Permissions & Ownership
An owner, a group and nine bits decide every "Permission denied". Learn to read them, change them, and work out which rule said no.
An interactive Linux lesson: 24 steps, about 35 minutes, on a live simulation in your browser.
web01 runs a small application out of /srv/app. Three people have accounts: you (alice), your teammate carol, and bob, a contractor from another team. config.yml holds the database password.
You run cat config.yml and read it. Then watch the prompt: the line that starts bob@web01 is bob typing the same thing. He gets Permission denied.
What you will learn
An owner, a group, nine bits
- Same command, different answer
- Reading the nine bits: Every file carries an owner, a group and nine bits: read, write and execute for the owner, for the group, and for everyone else.
- The kernel picks one class: The kernel picks exactly one class: owner, else group, else other. Only that triplet is consulted.
- The owner with fewer rights: Classes do not add up and do not fall through. If you are the owner, the group and other bits are not yours to use.
What r, w and x mean
- r, w and x on a file: On a file: r reads the contents, w changes the contents, x runs it as a program.
- r, w and x on a directory: On a directory: r lists the names, w adds and removes names, x lets you pass through to what a name refers to.
- Delete a file you cannot read: Creating, deleting and renaming are changes to the directory. The directory's w and x decide; the file's own bits do not.
- chmod 777 does not fix it: To open a file you need x on every directory along its path, and then the right bit on the file itself.
Changing the bits
- Octal: three digits, nine bits: Each octal digit is one class: r is 4, w is 2, x is 1, added together. 640 reads rw- r-- ---.
- Symbolic: change one thing
- Drill: let the group run it
- Break it: a directory set to 644
Owners, groups and defaults
- Who may change what: chown: Only the owner, or root, may change a file's mode. Only root may change its owner.
- New files and chgrp: A new file belongs to the user who created it and to that user's primary group, wherever it is created.
- umask: where default modes come from: New files start from 666 and new directories from 777. The umask is the set of bits removed from that.
- Drill: a stricter default
Three special bits
- setuid: why passwd works: A setuid program runs as the file's owner, not as the person who started it.
- Break it: take the s away
- setgid on a shared directory: setgid on a directory: new files inside take the directory's group, not the creator's primary group.
- The sticky bit on /tmp: Sticky bit on a directory: you may only delete or rename the entries you own, however writable the directory is.
Root, and how to debug
- root skips the checks: root is not a fourth class. For uid 0 the kernel skips the read and write checks altogether.
- Four questions for any denial: For any denial: who is asking, x on every directory of the path, then the one class that applies on the file.
Recap & playground
- Cheat sheet
- Playground