From "what is rwx?" to setuid, sticky bits and umask. Read the levels, play the mini-games, hack the practice terminal, earn XP and badges, and finish as a Permissions Root.
How to play: every level gives XP when you mark it complete · the sandbox terminal has real missions · the quiz rewards streaks · badges unlock as you go.
▶ Start Level 1Level 1 · Why do permissions exist?
Linux is a multi-user system. Many people (and many programs) share one machine, one disk, one set of files. Without rules, anyone could read your private notes, edit the system configuration, or delete your work by accident. Permissions are those rules: they describe how someone can use a file or directory.
A file is a room. The permissions are the keys. The owner is the person who lives in the room, the group is their family or flatmates, and others are everyone else in the city. Some people may only peek through the window (read), some may rearrange the furniture (write), and some may switch the machines on (execute).
Three questions Linux asks every time you touch a file
1. Who are you?
The owner (user), a member of the file's group, or someone else (other).
2. What do you want to do?
Read it, change it (write), or run it (execute).
3. Is that allowed?
Linux checks the 9 permission bits and says yes, or Permission denied.
Almost every "Permission denied" error you will ever see is one of these questions getting the answer "no". Learn to ask them and you can debug any of them.
Level 2 · The three permissions
Files and directories have three permissions. They mean different things on a file and on a directory, and this is the single most important idea in the whole tutorial.
| Permission | Letter | On a file | On a directory |
|---|---|---|---|
| Read | r | Open and read the contents (cat, less). | List the names inside (ls). |
| Write | w | Change the contents (edit, append, truncate). | Add, remove and rename entries in it. (Needs x too.) |
| Execute | x | Run it as a program or script. | Enter it (cd) and reach files inside by path. |
You have w on report.txt, but not on the folder that holds it. You can change what is inside the file, but you cannot rename or delete it, because those change the folder, not the file.
The opposite also happens: no w on the file, but w on the folder means you can delete the file (Linux just asks the folder's permission).
The notes say "read permission on a directory lets you print out the file's content". Precisely: r on a directory lets you list the names inside. To read a file's content you need r on the file and x on every directory along its path.
# a script with no x bit $ ./hello.sh bash: ./hello.sh: Permission denied $ chmod u+x hello.sh $ ./hello.sh Hello, Linux!
Without x you can still see and edit the script (if you have r and w); you just cannot run it.
Click the buttons to switch permissions on and off. Watch the string, the number and the command update.
Level 3 · Who is asking? Ownership
Every file belongs to exactly one user (the owner) and one group (the group owner). Everyone else is other. Each of the three classes has its own r, w, x set, which gives 3 × 3 = 9 bits in total.
User (u)
The owner. When you create a file, its owner is you. The owner controls the permissions.
Group (g)
A set of users who share the same access. Great for teams: give the group access once instead of each person.
Other (o)
Anyone who is not the owner and not in the group.
File plan.txt is owned by alice, group devs, permissions rw-r-----.
- alice (owner) → can read and write.
- bob, who is in group
devs→ can only read. - carol, not in
devs→ nothing.Permission denied.
Linux picks one class: if you are the owner, only the owner bits apply (even if the group bits are more generous). Else if you are in the group, the group bits apply. Else the other bits apply. It never combines them.
Instead of editing permissions for 20 students, put them in group students and give that group access once.
Level 4 · Reading ls -l
ls -l (long listing) shows permissions, links, owner, group, size, modified date and name.
$ ls -l
-rw-r--r-- 1 alice devs 1204 Oct 1 10:22 notes.txt
drwxr-xr-x 2 alice devs 4096 Oct 1 10:20 photos
-rwxr-x--- 1 alice devs 310 Sep 30 18:05 backup.sh
Breaking the permission string down
- rwx r-x r-- | | | | type user group other
| First character | Meaning |
|---|---|
- | Regular file |
d | Directory |
l | Symbolic link (shortcut) |
c / b | Character / block device (like /dev/tty, /dev/sda) |
-rw------- → regular file, only the owner can read/write (perfect for private keys).
drwxrwx--- → directory, owner and group can do everything, others are locked out.
-r-xr-xr-x → read-only program everyone can run.
The owner name is shown to the right of the link count, and the group name to the right of that. Default permissions vary by distribution (they come from umask, see the Expert level).
Level 5 · chmod absolute (numeric) mode
chmod means change mode. Only the owner of the file or root may change its permissions. In absolute mode you describe permissions with a three-digit octal number, one digit each for user, group and other. This is the most commonly used mode.
The magic: r = 4, w = 2, x = 1
| Permissions | Math | Digit |
|---|---|---|
--- | 0 | 0 |
--x | 1 | 1 |
-w- | 2 | 2 |
-wx | 2+1 | 3 |
r-- | 4 | 4 |
r-x | 4+1 | 5 |
rw- | 4+2 | 6 |
rwx | 4+2+1 | 7 |
Want rwxr-x---? User rwx = 7, group r-x = 5, other --- = 0 → chmod 750 file.
From the slide: chmod 400 file_1 → user = 4 (read only), group = 0, other = 0. Only the owner can read it, nobody can write or run it.
The numbers you will meet every day
| Mode | String | Typical use |
|---|---|---|
644 | rw-r--r-- | Normal files, e.g. web pages, text files |
755 | rwxr-xr-x | Programs, scripts and directories |
600 | rw------- | Private files, e.g. SSH private keys |
700 | rwx------ | Private directory, e.g. ~/.ssh |
400 | r-------- | Read-only for owner, e.g. cloud key pairs |
750 | rwxr-x--- | Team-only program or folder |
777 | rwxrwxrwx | Avoid. Everyone can do everything. |
chmod 777?It grants read, write and execute to every user on the system. Anyone (or any compromised program) can replace your file with something malicious. Fix the real cause instead: correct owner, correct group, or add the one permission that is missing.
What number is rw-r-----? (6 · 4 · 0 → 640). Need more practice? The Octal Dojo level below has endless drills.
Level 6 · chmod symbolic mode
Symbolic mode uses letters and symbols to add or remove particular permissions without touching the rest. It reads almost like English.
chmod [who][operator][permissions] file
u g o a + - = r w x
Who
u user (owner)g groupo othera all three
Operator
+ add the permission- remove it= set exactly this (clears the rest)
Permission
r readw writex executeX execute only for dirs / already-executable files
Examples
| Command | What it does |
|---|---|
chmod u+x script.sh | Give the owner execute permission |
chmod g-w notes.txt | Remove write from the group |
chmod o= secret.txt | Others get nothing |
chmod a+r page.html | Everyone can read |
chmod u=rw,g=r,o= file | Exactly rw-r----- (same as 640) |
chmod go-rwx private.txt | Remove everything from group and others |
chmod -R u+rwX,go-w project/ | Recursive: dirs stay enterable, files don't get blanket x |
$ ls -l app.sh -rw-r--r-- 1 alice devs 52 Oct 1 10:30 app.sh $ chmod u+x,g+x app.sh $ ls -l app.sh -rwxr-xr-- 1 alice devs 52 Oct 1 10:30 app.sh
Use absolute when you know the exact final result (chmod 640 file). Use symbolic when you want to tweak one thing and keep the rest (chmod g+w file). You must be able to read both.
Level 7 · Changing ownership and using sudo
chown: change the owner (and group)
chown [options] [user][:][group] file(s)
| Part | Meaning |
|---|---|
[options] | Optional, for example -R to apply recursively inside directories |
[user] | Name or ID of the new owner |
[:] | The colon, used when you also want to change the group |
[group] | The new group (optional) |
[file(s)] | The file or directory to change |
$ sudo chown bob report.txt # owner → bob $ sudo chown bob:devs report.txt # owner → bob, group → devs $ sudo chown :devs report.txt # only the group changes $ sudo chgrp devs report.txt # same thing, group only $ sudo chown -R alice:devs project/ # whole folder tree
sudo: borrow root's power for one command
The root account is the superuser. It can do anything. Normal users can run a single command with root's power using sudo; you are asked for your own password.
$ chown bob report.txt chown: changing ownership of 'report.txt': Operation not permitted $ sudo chown bob report.txt [sudo] password for alice: ******** $
chmod → the file's owner or root. chown → only root (a normal user cannot give files away). chgrp → the owner, but only to a group they belong to.
Use sudo for the one command that needs it, not for everything. A typo as root can damage the whole system.
Level 8 · Expert zone
1. umask: where default permissions come from
New files start from 666 (no free execute bit) and new directories from 777; the umask subtracts bits.
| umask | New file | New directory | Typical on |
|---|---|---|---|
022 | 644 | 755 | Root, many servers |
002 | 664 | 775 | Ubuntu / Debian / Fedora normal users (private groups) |
077 | 600 | 700 | Security-focused setups |
2. Special permission bits
| Bit | Octal | Symbolic | Effect |
|---|---|---|---|
| setuid | 4000 | u+s | Program runs as the file owner (e.g. /usr/bin/passwd). Shown as s in the owner x spot. |
| setgid | 2000 | g+s | On a program: runs as file's group. On a directory: new files inherit the directory's group (perfect for team folders). |
| sticky | 1000 | +t | On a directory: only the file's owner (or dir owner / root) may delete files inside. /tmp uses it: drwxrwxrwt. |
$ sudo mkdir /srv/team $ sudo chgrp devs /srv/team $ sudo chmod 2770 /srv/team # setgid + rwx for owner/group, nothing for others $ ls -ld /srv/team drwxrws--- 2 root devs 4096 Oct 1 11:00 /srv/team
Anything a team member creates in there automatically belongs to group devs. Add +t (3770) so members can't delete each other's files.
3. Directory traversal rule
To open /a/b/c.txt you need x on /, /a, /a/b and r on c.txt. A world-readable file inside a 700 directory is still unreachable. chmod 777 file does not help if the parent is locked.
4. Root is not bound (mostly)
Root bypasses read/write checks. But even root needs at least one x bit to execute a regular file.
5. Beyond rwx
| Tool | Use |
|---|---|
stat -c '%a %A %U:%G %n' file | Show numeric + symbolic mode, owner and group in one line |
getfacl / setfacl -m u:bob:rw file | ACLs: give one extra user/group access without changing the group |
chattr +i file / lsattr | Immutable flag: even root can't modify until -i |
find / -perm -4000 -type f | Audit: list all setuid programs |
find . -type f -perm 777 | Hunt dangerous world-writable files |
chmod --reference=a b | Copy the mode of a onto b |
id, groups, sudo usermod -aG devs bob | See and change group membership (log in again to apply) |
| SELinux / AppArmor | A second, independent layer on RHEL/Ubuntu: even with correct rwx a request can be denied by policy (ls -Z) |
① id — who am I and which groups? ② ls -ld on the file and each parent (or namei -l /path/to/file). ③ Right bit for the action (r/w/x)? ④ Mounted read-only or immutable? ⑤ SELinux/AppArmor?
Level 9 · Best practices
🚫 No chmod 777
Read + write + execute for every user is almost never the right fix.
🔐 Least privilege
Start with the fewest users and the least access. Grant more only when someone has a real need.
📝 Safe file names
Stick to letters, digits, dots, dashes and underscores. Spaces, *, $, ;, & have special shell meanings and cause surprises (and security bugs).
👥 Use groups
Manage access by group rather than fixing individual files for individual people.
Q1. Why should you not use chmod 777?
Show answer
Q2. What are the two modes for configuring permissions, and how do they differ?
Show answer
g-w) to add or remove individual permissions.Permissions are set with chmod in absolute or symbolic mode · ls -l shows them · chown changes ownership.
Level 10 · Hands-on labs
Do these in a disposable VM, WSL or container, never on a production server. Work inside a scratch folder: mkdir ~/permlab && cd ~/permlab. Tick each checkpoint when done: +10 XP each.
Lab 1 · Identify and configure file permissions
⏱ 10 min · BeginnerPurpose: create a file, examine its default permissions, then make it read-only. (This is the demonstration from the course.)
- Create a new file:
touch file_1
- List it in long format:
ls -l file_1 # -rw-r--r-- 1 alice alice 0 Oct 1 10:00 file_1Q: Who owns the file? Which group owns the file?
The owner is the 3rd column (the user who rantouch, e.g.alice); the group is the 4th column (usually that user's primary group, often the same name). - Make it read-only for the owner and closed to everyone else:
chmod 400 file_1
- Verify the change:
ls -l file_1 # -r-------- 1 alice alice 0 Oct 1 10:00 file_1 - Try to write to it, and see the protection working:
echo "hello" > file_1 # bash: file_1: Permission denied
Bonus: as the owner you can still fix it: chmod u+w file_1. Ownership means you control the lock.
Lab 2 · Symbolic mode playground
⏱ 10 min · Beginner- Create a script and try to run it:
printf '#!/bin/bash\necho "It works!"\n' > hi.sh ls -l hi.sh ./hi.sh # Permission denied - Add execute for the owner and run again:
chmod u+x hi.sh ./hi.sh # It works! - Practise the operators:
chmod g+w hi.sh # add chmod o-r hi.sh # remove chmod a=r hi.sh # set exactly: everyone read-only chmod u=rwx,g=rx,o= hi.sh ls -l hi.sh # -rwxr-x---
- Convert to numbers, and confirm with
stat:stat -c '%a %A' hi.sh # 750 -rwxr-x---
Lab 3 · Directory permissions are different
⏱ 15 min · Intermediate- Build a folder with a file:
mkdir box && echo secret > box/note.txt
- Remove r from the directory and list it:
chmod u-r box ls box # Permission denied (can't list names) cat box/note.txt # still works! x lets you pass through
- Remove x (restore r first):
chmod u+r,u-x box ls box # names shown, but errors on details cat box/note.txt # Permission denied (can't enter)
- Remove w from the directory, then try to delete a file you own:
chmod u+x,u-w box rm box/note.txt # Permission denied: deleting changes the folder chmod u+w box # restore
Checkpoint question: why could I cat with no r on the folder?
x on each directory in the path (to traverse) and r on the file. The directory's own r only matters for listing its names, and you already knew the name.Lab 4 · Ownership with chown, chgrp and sudo
⏱ 15 min · Intermediate- Create a helper user and group:
sudo groupadd devs sudo useradd -m -G devs alice
- Create a file, then try to give it away without sudo:
touch handoff.txt chown alice handoff.txt # Operation not permitted - Use sudo:
sudo chown alice:devs handoff.txt ls -l handoff.txt # -rw-r--r-- 1 alice devs ... - Now you are "other". Try to modify it:
echo hi >> handoff.txt # Permission denied sudo chmod g+w handoff.txt # give the group write sudo usermod -aG devs $USER # add yourself to devs (log out/in to apply)
- Clean up:
sudo userdel -r alice; sudo groupdel devs
Lab 5 · Team folder with setgid and sticky bit
⏱ 20 min · Expert- Create the folder for group
devs:sudo mkdir /srv/team sudo chgrp devs /srv/team sudo chmod 2770 /srv/team ls -ld /srv/team # drwxrws--- (note the 's') - Create a file as a group member. See that the group is inherited:
sudo -u alice touch /srv/team/a.txt ls -l /srv/team # group = devs, not alice - Add the sticky bit and observe
t:sudo chmod +t /srv/team ls -ld /srv/team # drwxrws--TCapital
Tmeans sticky is set butxfor others is not. Trychmod 3771to see lowercaset. - Audit the system:
find /usr/bin -perm -4000 -type f 2>/dev/null
Lab 6 · umask experiment
⏱ 10 min · Expertumask # e.g. 0022 touch a.txt; mkdir a_dir ls -ld a.txt a_dir # 644 and 755 with 022 umask 077 touch b.txt; mkdir b_dir ls -ld b.txt b_dir # 600 and 700 umask 022 # put it back (affects this shell only)
Level 11 · The Sandbox Terminal
No Linux machine handy? This is a safe simulated terminal. You are user student (groups: student, devs). Complete the 8 missions; each pays XP. Type help to see supported commands.
Supported: ls [-l -a] cd pwd touch mkdir cat echo "text" > file ./script chmod chown chgrp rm [-r] whoami id stat sudo … clear. ↑ recalls history.
Level 12 · Octal Dojo
Convert permission strings to numbers and back. +5 XP per correct answer (first 20). Get 5 in a row for the Octal Ninja badge.
Level 13 · The MCQ Challenge
20 multiple-choice questions from beginner to expert. +10 XP per correct answer, +5 bonus for every 3rd correct in a row. Score 90%+ for the Quiz Master badge.
Level 14 · FAQ: questions learners really ask
Level 15 · Practice questions with model answers
Try to answer in your own words first, then reveal. These are the kind of questions asked in exams and interviews.
Level 16 · Cheat sheet and key takeaways
| I want to… | Command |
|---|---|
| See permissions | ls -l · ls -ld dir · stat file |
| Set exact permissions | chmod 640 file · chmod u=rw,g=r,o= file |
| Add / remove one permission | chmod u+x file · chmod go-w file |
| Make script runnable | chmod +x script.sh |
| Make file read-only for owner | chmod 400 file |
| Change owner / group | sudo chown user:group file · sudo chgrp group file |
| Change a whole tree | chmod -R … · chown -R … (double-check the path!) |
| Who am I? | whoami · id · groups |
| Default permissions | umask · umask 027 |
| Team folder | chmod 2770 dir (setgid) · chmod +t dir (sticky) |
① r=4 w=2 x=1 · ② three classes: user, group, other · ③ directory x = enter, w = add/remove · ④ never 777, use least privilege · ⑤ chmod = owner or root, chown = root only.
🎓 Your progress
Keep playing to unlock your certificate.