The Permission Model
Read, Write, Execute
You've already typed ls -la in the Foundations modules and seen a cryptic string like -rwxr-x r-- at the start of each line. Now let's decode it fully, because permissions are the single most exam-tested and job-tested topic in all of Linux.
Every file on Linux has an owner (one user) and a group (one group), and permissions are granted separately to three different audiences:
-rwxr-x r-- 1 alice devs 4096 file
│└┬┘└┬┘└┬┘
│ u g o
└ type (- file, d dir, l link)
Reading left to right: the very first character is the file type (- for a regular file, d for directory, l for a symbolic link). Then come three groups of three characters each: what the owner (u = user) can do, what the group can do, and what everyone else (o = other) can do.
Each of those three characters is a yes/no switch for one permission:
| Symbol | Octal | File meaning | Directory meaning |
|---|---|---|---|
| r | 4 | read contents | list entries |
| w | 2 | modify contents | create/delete entries |
| x | 1 | execute | enter (cd into) |
Notice permissions mean something different on a directory than on a file. Read on a directory lets you list what's inside (ls); write lets you create or delete entries inside it (note: not edit their content - that's the file's own permissions); execute lets you cd into it at all. This is why you'll sometimes see a directory you can list but not enter, or vice versa - each bit is independent.
Common octal modes collapse the three rwx triplets into three digits by adding up the values: 755 (rwxr-xr-x - owner full access, everyone else can read/enter but not modify), 644 (rw-r--r-- - a normal readable file), 700 (rwx------ - private to the owner), 600 (rw------- - a private file, like an SSH key).
| Command | Action |
|---|---|
chmod 640 file | Set octal permissions |
chmod u+x,g-w file | Symbolic change |
chown alice:devs file | Change owner + group |
chgrp devs file | Change group only |
chmod -R | Recurse into directories |
$ chmod 640 report.txt && ls -l report.txt
-rw-r----- 1 alice devs 0 Jan 1 10:00 report.txt
640 breaks down as owner=6 (rw-), group=4 (r--), other=0 (---) - alice can read and write it, anyone in the devs group can read it, and nobody else can touch it at all. That matches exactly what ls -l prints back.
Tip:chmodaccepts two totally different styles and it's worth being fluent in both: octal (chmod 755 file) sets the entire permission set at once - fast, but you must know the whole target state. Symbolic (chmod u+x,g-w file) makes a relative change - add execute for the owner, remove write for the group - without disturbing anything else. Use symbolic mode when you want to tweak one thing without recomputing the whole octal number.