Skip to Content

Common Permission Errors

“Permission denied”

# View file permissions ls -la /path/to/file # View current user and groups id

“Operation not permitted”

Usually requires root privileges — use sudo:

sudo COMMAND

File Permission Basics

-rwxr-xr-- 1 user group 4096 Mar 24 10:00 file.txt |---|---|---| | | | +-- Other users: r-- (read) | | +----- Group: r-x (read+execute) | +--------- Owner: rwx (read+write+execute) +------------- File type (- regular file, d directory, l symlink)

Common Scenario Fixes

Cannot edit configuration files

# Files in /etc belong to root sudo nano /etc/xxx/config.conf # Or temporarily change permissions (not recommended for system files) sudo chmod 666 /path/to/file

Cannot execute a script

# Add execute permission chmod +x script.sh # Owner only can execute chmod u+x script.sh

Web server directory permissions

# Typical web directory permission setup sudo chown -R www-data:www-data /var/www/html sudo chmod -R 755 /var/www/html sudo chmod -R 644 /var/www/html/*.html

Cannot write to mounted drive

NTFS or FAT32 partition permissions are controlled by mount options:

# View current mounts mount | grep /dev/sd # Remount NTFS as writable sudo mount -o rw,uid=$(id -u),gid=$(id -g) /dev/sdX1 /mnt/data # Configure in /etc/fstab # UUID=xxx /mnt/data ntfs-3g defaults,uid=1000,gid=1000 0 0

SSH key permissions

SSH has strict requirements for key file permissions:

chmod 700 ~/.ssh chmod 600 ~/.ssh/id_rsa chmod 644 ~/.ssh/id_rsa.pub chmod 600 ~/.ssh/authorized_keys chmod 644 ~/.ssh/config

Home directory permissions changed

# Restore home directory permissions sudo chown -R $USER:$USER ~/ chmod 755 ~/

User not in sudo group

# Need to log in as root or use recovery mode su - root usermod -aG sudo USERNAME # User needs to log out and log back in

sudo password forgotten

If you forgot your password, reset it through recovery mode:

  1. GRUB menu > Advanced options > Recovery mode
  2. Select root command line
  3. Run: passwd USERNAME

/etc/sudoers syntax error causing sudo to break

# Use pkexec to fix (no sudo needed) pkexec visudo # Or fix from recovery mode # Make sure /etc/sudoers contains: # %sudo ALL=(ALL:ALL) ALL

Special Permissions

SUID/SGID/Sticky Bit

# Set SUID (execute as file owner) chmod u+s /path/to/file # Set SGID (new files inherit the directory's group) chmod g+s /path/to/directory # Set Sticky Bit (only owner can delete files in the directory) chmod +t /path/to/directory

ACL Extended Permissions

# Install ACL tools sudo apt install acl # Set permissions for a specific user setfacl -m u:USERNAME:rwx /path/to/file # View ACL getfacl /path/to/file # Remove ACL setfacl -b /path/to/file

AppArmor Restrictions

Ubuntu uses AppArmor for mandatory access control:

# View AppArmor status sudo aa-status # Temporarily set a program to complain mode sudo aa-complain /usr/bin/PROGRAM_NAME # Disable a profile sudo aa-disable /etc/apparmor.d/PROFILE_NAME

Troubleshooting Summary

  1. Use ls -la to check the file’s owner, group, and permission bits
  2. Use id to confirm the current user identity
  3. Check if the user belongs to the required group: groups USERNAME
  4. Check if AppArmor or SELinux has restrictions
  5. Check mount options (especially for external partitions)
Last updated on