Common Permission Errors
“Permission denied”
# View file permissions
ls -la /path/to/file
# View current user and groups
id“Operation not permitted”
Usually requires root privileges — use sudo:
sudo COMMANDFile Permission Basics
-rwxr-xr-- 1 user group 4096 Mar 24 10:00 file.txt
|---|---|---|
| | | +-- Other users: r-- (read)
| | +----- Group: r-x (read+execute)
| +--------- Owner: rwx (read+write+execute)
+------------- File type (- regular file, d directory, l symlink)Common Scenario Fixes
Cannot edit configuration files
# Files in /etc belong to root
sudo nano /etc/xxx/config.conf
# Or temporarily change permissions (not recommended for system files)
sudo chmod 666 /path/to/fileCannot execute a script
# Add execute permission
chmod +x script.sh
# Owner only can execute
chmod u+x script.shWeb server directory permissions
# Typical web directory permission setup
sudo chown -R www-data:www-data /var/www/html
sudo chmod -R 755 /var/www/html
sudo chmod -R 644 /var/www/html/*.htmlCannot write to mounted drive
NTFS or FAT32 partition permissions are controlled by mount options:
# View current mounts
mount | grep /dev/sd
# Remount NTFS as writable
sudo mount -o rw,uid=$(id -u),gid=$(id -g) /dev/sdX1 /mnt/data
# Configure in /etc/fstab
# UUID=xxx /mnt/data ntfs-3g defaults,uid=1000,gid=1000 0 0SSH key permissions
SSH has strict requirements for key file permissions:
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa
chmod 644 ~/.ssh/id_rsa.pub
chmod 600 ~/.ssh/authorized_keys
chmod 644 ~/.ssh/configHome directory permissions changed
# Restore home directory permissions
sudo chown -R $USER:$USER ~/
chmod 755 ~/sudo-Related Issues
User not in sudo group
# Need to log in as root or use recovery mode
su - root
usermod -aG sudo USERNAME
# User needs to log out and log back insudo password forgotten
If you forgot your password, reset it through recovery mode:
- GRUB menu > Advanced options > Recovery mode
- Select root command line
- Run:
passwd USERNAME
/etc/sudoers syntax error causing sudo to break
# Use pkexec to fix (no sudo needed)
pkexec visudo
# Or fix from recovery mode
# Make sure /etc/sudoers contains:
# %sudo ALL=(ALL:ALL) ALLSpecial Permissions
SUID/SGID/Sticky Bit
# Set SUID (execute as file owner)
chmod u+s /path/to/file
# Set SGID (new files inherit the directory's group)
chmod g+s /path/to/directory
# Set Sticky Bit (only owner can delete files in the directory)
chmod +t /path/to/directoryACL Extended Permissions
# Install ACL tools
sudo apt install acl
# Set permissions for a specific user
setfacl -m u:USERNAME:rwx /path/to/file
# View ACL
getfacl /path/to/file
# Remove ACL
setfacl -b /path/to/fileAppArmor Restrictions
Ubuntu uses AppArmor for mandatory access control:
# View AppArmor status
sudo aa-status
# Temporarily set a program to complain mode
sudo aa-complain /usr/bin/PROGRAM_NAME
# Disable a profile
sudo aa-disable /etc/apparmor.d/PROFILE_NAMETroubleshooting Summary
- Use
ls -lato check the file’s owner, group, and permission bits - Use
idto confirm the current user identity - Check if the user belongs to the required group:
groups USERNAME - Check if AppArmor or SELinux has restrictions
- Check mount options (especially for external partitions)
Last updated on