Permission Bits
-rwxr-xr-- 1 user group filename
├─┤├─┤├─┤
│ │ └── Other users (other)
│ └───── Group (group)
└───────── Owner (user/owner)| Character | Number | Meaning |
|---|---|---|
r | 4 | Read |
w | 2 | Write |
x | 1 | Execute (enter for directories) |
- | 0 | No permission |
Common Permission Numbers
| Number | Permission | Description |
|---|---|---|
777 | rwxrwxrwx | Full permissions for everyone (use with caution) |
755 | rwxr-xr-x | Full for owner, read+execute for others |
750 | rwxr-x--- | Full for owner, read+execute for group |
700 | rwx------ | Full for owner only |
644 | rw-r—r— | Read+write for owner, read-only for others |
640 | rw-r----- | Read+write for owner, read-only for group |
600 | rw------- | Read+write for owner only |
555 | r-xr-xr-x | Read+execute for everyone |
444 | r—r—r— | Read-only for everyone |
chmod Command
Numeric Mode
chmod 755 filename
chmod 644 filename
chmod -R 755 directory # RecursiveSymbolic Mode
# Add permissions
chmod u+x file # Add execute for owner
chmod g+w file # Add write for group
chmod o-r file # Remove read for others
chmod a+r file # Add read for everyone
# Set exact permissions
chmod u=rwx,g=rx,o=r file
# Common combinations
chmod +x script.sh # Add execute permission
chmod -w file.txt # Remove write permissionTargets: u=owner, g=group, o=others, a=all
Operations: +=add, -=remove, ==set
chown Command
# Change owner
sudo chown username filename
# Change owner and group
sudo chown username:groupname filename
# Change group only
sudo chown :groupname filename
# Or use chgrp
chgrp groupname filename
# Recursive
sudo chown -R username:groupname directorySpecial Permission Bits
SUID (Set User ID) - 4xxx
File executes as the owner, not the user who runs it.
chmod u+s file
chmod 4755 file
# Example: passwd command uses SUID
ls -la /usr/bin/passwd
# -rwsr-xr-x 1 root root ...SGID (Set Group ID) - 2xxx
New files created in the directory inherit the directory’s group.
chmod g+s directory
chmod 2755 directorySticky Bit - 1xxx
Only the owner of a file can delete it within the directory (e.g., /tmp).
chmod +t directory
chmod 1777 directory
ls -la /tmp
# drwxrwxrwt ... # Note the trailing tDefault Permissions (umask)
# Check current umask
umask
# Common value: 0022
# umask calculation:
# File default permissions = 666 - umask = 644
# Directory default permissions = 777 - umask = 755
# Temporary change
umask 027 # Files 640, directories 750
# Permanent change: add to ~/.bashrc
echo "umask 027" >> ~/.bashrcACL Extended Permissions
When basic permissions are not flexible enough:
# Install ACL tools
sudo apt install acl
# Set permissions for a specific user
setfacl -m u:username:rwx filename
# Set permissions for a specific group
setfacl -m g:groupname:rx filename
# Set default ACL (new files auto-inherit)
setfacl -d -m u:username:rwx directory
# View ACL
getfacl filename
# Remove all ACL
setfacl -b filenameUser and Group Management
# Check current user info
id
# Check user's groups
groups username
# Add user to a group
sudo usermod -aG groupname username
# Create a new group
sudo groupadd groupname
# Common system groups
# sudo - Administrator privileges
# docker - Docker operations
# video - Camera/GPU access
# audio - Audio devices
# dialout - Serial port devices
# plugdev - Pluggable devicesCommon Scenario Permission Settings
# Web directory
sudo chown -R www-data:www-data /var/www/html
sudo chmod -R 755 /var/www/html
# SSH keys
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa
chmod 644 ~/.ssh/id_rsa.pub
# Shared directory (group read+write)
sudo mkdir /shared
sudo chown :shared-group /shared
sudo chmod 2775 /shared
# Script files
chmod 755 script.sh # Everyone can execute
chmod 700 script.sh # Only owner can executeLast updated on