Linux Tutorial / File Permissions and Safe sudo Use

Linux file permissions decide whether the owner, the owning group, and everyone else may read (r), write (w), or execute (x) an object. sudo lets an authorized user run a particular command as another user, usually the administrator. When access fails, inspect ownership and permissions first; use elevated privileges only for the operation that actually needs them.

Check your identity and the file owner first

Permissions are not an isolated number attached to a file. The current process's user and groups, the file's owner and group, and permissions on directories along the path all matter. Use id for the current session and ls -l and stat for the target. The preceding lesson on users, groups, and ownership provides the identity concepts needed to interpret these permissions.

id
ls -l notes.txt
stat -c '%A %a %U %G %n' notes.txt

If ls -l shows -rw-r----- 1 learner editors ... notes.txt, the leading - identifies a regular file. The next three groups, rw-, r--, and ---, apply to the owner, owning group, and others. The names are illustrative; your system will differ. The %a field from GNU stat shows an octal form such as 640.

What r, w, and x mean for files and directories

The same letters permit different operations on regular files and directories. This distinction explains why a readable file may still be inaccessible through its directory path.

Permission Regular file Directory
r Read contents Read the names in the directory
w Modify contents Necessary for creating, deleting, and renaming entries
x Permit execution of an executable file Traverse the directory to reach known entries

Opening a file requires traversal permission on directories in its path. Removing a file usually depends on w and x on its parent directory, not w on the file itself. The sticky bit, access control lists (ACLs), filesystem behavior, or a policy such as SELinux can impose further restrictions.

Change a practice file's permissions with chmod

The example creates a new practice directory and file in your home directory. If that directory name already exists, choose another. Stop if mkdir or cd fails. printf writes notes.txt in the current directory, so check that you are not replacing an existing file.

mkdir ~/linux-course-17-practice
cd ~/linux-course-17-practice
printf 'private notes\n' > notes.txt
ls -l notes.txt
chmod u=rw,g=r,o= notes.txt
stat -c '%A %a %n' notes.txt

u means owner, g owning group, and o others. The = operator sets each category to exactly the stated permissions. On a typical GNU stat system, the final line resembles -rw-r----- 640 notes.txt. Which users can actually read the file still depends on their identities and the directory path.

In numeric form, r=4, w=2, and x=1 are added for each category. Thus 640 means rw-, r--, and ---. The next command changes the file to 600, allowing only the owner to read and write. Verify the numeric result with stat.

chmod 600 notes.txt
stat -c '%A %a %n' notes.txt

By contrast, chmod g+r notes.txt adds only group read permission to the existing mode, and chmod o-rwx notes.txt removes all permissions for others. Choose deliberately between replacing a category with = and changing selected bits with + or -.

Inspect directory permissions separately

For a private directory, 700 allows only its owner to list, traverse, and change its entries. Run this example only inside the practice directory created above.

mkdir private
chmod 700 private
ls -ld private
stat -c '%A %a %n' private

A typical result is drwx------ 700 private. The -d option makes ls show the directory itself rather than its contents. Removing directory x by mistake can prevent even the owner from reaching its files. Applying a single mode recursively with chmod -R is especially easy to get wrong because regular files and directories have different needs for x.

When and how to use sudo

sudo runs one command as another user under the current account's authorization policy. Not every account has administrator access. sudo -l lists the commands permitted to your account and may ask for authentication. A denial is an expected result if the account is not authorized.

sudo -l

Use sudo command only when that specific command needs elevation. If a file owned by another user is inaccessible, first establish the intended access policy instead of opening its permissions indiscriminately. sudo does not permanently change the file's owner. Files created through an elevated command may, however, end up owned by the administrator, so inspect where the command writes.

The current shell can process output redirection before sudo runs. Consequently, sudo echo ... > protected-file may not work as expected. For configuration edits, consider an appropriate tool such as sudoedit rather than piecing together a privileged redirection. Edit the sudo policy with visudo, which checks syntax, rather than changing its file blindly and risking loss of administrative access.

A practical sequence for diagnosing permission errors

  1. Run id to see the current session's user and groups. If group membership recently changed, determine whether this login session has picked it up.
  2. Use ls -l or stat for the target's owner and mode. Use ls -ld for a directory itself.
  3. Check traverse permission on each parent directory. On GNU systems, namei -l path can help inspect each component.
  4. If ordinary mode bits do not explain the failure, investigate ACLs, SELinux, a read-only mount, or a sticky bit. Do not start by running chmod 777.
  5. Once the required access is clear, make the smallest change and test again as the intended user.

After the exercise, use pwd to verify your location before cleaning up the practice directory later. Never apply these practice chmod commands to production data or another user's files.

Official references

The GNU Coreutils mode-structure chapter and permission-setting reference cover mode notation and behavior. See the sudoers(5) manual for administrative authorization and safe policy editing.

More in This Category
Linux chgrp Command: Change a File's Group

Linux chgrp Command: Change a File's Group

Learn how to change a File's Group with the Linux chgrp command, including practical examples, key options, and important precautions.

Linux fsck Command: Check and Repair Filesystems

Linux fsck Command: Check and Repair Filesystems

Learn how to check and Repair Filesystems with the Linux fsck command, including practical examples, key options, and important precautions.

Linux uname Command: Check Kernel and System Architecture

Linux uname Command: Check Kernel and System Architecture

Learn how to check Kernel and System Architecture with the Linux uname command, including practical examples, key options, and important precautions.

Linux printf Command: Print Values with a Defined Format

Linux printf Command: Print Values with a Defined Format

Learn how to print Values with a Defined Format with the Linux printf command, including practical examples, key options, and important precautions.

Linux Tutorial / Navigate Directories with pwd, ls, cd, and tree

Linux Tutorial / Navigate Directories with pwd, ls, cd, and tree

Use pwd, ls, cd, and tree to find your current location, inspect directories, navigate paths, and check where each command takes you.

Linux truncate Command: Shrink or Extend File Size

Linux truncate Command: Shrink or Extend File Size

Learn how to shrink or extend files with Linux truncate, adjust sizes relatively, match a reference file, and distinguish sparse logical size from disk usage.

Linux command Command: Run Commands While Bypassing Aliases and Functions

Linux command Command: Run Commands While Bypassing Aliases and Functions

Learn how to use the Linux command command to check command availability and bypass shell aliases or functions, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux uptime Command: Check Uptime and Load Averages

Linux uptime Command: Check Uptime and Load Averages

Learn how to use the Linux uptime command to check how long the system has been running and interpret load averages, with essential options, practical examples, output interpretation, and common troubleshooting tips.

Linux Tutorial / Find Files and Commands with find, locate, which, and whereis

Linux Tutorial / Find Files and Commands with find, locate, which, and whereis

Compare find and locate for file searches, then use which, whereis, and Bash type to distinguish executable paths from shell command resolution.

Linux pkill Command: Signal Processes by Name

Linux pkill Command: Signal Processes by Name

Learn how to signal Processes by Name with the Linux pkill command, including practical examples, key options, and important precautions.