
और जब आप एक नई file create करते हैं, इसकी starting permissions umask से आती हैं, जो कुछ bits mask off करता है। एक typical umask 022 नई files को 644 और नई directories को 755 देता है, यही वजह है fresh files सबसे readable होती हैं पर सिर्फ़ आपके द्वारा writable। (Directories 777 से शुरू होती हैं और files 666 से, mask apply होने से पहले।)
Think first
एक Directory को Execute Permission की ज़रूरत क्यों होती है?
एक program पर Execute का मतलब है 'इसे चलाओ'। पर एक directory पर execute permission का क्या मतलब है, और आपको यह क्यों चाहिए? फिर tap कीजिए।
Show the answer
एक DIRECTORY पर, execute (x) का मतलब है 'आप इसमें ENTER कर सकते हैं और अंदर की files को नाम से access कर सकते हैं', यह directory में traverse करने की permission है, इसे चलाने की नहीं। यह एक subtlety है जो लोगों को trip करती है। एक directory पर Read (r) आपको इसमें मौजूद names LIST करने देता है; execute (x) आपको actually इसमें cd करने और अंदर एक specific file तक पहुँचने देता है। आपको अक्सर दोनों चाहिए होते हैं: x के बिना आप directory में बिल्कुल enter नहीं कर सकते, भले ही आप एक file का exact नाम जानते हों; r के बिना आप वहाँ क्या है यह list नहीं कर सकते। यही वजह है directories commonly 755 (rwxr-xr-x) होती हैं: x bits लोगों को enter करने और files तक पहुँचने देते हैं, जबकि write owner के लिए reserved है। अगर आप कभी एक folder में cd करने की कोशिश करते हुए 'Permission denied' पाएँ, भले ही अंदर की files readable दिखें, missing execute bit directory पर usual culprit है। तो directories के लिए, x को 'दरवाज़े से चलने की key' सोचिए, एक program चलाने से अलग मतलब, पर same bit और octal math में 1 की same value।
Summary
Key takeaways
- हर file में तीन permissions होती हैं, r (read, 4), w (write, 2), x (execute, 1), तीन classes के लिए: user/owner, group, others।
- ls -l नौ permission characters दिखाता है, per class तीन, -rwxr-xr-x जैसा।
- हर class के लिए, एक octal digit पाने के लिए values add कीजिए: rwx=7, r-x=5, rw-=6, r--=4।
- तो chmod 755 = rwxr-xr-x (7,5,5), programs के लिए typical; chmod 644 = rw-r--r-- (6,4,4), data files के लिए typical।
- chown owner बदलता है (chown user:group दोनों set करता है); chgrp group बदलता है।
- umask bits mask off करके default permissions set करता है; umask 022 नई files को 644 और नई directories को 755 देता है।
- एक directory पर, execute (x) का मतलब है इसमें enter करने की permission; memory hook: r=4, w=2, x=1, per class add कीजिए।