← Linux from ScratchCheat sheet
M12Linux from Scratch

M12 — Permissions, ownership, and umask

Time: about 60–90 minutes
Lab root: /tmp/linux-lab-pushpjeet/perms

Prerequisites#

  • M3 (ls -l familiarity) and M5 (creating files and directories)
  • Knowing your identity: whoami / id

Learning objectives#

By the end of this module you will be able to:

  1. Read the permission bits on an ls -l line
  2. Change mode with symbolic and octal chmod
  3. Explain owner / group / others, and use chown / chgrp where you have rights
  4. Describe setuid, setgid, and the sticky bit at a practical level
  5. Predict new-file modes using umask

Reading ls -l#

mkdir -p /tmp/linux-lab-pushpjeet/perms
cd /tmp/linux-lab-pushpjeet/perms
touch notes.txt secret.txt
mkdir shared
ls -l

Example before tightening modes:

-rw-r--r-- 1 box box    0 Sep 26 11:05 notes.txt
-rw-r--r-- 1 box box    0 Sep 26 11:05 secret.txt
drwxr-xr-x 2 box box 4096 Sep 26 11:05 shared

Break down -rw-r--r--:

type  owner  group  others
 -    rw-    r--    r--
Column Meaning
First char File type: - file, d directory, l symlink, …
rwx triplet 1 Owner (user) permissions
triplet 2 Group permissions
triplet 3 Others permissions
Next fields link count, owner name, group name, size, mtime, name

r = read, w = write, x = execute (for a directory, x means “traverse / enter”).

Check who you are:

id
uid=1000(box) gid=1000(box) groups=1000(box)

Your uid/gid numbers and names will differ.


Octal modes (quick mental map)#

Each triplet is a 3-bit number:

Permission Value
r 4
w 2
x 1

Add them per class:

Mode Meaning (typical file)
644 rw-r--r-- owner read/write; group/other read
600 rw------- owner only
755 rwxr-xr-x common for executables / dirs
750 rwxr-x--- owner full; group read+enter; others none
700 private directory
chmod 644 notes.txt
chmod 600 secret.txt
chmod 750 shared
ls -l

Real output after those changes:

-rw-r--r-- 1 box box    0 Sep 26 11:05 notes.txt
-rw------- 1 box box    0 Sep 26 11:05 secret.txt
drwxr-x--- 2 box box 4096 Sep 26 11:05 shared

Symbolic chmod#

Useful when you want to flip one bit without thinking in octal:

chmod u+x notes.txt      # add execute for owner
chmod g-w notes.txt      # remove write for group
chmod o= notes.txt       # clear others
chmod a+r notes.txt      # all classes get read

Classes: u user (owner), g group, o others, a all.
Operators: + add, - remove, = set exactly.


Ownership: chown and chgrp#

ls -n     # show numeric uid/gid
# chown newuser file          # often needs sudo
# chgrp newgroup file
# chown user:group file

On a personal lab directory you already own, you can usually chmod freely. Changing owner to another account typically requires administrator privileges. Practice ownership changes only on a disposable VM when you have sudo and a second test user.


Special bits (short tour)#

Bit Octal On a file On a directory
setuid 4xxx Run as file’s owner (rare / not our focus)
setgid 2xxx Run as file’s group New files inherit directory group
sticky 1xxx (legacy) Only owner can delete their own files (e.g. /tmp)

Sticky demo you can run without special privileges in your own tree:

mkdir -p /tmp/linux-lab-pushpjeet/perms/sticky-demo
chmod 1777 sticky-demo
ls -ld sticky-demo
drwxrwxrwt 2 box box 4096 Sep 26 11:05 sticky-demo

The trailing t in drwxrwxrwt marks the sticky bit. That is the same idea that protects /tmp on shared systems: everyone can write, but you cannot delete someone else’s files.


umask — the quiet filter#

New files do not start at 777/666 and stay there. The kernel proposes a default, then umask bits are turned off.

umask

Common default:

0022

With umask 022, new files often end up 644 and directories 755. Try a stricter mask in this shell only:

cd /tmp/linux-lab-pushpjeet/perms
umask 027
touch umask-demo.txt
ls -l umask-demo.txt
umask 022    # restore a typical default

Lab result:

-rw-r----- 1 box box 0 Sep 26 11:05 umask-demo.txt

027 removed group-write and all other permissions from the base defaults — hence rw-r-----.

umask changes apply to the current shell until you reset them. Persist in startup files only when you intend that for every session (M11).


Shared-directory mental scenario#

Imagine a small team folder:

Path Mode Intent
shared/ 770 or 750 Members of a group can enter; outsiders cannot
files inside 660 or 640 Collaboration vs read-only for group

You need matching group ownership (chgrp) and users in that group for the story to work end-to-end. On a solo lab account, still practice the modes — that skill transfers.


Common mistakes#

  1. Forgetting directory execute — chmod 644 on a directory blocks cd (no traverse bit). Directories almost always need x for anyone who should enter.
  2. World-writable secrets — chmod 777 is almost never the answer on multi-user systems.
  3. Mixing up order of octal digits — it is owner, group, others — not the reverse.
  4. Assuming chmod changes owner — that is chown.
  5. Leaving a test umask in a long-lived session — restore when done experimenting.

Hands-on lab#

mkdir -p /tmp/linux-lab-pushpjeet/m12-lab
cd /tmp/linux-lab-pushpjeet/m12-lab
  1. Create public.txt, private.txt, and directory team/.
  2. chmod 644 public.txt, chmod 600 private.txt, chmod 750 team.
  3. Confirm with ls -l and ls -ld team.
  4. Symbolically add owner execute on a copy of a script stub: touch run.sh && chmod u+x run.sh && ls -l run.sh.
  5. mkdir sticky && chmod 1777 sticky && ls -ld sticky — confirm a t appears.
  6. Note your umask; set umask 077; touch locked.txt; inspect; restore umask to 022.

Verify: private.txt shows rw-------; sticky shows drwxrwxrwt; locked.txt is owner-only.


Practice: check your understanding#

Multiple choice#

1. In -rw-r-----, what can the group do?

  • A. Read and write
  • B. Read only
  • C. Execute only
  • D. Nothing
Answer

B. The group triplet is r-- — read only.

2. Which octal mode matches rwxr-x---?

  • A. 644
  • B. 755
  • C. 750
  • D. 700
Answer

C. 7=rwx for owner, 5=r-x for group, 0 for others.

3. What does the x bit mean on a directory?

  • A. The directory is a program
  • B. Permission to traverse / enter the directory
  • C. Sticky bit
  • D. Automatic execute of all files inside
Answer

B. Without execute on a directory, cd into it fails.

4. umask 027 primarily:

  • A. Raises all permissions to 027
  • B. Clears bits so new files/dirs lack certain group/other perms
  • C. Deletes files older than 027 days
  • D. Sets sticky bit
Answer

B. umask masks away permission bits from defaults.

5. The t in drwxrwxrwt indicates:

  • A. Temporary compression
  • B. Sticky bit on a directory
  • C. setuid
  • D. Immutable file
Answer

B. Sticky bit — typical on shared writeable directories like /tmp.

6. Which command changes permission bits (not ownership)?

  • A. chown
  • B. chmod
  • C. passwd
  • D. tee
Answer

B. chmod changes the mode bits.

Flashcards#

Front Back
r w x read / write / execute (enter for dirs)
644 rw-r--r--
600 rw-------
755 rwxr-xr-x
750 rwxr-x---
chmod u+x Add execute for owner
umask Mask applied to new file modes
sticky 1777 Shared dir; delete only own files
chown Change owner (often needs admin)
ls -l first char d Directory

Match the columns#

Octal / bit Meaning
1 644 A Owner rwx, group r-x, others none
2 600 B Owner rw, group r, others r
3 750 C Owner rw only
4 chmod g+w D Sticky directory mode example
5 1777 E Add write for group
6 chmod o= F Clear permissions for others
Answer key

1→B, 2→C, 3→A, 4→E, 5→D, 6→F

Fill in the blank#

  1. Private file: chmod 600 secret.txt
  2. Add owner execute: chmod u+x script.sh
  3. Show numeric owners: ls -n
  4. Stricter shell umask: umask 077
Answer key
  1. 600
  2. u+x
  3. ls -n
  4. umask 077

Mini terminal challenge#

Goal: Build a mini “team drop” directory with correct bits.

Setup

rm -rf /tmp/linux-lab-pushpjeet/m12-challenge
mkdir -p /tmp/linux-lab-pushpjeet/m12-challenge
cd /tmp/linux-lab-pushpjeet/m12-challenge

Tasks

  1. mkdir drop && chmod 1770 drop (sticky + owner/group rwx; others none — adjust if your umask fights you; confirm with ls -ld).
  2. touch drop/readme.txt && chmod 640 drop/readme.txt.
  3. Write one sentence in a course note: who can delete files in a sticky directory?

Verify: ls -ld drop shows a t or T in the other-execute position; readme.txt is rw-r-----.

Stretch: Compare ls -l vs ls -n on the same file.


Next: M13 — Processes and signals — list jobs, send signals, and stop runaway processes safely.

Continue

← Linux from Scratch hub · Cheat sheet · All tutorials