Linux Basics · Lesson 10 · 20 min

Permissions: who can do what

Linux was designed for many people sharing one computer. Every single file carries a tiny rulebook that says who may read it, change it, or run it. Once you can read that rulebook, a lot of mysterious “Permission denied” errors suddenly make sense.

You will learn

  • How to read -rwxr-xr-- in ls -l
  • What r, w and x mean for files and for folders (they're different!)
  • How to change permissions with chmod, using both letters and numbers
  • How ownership (chown) and default permissions (umask) work
  • Where Rocky and Ubuntu choose different defaults

Three questions, three groups of people

Every file has an owner (a user) and a group. Linux sorts everyone into exactly one of three classes, then checks the matching three letters:

-type rwxowner (u) r-xgroup (g) r--others (o) studentstudentbackup.shname

Files vs folders

LetterOn a file it means…On a folder it means…
rYou can read what's inside (cat)You can list the names inside (ls)
wYou can change itYou can create, rename and delete files inside
xYou can run it as a program or scriptYou can enter it (cd) and reach things inside
Surprise!

Whether you can delete a file depends on the folder's w permission, not the file's. And without x on a folder you can't get into it at all, even if you could read the files inside.

Permissions as numbers

Admins usually write permissions as three digits. Each letter has a value: r = 4, w = 2, x = 1. Add them up for each class:

74+2+1 = rwx 54+0+1 = r-x 54+0+1 = r-x
NumberLettersTypical use
755rwxr-xr-xScripts, programs and folders everyone may use
644rw-r--r--Normal files: web pages, notes
700rwx------Private folders
600rw-------Secrets: SSH private keys, passwords
777rwxrwxrwx🚩 Almost never! Anyone on the system can change or replace it.

Changing permissions: chmod

Same on both
chmod +x backup.sh        # add execute for everyone (so you can ./backup.sh)
chmod u+x,go-w notes.txt  # owner gets x, group & others lose w
chmod 600 diary.txt       # only me: read + write
chmod 755 website/        # folder: everyone can enter and look, only I can change
chmod -R g+w shared/      # -R = everything inside, too

With letters you pick who (u owner, g group, o others, a all), an action (+ add, - remove, = set exactly), and which letters. Only a file's owner (or root) may chmod it.

Why won't my script run?

New files are never executable. Running ./hello.sh gives “Permission denied” until you chmod +x hello.sh. (Or run it through bash: bash hello.sh. That only needs r.)

Changing owners: chown and chgrp

Same on both
sudo chown alex report.txt            # new owner
sudo chown alex:webteam report.txt    # new owner AND group
sudo chown -R alex:alex /home/alex    # everything inside, too
sudo chgrp webteam report.txt         # just the group

Giving files away needs root. Otherwise you could make a file look like someone else's.

Default permissions: umask

New files start from 666 and new folders from 777. Then the umask takes permissions away. For normal users, both families use a umask of 0002 (a mask from the “user private group” setup), so:

new file   → 666 - 002 = 664  rw-rw-r--
new folder → 777 - 002 = 775  rwxrwxr-x
(root uses umask 0022 → files 644, folders 755)

Where the families differ

Rocky / RHELUbuntu / Debian
Your home folderdrwx------ (700): nobody else can peekdrwxr-x--- (750): your group can look (Ubuntu 21.04 and newer)
/etc/shadow (password hashes)---------- (000) root:root. Only root, no exceptions.-rw-r----- (640) root:shadow. Login tools in the shadow group can read it.
root's home /rootdr-xr-x--- (550)drwx------ (700)
Extra security layerSELinux labels every file. That's the . after the permissions. Even correct rwx can be blocked by SELinux. See labels with ls -Z.AppArmor puts limits on specific programs instead of labeling files.
The web server reads files asuser apacheuser www-data

That last row matters. If you chmod 600 a web page, the web server's user can't read it anymore, and visitors get 403 Forbidden. Web files need r for “others”: 644 for files, 755 for folders.

The chmod 777 trap

When something says “Permission denied,” it's tempting to chmod -R 777 it. Don't! It lets every user and every hacked program change those files. Work out who needs access, then give exactly that.

Try it

Quick check

1. What does chmod 640 notes.txt give?

2. You have rw- on a file, but the folder it's in is r-x for you. Can you delete the file?

3. ./deploy.sh says “Permission denied,” but you own it and it's rw-r--r--. Fix?

Finished the missions and the quiz? Mark it done to track your progress.