Skip to content

Understand Linux Users, Groups, and File Permissions

Linux decides who can access a file by checking which user is running the command, who owns the file, and the file’s permissions. Groups let administrators grant access to several users at once.

This guide starts with read-only checks, then uses a practice folder in your home directory. Creating users, changing ownership, and changing permissions affect the system, so try those commands in a lab or on paths you are authorized to manage.


Step 1: See Which User and Groups You Are Using

01

Check Your Login and Group Membership

Start Here

Every process runs as a user and has a set of groups. whoami prints your current username. id shows your user ID, primary group, and supplementary groups. These checks do not change anything.

Terminal window
whoami
id
groups
❯ View Expected Console Output
sam
uid=1000(sam) gid=1000(sam) groups=1000(sam),27(sudo)
sam sudo

The sudo group shown here is an example. Group names and administrative groups vary by distribution. Being a member of a group does not automatically mean every command runs with extra privileges; sudo asks an administrator to run a specific command as root.


Step 2: Understand Users and Groups

02

Create a Practice Group and User

Account Basics

Users represent accounts; groups collect accounts that should share access. The example below creates a group named app-team, a user named appuser, and adds that user to the group. Run it only on a lab system, and choose names that do not already exist. passwd prompts you to set the new user’s password without displaying it.

When adding an existing user to a group, keep both -a and -G in usermod -aG. The -a means “append”; leaving it out can replace the user’s other supplementary group memberships.

Terminal window
sudo groupadd app-team
sudo useradd --create-home --user-group --shell /bin/bash appuser
sudo passwd appuser
sudo usermod --append --groups app-team appuser
id appuser
getent group app-team
❯ View Expected Console Output
uid=1001(appuser) gid=1002(appuser) groups=1002(appuser),1001(app-team)
app-team:x:1001:appuser

On Debian and Ubuntu, adduser is also available as an interactive helper. After adding your own account to a group, sign out and back in before expecting your new shell sessions to use that membership.


Step 3: Read a File’s Owner and Permission Mode

03

Create a Safe Practice File and Read Its Listing

Owner and Group

The first field from ls -l shows the entry type and nine permission letters. After that, the listing shows the owner, group, size, date, and name. This creates a small example file under your home directory; it does not touch system files.

In -rw-r—r—, the first character - means “regular file.” The next three letters belong to the owner, the next three to the group, and the final three to everyone else.

Terminal window
mkdir -p "$HOME/permissions-lab"
printf 'Practice file\n' > "$HOME/permissions-lab/report.txt"
ls -l "$HOME/permissions-lab/report.txt"
❯ View Expected Console Output
-rw-r--r-- 1 sam sam 14 Oct 4 10:00 /home/sam/permissions-lab/report.txt

For this example, sam is the owner and sam is also the group. On some distributions, your primary group may have a different name.


Step 4: Learn What Read, Write, and Execute Mean

04

Apply the Permission Letters to Files and Directories

Permission Basics

The letters mean different things depending on whether the item is a file or a directory. Directory permissions are a common source of confusion: a user usually needs x on every parent directory in the path to reach a file inside it.

  • File: r reads contents, w changes contents, and x runs the file as a program or script.
  • Directory: r lists names, w creates, removes, or renames entries, and x lets a user enter or traverse it.

On a directory, write permission is usually useful only together with execute permission. A directory’s permissions control its entries; they do not automatically change the permissions on files already inside it.

Terminal window
ls -ld "$HOME/permissions-lab"
ls -l "$HOME/permissions-lab"
❯ View Expected Console Output
drwxr-xr-x 2 sam sam 4096 Oct 4 10:00 /home/sam/permissions-lab
-rw-r--r-- 1 sam sam 14 Oct 4 10:00 /home/sam/permissions-lab/report.txt

Step 5: Change Permissions with chmod

05

Set a File and Directory to Specific Modes

chmod

chmod means “change mode”: it changes a file or directory’s permission mode, not its owner or contents. A numeric mode has three digits: owner, group, and everyone else. Each digit adds 4 for read, 2 for write, and 1 for execute. For example, 6 means read plus write, and 5 means read plus execute.

This sets the practice file to 640 (owner can read and write, group can read, others have no access) and the directory to 750 (owner has full access, group can list and enter, others have no access). stat displays both the letters and numeric mode.

Terminal window
chmod 640 "$HOME/permissions-lab/report.txt"
chmod 750 "$HOME/permissions-lab"
stat -c '%A %a %n' "$HOME/permissions-lab/report.txt" "$HOME/permissions-lab"
❯ View Expected Console Output
-rw-r----- 640 /home/sam/permissions-lab/report.txt
drwxr-x--- 750 /home/sam/permissions-lab

A few common modes are 600 for a private file, 644 for a file most users may read, 700 for a private directory or script, and 755 for a directory or program others may read or run. To decode 755, read one digit at a time: owner 7 is 4+2+1 (rwx); group 5 is 4+1 (r-x); others 5 is also r-x. That produces rwxr-xr-x: owner can change it, while group and others can read and run it or enter the directory. Choose the least access people need; 777 gives everyone read, write, and execute access and is rarely a safe fix.


Step 6: Make a Small Change with Symbolic chmod

06

Add or Remove One Permission at a Time

Targeted Changes

Symbolic modes let you change selected permissions without replacing the whole mode. The letters before the operator say whose access to change: u is the owner (“user”), g is the group, o is others, and a means all three classes. The operator + adds a permission, - removes it, and = sets the selected class to exactly the permissions that follow. The letters after the operator are the permissions: r, w, or x. For example, u+x means “add execute for the owner.” A fragment such as u+o is incomplete because it does not name a permission; use forms such as u+r or o-r. Separate multiple changes with commas, as in u+r,o-r.

Terminal window
chmod o-r "$HOME/permissions-lab/report.txt"
chmod u+x "$HOME/permissions-lab/report.txt"
ls -l "$HOME/permissions-lab/report.txt"
❯ View Expected Console Output
-rwxr----- 1 sam sam 14 Oct 4 10:00 /home/sam/permissions-lab/report.txt

The file now has execute permission for its owner. That does not make a plain text file a useful program; it only changes the permission bit. Avoid using chmod -R (recursive changes) until you have checked exactly which files and directories it will affect.


Step 7: Change Ownership and Set Up a Shared Group Directory

07

Assign a File or Directory to the Right Account

chown and chgrp

The owner and group are separate from the permission bits. Use chown user:group path to change both, or chgrp group path to change only the group. These commands usually require sudo when changing ownership to another account.

For a shared team directory, the 2 at the start of mode 2770 sets the setgid bit. New items created inside inherit the directory’s group. Team members still need group write permission, and must belong to that group.

Terminal window
# Example ownership change for an approved file:
sudo chown appuser:app-team /path/to/approved-file
# Create a shared directory owned by root and the app-team group:
sudo install -d -o root -g app-team -m 2770 /srv/app-team
ls -ld /srv/app-team
❯ View Expected Console Output
drwxrws--- 2 root app-team 4096 Oct 4 10:05 /srv/app-team

Replace /path/to/approved-file with a real, reviewed target before running the ownership example. The second command creates /srv/app-team; use a lab machine or a location approved by your system owner.


Step 8: Use umask to Limit New Permissions

08

Choose Safer Defaults for New Files

Default Permissions

umask is the “user file-creation mode mask.” It tells Linux which permission bits to block when a program creates a new file or directory; it does not change existing items. As a simple way to read it, a 027 umask blocks no owner permissions, blocks group write, and blocks all permissions for others. Typical starting modes are 666 for files and 777 for directories, so this produces a 640 file and a 750 directory. Files do not gain execute permission just because the umask allows it.

The setting applies to the current shell and programs started from it. Use umask with no argument to see the current value.

Terminal window
umask
umask 027
touch "$HOME/permissions-lab/private.txt"
mkdir -p "$HOME/permissions-lab/private-dir"
stat -c '%A %a %n' "$HOME/permissions-lab/private.txt" "$HOME/permissions-lab/private-dir"
❯ View Expected Console Output
0022
-rw-r----- 640 /home/sam/permissions-lab/private.txt
drwxr-x--- 750 /home/sam/permissions-lab/private-dir

For comparison, a common umask of 022 blocks write access for group and others: new files are usually 644 and new directories 755. A group-friendly umask such as 007 blocks all access for others while leaving owner and group access available, so new files are usually 660 and directories 770. Set defaults deliberately for the account, service, or application that creates the files.


Step 9: Troubleshoot “Permission Denied” Safely

09

Check the Account, Ownership, and Whole Path

Troubleshooting

Check the account running the command, then inspect the file and every directory leading to it. A correct-looking file mode cannot help if a parent directory blocks traversal. If a group was just added, start a new login session so the group list refreshes.

Terminal window
id
stat -c '%U:%G %A (%a) %n' "$HOME/permissions-lab/report.txt"
namei -l "$HOME/permissions-lab/report.txt"
❯ View Expected Console Output
sam:sam -rwxr----- (740) /home/sam/permissions-lab/report.txt
f: /home/sam/permissions-lab/report.txt
drwxr-xr-x root root /
drwxr-xr-x root root home
drwxr-x--- sam sam sam
drwxr-x--- sam sam permissions-lab
-rwxr----- sam sam report.txt

Comments