Begin Linux

Users, groups and permissions, explained with real examples

Permissions are the first thing that stops a beginner and the first thing an employer checks you understand.

Reading ls -l

-rw-r----- 1 www-data adm  4096 Oct  5 09:12 access.log
drwxr-x--- 2 alice    dev  4096 Oct  5 09:12 project/

Column one has ten characters: the type (- file, d directory, l link) and three groups of rwx for owner, group and others. access.log can be read and written by www-data, read by members of adm, and not touched by anyone else.

What rwx means on a directory

Changing permissions

chmod u+x deploy.sh          # owner may execute
chmod g-w shared.conf        # group loses write
chmod 640 secrets.env        # owner rw, group r, others nothing
chown alice:dev project/     # owner alice, group dev
chmod -R g+rX project/       # recursive; capital X adds x only to dirs and already-executable files

The numeric form adds r=4, w=2, x=1: 750 is rwxr-x---.

Groups are the tool for collaboration

sudo groupadd dev
sudo usermod -aG dev alice     # -a appends; without it you replace all her groups
sudo chgrp -R dev /srv/project
sudo chmod -R 2775 /srv/project   # 2 = setgid: new files inherit the dev group

Why chmod 777 is the wrong fix

It makes a permission error disappear by letting every account on the machine modify the file, including a compromised web process. The right fix is to find out which user needs access and give that user or group exactly that.

sudo, not root

Log in as a normal user and use sudo for the individual commands that need it. Every elevated command is logged with your username, which is what an auditor, and your future self, will want to see.

Exercise: create users anna and ben and a group reports. Make /srv/reports writable by both via the group, with new files automatically owned by the group, and confirm a third user cannot read it.