Linux Tutorial / File Permissions and Safe sudo Use

Linux file permissions decide whether the owner, the owning group, and everyone else may read (r), write (w), or execute (x) an object. sudo lets an authorized user run a particular command as another user, usually the administrator. When access fails, inspect ownership and permissions first; use elevated privileges only for the operation that actually needs them.

Check your identity and the file owner first

Permissions are not an isolated number attached to a file. The current process's user and groups, the file's owner and group, and permissions on directories along the path all matter. Use id for the current session and ls -l and stat for the target. The preceding lesson on users, groups, and ownership provides the identity concepts needed to interpret these permissions.

id
ls -l notes.txt
stat -c '%A %a %U %G %n' notes.txt

If ls -l shows -rw-r----- 1 learner editors ... notes.txt, the leading - identifies a regular file. The next three groups, rw-, r--, and ---, apply to the owner, owning group, and others. The names are illustrative; your system will differ. The %a field from GNU stat shows an octal form such as 640.

What r, w, and x mean for files and directories

The same letters permit different operations on regular files and directories. This distinction explains why a readable file may still be inaccessible through its directory path.

Permission Regular file Directory
r Read contents Read the names in the directory
w Modify contents Necessary for creating, deleting, and renaming entries
x Permit execution of an executable file Traverse the directory to reach known entries

Opening a file requires traversal permission on directories in its path. Removing a file usually depends on w and x on its parent directory, not w on the file itself. The sticky bit, access control lists (ACLs), filesystem behavior, or a policy such as SELinux can impose further restrictions.

Change a practice file's permissions with chmod

The example creates a new practice directory and file in your home directory. If that directory name already exists, choose another. Stop if mkdir or cd fails. printf writes notes.txt in the current directory, so check that you are not replacing an existing file.

mkdir ~/linux-course-17-practice
cd ~/linux-course-17-practice
printf 'private notes\n' > notes.txt
ls -l notes.txt
chmod u=rw,g=r,o= notes.txt
stat -c '%A %a %n' notes.txt

u means owner, g owning group, and o others. The = operator sets each category to exactly the stated permissions. On a typical GNU stat system, the final line resembles -rw-r----- 640 notes.txt. Which users can actually read the file still depends on their identities and the directory path.

In numeric form, r=4, w=2, and x=1 are added for each category. Thus 640 means rw-, r--, and ---. The next command changes the file to 600, allowing only the owner to read and write. Verify the numeric result with stat.

chmod 600 notes.txt
stat -c '%A %a %n' notes.txt

By contrast, chmod g+r notes.txt adds only group read permission to the existing mode, and chmod o-rwx notes.txt removes all permissions for others. Choose deliberately between replacing a category with = and changing selected bits with + or -.

Inspect directory permissions separately

For a private directory, 700 allows only its owner to list, traverse, and change its entries. Run this example only inside the practice directory created above.

mkdir private
chmod 700 private
ls -ld private
stat -c '%A %a %n' private

A typical result is drwx------ 700 private. The -d option makes ls show the directory itself rather than its contents. Removing directory x by mistake can prevent even the owner from reaching its files. Applying a single mode recursively with chmod -R is especially easy to get wrong because regular files and directories have different needs for x.

When and how to use sudo

sudo runs one command as another user under the current account's authorization policy. Not every account has administrator access. sudo -l lists the commands permitted to your account and may ask for authentication. A denial is an expected result if the account is not authorized.

sudo -l

Use sudo command only when that specific command needs elevation. If a file owned by another user is inaccessible, first establish the intended access policy instead of opening its permissions indiscriminately. sudo does not permanently change the file's owner. Files created through an elevated command may, however, end up owned by the administrator, so inspect where the command writes.

The current shell can process output redirection before sudo runs. Consequently, sudo echo ... > protected-file may not work as expected. For configuration edits, consider an appropriate tool such as sudoedit rather than piecing together a privileged redirection. Edit the sudo policy with visudo, which checks syntax, rather than changing its file blindly and risking loss of administrative access.

A practical sequence for diagnosing permission errors

  1. Run id to see the current session's user and groups. If group membership recently changed, determine whether this login session has picked it up.
  2. Use ls -l or stat for the target's owner and mode. Use ls -ld for a directory itself.
  3. Check traverse permission on each parent directory. On GNU systems, namei -l path can help inspect each component.
  4. If ordinary mode bits do not explain the failure, investigate ACLs, SELinux, a read-only mount, or a sticky bit. Do not start by running chmod 777.
  5. Once the required access is clear, make the smallest change and test again as the intended user.

After the exercise, use pwd to verify your location before cleaning up the practice directory later. Never apply these practice chmod commands to production data or another user's files.

Official references

The GNU Coreutils mode-structure chapter and permission-setting reference cover mode notation and behavior. See the sudoers(5) manual for administrative authorization and safe policy editing.

More in This Category
Linux Tutorial / Install and Update Packages with APT and DNF

Linux Tutorial / Install and Update Packages with APT and DNF

Compare APT on Debian or Ubuntu with DNF on Rocky Linux for searching, installing, updating, and removing packages, including repository and transaction checks.

Linux more Command: View Text One Screen at a Time

Linux more Command: View Text One Screen at a Time

Learn how to use Linux more to read text one screen at a time, move and search interactively, start at a line or pattern, and choose between more and less.

Essential Linux Commands: A Practical Reference by Task

Essential Linux Commands: A Practical Reference by Task

Browse essential Linux commands by task, including help, files, text processing, permissions, processes, networking, packages, storage, and system administration.

Linux help Command: Read Help for Bash Built-in Commands

Linux help Command: Read Help for Bash Built-in Commands

Learn how to use the Linux help command to read usage information for Bash built-in commands, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Best Linux Distributions for Web Servers: Ubuntu, Debian, or Rocky Linux?

Best Linux Distributions for Web Servers: Ubuntu, Debian, or Rocky Linux?

Compare Ubuntu Server, Debian, and Rocky Linux for web hosting based on support lifecycle, package freshness, documentation, operational stability, and application requirements.

Linux dirname Command: Extract the Directory Part of a Path

Linux dirname Command: Extract the Directory Part of a Path

Learn how to use the Linux dirname command to remove the final component of a path and return its directory portion, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux killall Command: Signal Processes by Name

Linux killall Command: Signal Processes by Name

Learn how to signal Processes by Name with the Linux killall command, including practical examples, key options, and important precautions.

Linux unxz Command: Decompress xz Files

Linux unxz Command: Decompress xz Files

Learn how to decompress xz Files with the Linux unxz command, including practical examples, key options, and important precautions.

Linux chown Command: Change File Owner and Group

Linux chown Command: Change File Owner and Group

Learn how to change File Owner and Group with the Linux chown command, including practical examples, key options, and important precautions.

Linux shutdown Command: Schedule a Shutdown or Restart

Linux shutdown Command: Schedule a Shutdown or Restart

Learn how to schedule a Shutdown or Restart with the Linux shutdown command, including practical examples, key options, and important precautions.