Permissions & ownership
rwx for user, group and others, chmod in symbolic and octal form, chown, umask and special bits.
Linux was built as a multi-user system from day one. Every file and directory has an owner, a group and a set of permissions that decide who can read, write or execute it. Understanding them prevents both "Permission denied" frustration and dangerous security holes.
Reading permissions#
The first column breaks down like this:
Then come the link count, the owner (ada) and the group (ada). On Ubuntu, every user gets a personal group with the same name.
Note the directory rule. Deleting a file needs write permission on the directory, not on the file itself.
Running a script needs x#
chmod: symbolic mode#
chmod who±what file:
- who:
u(user/owner),g(group),o(others),a(all) - operator:
+add,-remove,=set exactly - what:
r,w,x
chmod: octal (numeric) mode#
Each permission has a value. r = 4, w = 2, x = 1, and you add them up per group:
stat -c '%a' prints the octal form, which is handy in scripts.
Recursive changes use -R, but be careful: you usually want different modes for files and directories. Let find pick them separately:
(Or use chmod -R u=rwX,go=rX shared, where a capital X adds execute only to directories and files that are already executable.)
🚫 Never
chmod -R 777to "fix" a permission problem. It makes everything writable by every user and process on the system, a classic security hole. Find out who needs access and grant exactly that.
Ownership: chown and chgrp#
Only root can give a file to another user, so these usually need sudo:
A common real-world fix: files created with sudo belong to root, so your user can't edit them. Run sudo chown -R "$USER": path to take them back.
umask: default permissions#
New files start from 666 (files) or 777 (directories), and the umask removes bits from that:
With umask 0022, new files get 644 and new directories 755. A stricter umask 077 (set it in ~/.bashrc) makes new files private (600/700).
Special bits: setuid, setgid and sticky#
- setuid (
sin the user's x position, octal4000): the program runs with its owner's privileges.passwdis owned by root and setuid, which is how ordinary users can update the root-owned/etc/shadow. setuid programs are powerful, so audit them:find / -perm -4000 -type f 2>/dev/null. - setgid (
sin the group position,2000): on a directory, new files inherit the directory's group. That's perfect for shared team folders:chmod 2775 /srv/project. - sticky bit (
tin the others position,1000): in a shared writable directory, users can delete only their own files. That's why/tmpis1777.
Access control lists (ACLs)#
When owner/group/others isn't flexible enough, for example "give one extra user read access", use ACLs (package acl):
(getfacl was run before setfacl -b, so the extra user:www-data entry is still visible.)
A + at the end of the permission string in ls -l (-rw-r-----+) tells you a file has ACL entries.
Diagnosing "Permission denied"#
- Who am I? Run
idto see your user and groups. - What does the file allow?
ls -l file. - What about every directory on the path? You need
xon each one.namei -l /path/to/fileshows the permissions along the whole path. - Is it a system file? Use
sudo, or better,sudoedit. - Just added to a group? Group membership applies at the next login (or run
newgrp groupname).
Common mistakes#
chmod -R 777as a fix-all. It hides the real problem and opens a security hole.- Removing
xfrom directories with a carelesschmod -R 644 dir. After that nobody cancdinto the subdirectories. Useu=rwX,go=rXinstead. - Editing files as root and leaving them root-owned in your home directory or project, so your editor or app can't write them later.
- SSH keys that are too open.
sshrefuses a private key that others can read. Keep~/.sshat700and keys at600. - Forgetting the directory's permissions. A file set to
644is still unreachable if a parent directory lacksx.
What's next#
Permissions are about users and groups. Next you'll create and manage users, groups and sudo access.
Check your understanding
Quick quiz
1.What permissions does
chmod 640 report.txtset?2.What does the execute (x) permission mean on a directory?
3.Why does
/tmpshowdrwxrwxrwt?
Finished reading?
Mark this lesson complete to track your progress.