Linux Basics 2 · Final challenge

Final challenge: Monday morning

You're back from a week away, and the family server has a to-do list waiting. Updates piled up, a website arrived as a zip, the logs folder is overflowing, the app is moving to a new domain, and something on the server says "permission denied" even to root.

How this works

No step-by-step instructions: the objectives say what must be true when you're done. Everything you need is in Linux Basics 2; the cheat sheet and search (/) are allowed, and hints are below the terminal. Objective 5 is different on the two families: do it on both for bragging rights.

The brief

  1. Fully patched. Every update is installed, and the server is running the new kernel.
  2. The website is unpacked. The files from downloads/website.zip are in ~/site, so ~/site/index.html exists.
  3. The logs are tidied. In ~/logs, the app logs for September 1 to 5 are gone. Days 6 to 9 and both error logs stay.
  4. The app has moved. In ~/app.conf, every old.example.com becomes cht.example.com, the port is 8081 and debug is false.
  5. Protection on, problem fixed. On Rocky, the site in /srv/www loads with SELinux enforcing. On Ubuntu, the notes service saves to /srv/notes with its AppArmor profile enforcing. No switching the protection off to "fix" it.

Stuck? Hints

Open only as many as you need.

1. Fully patched

Upgrade everything with the family's package manager, then check whether a reboot is needed (needs-restarting -r on Rocky, /var/run/reboot-required on Ubuntu). uname -r before and after tells you which kernel is running.

Still stuck: lesson 6.

2. The website

Look inside before you extract: unzip -l. If the zip already has a top folder, you don't need -d. You may need to install unzip first.

Still stuck: lesson 5.

3. The logs

A range in square brackets matches one character: [1-5]. Put echo in front of rm first to see exactly what it would delete.

Still stuck: lesson 2.

4. The app

On Rocky only vi is installed out of the box (it's vim too, just smaller); vim-enhanced gives you the full one. In vim, :%s/old/new/g replaces everywhere. Then find the port line with /port, and change the value with cw. Save with :wq.

Still stuck: lesson 1.

5. Protection on

Rocky: the files have the wrong SELinux label. Add a permanent rule with semanage fcontext, then apply it with restorecon. Ubuntu: the profile doesn't allow /srv/notes. Add the path to the profile, reload it with apparmor_parser -r, and restart the service.

Still stuck: lesson 8.

Complete every objective in the terminal and the challenge is marked done automatically. It's optional, but it goes on your certificate.