Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

For a basic change, open Files, right-click the item, choose Properties, and open Permissions. For precise, repeatable, or shared access, use chmod, chown, groups, and POSIX ACLs. The labels can vary slightly between Ubuntu 24.04 LTS, Ubuntu 26.04 LTS, GNOME versions, translations, and file systems.

Understand Ubuntu permissions

Linux assigns a file or directory an owner, an owning group, and permissions for everyone else. Each category can have read (r), write (w), and execute/search (x) rights.

Reading an ls -l result

ls -l report.txt
-rw-r----- 1 alice developers 2450 Aug 18 10:30 report.txt

The first character identifies the type: - is a regular file and d is a directory. The next nine characters are three sets: owner, group, then others. In this example, Alice can read and write, members of developers can read, and all other users have no listed rights. GNOME describes the same owner/group/other layout in its Files list view (GNOME help).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Files and directories use rwx differently

Permission Regular file Directory
r Read contents List names
w Modify contents Create, delete, or rename entries, subject to directory rules
x Run the file when it is executable Enter/search the directory and reach items by pathname

Deleting a file is normally controlled by the parent directory, not the file’s own write bit. A directory usually needs x to be usable. Removing search permission from any parent can block access to descendants even when their modes look open. See Ubuntu’s directory-permission guidance.

#1 Best Overall
Sale
Logitech MK270 Full Size Wireless Keyboard and Mouse Combo - Black
  • Reliable Plug and Play: The USB receiver provides a reliable wireless connection up to 33 ft (1), so you can forget about drop-outs and delays and you can take it wherever you use your computer
  • Type in Comfort: The design of this keyboard creates a comfortable typing experience thanks to the low-profile, quiet keys and standard layout with full-size F-keys, number pad, and arrow keys
  • Durable and Resilient: This full-size wireless keyboard features a spill-resistant design (2), durable keys and sturdy tilt legs with adjustable height
  • Long Battery Life: MK270 combo features a 36-month keyboard and 12-month mouse battery life (3), along with on/off switches allowing you to go months without the hassle of changing batteries
  • Easy to Use: This wireless keyboard and mouse combo features 8 multimedia hotkeys for instant access to the Internet, email, play/pause, and volume so you can easily check out your favorite sites

Change permissions in GNOME Files

  1. Open Files and browse to the item.
  2. Right-click it and select Properties.
  3. Open the Permissions tab.
  4. Set the controls for Owner, Group, and Others.
  5. Close the dialog; changes normally apply immediately.

For a document, a typical least-privilege choice is owner Read and write, group Read-only, and others None. Folder controls are directory-specific and may be worded as no access, list/view contents, access files, or create and delete files. GNOME also offers applying selected permissions to folder contents; use that cautiously when a folder mixes documents, subdirectories, scripts, links, or private data (GNOME permission properties).

The dialog does not expose every symbolic mode, special bit, ACL mask, or default ACL. System-owned items may require administrator rights. NTFS, exFAT, SMB, removable, and other mounts may synthesize or ignore Unix ownership and modes. A symbolic link has no independently useful Unix permission set; operations generally concern its target.

Inspect permissions safely in Terminal

ls -l -- "file name"
ls -ld -- "folder name"
stat -- "file name"
namei -l /path/to/file
id
groups
getfacl -- "file name"

ls -ld examines the directory itself rather than its contents. namei -l shows every path component, which is essential when a parent lacks search permission. getfacl reveals named users or groups, the effective-rights mask, and default ACLs that ordinary ls -l hides (getfacl).

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Change modes with chmod

Symbolic syntax

The form is chmod [who][operator][permissions] file. Use u for owner, g for group, o for others, and a for all; operators are + (add), - (remove), and = (set exactly).

Rank #2
Sale
Logitech MK345 Full Size Wireless Keyboard and Mouse Combo - Black
  • Dependable wireless connection: Enjoy the reliability and convenience of 2.4 GHz connectivity with your logitech wireless keyboard and mouse combo, wireless range up to 10 meters away at home, or work.
  • Full-Size Wireless Keyboard: Comfortable, quiet typing on a familiar keyboard layout with palm rest, spill-resistant design, and media keys. This wireless keyboard and mouse logitech has easy-access to media keys
  • Plug and Play: MK345 works seamlessly with Windows, macOS, and ChromeOS. Experience hassle-free setup with the logitech mk345 wireless combo and wireless keyboard mouse combo for various operating systems.
  • Long-lasting Battery: The MK345 combo offers a full size keyboard battery life of up to 3 years and a mouse battery life of 18 months (1); batteries included
  • Comfortable Right-handed Mouse: This wireless USB mouse with dongle works well for this wireless mouse and keyboard combo, featuring a contoured shape for all-day comfort and smooth, precise tracking and scrolling for easier navigation.
chmod u+x script.sh
chmod g+r report.txt
chmod o-r private.txt
chmod u=rw,go= file.txt
chmod a+r public.txt
chmod u+rw,go-rwx private.txt
chmod u+rwx project/
chmod g+rx project/
chmod o-rwx project/

For recursive work, X adds execute/search only to directories and files that already have an execute bit:

chmod -R a+rX shared-folder/

This is safer than recursively adding +x to every document. GNU’s chmod manual also documents special bits and symbolic-link behavior.

Numeric modes

Permission Value
Read 4
Write 2
Execute/search 1

Add values for owner, group, and others:

chmod 644 document.txt
chmod 600 private-key
chmod 755 script.sh
chmod 700 private-folder
chmod 750 shared-project
chmod 770 team-folder
Mode Common result
644 Owner reads/writes; group and others read
600 Owner reads/writes; no group or other access
755 Owner full access; group and others read/execute
700 Owner full access only
750 Owner full; group read/execute; others none
770 Owner and group full; others none

These are conventions, not universal answers. GNU chmod accepts one to four octal digits; an optional leading digit controls special bits.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Change ownership and group access

chmod changes what existing owner/group/other categories may do. chown changes the owner, and chgrp changes the owning group; neither automatically grants access to everyone.

Rank #3
Sale
Wireless Keyboard and Mouse Combo, Full Size Silent Ergonomic Keyboard and Mouse, Long Battery Life, Optical Mouse, 2.4G Lag-Free Cordless Mice Keyboard for Computer, Mac, Laptop, PC, Windows
  • 【Ergonomic Wireless Keyboard Mouse 】: Wireless ergonomic keyboard is equipped with adjustable height tilt legs to increase comfort and prevent your wrists injury when typing for a long time. The full size wireless keyboard with numeric keypad and 12 multimedia shortcut keys, such as play/ pause, volume increase and decrease, and email, to help you improve work efficiency
  • 【Stable & Reliable Wireless Connection】: This wireless keyboard and mouse combo share the same USB receiver(stored in the mouse), and they can also be used separately. Plug & play, no need to download any software, 2.4 GHz wireless provides a powerful and reliable connection up to 33 feet(10m) without any delays.You can enjoy the convenience and freedom of wireless connection at home or at work
  • 【Comfortable Optical Mouse】: This compact lightweight wireless mouse features a hand-friendly contoured shape for all-day comfort, and smooth, precise tracking.1600 DPI to meet your daily needs. Perfect for home & office work and entertainment
  • 【Long Battery Life】: Up to 365 Days of battery life for keyboard and mouse wireless, say goodbye to the hassle of charging cables and replacing batteries. After 10 minutes of inactivity, the wireless keyboard mouse combo will automatically go into sleep mode to save energy. The wireless keyboard requires one AAA battery, and the wireless mouse requires one AA battery.
  • 【Less Noise, More Quiet Keys】: Soft membrane keys provide a quiet and comfortable typing experience, So you can type with confidence on a wireless keyboard crafted for comfort, precision and fluidity. The wireless mouse adopts silent micro-motion technology, which is almost completely silent when clicked. No more concerns about disturbing others.
ls -l -- file.txt
sudo chown alice -- file.txt
sudo chown alice:developers -- file.txt
sudo chgrp developers -- file.txt

Use chown and chgrp recursively only for a specifically understood tree:

sudo chown -R alice:developers -- project/

Never casually run recursive ownership changes on /, /usr, /etc, /var, /bin, /lib, or an entire home directory. They can break services, package management, SSH keys, and desktop applications. Prefer a single known-bad path or:

sudo chown --reference=/path/to/correct-file -- /path/to/problem-file

Share with a group

groups
id username
sudo usermod -aG developers username
newgrp developers

The user normally must log out and back in before all sessions see supplementary-group changes. A team directory can use setgid inheritance:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo mkdir -p /srv/project
sudo chown root:developers /srv/project
sudo chmod 2770 /srv/project

The leading 2 makes new items typically inherit the directory’s group. The whole parent path must also be searchable by intended users.

Rank #4
Logitech MK335 Full Size Quiet Wireless Keyboard Mouse Combo - Black/Silver
  • The keyboard's sleek and stylish design features low-profile, whisper-quiet keys that provide a comfortable typing experience, suitable for those seeking a Logitech wireless keyboard and mouse combo or quiet keyboard enthusiasts
  • Logitech advanced 2.4 GHz wireless connectivity gives you the reliability of a cord plus wireless convenience; suitable for a keyboard and mouse wireless setup with fast data transmission, virtually no delays or dropouts, and wireless encryption
  • The ambidextrous portable mouse with plug-and-forget nano-receiver storage integrates seamlessly into any wireless keyboard mouse combo, letting you stay connected as you roam around your home, in the office, and all points in between
  • You can go up to 24 months for the keyboard and up to 12 months for the mouse without the hassle of changing batteries. The wireless mouse and keyboard combo puts power management in your hands. Battery life varies with use and conditions
  • Want to play your favorite movie, skip a boring song, or jump to Taobao? It's all at your fingertips with the logitech keyboard wireless and 11 hot keys plus 4 programmable F-keys for instant multimedia access

Apply recursive changes without breaking a tree

chmod -R 755 folder/ gives execute permission to ordinary documents, images, and archives. chmod -R 777 makes everything broadly writable and is rarely appropriate. Prefer a stated policy and separate file types:

find folder/ -type d -exec chmod 755 {} +
find folder/ -type f -exec chmod 644 {} +

find private/ -type d -exec chmod 700 {} +
find private/ -type f -exec chmod 600 {} +

find project/ -type d -exec chmod 755 {} +
find project/ -type f -exec chmod 644 {} +
find project/ -type f -perm /111 -exec chmod a+x {} +

Check the path first, back up important data, and account for links, special files, and mixed-content trees. Do not use broad recursive commands on system paths.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Use ACLs for per-user exceptions

Standard permissions cannot express, for example, “Alice read/write, Bob read-only, everyone else none.” POSIX ACLs can, where the file system and mount support them.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
sudo apt update
sudo apt install acl
getfacl -- project/
setfacl -m u:bob:rw -- report.txt
setfacl -m u:bob:rwx -- shared-folder/
setfacl -m g:designers:rwx -- shared-folder/
setfacl -x u:bob -- report.txt
setfacl -d -m u::rwx,g::rwx,o::---,m::rwx -- shared-folder/
getfacl -- shared-folder/

A directory default ACL is inherited by newly created items; regular files cannot have default ACLs. The ACL mask:: limits effective rights for the owning group and named users/groups, but not the file owner or other entry. setfacl recalculates the mask by default; setfacl -R is deliberately recursive. See setfacl and ACL concepts.

Best Value
Logitech MK540 Full Size Advanced Wireless Keyboard and Mouse Combo
  • Precision Typing: An instantly familiar experience, type with ease and comfort on this full-size wireless keyboard, featuring reduced noise, palm rest, spill-resistant design (1), adjustable tilt legs
  • Built For Comfort: The sleek combo's wireless mouse features an ambidextrous shape and soft rubber side grips that fit comfortably in your palm, as well as enhanced tracking and precise cursor control
  • Long-Lasting Autonomy: The wireless keyboard and mouse set come with long-lasting battery life, with the keyboard lasting up to 36 months and the wireless mouse for up to 18 months (3)
  • Customized Control: Enhanced productivity at your fingertips, the computer keyboard comes built with convenient, essential hotkeys providing direct access to media, calculator, battery check functions
  • Wireless Freedom: Plug-and-play your keyboard and mouse with the mini Logitech Unifying USB receiver, for a reliable wireless connection up to 33 ft away from your PC or laptop (2)

Understand umask

umask
umask -S

umask removes permissions from newly created items; it does not directly alter existing files. With umask 022, files commonly start as 644 (from a maximum of 666) and directories as 755 (from 777). Applications can request different initial modes, and ACLs or file-system behavior can change the result (umask manual).

Fix “Permission denied” methodically

  1. Inspect the path and item: ls -ld -- /path/to and ls -l -- /path/to/file.
  2. Trace every parent: namei -l /path/to/file.
  3. Confirm the account and groups: id username.
  4. Check extended rules: getfacl -- /path/to/file.
  5. Check whether the mount is read-only or uses server-side permissions when local modes look correct.
  • Cannot open: check file read permission, parent search permission, ACLs, ownership, and mount policy.
  • Cannot save: check file write permission and parent directory write/search permission.
  • Cannot enter: restore search permission on the folder and every required ancestor.
  • Can list but not open: directory read without search, or file-level restrictions.
  • sudo works temporarily: ownership or location may be wrong; routine root use can create root-owned files.

For a folder made inaccessible by its mode, restore the appropriate owner access:

chmod u+rwx -- folder/

If ownership is wrong:

sudo chown "$USER":"$(id -gn)" -- folder/

Do not routinely run graphical editors as root. To find root-owned items in your home, inspect first:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
find "$HOME" -user root -print

Repair only known mistakes:

sudo chown "$USER":"$(id -gn)" -- "$HOME/path/to/file"

Special bits and practical limits

The setuid bit (4xxx) changes an executable’s effective user identity; setgid (2xxx) affects executable group identity and directory group inheritance; the sticky bit (1xxx) restricts deletion or renaming in a directory to the entry owner, directory owner, or a privileged user.

chmod 2770 shared-folder/
chmod 1777 temporary-folder/

Set these only for a specific, understood purpose. Root and equivalent capabilities can bypass many ordinary discretionary checks, and Unix mode bits are only one layer of access control.

Quick reference

Need Command or method
Basic desktop change Files → Properties → Permissions
Inspect mode and owner ls -l, stat
Trace parent access namei -l
Change permissions chmod
Change owner/group chown, chgrp
Team sharing Group ownership plus group modes
One-user exception setfacl
Creation defaults umask or a directory default ACL

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.