Permissions: who can do what
Linux was designed for many people sharing one computer. Every single file carries a tiny rulebook that says who may read it, change it, or run it. Once you can read that rulebook, a lot of mysterious “Permission denied” errors suddenly make sense.
You will learn
- How to read
-rwxr-xr--inls -l - What r, w and x mean for files and for folders (they're different!)
- How to change permissions with
chmod, using both letters and numbers - How ownership (
chown) and default permissions (umask) work - Where Rocky and Ubuntu choose different defaults
Three questions, three groups of people
Every file has an owner (a user) and a group. Linux sorts everyone into exactly one of three classes, then checks the matching three letters:
- r = read, w = write, x = execute. A
-means “not allowed.” - If you're the owner, only the owner letters count. If you're in the file's group, the group letters count. Otherwise, the “others” letters count.
- root ignores all of this. That's why
sudofixes “Permission denied.” It's also why you should use it carefully.
Files vs folders
| Letter | On a file it means… | On a folder it means… |
|---|---|---|
r | You can read what's inside (cat) | You can list the names inside (ls) |
w | You can change it | You can create, rename and delete files inside |
x | You can run it as a program or script | You can enter it (cd) and reach things inside |
Whether you can delete a file depends on the folder's w permission, not the file's. And without x on a folder you can't get into it at all, even if you could read the files inside.
Permissions as numbers
Admins usually write permissions as three digits. Each letter has a value: r = 4, w = 2, x = 1. Add them up for each class:
| Number | Letters | Typical use |
|---|---|---|
755 | rwxr-xr-x | Scripts, programs and folders everyone may use |
644 | rw-r--r-- | Normal files: web pages, notes |
700 | rwx------ | Private folders |
600 | rw------- | Secrets: SSH private keys, passwords |
777 | rwxrwxrwx | 🚩 Almost never! Anyone on the system can change or replace it. |
Changing permissions: chmod
chmod +x backup.sh # add execute for everyone (so you can ./backup.sh) chmod u+x,go-w notes.txt # owner gets x, group & others lose w chmod 600 diary.txt # only me: read + write chmod 755 website/ # folder: everyone can enter and look, only I can change chmod -R g+w shared/ # -R = everything inside, too
With letters you pick who (u owner, g group, o others, a all), an action (+ add, - remove, = set exactly), and which letters. Only a file's owner (or root) may chmod it.
New files are never executable. Running ./hello.sh gives “Permission denied” until you chmod +x hello.sh. (Or run it through bash: bash hello.sh. That only needs r.)
Changing owners: chown and chgrp
sudo chown alex report.txt # new owner sudo chown alex:webteam report.txt # new owner AND group sudo chown -R alex:alex /home/alex # everything inside, too sudo chgrp webteam report.txt # just the group
Giving files away needs root. Otherwise you could make a file look like someone else's.
Default permissions: umask
New files start from 666 and new folders from 777. Then the umask takes permissions away. For normal users, both families use a umask of 0002 (a mask from the “user private group” setup), so:
new file → 666 - 002 = 664 rw-rw-r-- new folder → 777 - 002 = 775 rwxrwxr-x (root uses umask 0022 → files 644, folders 755)
Where the families differ
| Rocky / RHEL | Ubuntu / Debian | |
|---|---|---|
| Your home folder | drwx------ (700): nobody else can peek | drwxr-x--- (750): your group can look (Ubuntu 21.04 and newer) |
/etc/shadow (password hashes) | ---------- (000) root:root. Only root, no exceptions. | -rw-r----- (640) root:shadow. Login tools in the shadow group can read it. |
root's home /root | dr-xr-x--- (550) | drwx------ (700) |
| Extra security layer | SELinux labels every file. That's the . after the permissions. Even correct rwx can be blocked by SELinux. See labels with ls -Z. | AppArmor puts limits on specific programs instead of labeling files. |
| The web server reads files as | user apache | user www-data |
That last row matters. If you chmod 600 a web page, the web server's user can't read it anymore, and visitors get 403 Forbidden. Web files need r for “others”: 644 for files, 755 for folders.
chmod 777 trapWhen something says “Permission denied,” it's tempting to chmod -R 777 it. Don't! It lets every user and every hacked program change those files. Work out who needs access, then give exactly that.
Try it
Quick check
1. What does chmod 640 notes.txt give?
✓ 6 = 4+2 (rw), 4 = r, 0 = nothing.
2. You have rw- on a file, but the folder it's in is r-x for you. Can you delete the file?
✓ Deleting changes the folder's list of names, so the folder's permissions decide.
3. ./deploy.sh says “Permission denied,” but you own it and it's rw-r--r--. Fix?
✓ Just add execute. 777 would also “work,” but it opens the file to everyone.