Your Freedom server is a multi-user environment. It handles multiple users all working simultaneously on completely unrelated tasks. The system is responsible for properly sharing and managing requests for hardware devices such as memory, disk access, network connectivity and CPU time appropriately to each user. Every user on the system also belongs to one or more user groups.
Because the system is capable of supporting multiple users, everything the system manages has an owner, a group, and a set of permissions governing who can read, write, and execute the resource. Most of the work you will do with ownership and permissions will be on files and directories.
When listing files with the ll command, information about the owner, group and permissions of the file are included in the list, along with information about the file’s size and when it was last modified. For example, the following command displays information about a file named aliases in the current directory:
> ll aliases
-rw-rw-r-- 1 root mailadmin 1459 Jan 21 06:46 aliases
In this example, the file is owned by the root user and belongs to the group named mailadmin. The permissions of the file are displayed as a series or letters and dashes in the first column of the display. This set of characters tells us four things about the file: what type of file it is, what the owner can do to the file, what the group can do to the file, and what everyone else (e.g. “the world”) can do to the file. There are three basic types of permissions that are represented as follows:
r - Read the file or directory
w - Write to the file or directory
x - Execute the file or search the directory
You can view file and directory ownership and permissions by displaying a long directory listing via the ll command. The set of permissions for each file or directory is displayed as a string of characters, as shown below:
-rw-rw-r--
Here is an explanation of how to interpret these characters in order to understand the permissions:
The first character, from left to right, is a special character that tells if this is a regular file (-), a directory (d), or something special such as a symbolic link (represented by an l). In the above example, the beginning dash (-) denotes that this is a regular file.
The next three characters, designated in this example as rw-, indicate what the user who owns the file can do with it. In this example, the owner is allowed to read and write to the file.
The next three characters, r--, give the permissions for the group (g) that the file belongs to. The group that owns this sample file can read and write to the file.
The final three characters, r--, give the permissions for the rest of the world (o). In this example, the “world” may read the file, but not write to it.
To summarize, the permissions on this sample file are set so the owner and group can read and write to the file, but the rest of the world can only read the file.
Note that directories are also treated as files. They have read, write, and execute permissions. The executable bit for a directory has a slightly different meaning than it does for a file. When a directory is marked executable, it means it can be searched into; for example, a directory listing can be done in that directory. Taking the execute permissions off of a directory prevents users from viewing its contents.