Understand Linux Users, Groups, and File Permissions
Linux decides who can access a file by checking which user is running the command, who owns the file, and the file’s permissions. Groups let administrators grant access to several users at once.
This guide starts with read-only checks, then uses a practice folder in your home directory. Creating users, changing ownership, and changing permissions affect the system, so try those commands in a lab or on paths you are authorized to manage.
Step 1: See Which User and Groups You Are Using
Check Your Login and Group Membership
Start HereEvery process runs as a user and has a set of groups. whoami prints your current username. id shows your user ID, primary group, and supplementary groups. These checks do not change anything.
whoamiidgroups❯ View Expected Console Output
samuid=1000(sam) gid=1000(sam) groups=1000(sam),27(sudo)sam sudoThe sudo group shown here is an example. Group names and administrative groups vary by distribution. Being a member of a group does not automatically mean every command runs with extra privileges; sudo asks an administrator to run a specific command as root.
Step 2: Understand Users and Groups
Create a Practice Group and User
Account BasicsUsers represent accounts; groups collect accounts that should share access. The example below creates a group named app-team, a user named appuser, and adds that user to the group. Run it only on a lab system, and choose names that do not already exist. passwd prompts you to set the new user’s password without displaying it.
When adding an existing user to a group, keep both -a and -G in usermod -aG. The -a means “append”; leaving it out can replace the user’s other supplementary group memberships.
sudo groupadd app-teamsudo useradd --create-home --user-group --shell /bin/bash appusersudo passwd appusersudo usermod --append --groups app-team appuserid appusergetent group app-team❯ View Expected Console Output
uid=1001(appuser) gid=1002(appuser) groups=1002(appuser),1001(app-team)app-team:x:1001:appuserOn Debian and Ubuntu, adduser is also available as an interactive helper. After adding your own account to a group, sign out and back in before expecting your new shell sessions to use that membership.
Step 3: Read a File’s Owner and Permission Mode
Create a Safe Practice File and Read Its Listing
Owner and GroupThe first field from ls -l shows the entry type and nine permission letters. After that, the listing shows the owner, group, size, date, and name. This creates a small example file under your home directory; it does not touch system files.
In -rw-r—r—, the first character - means “regular file.” The next three letters belong to the owner, the next three to the group, and the final three to everyone else.
mkdir -p "$HOME/permissions-lab"printf 'Practice file\n' > "$HOME/permissions-lab/report.txt"ls -l "$HOME/permissions-lab/report.txt"❯ View Expected Console Output
-rw-r--r-- 1 sam sam 14 Oct 4 10:00 /home/sam/permissions-lab/report.txtFor this example, sam is the owner and sam is also the group. On some distributions, your primary group may have a different name.
Step 4: Learn What Read, Write, and Execute Mean
Apply the Permission Letters to Files and Directories
Permission BasicsThe letters mean different things depending on whether the item is a file or a directory. Directory permissions are a common source of confusion: a user usually needs x on every parent directory in the path to reach a file inside it.
- File:
rreads contents,wchanges contents, andxruns the file as a program or script. - Directory:
rlists names,wcreates, removes, or renames entries, andxlets a user enter or traverse it.
On a directory, write permission is usually useful only together with execute permission. A directory’s permissions control its entries; they do not automatically change the permissions on files already inside it.
ls -ld "$HOME/permissions-lab"ls -l "$HOME/permissions-lab"❯ View Expected Console Output
drwxr-xr-x 2 sam sam 4096 Oct 4 10:00 /home/sam/permissions-lab-rw-r--r-- 1 sam sam 14 Oct 4 10:00 /home/sam/permissions-lab/report.txtStep 5: Change Permissions with chmod
Set a File and Directory to Specific Modes
chmodchmod means “change mode”: it changes a file or directory’s permission mode, not its owner or contents. A numeric mode has three digits: owner, group, and everyone else. Each digit adds 4 for read, 2 for write, and 1 for execute. For example, 6 means read plus write, and 5 means read plus execute.
This sets the practice file to 640 (owner can read and write, group can read, others have no access) and the directory to 750 (owner has full access, group can list and enter, others have no access). stat displays both the letters and numeric mode.
chmod 640 "$HOME/permissions-lab/report.txt"chmod 750 "$HOME/permissions-lab"stat -c '%A %a %n' "$HOME/permissions-lab/report.txt" "$HOME/permissions-lab"❯ View Expected Console Output
-rw-r----- 640 /home/sam/permissions-lab/report.txtdrwxr-x--- 750 /home/sam/permissions-labA few common modes are 600 for a private file, 644 for a file most users may read, 700 for a private directory or script, and 755 for a directory or program others may read or run. To decode 755, read one digit at a time: owner 7 is 4+2+1 (rwx); group 5 is 4+1 (r-x); others 5 is also r-x. That produces rwxr-xr-x: owner can change it, while group and others can read and run it or enter the directory. Choose the least access people need; 777 gives everyone read, write, and execute access and is rarely a safe fix.
Step 6: Make a Small Change with Symbolic chmod
Add or Remove One Permission at a Time
Targeted ChangesSymbolic modes let you change selected permissions without replacing the whole mode. The letters before the operator say whose access to change: u is the owner (“user”), g is the group, o is others, and a means all three classes. The operator + adds a permission, - removes it, and = sets the selected class to exactly the permissions that follow. The letters after the operator are the permissions: r, w, or x. For example, u+x means “add execute for the owner.” A fragment such as u+o is incomplete because it does not name a permission; use forms such as u+r or o-r. Separate multiple changes with commas, as in u+r,o-r.
chmod o-r "$HOME/permissions-lab/report.txt"chmod u+x "$HOME/permissions-lab/report.txt"ls -l "$HOME/permissions-lab/report.txt"❯ View Expected Console Output
-rwxr----- 1 sam sam 14 Oct 4 10:00 /home/sam/permissions-lab/report.txtThe file now has execute permission for its owner. That does not make a plain text file a useful program; it only changes the permission bit. Avoid using chmod -R (recursive changes) until you have checked exactly which files and directories it will affect.
Step 7: Change Ownership and Set Up a Shared Group Directory
Assign a File or Directory to the Right Account
chown and chgrpThe owner and group are separate from the permission bits. Use chown user:group path to change both, or chgrp group path to change only the group. These commands usually require sudo when changing ownership to another account.
For a shared team directory, the 2 at the start of mode 2770 sets the setgid bit. New items created inside inherit the directory’s group. Team members still need group write permission, and must belong to that group.
# Example ownership change for an approved file:sudo chown appuser:app-team /path/to/approved-file
# Create a shared directory owned by root and the app-team group:sudo install -d -o root -g app-team -m 2770 /srv/app-teamls -ld /srv/app-team❯ View Expected Console Output
drwxrws--- 2 root app-team 4096 Oct 4 10:05 /srv/app-teamReplace /path/to/approved-file with a real, reviewed target before running the ownership example. The second command creates /srv/app-team; use a lab machine or a location approved by your system owner.
Step 8: Use umask to Limit New Permissions
Choose Safer Defaults for New Files
Default Permissionsumask is the “user file-creation mode mask.” It tells Linux which permission bits to block when a program creates a new file or directory; it does not change existing items. As a simple way to read it, a 027 umask blocks no owner permissions, blocks group write, and blocks all permissions for others. Typical starting modes are 666 for files and 777 for directories, so this produces a 640 file and a 750 directory. Files do not gain execute permission just because the umask allows it.
The setting applies to the current shell and programs started from it. Use umask with no argument to see the current value.
umaskumask 027touch "$HOME/permissions-lab/private.txt"mkdir -p "$HOME/permissions-lab/private-dir"stat -c '%A %a %n' "$HOME/permissions-lab/private.txt" "$HOME/permissions-lab/private-dir"❯ View Expected Console Output
0022-rw-r----- 640 /home/sam/permissions-lab/private.txtdrwxr-x--- 750 /home/sam/permissions-lab/private-dirFor comparison, a common umask of 022 blocks write access for group and others: new files are usually 644 and new directories 755. A group-friendly umask such as 007 blocks all access for others while leaving owner and group access available, so new files are usually 660 and directories 770. Set defaults deliberately for the account, service, or application that creates the files.
Step 9: Troubleshoot “Permission Denied” Safely
Check the Account, Ownership, and Whole Path
TroubleshootingCheck the account running the command, then inspect the file and every directory leading to it. A correct-looking file mode cannot help if a parent directory blocks traversal. If a group was just added, start a new login session so the group list refreshes.
idstat -c '%U:%G %A (%a) %n' "$HOME/permissions-lab/report.txt"namei -l "$HOME/permissions-lab/report.txt"❯ View Expected Console Output
sam:sam -rwxr----- (740) /home/sam/permissions-lab/report.txtf: /home/sam/permissions-lab/report.txtdrwxr-xr-x root root /drwxr-xr-x root root homedrwxr-x--- sam sam samdrwxr-x--- sam sam permissions-lab-rwxr----- sam sam report.txt