DEV Community

Cover image for Linux File Permissions: Understanding chmod and chown
Yeasin's
Yeasin's

Posted on AI-assisted

Linux File Permissions: Understanding chmod and chown

If you have ever seen the error "Permission denied" on a Linux system, you have already met file permissions. Every file and directory on a Linux system has an owner, a group, and a set of permissions that decide exactly who can read, write, or execute it.

Understanding chmod and chown is one of the most practical skills for any Linux user, developer, or system administrator. In this article, we will break it down step by step.


How Linux Views File Permissions

Run this command on any file:

ls -l file.txt
Enter fullscreen mode Exit fullscreen mode

You will see something like this:

-rw-r--r-- 1 deploy deploy 2048 Oct  8 10:24 file.txt
Enter fullscreen mode Exit fullscreen mode

The first part (-rw-r--r--) is the permission string. Let's decode it:

Position Meaning
1st character File type (- = file, d = directory, l = symlink)
Characters 2–4 Permissions for the owner (rw-)
Characters 5–7 Permissions for the group (r--)
Characters 8–10 Permissions for others (r--)

Each permission has a meaning:

  • r (read) — view the file contents (or list a directory)
  • w (write) — modify the file (or create/delete files inside a directory)
  • x (execute) — run the file as a program (or enter a directory)

Note: For directories, x means "can enter". Without it, you cannot cd into the directory, even if you can read it.


chown: Changing Ownership

The chown command changes who owns a file.

Basic syntax:

chown owner\:group file
Enter fullscreen mode Exit fullscreen mode

Practical examples:

# Change the owner to "deploy"
sudo chown deploy file.txt

# Change both owner and group
sudo chown deploy\:deploy file.txt

# Recursively change ownership of a whole directory
sudo chown -R deploy\:deploy /var/www/app
Enter fullscreen mode Exit fullscreen mode

Warning: chown usually requires sudo. Be careful with -R — it changes everything inside the directory, including files you may not expect. A wrong recursive chown on a system directory can break your system.


chmod: Changing Permissions

While chown decides who, chmod decides what they can do.

There are two ways to use chmod:

1. Symbolic Mode (letters)

chmod u+x script.sh
Enter fullscreen mode Exit fullscreen mode
  • u = owner (user), g = group, o = others, a = all
  • + adds a permission, - removes it, = sets it exactly

Examples:

chmod u+x script.sh       # Owner can execute
chmod g-w file.txt        # Remove write from group
chmod a=r file.txt        # Everyone can only read
chmod u=rwx,g=rx,o= file.txt  # Full control for owner, read+execute for group, nothing for others
Enter fullscreen mode Exit fullscreen mode

2. Numeric (Octal) Mode

Each permission has a value:

  • r = 4
  • w = 2
  • x = 1

You add them up for each category (owner, group, others):

Number Permission
7 rwx (4+2+1)
6 rw- (4+2)
5 r-x (4+1)
4 r--
0 ---

So:

chmod 755 script.sh
Enter fullscreen mode Exit fullscreen mode

means:

  • Owner: 7 → read, write, execute
  • Group: 5 → read, execute
  • Others: 5 → read, execute

Common real-world values:

chmod 644 file.txt      # Normal file: owner reads/writes, everyone else reads
chmod 755 script.sh     # Executable script or open directory
chmod 600 ~/.ssh/id_ed25519   # Private SSH key: only owner can read/write
chmod 700 ~/.ssh        # SSH directory: only owner has full access
Enter fullscreen mode Exit fullscreen mode

Tip: The 600 permission on SSH private keys is not optional. ssh will refuse to use a private key that others can read.


A Real-World Scenario

Imagine you deploy a web app on an Ubuntu server:

sudo chown -R www-data\:www-data /var/www/app
sudo chmod -R 755 /var/www/app
Enter fullscreen mode Exit fullscreen mode
  • www-data is the user the web server runs as on Debian/Ubuntu.
  • 755 lets the web server read and use the files, while other users can read but not modify them.
  • Secrets like .env should be locked down further:
sudo chmod 640 /var/www/app/.env
Enter fullscreen mode Exit fullscreen mode

This is the everyday reality of permissions: give the minimum access needed, and nothing more.


Common Mistakes and Troubleshooting

  1. chmod 777 as a "fix" — It makes the file writable by everyone. It often "works", but it is a security hole. Almost always, the correct answer is proper ownership, not 777.
  2. Forgetting -R on directories — chmod 644 mydir changes the directory itself, not its contents.
  3. Removing x from a directory — You lose the ability to enter it, even as the owner.
  4. Ownership vs permission confusion — If you own a file, you can change its permissions even without write access to the file itself.

Quick diagnostic habit:

ls -l file.txt        # Who owns it? What are the permissions?
id                    # What groups am I in?
namei -l /var/www/app/index.html   # Check permissions on every level of the path
Enter fullscreen mode Exit fullscreen mode

The namei -l trick is underrated — "Permission denied" can come from any parent directory in the path, not just the file itself.


Summary

  • Every file has an owner, a group, and others, each with r, w, and x permissions.
  • chown changes who owns a file; chmod changes what they can do.
  • Symbolic mode (u+x) is readable; numeric mode (755) is compact and fast.
  • Follow the principle of least privilege: give the minimum permission required.
  • Avoid chmod 777. Diagnose with ls -l, id, and namei -l instead.

Once this clicks, "Permission denied" stops being a mystery and becomes a simple question: who owns this file, and what are they allowed to do?

Top comments (1)

Collapse
 
nikkhielseath profile image
Nikkhiel Seath •

For all the readers, do follow the principle of least privilege, whenever you can. Especially when people got agents running around! :)