Posts

Showing posts with the label Linux Administration

Linux Octal Permissions: Reading and Setting chmod Values

Linux expresses file permissions as three digits — 755, 644, 600. Each digit is a single octal number that encodes three yes-or-no answers at once. Once you see why octal was chosen, the notation stops being something to memorize and becomes something you can derive on the spot, which is exactly what the Linux+ exam wants. Why octal Every file has three permission bits for each of three identities. The bits are read, write, and execute; the identities are the owner (user), the group, and everyone else (other). Three bits per identity means eight possible combinations, and eight possible values is precisely one octal digit. Three identities, three digits. Inside a digit the bits carry fixed weights: read is 4, write is 2, execute is 1. Add the ones you want. Read plus write is 6. Read plus execute is 5. All three is 7. Read only is 4. Nothing is 0. Because 4, 2, and 1 are powers of two, every sum is unique — there is only one way to make each number from 0 through 7, so ...

YUM and DNF: Package Management and Patching on RPM Systems

YUM and its successor DNF are the package managers for RPM-based distributions — Red Hat Enterprise Linux, Fedora, CentOS Stream, Rocky, AlmaLinux. They sit on top of the low-level RPM tool and add the two things that make package management usable: automatic dependency resolution and repository management. RPM, YUM and DNF The rpm command installs, queries and removes individual package files. It does not fetch anything and it does not resolve dependencies — it tells you a dependency is missing and stops. That is the behaviour that produced the phrase "dependency hell," where satisfying one requirement reveals three more. yum added repositories and dependency resolution. dnf rewrote it with a better resolver and faster metadata handling, and on current releases yum is a symbolic link to dnf , so the commands are interchangeable and the older name persists in documentation and muscle memory. The division of labour is worth holding: RPM is the package format and the ...

SELinux: Mandatory Access Control, Contexts, and Enforcing Mode

SELinux enforces access rules that the file owner cannot change and that root cannot casually override. That single property — policy set by the system rather than by the resource owner — is what makes it mandatory access control, and it is the distinction the exam is testing when SELinux appears. Discretionary versus mandatory Standard Linux permissions are discretionary: the owner of a file decides who may read or write it, and root may do anything. That model works until a process is compromised, at which point the attacker inherits everything that process was allowed to do — which, for a service running as root, is everything. Mandatory access control adds a second layer that the process cannot negotiate with. A system-wide policy states which subject types may perform which operations on which object types, and the kernel enforces it regardless of ownership or user identity. A compromised web server confined by policy can read its document root and open its l...