File Permissions
- In Turkish
- Dosya İzinleri
In short
File permissions are rules stored with each file that decide which users may read it, change it, or run it, enforced by the operating system on every access.
What are file permissions?
File permissions are the operating system's way of controlling who can do what with each file and directory. On Unix-like systems every file has an owning user, an owning group, and three sets of permissions: one for the owner, one for members of the group, and one for everyone else. Each set can allow reading (r), writing (w), and executing (x).
Running ls -l shows permissions as a string such as -rwxr-xr--: the first character is the file type, followed by the owner, group, and others triplets. The same permissions can be written in octal, where read is 4, write is 2, and execute is 1, so 754 means the owner can do everything, the group can read and execute, and others can only read. On directories the letters mean something slightly different: read lists the names, write allows creating, deleting, and renaming entries, and execute allows entering the directory. You change permissions with chmod and ownership with chown, and the kernel checks them every time a program opens a file.
Permissions are like keys in an office building: the owner has a key to their own office, the team shares a key to the project room, and visitors can only look through the window. They matter in daily work: SSH refuses to use a private key that other users can read, a script needs the execute bit before you can run it, and a web server should not be able to overwrite its own code. Windows and many Linux systems also support access control lists (ACLs), which allow more fine-grained rules for specific users.
File permissions are sometimes confused with authorization inside applications, such as role-based access control. File permissions are enforced by the operating system kernel for files and directories, while application authorization decides what a logged-in user may do inside that app. A common mistake is running chmod 777 to fix an access error, which lets every user modify the file; following the principle of least privilege and granting only what is needed is much safer.
Key takeaways
- Each file has an owner, a group, and permissions for owner, group, and others.
- The basic permissions are read, write, and execute.
- Octal notation adds read (4), write (2), and execute (1), as in
755or600. chmodchanges permissions andchownchanges ownership.- Avoid
chmod 777; grant the least access that works.
Example
# Type, then owner (rwx), group (r-x), and others (r--)
ls -l deploy.sh
# -rwxr-xr-- 1 ada devs 512 Sep 30 10:00 deploy.sh
# Make a script executable for its owner
chmod u+x deploy.sh
# Owner can read and write; nobody else has access (needed for SSH keys)
chmod 600 ~/.ssh/id_ed25519
# Change the owner and the group
sudo chown ada:devs deploy.shReaders ask
What does chmod 755 mean?
It gives the owner read, write, and execute permission (7), and gives the group and everyone else read and execute permission (5). It is a common setting for scripts and directories that others may use but not change.
Why is chmod 777 dangerous?
It gives every user on the system permission to read, modify, and run the file. Any compromised account or process could then change it, for example to insert malicious code.
What is the difference between Unix permissions and ACLs?
Classic Unix permissions allow rules for just three groups: owner, group, and others. Access control lists add entries for any number of specific users and groups, which is how Windows manages file access and an option on most Linux file systems.
See also
- File SystemOperating Systems, p. 12A file system is the part of an operating system that organizes data on a storage device into files and folders and tracks where each piece is stored.
- User SpaceOperating Systems, p. 36User space is the restricted area where ordinary programs run, kept separate from kernel space so a buggy or malicious app cannot take down the whole system.
- AuthorizationSecurity, p. 3Authorization is the process of deciding what an authenticated user or service is allowed to do, such as which data it can read, change, or delete.
- Principle of Least PrivilegeSecurity, p. 28The principle of least privilege is a security rule that every user, program, and service gets only the minimum access it needs to do its job, and no more.
- ShellOperating Systems, p. 27A shell is a program that reads commands typed by a user or written in a script and asks the operating system to run them, usually through a text interface.
- LinuxDevOps & Cloud, p. 33Linux is an open-source operating system kernel that powers most servers, cloud platforms, containers, and Android phones, usually packaged as a distribution.
- sudoOperating Systems, p. 29sudo lets a permitted user run a single command with root's or another user's privileges, after confirming their own password, and logs what was run.
Spotted a mistake or something missing on this page?Suggest an edit