Prerequisites#
- M3 (
ls -lfamiliarity) and M5 (creating files and directories) - Knowing your identity:
whoami/id
Learning objectives#
By the end of this module you will be able to:
- Read the permission bits on an
ls -lline - Change mode with symbolic and octal
chmod - Explain owner / group / others, and use
chown/chgrpwhere you have rights - Describe setuid, setgid, and the sticky bit at a practical level
- Predict new-file modes using
umask
Reading ls -l#
mkdir -p /tmp/linux-lab-pushpjeet/perms
cd /tmp/linux-lab-pushpjeet/perms
touch notes.txt secret.txt
mkdir shared
ls -l
Example before tightening modes:
-rw-r--r-- 1 box box 0 Sep 26 11:05 notes.txt
-rw-r--r-- 1 box box 0 Sep 26 11:05 secret.txt
drwxr-xr-x 2 box box 4096 Sep 26 11:05 shared
Break down -rw-r--r--:
type owner group others
- rw- r-- r--
| Column | Meaning |
|---|---|
| First char | File type: - file, d directory, l symlink, … |
rwx triplet 1 |
Owner (user) permissions |
| triplet 2 | Group permissions |
| triplet 3 | Others permissions |
| Next fields | link count, owner name, group name, size, mtime, name |
r = read, w = write, x = execute (for a directory, x means “traverse / enter”).
Check who you are:
id
uid=1000(box) gid=1000(box) groups=1000(box)
Your uid/gid numbers and names will differ.
Octal modes (quick mental map)#
Each triplet is a 3-bit number:
| Permission | Value |
|---|---|
r |
4 |
w |
2 |
x |
1 |
Add them per class:
| Mode | Meaning (typical file) |
|---|---|
644 |
rw-r--r-- owner read/write; group/other read |
600 |
rw------- owner only |
755 |
rwxr-xr-x common for executables / dirs |
750 |
rwxr-x--- owner full; group read+enter; others none |
700 |
private directory |
chmod 644 notes.txt
chmod 600 secret.txt
chmod 750 shared
ls -l
Real output after those changes:
-rw-r--r-- 1 box box 0 Sep 26 11:05 notes.txt
-rw------- 1 box box 0 Sep 26 11:05 secret.txt
drwxr-x--- 2 box box 4096 Sep 26 11:05 shared
Symbolic chmod#
Useful when you want to flip one bit without thinking in octal:
chmod u+x notes.txt # add execute for owner
chmod g-w notes.txt # remove write for group
chmod o= notes.txt # clear others
chmod a+r notes.txt # all classes get read
Classes: u user (owner), g group, o others, a all.
Operators: + add, - remove, = set exactly.
Ownership: chown and chgrp#
ls -n # show numeric uid/gid
# chown newuser file # often needs sudo
# chgrp newgroup file
# chown user:group file
On a personal lab directory you already own, you can usually chmod freely. Changing owner to another account typically requires administrator privileges. Practice ownership changes only on a disposable VM when you have sudo and a second test user.
Special bits (short tour)#
| Bit | Octal | On a file | On a directory |
|---|---|---|---|
| setuid | 4xxx |
Run as file’s owner | (rare / not our focus) |
| setgid | 2xxx |
Run as file’s group | New files inherit directory group |
| sticky | 1xxx |
(legacy) | Only owner can delete their own files (e.g. /tmp) |
Sticky demo you can run without special privileges in your own tree:
mkdir -p /tmp/linux-lab-pushpjeet/perms/sticky-demo
chmod 1777 sticky-demo
ls -ld sticky-demo
drwxrwxrwt 2 box box 4096 Sep 26 11:05 sticky-demo
The trailing t in drwxrwxrwt marks the sticky bit. That is the same idea that protects /tmp on shared systems: everyone can write, but you cannot delete someone else’s files.
umask — the quiet filter#
New files do not start at 777/666 and stay there. The kernel proposes a default, then umask bits are turned off.
umask
Common default:
0022
With umask 022, new files often end up 644 and directories 755. Try a stricter mask in this shell only:
cd /tmp/linux-lab-pushpjeet/perms
umask 027
touch umask-demo.txt
ls -l umask-demo.txt
umask 022 # restore a typical default
Lab result:
-rw-r----- 1 box box 0 Sep 26 11:05 umask-demo.txt
027 removed group-write and all other permissions from the base defaults — hence rw-r-----.
umask changes apply to the current shell until you reset them. Persist in startup files only when you intend that for every session (M11).
Shared-directory mental scenario#
Imagine a small team folder:
| Path | Mode | Intent |
|---|---|---|
shared/ |
770 or 750 |
Members of a group can enter; outsiders cannot |
| files inside | 660 or 640 |
Collaboration vs read-only for group |
You need matching group ownership (chgrp) and users in that group for the story to work end-to-end. On a solo lab account, still practice the modes — that skill transfers.
Common mistakes#
- Forgetting directory execute —
chmod 644on a directory blockscd(no traverse bit). Directories almost always needxfor anyone who should enter. - World-writable secrets —
chmod 777is almost never the answer on multi-user systems. - Mixing up order of octal digits — it is owner, group, others — not the reverse.
- Assuming
chmodchanges owner — that ischown. - Leaving a test
umaskin a long-lived session — restore when done experimenting.
Hands-on lab#
mkdir -p /tmp/linux-lab-pushpjeet/m12-lab
cd /tmp/linux-lab-pushpjeet/m12-lab
- Create
public.txt,private.txt, and directoryteam/. chmod 644 public.txt,chmod 600 private.txt,chmod 750 team.- Confirm with
ls -landls -ld team. - Symbolically add owner execute on a copy of a script stub:
touch run.sh && chmod u+x run.sh && ls -l run.sh. mkdir sticky && chmod 1777 sticky && ls -ld sticky— confirm atappears.- Note your umask; set
umask 077;touch locked.txt; inspect; restore umask to022.
Verify: private.txt shows rw-------; sticky shows drwxrwxrwt; locked.txt is owner-only.
Practice: check your understanding#
Multiple choice#
1. In -rw-r-----, what can the group do?
- A. Read and write
- B. Read only
- C. Execute only
- D. Nothing
Answer
B. The group triplet is r-- — read only.
2. Which octal mode matches rwxr-x---?
- A.
644 - B.
755 - C.
750 - D.
700
Answer
C. 7=rwx for owner, 5=r-x for group, 0 for others.
3. What does the x bit mean on a directory?
- A. The directory is a program
- B. Permission to traverse / enter the directory
- C. Sticky bit
- D. Automatic execute of all files inside
Answer
B. Without execute on a directory, cd into it fails.
4. umask 027 primarily:
- A. Raises all permissions to 027
- B. Clears bits so new files/dirs lack certain group/other perms
- C. Deletes files older than 027 days
- D. Sets sticky bit
Answer
B. umask masks away permission bits from defaults.
5. The t in drwxrwxrwt indicates:
- A. Temporary compression
- B. Sticky bit on a directory
- C. setuid
- D. Immutable file
Answer
B. Sticky bit — typical on shared writeable directories like /tmp.
6. Which command changes permission bits (not ownership)?
- A.
chown - B.
chmod - C.
passwd - D.
tee
Answer
B. chmod changes the mode bits.
Flashcards#
| Front | Back |
|---|---|
r w x |
read / write / execute (enter for dirs) |
644 |
rw-r--r-- |
600 |
rw------- |
755 |
rwxr-xr-x |
750 |
rwxr-x--- |
chmod u+x |
Add execute for owner |
umask |
Mask applied to new file modes |
sticky 1777 |
Shared dir; delete only own files |
chown |
Change owner (often needs admin) |
ls -l first char d |
Directory |
Match the columns#
| Octal / bit | Meaning | ||
|---|---|---|---|
| 1 | 644 |
A | Owner rwx, group r-x, others none |
| 2 | 600 |
B | Owner rw, group r, others r |
| 3 | 750 |
C | Owner rw only |
| 4 | chmod g+w |
D | Sticky directory mode example |
| 5 | 1777 |
E | Add write for group |
| 6 | chmod o= |
F | Clear permissions for others |
Answer key
1→B, 2→C, 3→A, 4→E, 5→D, 6→F
Fill in the blank#
- Private file:
chmod 600 secret.txt - Add owner execute:
chmod u+x script.sh - Show numeric owners:
ls -n - Stricter shell umask:
umask 077
Answer key
600u+xls -numask 077
Mini terminal challenge#
Goal: Build a mini “team drop” directory with correct bits.
Setup
rm -rf /tmp/linux-lab-pushpjeet/m12-challenge
mkdir -p /tmp/linux-lab-pushpjeet/m12-challenge
cd /tmp/linux-lab-pushpjeet/m12-challenge
Tasks
mkdir drop && chmod 1770 drop(sticky + owner/group rwx; others none — adjust if your umask fights you; confirm withls -ld).touch drop/readme.txt && chmod 640 drop/readme.txt.- Write one sentence in a course note: who can delete files in a sticky directory?
Verify: ls -ld drop shows a t or T in the other-execute position; readme.txt is rw-r-----.
Stretch: Compare ls -l vs ls -n on the same file.
Next: M13 — Processes and signals — list jobs, send signals, and stop runaway processes safely.