Permissions and ownership
Read a mode string, predict access for any user, and grant only what a job needs.
One question, three classes
Every access check the kernel performs on a file asks the same question: which class does this process belong to? The process is the owner class if its user ID matches the file's owner. Otherwise it is the group class if one of its groups matches the file's group. Otherwise it is other. Exactly one class applies, and only that class's three bits are consulted. A frequent surprise follows: a file owned by you with mode 0077 is unreadable to you even though everyone else can read it.
The symbolic form rwxr-x--- lists the three classes left to right. Each triple maps to an octal digit: read is 4, write is 2, and execute is 1. So rwx is 7, r-x is 5, and --- is 0, giving 750. Learn to read both forms quickly. Runbooks and configuration tools tend to use octal, and ls -l shows symbols.
Directories are lists of names
A directory is a table mapping names to files, and its bits mean something different:
- read lets you list the names (
ls). - write lets you add, remove, or rename entries. You can delete a file you cannot write, if you can write its directory.
- execute (search) lets you use the directory in a path to reach what is inside.
The last one causes the most confusing incident on this topic. A report can be group-readable, the user can be in the group, and the open still fails. One directory on the path lacks execute for that user. namei -l /full/path prints the owner and mode of every component, which turns the hunt into one command.
Identity is numbers
Names such as deploy and oncall are a convenience. The kernel stores numeric user and group IDs, and /etc/passwd and /etc/group (or a directory service) map them to names. Two consequences matter in operations. First, files restored from another host may show odd owners if the numbers differ there. Second, a process's group list is fixed when it starts. Adding a user to a group does not help a shell that is already open. They need a new login session.
Changing access with the smallest grant
chmod changes bits, chgrp changes the group, and chown changes the owner (normally only root can give a file away). The symbolic forms make intent obvious: g+x reads as "let the group execute". Before granting, name the actor and the action. "On-call engineers must run the rotation script" leads to g+x on that file, with the group already set to oncall. It does not lead to 777, which also lets every account on the host rewrite the script that on-call engineers later run.
umask shapes the default. Programs request a mode, typically 666 for files and 777 for directories, and the umask removes bits from it. Service accounts often run with 027 so new files are invisible to other users. If a service creates files that a reader cannot open, look at the creating process's umask before you start running chmod on files.
Escalation is a tool, not a habit
sudo runs one command as another user, usually root, and records it. Use it for the one command that needs it, not to run a whole investigation. Reading as an ordinary user shows what the service experiences. Root's view hides exactly the permission problems you are trying to find.
Key terms
- Mode
- Nine permission bits in three classes (user, group, other), plus special bits. Shown as
rwxr-x---or octal750. - Execute on a directory
- Permission to traverse it, that is, to use it as part of a path. Without it, even readable files inside are unreachable.
- umask
- Bits removed from the default mode of newly created files. A umask of
027yields640files. - Least privilege
- Granting exactly the access a task needs and nothing broader.
Read further
- The Linux Command Line, Chapter "Permissions" (Free PDF (CC BY-NC-ND))
Thels -lattribute string, octal notation,chmodin symbolic form,umask, and the section on changing identities withsuandsudo. Notice the table of what each bit means on a directory. - How Linux Works, 3rd edition, Ch. 7, "System Configuration — Logging, System Time, Batch Jobs, and Users" (Purchase)
The sections on user IDs and the/etc/passwdand/etc/groupfiles. Note that the kernel works with numeric IDs, and names are a lookup.