← pushpjeet.com · TutorialsLinux from Scratch course
Interactive quest16 levels6 hands-on labsPractice terminalBeginner → expert

Linux File Permissions Quest

>_ linux-permissions.lab
Level 1 · Newbie0 XP
🔥 Streak 0

From "what is rwx?" to setuid, sticky bits and umask. Read the levels, play the mini-games, hack the practice terminal, earn XP and badges, and finish as a Permissions Root.

How to play: every level gives XP when you mark it complete · the sandbox terminal has real missions · the quiz rewards streaks · badges unlock as you go.

▶ Start Level 1
Beginner

Level 1 · Why do permissions exist?

Linux is a multi-user system. Many people (and many programs) share one machine, one disk, one set of files. Without rules, anyone could read your private notes, edit the system configuration, or delete your work by accident. Permissions are those rules: they describe how someone can use a file or directory.

Real-life analogy · an apartment building

A file is a room. The permissions are the keys. The owner is the person who lives in the room, the group is their family or flatmates, and others are everyone else in the city. Some people may only peek through the window (read), some may rearrange the furniture (write), and some may switch the machines on (execute).

Three questions Linux asks every time you touch a file

👤

1. Who are you?

The owner (user), a member of the file's group, or someone else (other).

🛠️

2. What do you want to do?

Read it, change it (write), or run it (execute).

✅

3. Is that allowed?

Linux checks the 9 permission bits and says yes, or Permission denied.

Tip for learners

Almost every "Permission denied" error you will ever see is one of these questions getting the answer "no". Learn to ask them and you can debug any of them.

Beginner

Level 2 · The three permissions

Files and directories have three permissions. They mean different things on a file and on a directory, and this is the single most important idea in the whole tutorial.

PermissionLetterOn a fileOn a directory
ReadrOpen and read the contents (cat, less).List the names inside (ls).
WritewChange the contents (edit, append, truncate).Add, remove and rename entries in it. (Needs x too.)
ExecutexRun it as a program or script.Enter it (cd) and reach files inside by path.
Example · the classic surprise

You have w on report.txt, but not on the folder that holds it. You can change what is inside the file, but you cannot rename or delete it, because those change the folder, not the file.

The opposite also happens: no w on the file, but w on the folder means you can delete the file (Linux just asks the folder's permission).

Careful: a note on the slide wording

The notes say "read permission on a directory lets you print out the file's content". Precisely: r on a directory lets you list the names inside. To read a file's content you need r on the file and x on every directory along its path.

Example · execute needs to be on
# a script with no x bit
$ ./hello.sh
bash: ./hello.sh: Permission denied
$ chmod u+x hello.sh
$ ./hello.sh
Hello, Linux!

Without x you can still see and edit the script (if you have r and w); you just cannot run it.

🎮 Try it: Permission Explorer

Click the buttons to switch permissions on and off. Watch the string, the number and the command update.

Beginner

Level 3 · Who is asking? Ownership

Every file belongs to exactly one user (the owner) and one group (the group owner). Everyone else is other. Each of the three classes has its own r, w, x set, which gives 3 × 3 = 9 bits in total.

🙋

User (u)

The owner. When you create a file, its owner is you. The owner controls the permissions.

👨‍👩‍👧

Group (g)

A set of users who share the same access. Great for teams: give the group access once instead of each person.

🌍

Other (o)

Anyone who is not the owner and not in the group.

Example · one file, three people

File plan.txt is owned by alice, group devs, permissions rw-r-----.

  • alice (owner) → can read and write.
  • bob, who is in group devs → can only read.
  • carol, not in devs → nothing. Permission denied.
Order of checking

Linux picks one class: if you are the owner, only the owner bits apply (even if the group bits are more generous). Else if you are in the group, the group bits apply. Else the other bits apply. It never combines them.

Why groups simplify admin

Instead of editing permissions for 20 students, put them in group students and give that group access once.

Beginner

Level 4 · Reading ls -l

ls -l (long listing) shows permissions, links, owner, group, size, modified date and name.

$ ls -l
-rw-r--r-- 1 alice devs 1204 Oct  1 10:22 notes.txt
drwxr-xr-x 2 alice devs 4096 Oct  1 10:20 photos
-rwxr-x--- 1 alice devs  310 Sep 30 18:05 backup.sh
🎮 Try it: click each part of the line to decode it
Click any dashed part above.

Breaking the permission string down

  -   rwx   r-x   r--
  |    |     |     |
 type user  group other
First characterMeaning
-Regular file
dDirectory
lSymbolic link (shortcut)
c / bCharacter / block device (like /dev/tty, /dev/sda)
Practice · decode these in your head

-rw------- → regular file, only the owner can read/write (perfect for private keys).

drwxrwx--- → directory, owner and group can do everything, others are locked out.

-r-xr-xr-x → read-only program everyone can run.

Who is the owner?

The owner name is shown to the right of the link count, and the group name to the right of that. Default permissions vary by distribution (they come from umask, see the Expert level).

Intermediate

Level 5 · chmod absolute (numeric) mode

chmod means change mode. Only the owner of the file or root may change its permissions. In absolute mode you describe permissions with a three-digit octal number, one digit each for user, group and other. This is the most commonly used mode.

The magic: r = 4, w = 2, x = 1

PermissionsMathDigit
---00
--x11
-w-22
-wx2+13
r--44
r-x4+15
rw-4+26
rwx4+2+17
Worked example

Want rwxr-x---? User rwx = 7, group r-x = 5, other --- = 0 → chmod 750 file.

From the slide: chmod 400 file_1 → user = 4 (read only), group = 0, other = 0. Only the owner can read it, nobody can write or run it.

The numbers you will meet every day

ModeStringTypical use
644rw-r--r--Normal files, e.g. web pages, text files
755rwxr-xr-xPrograms, scripts and directories
600rw-------Private files, e.g. SSH private keys
700rwx------Private directory, e.g. ~/.ssh
400r--------Read-only for owner, e.g. cloud key pairs
750rwxr-x---Team-only program or folder
777rwxrwxrwxAvoid. Everyone can do everything.
Why avoid chmod 777?

It grants read, write and execute to every user on the system. Anyone (or any compromised program) can replace your file with something malicious. Fix the real cause instead: correct owner, correct group, or add the one permission that is missing.

🎮 Mental-math warm-up

What number is rw-r-----? (6 · 4 · 0 → 640). Need more practice? The Octal Dojo level below has endless drills.

Intermediate

Level 6 · chmod symbolic mode

Symbolic mode uses letters and symbols to add or remove particular permissions without touching the rest. It reads almost like English.

chmod  [who][operator][permissions]  file
       u g o a     + - =          r w x

Who

u user (owner)
g group
o other
a all three

Operator

+ add the permission
- remove it
= set exactly this (clears the rest)

Permission

r read
w write
x execute
X execute only for dirs / already-executable files

Examples

CommandWhat it does
chmod u+x script.shGive the owner execute permission
chmod g-w notes.txtRemove write from the group
chmod o= secret.txtOthers get nothing
chmod a+r page.htmlEveryone can read
chmod u=rw,g=r,o= fileExactly rw-r----- (same as 640)
chmod go-rwx private.txtRemove everything from group and others
chmod -R u+rwX,go-w project/Recursive: dirs stay enterable, files don't get blanket x
Example · before and after
$ ls -l app.sh
-rw-r--r-- 1 alice devs 52 Oct  1 10:30 app.sh
$ chmod u+x,g+x app.sh
$ ls -l app.sh
-rwxr-xr-- 1 alice devs 52 Oct  1 10:30 app.sh
Absolute or symbolic?

Use absolute when you know the exact final result (chmod 640 file). Use symbolic when you want to tweak one thing and keep the rest (chmod g+w file). You must be able to read both.

Intermediate

Level 7 · Changing ownership and using sudo

chown: change the owner (and group)

chown [options] [user][:][group] file(s)
PartMeaning
[options]Optional, for example -R to apply recursively inside directories
[user]Name or ID of the new owner
[:]The colon, used when you also want to change the group
[group]The new group (optional)
[file(s)]The file or directory to change
$ sudo chown bob report.txt          # owner → bob
$ sudo chown bob:devs report.txt      # owner → bob, group → devs
$ sudo chown :devs report.txt         # only the group changes
$ sudo chgrp devs report.txt          # same thing, group only
$ sudo chown -R alice:devs project/   # whole folder tree

sudo: borrow root's power for one command

The root account is the superuser. It can do anything. Normal users can run a single command with root's power using sudo; you are asked for your own password.

$ chown bob report.txt
chown: changing ownership of 'report.txt': Operation not permitted
$ sudo chown bob report.txt
[sudo] password for alice: ********
$ 
Who can do what?

chmod → the file's owner or root. chown → only root (a normal user cannot give files away). chgrp → the owner, but only to a group they belong to.

Golden rule

Use sudo for the one command that needs it, not for everything. A typo as root can damage the whole system.

Expert

Level 8 · Expert zone

1. umask: where default permissions come from

New files start from 666 (no free execute bit) and new directories from 777; the umask subtracts bits.

umaskNew fileNew directoryTypical on
022644755Root, many servers
002664775Ubuntu / Debian / Fedora normal users (private groups)
077600700Security-focused setups

2. Special permission bits

BitOctalSymbolicEffect
setuid4000u+sProgram runs as the file owner (e.g. /usr/bin/passwd). Shown as s in the owner x spot.
setgid2000g+sOn a program: runs as file's group. On a directory: new files inherit the directory's group (perfect for team folders).
sticky1000+tOn a directory: only the file's owner (or dir owner / root) may delete files inside. /tmp uses it: drwxrwxrwt.
Example · a shared team folder done right
$ sudo mkdir /srv/team
$ sudo chgrp devs /srv/team
$ sudo chmod 2770 /srv/team      # setgid + rwx for owner/group, nothing for others
$ ls -ld /srv/team
drwxrws--- 2 root devs 4096 Oct  1 11:00 /srv/team

Anything a team member creates in there automatically belongs to group devs. Add +t (3770) so members can't delete each other's files.

3. Directory traversal rule

To open /a/b/c.txt you need x on /, /a, /a/b and r on c.txt. A world-readable file inside a 700 directory is still unreachable. chmod 777 file does not help if the parent is locked.

4. Root is not bound (mostly)

Root bypasses read/write checks. But even root needs at least one x bit to execute a regular file.

5. Beyond rwx

ToolUse
stat -c '%a %A %U:%G %n' fileShow numeric + symbolic mode, owner and group in one line
getfacl / setfacl -m u:bob:rw fileACLs: give one extra user/group access without changing the group
chattr +i file / lsattrImmutable flag: even root can't modify until -i
find / -perm -4000 -type fAudit: list all setuid programs
find . -type f -perm 777Hunt dangerous world-writable files
chmod --reference=a bCopy the mode of a onto b
id, groups, sudo usermod -aG devs bobSee and change group membership (log in again to apply)
SELinux / AppArmorA second, independent layer on RHEL/Ubuntu: even with correct rwx a request can be denied by policy (ls -Z)
Expert debugging checklist for "Permission denied"

① id — who am I and which groups? ② ls -ld on the file and each parent (or namei -l /path/to/file). ③ Right bit for the action (r/w/x)? ④ Mounted read-only or immutable? ⑤ SELinux/AppArmor?

Intermediate

Level 9 · Best practices

🚫 No chmod 777

Read + write + execute for every user is almost never the right fix.

🔐 Least privilege

Start with the fewest users and the least access. Grant more only when someone has a real need.

📝 Safe file names

Stick to letters, digits, dots, dashes and underscores. Spaces, *, $, ;, & have special shell meanings and cause surprises (and security bugs).

👥 Use groups

Manage access by group rather than fixing individual files for individual people.

Think about it (from the lesson)

Q1. Why should you not use chmod 777?

Show answer
You might give access to users who shouldn't have it, threatening the security of your data. Always remember the principle of least privilege.

Q2. What are the two modes for configuring permissions, and how do they differ?

Show answer
Absolute mode uses numbers (e.g. 640), and is the most commonly used. Symbolic mode uses letters and symbols (e.g. g-w) to add or remove individual permissions.
Key takeaways

Permissions are set with chmod in absolute or symbolic mode · ls -l shows them · chown changes ownership.

Labs

Level 10 · Hands-on labs

Lab safety

Do these in a disposable VM, WSL or container, never on a production server. Work inside a scratch folder: mkdir ~/permlab && cd ~/permlab. Tick each checkpoint when done: +10 XP each.

Lab 1 · Identify and configure file permissions

⏱ 10 min · Beginner

Purpose: create a file, examine its default permissions, then make it read-only. (This is the demonstration from the course.)

  1. Create a new file:
    touch file_1
  2. List it in long format:
    ls -l file_1
    # -rw-r--r-- 1 alice alice 0 Oct  1 10:00 file_1
    Q: Who owns the file? Which group owns the file?
    The owner is the 3rd column (the user who ran touch, e.g. alice); the group is the 4th column (usually that user's primary group, often the same name).
  3. Make it read-only for the owner and closed to everyone else:
    chmod 400 file_1
  4. Verify the change:
    ls -l file_1
    # -r-------- 1 alice alice 0 Oct  1 10:00 file_1
  5. Try to write to it, and see the protection working:
    echo "hello" > file_1
    # bash: file_1: Permission denied

Bonus: as the owner you can still fix it: chmod u+w file_1. Ownership means you control the lock.

Lab 2 · Symbolic mode playground

⏱ 10 min · Beginner
  1. Create a script and try to run it:
    printf '#!/bin/bash\necho "It works!"\n' > hi.sh
    ls -l hi.sh
    ./hi.sh                # Permission denied
  2. Add execute for the owner and run again:
    chmod u+x hi.sh
    ./hi.sh                # It works!
  3. Practise the operators:
    chmod g+w hi.sh        # add
    chmod o-r hi.sh        # remove
    chmod a=r hi.sh        # set exactly: everyone read-only
    chmod u=rwx,g=rx,o= hi.sh
    ls -l hi.sh            # -rwxr-x---
  4. Convert to numbers, and confirm with stat:
    stat -c '%a %A' hi.sh   # 750 -rwxr-x---

Lab 3 · Directory permissions are different

⏱ 15 min · Intermediate
  1. Build a folder with a file:
    mkdir box && echo secret > box/note.txt
  2. Remove r from the directory and list it:
    chmod u-r box
    ls box                 # Permission denied (can't list names)
    cat box/note.txt       # still works! x lets you pass through
  3. Remove x (restore r first):
    chmod u+r,u-x box
    ls box                 # names shown, but errors on details
    cat box/note.txt       # Permission denied (can't enter)
  4. Remove w from the directory, then try to delete a file you own:
    chmod u+x,u-w box
    rm box/note.txt        # Permission denied: deleting changes the folder
    chmod u+w box          # restore
Checkpoint question: why could I cat with no r on the folder?
Reading a file needs x on each directory in the path (to traverse) and r on the file. The directory's own r only matters for listing its names, and you already knew the name.

Lab 4 · Ownership with chown, chgrp and sudo

⏱ 15 min · Intermediate
  1. Create a helper user and group:
    sudo groupadd devs
    sudo useradd -m -G devs alice
  2. Create a file, then try to give it away without sudo:
    touch handoff.txt
    chown alice handoff.txt     # Operation not permitted
  3. Use sudo:
    sudo chown alice:devs handoff.txt
    ls -l handoff.txt           # -rw-r--r-- 1 alice devs ...
  4. Now you are "other". Try to modify it:
    echo hi >> handoff.txt      # Permission denied
    sudo chmod g+w handoff.txt  # give the group write
    sudo usermod -aG devs $USER # add yourself to devs (log out/in to apply)
  5. Clean up:
    sudo userdel -r alice; sudo groupdel devs

Lab 5 · Team folder with setgid and sticky bit

⏱ 20 min · Expert
  1. Create the folder for group devs:
    sudo mkdir /srv/team
    sudo chgrp devs /srv/team
    sudo chmod 2770 /srv/team
    ls -ld /srv/team            # drwxrws--- (note the 's')
  2. Create a file as a group member. See that the group is inherited:
    sudo -u alice touch /srv/team/a.txt
    ls -l /srv/team             # group = devs, not alice
  3. Add the sticky bit and observe t:
    sudo chmod +t /srv/team
    ls -ld /srv/team            # drwxrws--T

    Capital T means sticky is set but x for others is not. Try chmod 3771 to see lowercase t.

  4. Audit the system:
    find /usr/bin -perm -4000 -type f 2>/dev/null

Lab 6 · umask experiment

⏱ 10 min · Expert
umask                    # e.g. 0022
touch a.txt; mkdir a_dir
ls -ld a.txt a_dir       # 644 and 755 with 022
umask 077
touch b.txt; mkdir b_dir
ls -ld b.txt b_dir       # 600 and 700
umask 022                # put it back (affects this shell only)
Game

Level 11 · The Sandbox Terminal

No Linux machine handy? This is a safe simulated terminal. You are user student (groups: student, devs). Complete the 8 missions; each pays XP. Type help to see supported commands.

student@linux-lab — simulated

Supported: ls [-l -a] cd pwd touch mkdir cat echo "text" > file ./script chmod chown chgrp rm [-r] whoami id stat sudo … clear. ↑ recalls history.

Game

Level 12 · Octal Dojo

Convert permission strings to numbers and back. +5 XP per correct answer (first 20). Get 5 in a row for the Octal Ninja badge.

…

Score 0 · Streak 0
Game

Level 13 · The MCQ Challenge

20 multiple-choice questions from beginner to expert. +10 XP per correct answer, +5 bonus for every 3rd correct in a row. Score 90%+ for the Quiz Master badge.

Reference

Level 14 · FAQ: questions learners really ask

Practice

Level 15 · Practice questions with model answers

Try to answer in your own words first, then reveal. These are the kind of questions asked in exams and interviews.

Finale

Level 16 · Cheat sheet and key takeaways

I want to…Command
See permissionsls -l · ls -ld dir · stat file
Set exact permissionschmod 640 file · chmod u=rw,g=r,o= file
Add / remove one permissionchmod u+x file · chmod go-w file
Make script runnablechmod +x script.sh
Make file read-only for ownerchmod 400 file
Change owner / groupsudo chown user:group file · sudo chgrp group file
Change a whole treechmod -R … · chown -R … (double-check the path!)
Who am I?whoami · id · groups
Default permissionsumask · umask 027
Team folderchmod 2770 dir (setgid) · chmod +t dir (sticky)
Remember

① r=4 w=2 x=1 · ② three classes: user, group, other · ③ directory x = enter, w = add/remove · ④ never 777, use least privilege · ⑤ chmod = owner or root, chown = root only.

🎓 Your progress

Keep playing to unlock your certificate.