Let on-call run the script OPS-2234

OpenShell basics · Easy · Do · about 10 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Mara Okafor opened OPS-2234 at 11:02task

Every morning at 07:00 the on-call engineer rotates the label printer queues. This morning Mara got "Permission denied" on the script.

srv/current/bin/rotate-labels is owned by the release account and belongs to the on-call group. Mara is in that group. She can cat the script but cannot run it.

"Do not make it 777 to get rid of the error, the deploy key lives in the same directory and Priya will have my head. Just the group, please." (Mara)

Unix permissions come in three sets: owner, group, everyone else. Each has read, write, and execute. Mara matches the group set.

Your task

Give the group execute permission on rotate-labels, keep the owner's full access, and give nobody else anything. Do not change deploy.key.

On the machine

  • rotate-labels and deploy.key (mode 600), with ls -l
  • TICKET.md

Timeline

07:00Mara runs rotate-labels: "Permission denied".
07:05She rotates the queues by hand. It takes twenty minutes.
11:02OPS-2234: let on-call run the script again.

Done when

  1. The group can read and execute rotate-labels.
  2. Others have no access, and deploy.key keeps mode 600.
  3. The owner keeps read, write, and execute.

Hints

Hint 1

ls -l shows three triplets: owner, group, others.

Hint 2

Translate the current mode digit by digit: 7 is rwx, 4 is r--, 0 is ---. Which of the group's bits are missing, and do others have any?

Hint 3

The target is owner rwx, group r-x, others nothing: 750.

Hint 4

Avoid 755 and 777: they give access to everyone.

Show the solution

Read the current mode with ls -l, then set chmod 750 srv/current/bin/rotate-labels (or the symbolic equivalent, such as chmod g=rx,o= ...): the owner keeps rwx, the group can read and execute, others get nothing.