Theory
"Permission denied"
Sooner or later the campus server tells you 'Permission denied'. That is Linux's security model doing its job. On a shared multiuser machine, not everyone should be able to read, change, or run every file, so each file carries permissions saying who may do what.
This is one of the most important topics in the whole course, and the one students most often get muddled on, because of the compact number code (like 755) that chmod uses. We will build it up carefully and verify the arithmetic, so the octal codes become second nature.
Theory
Three permissions, three classes
Every file has three permissions:
- r (read): view the file's contents.
- w (write): change or delete the file.
- x (execute): run the file as a program (or, for a directory, enter it).
And these are set separately for three classes of people:
- user (u): the file's owner.
- group (g): members of the file's group.
- others (o): everyone else.
So ls -l shows nine permission characters, three for each class: for example -rwxr-xr-x means the owner can read, write, execute; the group can read and execute; others can read and execute.
At a glance
| Permission | Letter | Value |
|---|---|---|
| Read | r | 4 |
| Write | w | 2 |
| Execute | x | 1 |
| (none) | - | 0 |
Theory
Adding up to an octal digit
Here is the trick that makes chmod codes work. For each class, you add up the values of the permissions it has, giving one digit from 0 to 7:
- rwx = 4 + 2 + 1 = 7 (all three)
- r-x = 4 + 0 + 1 = 5 (read and execute)
- rw- = 4 + 2 + 0 = 6 (read and write)
- r-- = 4 = 4 (read only)
Three classes give three digits. So -rwxr-xr-x becomes owner 7, group 5, others 5, which is the famous 755. And -rw-r--r-- becomes 6, 4, 4, which is 644. Those two, 755 and 644, are the most common settings you will meet.
Practical
chmod in action (verified output)
$ chmod 755 script.sh # owner rwx=7, group r-x=5, others r-x=5
$ chmod 644 notes.txt # owner rw-=6, group r--=4, others r--=4
$ ls -l
-rwxr-xr-x 1 riya riya ... script.sh # 755
-rw-r--r-- 1 riya riya ... notes.txt # 644
# 755 is typical for scripts/programs (runnable);
# 644 is typical for ordinary data files (not runnable).Quiz
You want a file to be readable, writable, and executable by the owner, and only readable by the group and others. What chmod octal code is that?
- 777, because that is full access
- 744, because owner rwx = 7, group r = 4, others r = 4
- 755, because owner rwx = 7, group and others r = 5
- 644, because owner rw = 6
Show the answer
744, because owner rwx = 7, group r = 4, others r = 4
Work each class into a digit. Owner needs rwx = 4 + 2 + 1 = 7. Group needs read only = r-- = 4. Others need read only = r-- = 4. So the code is 744. Option A (777) gives everyone rwx (write and execute too), far more than 'only readable' for group and others. Option C (755) gives group and others r-x = 5, that includes EXECUTE, but we wanted read only, so 5 is wrong for them. Option D (644) gives the owner only rw = 6, missing the required execute for the owner. Always convert each class separately: owner 7, group 4, others 4 -> 744.
Theory
Ownership and default permissions
Permissions decide what each class may do; ownership decides who is in each class.
- chown changes a file's owner (chown riya file), and
chown user:group filesets both owner and group. - chgrp changes just the group (chgrp students file).
And when you create a new file, its starting permissions come from the umask, which masks certain bits off. A typical umask of 022 gives new files 644 and new directories 755, which is why fresh files are readable by all but writable only by you. (Directories start from 777 and files from 666 before the mask is applied.)
Think first
Why does a directory need execute permission?
Execute on a program means 'run it'. But what does execute permission mean on a directory, and why do you need it? Then tap.
Show the answer
On a DIRECTORY, execute (x) means 'you may ENTER it and access files inside by name', it is permission to traverse into the directory, not to run it. This is a subtlety that trips people up. Read (r) on a directory lets you LIST the names it contains; execute (x) lets you actually cd into it and reach a specific file inside. You often need BOTH: without x you cannot enter the directory at all, even if you know a file's exact name; without r you cannot list what is there. That is why directories are commonly 755 (rwxr-xr-x): the x bits let people enter and reach files, while write is reserved for the owner. If you ever get 'Permission denied' trying to cd into a folder even though the files inside look readable, the missing execute bit on the directory is the usual culprit. So for directories, think of x as 'the key to walk through the door', a different meaning from running a program, but the same bit and the same value of 1 in the octal math.
Summary
Key takeaways
- Each file has three permissions, r (read, 4), w (write, 2), x (execute, 1), for three classes: user/owner, group, others.
- ls -l shows nine permission characters, three per class, like -rwxr-xr-x.
- For each class, add the values to get an octal digit: rwx=7, r-x=5, rw-=6, r--=4.
- So chmod 755 = rwxr-xr-x (7,5,5), typical for programs; chmod 644 = rw-r--r-- (6,4,4), typical for data files.
- chown changes the owner (chown user:group sets both); chgrp changes the group.
- umask sets default permissions by masking bits off; umask 022 gives new files 644 and new directories 755.
- On a directory, execute (x) means permission to enter it; memory hook: r=4, w=2, x=1, add per class.