If you have ever seen the error "Permission denied" on a Linux system, you have already met file permissions. Every file and directory on a Linux system has an owner, a group, and a set of permissions that decide exactly who can read, write, or execute it.
Understanding chmod and chown is one of the most practical skills for any Linux user, developer, or system administrator. In this article, we will break it down step by step.
How Linux Views File Permissions
Run this command on any file:
ls -l file.txt
You will see something like this:
-rw-r--r-- 1 deploy deploy 2048 Oct 8 10:24 file.txt
The first part (-rw-r--r--) is the permission string. Let's decode it:
| Position | Meaning |
|---|---|
| 1st character | File type (- = file, d = directory, l = symlink) |
| Characters 2–4 | Permissions for the owner (rw-) |
| Characters 5–7 | Permissions for the group (r--) |
| Characters 8–10 | Permissions for others (r--) |
Each permission has a meaning:
- r (read) — view the file contents (or list a directory)
- w (write) — modify the file (or create/delete files inside a directory)
- x (execute) — run the file as a program (or enter a directory)
Note: For directories,
xmeans "can enter". Without it, you cannotcdinto the directory, even if you can read it.
chown: Changing Ownership
The chown command changes who owns a file.
Basic syntax:
chown owner\:group file
Practical examples:
# Change the owner to "deploy"
sudo chown deploy file.txt
# Change both owner and group
sudo chown deploy\:deploy file.txt
# Recursively change ownership of a whole directory
sudo chown -R deploy\:deploy /var/www/app
Warning:
chownusually requiressudo. Be careful with-R— it changes everything inside the directory, including files you may not expect. A wrong recursivechownon a system directory can break your system.
chmod: Changing Permissions
While chown decides who, chmod decides what they can do.
There are two ways to use chmod:
1. Symbolic Mode (letters)
chmod u+x script.sh
-
u= owner (user),g= group,o= others,a= all -
+adds a permission,-removes it,=sets it exactly
Examples:
chmod u+x script.sh # Owner can execute
chmod g-w file.txt # Remove write from group
chmod a=r file.txt # Everyone can only read
chmod u=rwx,g=rx,o= file.txt # Full control for owner, read+execute for group, nothing for others
2. Numeric (Octal) Mode
Each permission has a value:
-
r= 4 -
w= 2 -
x= 1
You add them up for each category (owner, group, others):
| Number | Permission |
|---|---|
| 7 | rwx (4+2+1) |
| 6 | rw- (4+2) |
| 5 | r-x (4+1) |
| 4 | r-- |
| 0 | --- |
So:
chmod 755 script.sh
means:
- Owner: 7 → read, write, execute
- Group: 5 → read, execute
- Others: 5 → read, execute
Common real-world values:
chmod 644 file.txt # Normal file: owner reads/writes, everyone else reads
chmod 755 script.sh # Executable script or open directory
chmod 600 ~/.ssh/id_ed25519 # Private SSH key: only owner can read/write
chmod 700 ~/.ssh # SSH directory: only owner has full access
Tip: The
600permission on SSH private keys is not optional.sshwill refuse to use a private key that others can read.
A Real-World Scenario
Imagine you deploy a web app on an Ubuntu server:
sudo chown -R www-data\:www-data /var/www/app
sudo chmod -R 755 /var/www/app
-
www-datais the user the web server runs as on Debian/Ubuntu. -
755lets the web server read and use the files, while other users can read but not modify them. - Secrets like
.envshould be locked down further:
sudo chmod 640 /var/www/app/.env
This is the everyday reality of permissions: give the minimum access needed, and nothing more.
Common Mistakes and Troubleshooting
-
chmod 777as a "fix" — It makes the file writable by everyone. It often "works", but it is a security hole. Almost always, the correct answer is proper ownership, not 777. -
Forgetting
-Ron directories —chmod 644 mydirchanges the directory itself, not its contents. -
Removing
xfrom a directory — You lose the ability to enter it, even as the owner. - Ownership vs permission confusion — If you own a file, you can change its permissions even without write access to the file itself.
Quick diagnostic habit:
ls -l file.txt # Who owns it? What are the permissions?
id # What groups am I in?
namei -l /var/www/app/index.html # Check permissions on every level of the path
The namei -l trick is underrated — "Permission denied" can come from any parent directory in the path, not just the file itself.
Summary
- Every file has an owner, a group, and others, each with
r,w, andxpermissions. -
chownchanges who owns a file;chmodchanges what they can do. - Symbolic mode (
u+x) is readable; numeric mode (755) is compact and fast. - Follow the principle of least privilege: give the minimum permission required.
- Avoid
chmod 777. Diagnose withls -l,id, andnamei -linstead.
Once this clicks, "Permission denied" stops being a mystery and becomes a simple question: who owns this file, and what are they allowed to do?
Top comments (1)
For all the readers, do follow the principle of least privilege, whenever you can. Especially when people got agents running around! :)