Contents

Computer Science › Operating Systems

File Permissions

Read, write and execute rights for user, group and others.

Also known as: chmod, Unix permissions, rwx, file mode

On Linux and macOS, every file has permissions saying who can read it, write it and execute it. They’re set separately for three classes: the owner (user), the owner’s group, and everyone else (others).

ls -l
# -rwxr-xr-- 1 ana devs 1204 Oct 10 09:00 deploy.sh
#  │└┬┘└┬┘└┬┘
#  │ │  │  └─ others: r--  (read only)
#  │ │  └──── group:  r-x  (read and execute)
#  │ └─────── owner:  rwx  (read, write, execute)
#  └───────── file type: - is a regular file, d is a directory
LetterOn a fileOn a directory
rread the contentslist the files in it
wchange the contentscreate and delete files in it
xrun it as a programenter it (cd)

Changing them

chmod +x script.sh            # make it executable
chmod u+w,g-w file            # owner can write, group can't
chmod 644 notes.txt           # numeric form
chmod 755 deploy.sh
chown ana:devs file           # change owner and group (usually needs sudo)

The numbers add up per class: read = 4, write = 2, execute = 1.

ModeMeaning
644owner read/write, everyone else read
755owner all, others read/execute (scripts, directories)
600owner read/write only (private files)
700owner only (private directories)

Common problems

  • “Permission denied” when running a script: it needs x (chmod +x), or you aren’t the right user.
  • SSH keys must be private (chmod 600 ~/.ssh/id_ed25519), or SSH refuses them (SSH keys).
  • A web server can’t read your files: its user lacks read permission or directory x.
  • chmod 777 “fixes” everything by letting everybody do anything. It’s insecure. Find the right owner and mode instead (least privilege).
  • Don’t run things as root to get around permissions (sudo and root).
  • Containers and mounted volumes can map users differently, causing mismatches.