Read

Module 5 · Users, groups and permissions

chmod with symbolic modes

Change permissions by saying who gets what: u, g, o and a, plus, minus and equals, and the letters r, w and x.

What you will learn

  • Build a symbolic mode from who (`ugoa`), operator (`+-=`) and permissions (`rwx`).
  • Combine several changes in one `chmod` with commas.
  • Apply changes recursively and verify them with `ls -l`.

Say it in words

chmod (*change mode*) edits the nine permission bits you learned to read. It has two dialects. The symbolic one, this lesson, reads like a sentence: *who* +/-/= *what*. The octal one, next lesson, states the whole mode as a number. Symbolic modes shine when you want to change one thing and leave the rest alone: "make it executable for me", "take away everybody else's read access".

PartLettersMeaning
Whou g o auser (owner), group, others, all three. Nothing given = a
Operator+ - =add, remove, set exactly (clearing the rest)
Whatr w x (s t)read, write, execute (special bits, lesson 50)
~% cd /root/lab/l46
l46% ls -l
-rw-r--r--    1 root     root             0 Oct  4 19:10 run.sh
-rw-r--r--    1 root     root             0 Oct  4 19:10 secret.txt
-rw-r--r--    1 root     root             0 Oct  4 19:10 shared.txt
l46% chmod u+x run.sh
l46% chmod go-r secret.txt
l46% chmod g+w,o-r shared.txt
l46% ls -l
-rwxr--r--    1 root     root             0 Oct  4 19:10 run.sh
-rw-------    1 root     root             0 Oct  4 19:10 secret.txt
-rw-rw----    1 root     root             0 Oct  4 19:10 shared.txt

Read each one aloud. u+x: *user, add execute*. go-r: *group and others, remove read*; several who-letters may be stacked. g+w,o-r: two independent changes separated by a comma, no spaces. The equals sign is the blunt tool: chmod o= file sets the others triplet to exactly nothing, whatever it was, and chmod u=rw,go=r file fixes all nine bits in one go, which is the symbolic way to spell what octal 644 means.

The classic: +x

chmod +x script.sh is the single most typed chmod. With no who-letter it means a, so everybody gains execute, except that bits masked by your umask (lesson 49) are skipped; with the default umask of 022 that changes nothing here. It is how a text file with a #!/bin/sh first line becomes a program you can run as ./script.sh (module 9). The reverse, chmod -x, is a quick way to disable a script without deleting it.

Recursion and feedback

-R applies the change to a directory and everything below it. -c reports each file that actually changed and -v reports every file, which is how you check a big recursive change did what you meant. -f hides errors. The usage line, chmod [-Rcvf] MODE[,MODE]... FILE..., is all chmod --help has to say, and it is enough.

Commands in this lesson

CommandWhat it does
chmod u+x FILEOwner gains execute.
chmod go-r FILEGroup and others lose read.
chmod g+w,o-r FILETwo changes in one command.
chmod o= FILEOthers get nothing at all.
chmod u=rw,go=r FILESet all nine bits explicitly (= 644).
chmod +x script.shMake a script runnable for everyone.
chmod -R -c g+w DIRRecursive, reporting what changed.

Quiz

  1. What does `chmod go-w file` do?

    • Gives group and others write access
    • Removes write access from group and others
    • Removes write access from the owner
  2. Starting from `-rw-rw-rw-`, what does `chmod o= file` produce?

    • `-rw-rw----`
    • `-rw-rw-r--`
    • `----------`
  3. How do you apply two different changes in one chmod?

    • Separate them with a comma: `u+x,o-r`
    • Separate them with a space: `u+x o-r`
    • You cannot; run chmod twice
  4. Who may change a file's permissions?

    • Anyone with `w` on the file
    • Only its owner and root
    • Members of its group

Practice

  1. Make `/root/lab/l46/run.sh` executable for its owner only, changing nothing else (it should end up `-rwxr--r--`).

  2. Make `/root/lab/l46/secret.txt` readable and writable by its owner only: nobody else should have any permission (`-rw-------`).

  3. In one `chmod`, give the group write access to `/root/lab/l46/shared.txt` and take read access away from others (`-rw-rw----`).

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.