Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsClean PCRecommendedOne scan can reveal what keeps slowing WindowsLook for cleanup and repair opportunities.Run Scan×
Skip to content
ACLs

Linux for Starters: Files and Permissions (Part 10)

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Linux permissions answer three questions for each file or directory: who owns it, which group is associated with it, and what the owner, group members, and everyone else may do. Read the mode with ls -l, change access with chmod, change ownership with chown, and control the defaults for newly created objects with umask. When those three classes are not enough, use access-control lists (ACLs).

How to read a Linux permission listing

A listing such as -rw-r--r-- 1 alice staff 1200 Sep 30 notes.txt starts with a file-type character, followed by three permission triplets:

Part Example Meaning
File type - Regular file. A d indicates a directory; other characters identify such things as symbolic links or devices.
Owner rw- The owning user can read and write, but not execute.
Group r-- Users in the file’s associated group can read only.
Other r-- All other users can read only.

For regular files, r reads contents, w changes contents, and x permits execution. For directories, the letters describe directory operations differently:

  • Read (r) permits listing names in the directory.
  • Write (w) permits creating, deleting, or renaming directory entries, subject to other checks.
  • Execute (x) means search or traversal: entering the directory and accessing an item when its name is known.

Whether an operation succeeds can also depend on the file’s owner and group, ACLs, special bits, process capabilities, filesystem behavior, and mount options. A directory’s write bit alone, for example, does not guarantee that every attempted change will succeed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Changing access with chmod

chmod changes an existing file or directory’s mode bits. Use a symbolic mode for a targeted edit or an octal mode to set the ordinary permissions as a complete pattern.

Symbolic modes: make a focused change

Symbolic modes select classes—u (owner), g (group), o (other), or a (all)—and apply +, -, or = with r, w, and x. For example:

chmod u+x script.sh

This adds execute permission for the owner and leaves the other classes’ existing bits unchanged. A command such as chmod go-w report.txt removes group and other write permission; chmod u=rw,go=r notes.txt assigns an exact pattern for each selected class.

Octal modes: set a known pattern

In each ordinary octal digit, read is 4, write is 2, and execute is 1. Add the values within each class:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Command Result
chmod 644 notes.txt Owner read/write; group read; other read.
chmod 755 mydir Owner read/write/search; group read/search; other read/search.

The familiar three digits represent owner, group, and other. An optional leading digit represents special attributes: set-user-ID, set-group-ID, and the sticky bit. Treat those bits separately from ordinary rwx permissions and verify the result with ls -l. Avoid broad commands such as chmod -R 777; apply the narrowest change to a known path, then check it.

On ordinary Linux filesystems, a command-line symbolic link is generally followed by chmod, so the target is affected rather than a separately changeable set of link permissions. During recursive operations, symlinks encountered in the walk are not followed as ordinary files.

chmod versus chown

These commands solve different problems:

Need Command What changes
Adjust read, write, execute, or special mode bits chmod Access mode, not the owning identity.
Change the owning user, group, or both chown User and/or group ownership.

For example, chown alice:staff notes.txt requests both a user and group change. A form with only a group, such as chown :staff notes.txt, changes only the group. Success depends on privilege: changing a file’s owner requires the CAP_CHOWN capability, while an unprivileged owner has narrower rights to change group ownership. On systems that require it, use the appropriate administrative mechanism rather than assuming that adding sudo is always safe.

What umask does when files are created

umask is a process setting that filters permissions requested at creation time; it does not rewrite the modes of files that already exist. The Linux man-pages project describes it this way in umask(2) (Linux man-pages 6.19, manual dated 2026-02-08): “The umask is used by open(2), mkdir(2), and other system calls that create files to modify the permissions placed on newly created files or directories.”

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A common example is:

umask 022

For an ordinary newly created file requested with mode 0666, that mask normally yields 0644: the owner can read/write and group and other can read. This is a typical example, not a promise that every shell, service, or session uses the same value. Programs may request different modes, and directory creation commonly requests a mode that includes search permission.

Creation defaults are not an alternative to chmod

umask affects future creations in the process context. chmod changes the mode of an existing object. If a file is already too permissive, changing the shell’s umask will not repair it; use a targeted chmod and inspect the result.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When a default ACL changes the rule

A directory can have a default ACL that is inherited by newly created files and subdirectories. In that case, the default ACL—not the umask alone—establishes the inherited permissions; the requested creation mode still limits the resulting permissions. This is why a file created under a managed project directory may not follow the simple “requested mode minus umask” calculation.

ACLs extend the basic owner/group/other model with entries for named users and groups. They also use an ACL mask that limits the effective permissions of named-user, named-group, and owning-group entries. Support and exact behavior depend on the filesystem and system configuration, so verify on the target host.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
getfacl file

Use getfacl to inspect the complete ACL, including inherited information, and setfacl to add or modify ACL entries when the three basic classes cannot express the requirement. Recheck with getfacl after a change.

Special cases that explain surprising results

  • Special bits: set-user-ID, set-group-ID, and sticky attributes add behavior beyond ordinary rwx bits and appear in the mode representation.
  • ACL masks: an ACL entry can name a permission that is reduced by the mask, so the displayed effective access may differ from the entry’s raw value.
  • Capabilities: a process may possess specific privileges that change what it can do without ordinary mode bits granting that access.
  • Filesystem and mount rules: ACL availability, permission enforcement, and options such as read-only mounts vary by environment.

For advanced cases, consult the relevant chmod(1), chown(1), umask(2), and ACL manual pages on the system you are administering.

A safe permission-change workflow

  1. Identify the exact path and inspect it: ls -ld path for a directory or ls -l path for a file.
  2. Check ownership and, when necessary, the full ACL with getfacl path.
  3. Decide whether the problem is access mode (chmod), ownership (chown), or creation policy (umask or a default ACL).
  4. Apply the smallest change, such as chmod u+x script.sh or chmod 644 notes.txt, rather than changing an entire tree indiscriminately.
  5. Inspect again with ls -l or getfacl, then test the intended operation as the affected user or service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read next

Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.