Module 5 · Users, groups and permissions
chmod with symbolic modes
Change permissions by saying who gets what: u, g, o and a, plus, minus and equals, and the letters r, w and x.
What you will learn
- Build a symbolic mode from who (`ugoa`), operator (`+-=`) and permissions (`rwx`).
- Combine several changes in one `chmod` with commas.
- Apply changes recursively and verify them with `ls -l`.
Say it in words
chmod (*change mode*) edits the nine permission bits you learned to read. It has two dialects. The symbolic one, this lesson, reads like a sentence: *who* +/-/= *what*. The octal one, next lesson, states the whole mode as a number. Symbolic modes shine when you want to change one thing and leave the rest alone: "make it executable for me", "take away everybody else's read access".
| Part | Letters | Meaning |
|---|---|---|
| Who | u g o a | user (owner), group, others, all three. Nothing given = a |
| Operator | + - = | add, remove, set exactly (clearing the rest) |
| What | r w x (s t) | read, write, execute (special bits, lesson 50) |
~% cd /root/lab/l46
l46% ls -l
-rw-r--r-- 1 root root 0 Oct 4 19:10 run.sh
-rw-r--r-- 1 root root 0 Oct 4 19:10 secret.txt
-rw-r--r-- 1 root root 0 Oct 4 19:10 shared.txt
l46% chmod u+x run.sh
l46% chmod go-r secret.txt
l46% chmod g+w,o-r shared.txt
l46% ls -l
-rwxr--r-- 1 root root 0 Oct 4 19:10 run.sh
-rw------- 1 root root 0 Oct 4 19:10 secret.txt
-rw-rw---- 1 root root 0 Oct 4 19:10 shared.txt
Read each one aloud. u+x: *user, add execute*. go-r: *group and others, remove read*; several who-letters may be stacked. g+w,o-r: two independent changes separated by a comma, no spaces. The equals sign is the blunt tool: chmod o= file sets the others triplet to exactly nothing, whatever it was, and chmod u=rw,go=r file fixes all nine bits in one go, which is the symbolic way to spell what octal 644 means.
The classic: +x
chmod +x script.sh is the single most typed chmod. With no who-letter it means a, so everybody gains execute, except that bits masked by your umask (lesson 49) are skipped; with the default umask of 022 that changes nothing here. It is how a text file with a #!/bin/sh first line becomes a program you can run as ./script.sh (module 9). The reverse, chmod -x, is a quick way to disable a script without deleting it.
Recursion and feedback
-R applies the change to a directory and everything below it. -c reports each file that actually changed and -v reports every file, which is how you check a big recursive change did what you meant. -f hides errors. The usage line, chmod [-Rcvf] MODE[,MODE]... FILE..., is all chmod --help has to say, and it is enough.
Commands in this lesson
| Command | What it does |
|---|---|
chmod u+x FILE | Owner gains execute. |
chmod go-r FILE | Group and others lose read. |
chmod g+w,o-r FILE | Two changes in one command. |
chmod o= FILE | Others get nothing at all. |
chmod u=rw,go=r FILE | Set all nine bits explicitly (= 644). |
chmod +x script.sh | Make a script runnable for everyone. |
chmod -R -c g+w DIR | Recursive, reporting what changed. |
Quiz
What does `chmod go-w file` do?
- Gives group and others write access
- Removes write access from group and others
- Removes write access from the owner
Starting from `-rw-rw-rw-`, what does `chmod o= file` produce?
- `-rw-rw----`
- `-rw-rw-r--`
- `----------`
How do you apply two different changes in one chmod?
- Separate them with a comma: `u+x,o-r`
- Separate them with a space: `u+x o-r`
- You cannot; run chmod twice
Who may change a file's permissions?
- Anyone with `w` on the file
- Only its owner and root
- Members of its group
Practice
Make `/root/lab/l46/run.sh` executable for its owner only, changing nothing else (it should end up `-rwxr--r--`).
Make `/root/lab/l46/secret.txt` readable and writable by its owner only: nobody else should have any permission (`-rw-------`).
In one `chmod`, give the group write access to `/root/lab/l46/shared.txt` and take read access away from others (`-rw-rw----`).
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.