Skip to main content

File Permissions

Linux file permissions control which users can read, write, or execute a file using a three-level model: owner, group, and other. Each level has three bits that can be independently set, represented as rwxr-xr-- or in octal as 754.

What Are File Permissions in Simple Terms

Every file on a Linux system has a lock with three sets of keys. The first set belongs to the owner — the user who created the file or was assigned ownership. The second set belongs to the group — a collection of users who share access. The third set is for everyone else on the system.

For each set of keys, there are three doors: read (look inside), write (change contents), and execute (run as a program). A permission is simply which doors which key set can open.

How It Works

The permission model is stored in the inode as a 12-bit value. The first 9 bits are the basic permissions (3 per level). The final 3 are the special bits (setuid, setgid, sticky).

Reading the full permission string:

◈ DIAGRAM
- r w x r - x r - -
| | | | | |
| +--own---+ +--grp---+ +--other--+
|
+-- type: - file, d dir, l link
r (read) = 4
w (write) = 2
x (execute) = 1
- (none) = 0
Owner: rwx = 7
Group: r-x = 5
Other: r-- = 4
Octal: 754

What each permission does by context:

Bash
For regular files:
r = open and read the file contents
w = modify or truncate the file contents
x = execute as a program or script
For directories:
r = list the directory contents (ls)
w = create, rename, or delete files inside
x = enter the directory (cd) and access files inside
Note: directory x (traverse) is required to access
anything inside, even if you have r on the files.

chmod — changing permissions:

Bash
## Symbolic mode
chmod u+x script.sh ## add execute to owner
chmod go-w file.txt ## remove write from group and other
chmod a=r readme.txt ## set everyone to read only
chmod u+x,g=r,o= private.sh ## owner executes, group reads, other nothing
## Octal mode (faster once learned)
chmod 644 config.txt ## -rw-r--r--
chmod 755 script.sh ## -rwxr-xr-x
chmod 600 private.key ## -rw-------
chmod 700 ~/.ssh/ ## drwx------
## Recursive (all files in directory)
chmod -R 644 /var/www/html/
chmod -R 755 /var/www/html/
## Better: set files 644 and dirs 755 separately
find /var/www/html/ -type f -exec chmod 644 {} \;
find /var/www/html/ -type d -exec chmod 755 {} \;

Special permission bits:

Bash
## Setuid: file runs as its owner, not the caller
ls -la /usr/bin/passwd
## -rwsr-xr-x 1 root root -- the 's' in owner execute position = setuid
## passwd needs root to modify /etc/shadow, but any user runs it
chmod u+s filename # or chmod 4755 filename
## Setgid on directory: new files inherit directory group
chmod g+s /shared/team-dir/
## All files created here get the directory's group automatically
## Sticky bit on directory: only file owner can delete their files
ls -la /tmp
## drwxrwxrwt -- the 't' in other execute position = sticky
## You can write to /tmp but cannot delete others' files
chmod +t /shared/public/

Practical Commands

Bash
## View permissions
ls -la filename
stat filename
## Change permissions
chmod 644 file
chmod u+x script.sh
chmod -R 755 directory/
## Change owner
chown user file
chown user:group file
chown -R user:group directory/
## Check umask (default permission mask)
umask
## Find files with specific permissions
find / -perm 777 -type f 2>/dev/null ## world-writable files
find / -perm -4000 -type f 2>/dev/null ## setuid binaries
find / -perm -2000 -type f 2>/dev/null ## setgid binaries

Troubleshooting

Symptom Command What to Look For
Permission denied reading file ls -la filename Does user have r bit?
Cannot execute script ls -la script.sh Does user have x bit?
SSH key rejected ls -la ~/.ssh/ Key file should be 600, dir 700
Web server 403 Forbidden ls -la /var/www/html/ www-data needs r and x on path
Tip

When you get a permission denied error, check every directory in the path, not just the file. If any directory in /var/www/html/app/index.html is missing the execute bit for the web server user, the request fails even if the file itself has correct permissions.

Security

Audit setuid and setgid files regularly on production servers. They run with elevated privileges regardless of who calls them. An unexpected setuid binary is a major security red flag: find / -perm -4000 -type f 2>/dev/null.

Frequently Asked Questions

What does each digit in an octal permission like 754 actually represent?

Each digit is a sum of read (4), write (2), and execute (1) bits for one of three levels: owner, group, then other, in that order. 754 means the owner has read+write+execute (7), the group has read+execute (5), and everyone else has read-only (4). This octal shorthand is what `chmod 754 file` sets, and it maps directly to the rwxr-xr-- string shown by `ls -l`.

Why is `chmod 777` considered a bad practice even though it 'fixes' permission errors?

777 grants read, write, and execute to owner, group, and everyone else, meaning any user on the system (or any process running as another user) can modify or execute the file — a real security risk for anything reachable by untrusted users, like a shared web server directory. The correct fix is almost always to change file ownership (`chown`) or group membership to the actual user/service that needs access, then grant the minimum permission bits required, not to open the file to the world.