Sal can read the file but not reach it OPS-771

Open2 versionsLinux · Easy · Fix · about 20 min ·Linux, root

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Sal Brennan opened OPS-771 at 09:12SEV-4

Month-end close starts tomorrow. Since last night's archive migration, finance cannot open a single depot report, even though every file is group-readable.

Sal is in the reports group and report.csv is readable by that group. It still fails. Priya from security has one condition:

"Fix Sal, not the world. Noor is a contractor and must stay out, and nothing under /srv/reports becomes world-readable." (Priya)

To open a file, you need permission on the file and execute (search) permission on every directory on the way to it. The migration restored the directories from a template that was written for files.

Your task

Find the directory on the path that blocks the reports group and grant the group only what it needs to pass through. Do not add anyone to a group, and do not make anything world-readable or group-writable.

On the machine

  • namei -l /srv/reports/2026-09/report.csv shows every directory on the path
  • sudo -u sal cat … and sudo -u noor cat … test as each user
  • id sal, id noor

Timeline

22:00Archive migration moves /srv/reports to new storage and restores permissions from a template.
09:05Sal: "cat: report.csv: Permission denied".
09:12OPS-771 opened. Month-end close starts tomorrow 08:00.

Done when

  1. Sal can read report.csv.
  2. Noor still cannot, and nothing became world-readable or group-writable.

Hints

Hint 1

Reading a file needs read on the file and **execute** on every directory above it.

Hint 2

`namei -l` prints the owner, group, and mode of each component. Read all three, not just the bits.

Hint 3

`r` without `x` on a directory lets you list names but not open anything inside. And group bits only help the members of that directory's group.

Hint 4

Change the directory, not people's group memberships, and nothing for others.

Show the solution

Run `namei -l /srv/reports/2026-09/report.csv` and read each directory's owner, group, and mode. If `/srv/reports` shows `drwxr----- root reports`, the group can list it but not traverse it: `sudo chmod g+x /srv/reports`. If it shows `drwxr-x--- root archive`, the modes are right but the group is the export tool's: `sudo chgrp reports /srv/reports`. Verify with `sudo -u sal cat` (works) and `sudo -u noor cat` (denied).