Um momento
0x30Lesson 4 of 18

Permissions and ownership

Read ls -l, understand read, write and execute for owner, group and others, and change them with chmod.

20 min 7-question quiz 2 code exercises
By the end of this lesson you can
  • Read the permission string in ls -l output
  • Change permissions with chmod in symbolic (u+x) and octal (755) form
  • Explain why a script needs execute permission and what sudo does

Linux is multi-user: the reactor controls shouldn’t be editable by the tourist who booked a week on the station. Every file has an owner, a group, and permission bits for three audiences. Here’s a line from ls -l:

1-rwxr-x---  1  ada  crew  512  Oct  2 09:00  launch.sh
2│└┬┘└┬┘└┬┘     │    │
3│ │  │  │      │    └── group
4│ │  │  │      └─────── owner
5│ │  │  └── others (everyone else): ---  nothing
6│ │  └───── group (crew):           r-x  read, execute
7│ └──────── owner (ada):            rwx  read, write, execute
8└────────── type: - file, d directory, l symbolic link
BitOn a fileOn a directory
r readsee the contentslist the names inside
w writechange the contentscreate, rename and delete entries
x executerun it as a programenter it with cd and reach things inside

chmod: symbolic and octal

chmod (change mode) sets the bits. The symbolic form says who (u user/owner, g group, o others, a all), an operator (+ add, - remove, = set exactly) and which bits:

  • chmod u+x launch.sh - let the owner run it
  • chmod go-w notes.txt - take write away from group and others
  • chmod a=r manual.txt - everyone may read, nobody may write

The octal form gives each audience one digit, adding r = 4, w = 2, x = 1. So rwx is 7, r-x is 5, r-- is 4, and chmod 755 launch.sh means rwxr-xr-x. You’ll see these all the time:

ModeSymbolicTypical use
755rwxr-xr-xprograms and scripts everyone may run
644rw-r--r--ordinary files
700rwx------private directories
600rw-------secrets such as SSH keys

Try it

chmod lab

Flip the switches to give launch.sh each target permission. Watch the octal digits add up (r = 4, w = 2, x = 1) and the ls -l line change.

Target 1: Only the owner may read and write (an SSH key).Matched 0/5
WhoRead (4)Write (2)Execute (1)Digit
Owner (u)0
Group (g)0
Others (o)0

$ chmod 000 launch.sh

$ ls -l launch.sh

---------- 1 ada crew 512 Oct 2 09:00 launch.sh

Making a script runnable

To run a file as ./name, it needs the execute bit. Without it the shell refuses with Permission denied and exit status 126. (./ means “in this directory” - the shell doesn’t search the current directory for commands, which protects you from running a booby-trapped ls someone left lying around.)

make-it-run.sh
1cd "$(mktemp -d)"
2echo 'echo "Engines online"' > launch.sh
3ls -l launch.sh | cut -d' ' -f1    # just the permission column
4./launch.sh 2>/dev/null || echo "denied!"
5chmod u+x launch.sh
6ls -l launch.sh | cut -d' ' -f1
7./launch.sh
8stat -c '%a %A' launch.sh
Output
-rw-r--r--
denied!
-rwxr--r--
Engines online
744 -rwxr--r--

A few more permission tools you’ll meet:

  • chown ada:crew file changes the owner and group (usually needs administrator rights).
  • sudo command runs one command as root, the administrator, after checking you’re allowed. Use it for exactly the commands that need it - never as a reflex when something fails.
  • umask sets which bits new files don’t get. The common 022 is why new files start as 644 and new directories as 755.

Key takeaways

  • ls -l shows type, then rwx for owner, group and others.

  • Octal digits add r = 4, w = 2, x = 1: 755 is rwxr-xr-x, 644 is rw-r--r--.

  • chmod u+x script.sh makes a script runnable as ./script.sh.

  • Grant the least access that works; reach for sudo deliberately, not by reflex.

Lesson quiz

7 questions · pass with 5 correct · up to 50 XP

Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.

Practice: write Bash scripts

Write a script in the editor and run it for real against sample input. Each run gets a fresh Linux sandbox with Bash 5.2 and the GNU tools on Wandbox, a free public service - so experiment freely, even with rm. Your script and test input are sent there.

Exercise 1

Lock down the files

+25 XP

The starter code creates three files. Set their permissions so the stat line prints:

600 -rw------- airlock.key
644 -rw-r--r-- menu.txt
750 -rwxr-x--- reactor.sh
  • Permissions are right
script.sh
Loading editor…

Your script runs with Bash 5.2 and GNU tools on Wandbox, a free public service, in a fresh sandbox each time. Your script and test input are sent to that service.

Exercise 2

Launch the script

+25 XP

The starter code writes a tiny script, launch.sh, and tries to run it - but it’s refused. Add one command, using chmod’s symbolic form, so that ./launch.sh runs and prints Liftoff!.

  • The script runs
script.sh
Loading editor…

Your script runs with Bash 5.2 and GNU tools on Wandbox, a free public service, in a fresh sandbox each time. Your script and test input are sent to that service.

Questions about this lesson

Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.

Loading posts…

Gostou da aula? 😆👍
Apoie nosso trabalho com uma doação: