Understanding Permissions

Every file and directory in Linux has three sets of permissions assigned to three categories of users. When you run ls -l, you see permissions displayed as a 10-character string:

-rwxr-xr-- 1 alice developers 4096 Jan 15 10:30 script.sh
│├─┤├─┤├─┤
│ │   │  └── Other (everyone else): read only
│ │   └───── Group (developers): read + execute
│ └───────── Owner (alice): read + write + execute
└──────────── File type (- = regular file, d = directory, l = symlink)

The Three Permission Types

PermissionSymbolNumericOn FilesOn Directories
Readr4View file contentsList directory contents
Writew2Modify file contentsCreate/delete files in directory
Executex1Run as a programEnter (cd into) directory

The Three User Categories

  • Owner (u) — The user who created the file. Each file has exactly one owner.
  • Group (g) — A group of users who share access. Each file belongs to one group.
  • Other (o) — Everyone else on the system who is not the owner and not in the file's group.

Changing Permissions with chmod

The chmod (change mode) command modifies file permissions. There are two ways to use it: symbolic mode and numeric (octal) mode.

Symbolic Mode

Symbolic mode uses letters and operators to set permissions:

# Add execute permission for the owner
chmod u+x script.sh

# Remove write permission from group and others
chmod go-w document.txt

# Set read+write for owner, read-only for group, none for others
chmod u=rw,g=r,o= private.txt

# Add read permission for everyone
chmod a+r public.txt

# Remove all permissions for others
chmod o-rwx sensitive.dat

Numeric (Octal) Mode

Numeric mode uses three digits (0-7), one for each user category. Each digit is the sum of the permission values (read=4, write=2, execute=1):

NumericPermissionMeaning
7rwxRead + Write + Execute (4+2+1)
6rw-Read + Write (4+2)
5r-xRead + Execute (4+1)
4r--Read only (4)
3-wxWrite + Execute (2+1)
2-w-Write only (2)
1--xExecute only (1)
0---No permissions (0)
# Common permission patterns
chmod 755 script.sh      # rwxr-xr-x (owner: all, others: read+execute)
chmod 644 document.txt   # rw-r--r-- (owner: read+write, others: read)
chmod 700 private/       # rwx------ (owner only, full access)
chmod 600 secret.key     # rw------- (owner: read+write only)
chmod 775 shared/        # rwxrwxr-x (owner+group: full, others: read+execute)
chmod 666 writable.txt   # rw-rw-rw- (everyone: read+write)

# Recursive: apply to directory and all contents
chmod -R 755 /var/www/html

Changing Ownership with chown

The chown (change owner) command modifies file ownership. Only root can change file ownership.

# Change owner
sudo chown alice file.txt

# Change owner and group
sudo chown alice:developers file.txt

# Change group only
sudo chown :developers file.txt
# or use chgrp
sudo chgrp developers file.txt

# Recursive ownership change
sudo chown -R www-data:www-data /var/www/html

Special Permissions

Linux has three special permission bits that provide additional functionality beyond standard read/write/execute:

SUID (Set User ID) — 4000

When set on an executable file, the program runs with the permissions of the file owner rather than the user who executes it. This is how the passwd command allows regular users to change their password (it needs to write to /etc/shadow, owned by root).

# View SUID files (shown as 's' in owner execute position)
ls -l /usr/bin/passwd
-rwsr-xr-x 1 root root 68208 Jan 15 10:30 /usr/bin/passwd

# Set SUID
sudo chmod u+s /usr/local/bin/special-app
sudo chmod 4755 /usr/local/bin/special-app

SGID (Set Group ID) — 2000

On files, SGID works like SUID but for the group. On directories, it is more commonly used: new files created inside the directory automatically inherit the directory's group rather than the creating user's primary group. This is essential for shared project directories.

# Set SGID on a shared directory
sudo chmod g+s /opt/team-project/
sudo chmod 2775 /opt/team-project/

# New files will inherit the directory's group
touch /opt/team-project/newfile.txt
ls -l /opt/team-project/newfile.txt
# Group will be the directory's group, not your primary group

Sticky Bit — 1000

When set on a directory, only the file owner, directory owner, or root can delete or rename files within it — even if other users have write permission. This prevents users from deleting each other's files in shared directories. The classic example is /tmp.

# View sticky bit (shown as 't' in others execute position)
ls -ld /tmp
drwxrwxrwt 15 root root 4096 Jan 15 10:30 /tmp

# Set sticky bit
sudo chmod +t /shared/uploads/
sudo chmod 1777 /shared/uploads/

Default Permissions with umask

The umask (user file creation mask) determines the default permissions for newly created files and directories. It works by subtracting permissions from the maximum defaults (666 for files, 777 for directories).

# View current umask
umask         # numeric format (e.g., 0022)
umask -S      # symbolic format (e.g., u=rwx,g=rx,o=rx)

# Common umask values
umask 022     # Files: 644, Directories: 755 (default on most systems)
umask 027     # Files: 640, Directories: 750 (more restrictive)
umask 077     # Files: 600, Directories: 700 (private)

To make the umask persistent, add it to your shell profile file (~/.bashrc or ~/.profile).

Access Control Lists (ACLs)

Standard permissions are limited to one owner and one group. Access Control Lists (ACLs) provide fine-grained control by allowing permissions for multiple specific users and groups on a single file.

# View ACLs
getfacl filename.txt

# Grant read+write to a specific user
setfacl -m u:bob:rw filename.txt

# Grant read to a specific group
setfacl -m g:auditors:r filename.txt

# Set default ACLs for a directory (inherited by new files)
setfacl -d -m g:developers:rwx /opt/project/

# Remove a specific ACL entry
setfacl -x u:bob filename.txt

# Remove all ACLs
setfacl -b filename.txt

ACL Indicator

When a file has ACLs set, ls -l shows a + after the permission string (e.g., -rw-r--r--+). Use getfacl to view the full ACL details. ACLs require the filesystem to be mounted with ACL support (enabled by default on ext4 and most modern filesystems).