learninfra · Linux · Networking · Kubernetes · System Design · AI Infrastructure · Exam blueprints · Drills

Permissions & Ownership

An owner, a group and nine bits decide every "Permission denied". Learn to read them, change them, and work out which rule said no.

An interactive Linux lesson: 24 steps, about 35 minutes, on a live simulation in your browser.

web01 runs a small application out of /srv/app. Three people have accounts: you (alice), your teammate carol, and bob, a contractor from another team. config.yml holds the database password.

You run cat config.yml and read it. Then watch the prompt: the line that starts bob@web01 is bob typing the same thing. He gets Permission denied.

What you will learn

  1. An owner, a group, nine bits

    • Same command, different answer
    • Reading the nine bits: Every file carries an owner, a group and nine bits: read, write and execute for the owner, for the group, and for everyone else.
    • The kernel picks one class: The kernel picks exactly one class: owner, else group, else other. Only that triplet is consulted.
    • The owner with fewer rights: Classes do not add up and do not fall through. If you are the owner, the group and other bits are not yours to use.
  2. What r, w and x mean

    • r, w and x on a file: On a file: r reads the contents, w changes the contents, x runs it as a program.
    • r, w and x on a directory: On a directory: r lists the names, w adds and removes names, x lets you pass through to what a name refers to.
    • Delete a file you cannot read: Creating, deleting and renaming are changes to the directory. The directory's w and x decide; the file's own bits do not.
    • chmod 777 does not fix it: To open a file you need x on every directory along its path, and then the right bit on the file itself.
  3. Changing the bits

    • Octal: three digits, nine bits: Each octal digit is one class: r is 4, w is 2, x is 1, added together. 640 reads rw- r-- ---.
    • Symbolic: change one thing
    • Drill: let the group run it
    • Break it: a directory set to 644
  4. Owners, groups and defaults

    • Who may change what: chown: Only the owner, or root, may change a file's mode. Only root may change its owner.
    • New files and chgrp: A new file belongs to the user who created it and to that user's primary group, wherever it is created.
    • umask: where default modes come from: New files start from 666 and new directories from 777. The umask is the set of bits removed from that.
    • Drill: a stricter default
  5. Three special bits

    • setuid: why passwd works: A setuid program runs as the file's owner, not as the person who started it.
    • Break it: take the s away
    • setgid on a shared directory: setgid on a directory: new files inside take the directory's group, not the creator's primary group.
    • The sticky bit on /tmp: Sticky bit on a directory: you may only delete or rename the entries you own, however writable the directory is.
  6. Root, and how to debug

    • root skips the checks: root is not a fourth class. For uid 0 the kernel skips the read and write checks altogether.
    • Four questions for any denial: For any denial: who is asking, x on every directory of the path, then the one class that applies on the file.
  7. Recap & playground

    • Cheat sheet
    • Playground