9 ms·
How do groups work on Linux?
- ScottBurson 9y agoOne of the most useful group-related tricks (introduced in BSD Unix, I believe) is the setgid bit on a directory. If this is set, new files and subdirectories created within the directory will have the same group as the directory, rather than the group of the process that created them.
- jaymzcampbell 9y agoI use this as a basic indicator of someone's Unix competency. Not as a straight binary thing, but if I'm talking to someone (interviewing or maybe debugging something) I've found that if you know about setgid/setuid you have probably been interested enough to know what you are doing.
- eru 9y agoI've seen interviewers ask for the sticky bit and the difference between hard and soft links as similar shibboleths.
- dozzie 9y agoI've seen them ask how to restore execution permissions after `chmod a-x /bin/chmod'. I usually answer to those smartasses that I my favourite way is to run the very non-executable /bin/chmod without any file juggling. I'm yet to meet anybody who wasn't surprised that it's possible.
- pnutjam 9y agoexplain?
- shabble 9y agoshabble@host:~$ cp /bin/chmod /tmp/chmoo shabble@host:~$ chmod 600 /tmp/chmoo shabble@host:~$ ll /tmp/ch* -rw------- 1 shabble shabble 59K Nov 21 17:15 /tmp/chmoo shabble@host:~$ /tmp/chmoo -bash: /tmp/chmoo: Permission denied shabble@host:~$ /lib64/ld-linux-x86-64.so.2 /tmp/chmoo /tmp/chmoo: missing operand Try '/tmp/chmoo --help' for more information.
- ansible 9y agoWell, that's a new one on me. I'd just have 'cat'ted the chmod executable onto some other executable, which keeps the permissions.
- AnIdiotOnTheNet 9y agoThis technique fails if chmod is compiled statically.
- mnarayan01 9y agoManually call e.g. /lib/ld-linux.so.2 (man ld.so for more info).
- jandrese 9y agoI'm a little surprised some smartypants hasn't come along and added a check to ld to prevent this from working, probably for "security" reasons. I've known about this trick for a long time, but I've always thought its days were numbered. Another way to solve the problem: scp unfuckedhost:/bin/chmod . ./chmod (stuff)
- fapjacks 9y agoThis is my go-to method for doing that. Years ago, in the 90s, I used that trick (with ftp) to overwrite a custom login script used to "prevent" users from logging in. You'd login and it would spit out like "You are not allowed to login!" and then immediately log you out. Well, ftp (this is before sftp or scp) let me copy over that. This was actually one of the computers used by the newspaper in the next town over. I'm still shocked actually that the worst I ever got from the sysadmin there was a stern phone call.
- agumonkey 9y agoI've worked around this without knowing about setgid ... It's funny how easily I suffer tiny papercuts that way, it should be obvious "there's a better way".
- deleted 9y ago[deleted]
- Iolaum 9y agoI finally created an account specifically to upvote this. I have created a shared folder in my laptop, running Ubuntu, with symbolic links from 2 users home directories (to avoid having data (mostly photos) stored twice) and manually fixing the group of new files has been a chore! Thanks!!
- dozzie 9y ago[dozzie@zorn /srv]$ ls -ld foo drwxrwxrwx 2 root wheel uarch 2 Nov 21 12:57 foo/ [dozzie@zorn /srv]$ touch foo/nabla [dozzie@zorn /srv]$ ls -l foo/nabla -rw-r--r-- 1 dozzie wheel uarch 0 Nov 21 12:58 foo/nabla [dozzie@zorn /srv]$ id uid=1001(dozzie) gid=1001(dozzie) groups=1001(dozzie) [dozzie@zorn /srv]$ uname -s -r FreeBSD 11.0-RELEASE-p1 This is called "BSD semantics". You can get the same behaviour with appropriate mount option for Ext2/3/4 and XFS.
- jwilk 9y agoWhat filesystem was that? And why is this behavior filesystem-specific?
- dozzie 9y agoNot what filesystem, it's what OS. FreeBSD. And ZFS, but UFS works the same.
- laumars 9y agoI could be wrong but I thought the file system's "drivers" did the handling of file system permissions rather than the OS / kernel? Or at least this was my experience when playing around with FUSE on hobby projects.
- jwilk 9y agoSo why did you mentation "Ext2/3/4 and XFS" if filesystem doesn't matter?
- dozzie 9y agoI don't see what you don't understand. I demonstrated that on FreeBSD created file inherits the group of its parent directory even without SGID, i.e. that FreeBSD exhibits BSD semantics. I also added that if you can have BSD semantics on Ext2/3/4 and XFS if you mount them under Linux with appropriate options.
- chairmanwow 9y agoI absolutely love Julia Evan's writing. I find her articles / zines to cover interesting and useful technical topics while remaining _extremely_ accessible to me (especially when I was a student)! I really admire her ability to present technical topics in plain language.
- rubbsdecvik 9y agoI fully agree. Even on topics I feel I know well, she's 1) shown me something I didn't know, and 2) shown me how a "newbie" could see the topic, making it easier for me to help teach/mentor someone else.
- agumonkey 9y agoIt's pretty interesting how one can make a subject look accessible. Often the main factor for ignorance is ceremony.
- 3ap 9y agoAlso "newgrp" can be used for join "new" groups without re-login.
- yjftsjthsd-h 9y agoAnd here I've been using `su - $ME` all this time. Thanks!
- lathiat 9y agoWorth noting that it's not functionally all that different in that newgrp spawns a new shell under the current one; aside from the - creating a login shell anyway - but you can do that with newgrp too
- tiben_ 9y agoSome highlighted words do not appear using Firefox 57 on my Ubuntu 16.04.3, like the word "julia" at the third line. It's OK with Chromium. EDIT: Seems a Firefox related bug, i noticed this strange behavior with other websites inc. Stack Overflow since then. Will investigate asap.
- woodrowbarlow 9y agoi am also using firefox 57 on ubuntu 16.04.3 and it looks fine to me. it must be something with your specific setup.
- Asooka 9y agoOhh, so THAT's why I have to log out and back in to have my group changes take effect. That, along with having to start a new shell to pick up new env vars from ~/.profile, are my two biggest annoyances with the Linux process model. Reminds me a bit of the Windows 98 days when you had to restart to change your IP address. I really wish someone would sit down and figure out how to propagate group and environment changes to already running processes and implement them.
- heywire 9y agoTake a look at the command “newgrp”
- gjjrfcbugxbhf 9y agoI think the op is looking for something like addgroup && newgrp
- bartbes 9y agoYou can load your .profile into your current shell using either '. ~/.profile' or 'source ~/.profile'.
- deleted 9y ago[deleted]
- discreditable 9y agoFor what it's worth, you have to logout/login on Windows for group changes to take effect. This makes me suspect something similar is at play in the Windows world.
- mason55 9y agoThe book she mentions, "The Linux Programming Interface," sounds pretty useful, but it's seven years old at this point. Does anyone know how much has changed or if there's a new version coming any time soon? Seems like it's worth $70 but the age has me concerned. I'm sure the basics, like the things this article is about, haven't changed, but I bet all the stuff around cgroups would be useful for how setgid works with a process.
- joshbaptiste 9y agoUseful is an understatement of The Linux Programming Interface (TLPI), yes seven years old but the only major thing that has probably changed is the number of syscalls has risen, other than that, still solid for understanding the OS primitives and interfaces that the Kernel uses to interact with user land. On the BSD side "The Design and Implementation of the FreeBSD Operating System (2nd Edition)" is also a great book to further one's understanding of operating system interfaces on the BSD side.
- mason55 9y agoCool, thank you for the feedback!
- deleted 9y ago[deleted]
- james-mcelwain 9y agoThe big thing I've found missing is discussion of containerization primitives, e.g. cgroups. The other Linux namespaces are discussed where appropriate, but in 2017 it would be nice to have a section on all these together.
- yubiox 9y ago"dr--r--r-- 1 bork awesome 6872 Sep 24 11:09 file.txt" This doesn't make sense.
- biggerfisch 9y ago$ mkdir file.txt $ ls -l drwxr-xr-x 2 USER GROUP 4096 Nov 21 11:49 file.txt $ chmod -xw file.txt $ for i in {1..180}; do touch file.txt/long_name_$i; done $ ls -l dr--r--r-- 2 USER GROUP 12288 Nov 21 11:50 file.txt File size is a bit off, but that's based on sector size and may be separately configurable - that's a bit beyond my knowledge.
- yubiox 9y agobut she says right above it: "So, for example, if a process is owned by the julia user and julia is in the awesome group, then the process would be allowed to read this file."
- biggerfisch 9y agoI'm not sure what you aren't understanding. Directories are just a type of file, so that's not wrong, the dir/file is owned by the `awesome` group, and the group permissions are `r--` so the group can indeed read it.
- jwilk 9y agoOr one could apply Occam's razor and admit that "d" was a typo.
- biggerfisch 9y agoOf course, that's a much more likely scenario. I was attempting to show that the line was not completely nonsensical is all.
- jandrese 9y agoIt's kind of useless, but not illegal. You won't be able to stat/open any of the files in the directory, although anybody can read their names. Putting a .txt on a directory name is also perfectly legal and still in bad form. I agree the most likely explanation is accidentally putting the d in there in the editing process.
- halayli 9y agoRegarding setuid, this is why when you run programs like ping(8) it doesn't require root access to open a raw socket. ping's setuid is set so upon execution it executes as root since ping is owned by root and then calls setuid(getuid()) to run as the intended user.
- Huggernaut 9y agoIn some distributions, ping is now no longer setuid, but instead setcap with CAP_NET_RAW to narrow down the privileges gained.