Permissions and ownership
Read ls -l, understand read, write and execute for owner, group and others, and change them with chmod.
- Read the permission string in
ls -loutput - Change permissions with chmod in symbolic (u+x) and octal (755) form
- Explain why a script needs execute permission and what sudo does
Linux is multi-user: the reactor controls shouldn’t be editable by the tourist who booked a week on the station. Every file has an owner, a group, and permission bits for three audiences. Here’s a line from ls -l:
1-rwxr-x--- 1 ada crew 512 Oct 2 09:00 launch.sh
2│└┬┘└┬┘└┬┘ │ │
3│ │ │ │ │ └── group
4│ │ │ │ └─────── owner
5│ │ │ └── others (everyone else): --- nothing
6│ │ └───── group (crew): r-x read, execute
7│ └──────── owner (ada): rwx read, write, execute
8└────────── type: - file, d directory, l symbolic link| Bit | On a file | On a directory |
|---|---|---|
r read | see the contents | list the names inside |
w write | change the contents | create, rename and delete entries |
x execute | run it as a program | enter it with cd and reach things inside |
chmod: symbolic and octal
chmod (change mode) sets the bits. The symbolic form says who (u user/owner, g group, o others, a all), an operator (+ add, - remove, = set exactly) and which bits:
chmod u+x launch.sh- let the owner run itchmod go-w notes.txt- take write away from group and otherschmod a=r manual.txt- everyone may read, nobody may write
The octal form gives each audience one digit, adding r = 4, w = 2, x = 1. So rwx is 7, r-x is 5, r-- is 4, and chmod 755 launch.sh means rwxr-xr-x. You’ll see these all the time:
| Mode | Symbolic | Typical use |
|---|---|---|
755 | rwxr-xr-x | programs and scripts everyone may run |
644 | rw-r--r-- | ordinary files |
700 | rwx------ | private directories |
600 | rw------- | secrets such as SSH keys |
Try it
chmod lab
Flip the switches to give launch.sh each target permission. Watch the octal digits add up (r = 4, w = 2, x = 1) and the ls -l line change.
| Who | Read (4) | Write (2) | Execute (1) | Digit |
|---|---|---|---|---|
| Owner (u) | 0 | |||
| Group (g) | 0 | |||
| Others (o) | 0 |
$ chmod 000 launch.sh
$ ls -l launch.sh
---------- 1 ada crew 512 Oct 2 09:00 launch.sh
Making a script runnable
To run a file as ./name, it needs the execute bit. Without it the shell refuses with Permission denied and exit status 126. (./ means “in this directory” - the shell doesn’t search the current directory for commands, which protects you from running a booby-trapped ls someone left lying around.)
1cd "$(mktemp -d)"
2echo 'echo "Engines online"' > launch.sh
3ls -l launch.sh | cut -d' ' -f1 # just the permission column
4./launch.sh 2>/dev/null || echo "denied!"
5chmod u+x launch.sh
6ls -l launch.sh | cut -d' ' -f1
7./launch.sh
8stat -c '%a %A' launch.sh-rw-r--r-- denied! -rwxr--r-- Engines online 744 -rwxr--r--
A few more permission tools you’ll meet:
chown ada:crew filechanges the owner and group (usually needs administrator rights).sudo commandruns one command as root, the administrator, after checking you’re allowed. Use it for exactly the commands that need it - never as a reflex when something fails.umasksets which bits new files don’t get. The common022is why new files start as644and new directories as755.
Key takeaways
ls -lshows type, then rwx for owner, group and others.Octal digits add r = 4, w = 2, x = 1:
755isrwxr-xr-x,644isrw-r--r--.chmod u+x script.shmakes a script runnable as./script.sh.Grant the least access that works; reach for
sudodeliberately, not by reflex.
Lesson quiz
7 questions · pass with 5 correct · up to 50 XP
Passing this quiz completes the lesson and keeps your streak going. Questions you miss come back in review sessions later.
Practice: write Bash scripts
Write a script in the editor and run it for real against sample input. Each run gets a fresh Linux sandbox with Bash 5.2 and the GNU tools on Wandbox, a free public service - so experiment freely, even with rm. Your script and test input are sent there.
Lock down the files
The starter code creates three files. Set their permissions so the stat line prints:
600 -rw------- airlock.key
644 -rw-r--r-- menu.txt
750 -rwxr-x--- reactor.sh- Permissions are right
Your script runs with Bash 5.2 and GNU tools on Wandbox, a free public service, in a fresh sandbox each time. Your script and test input are sent to that service.
Launch the script
The starter code writes a tiny script, launch.sh, and tries to run it - but it’s refused. Add one command, using chmod’s symbolic form, so that ./launch.sh runs and prints Liftoff!.
- The script runs
Your script runs with Bash 5.2 and GNU tools on Wandbox, a free public service, in a fresh sandbox each time. Your script and test input are sent to that service.
Questions about this lesson
Stuck? Ask. Figured something out? Share it. Explaining is one of the best ways to learn.
Loading posts…