Module 5 · Users, groups and permissions
Directory permissions and special bits
What r, w and x really do on a directory, and the three extra bits, setuid, setgid and sticky, that explain /tmp, shared folders and why busybox is -rwsr-xr-x.
What you will learn
- Predict what a user can do in a directory from its rwx bits.
- Recognise `s`, `S`, `t` and `T` in a mode string and say what they mean.
- Set the sticky and setgid bits on directories with symbolic and octal chmod.
Directories are lists of names
A directory is a file whose contents are pairs of *name → inode number*. Once you hold that picture, its permission bits stop being mysterious. r lets you read the list, so ls works. x lets you *use* an entry: pass through the directory to reach something inside by name, cd into it, open dir/file. w lets you change the list: create, delete and rename entries, and it only counts together with x, because you must reach the entry to modify it.
| Directory mode | `ls dir` | `cat dir/known-file` | `touch dir/new`, `rm dir/file` |
|---|---|---|---|
r-x | yes | yes | no |
--x | no | yes, if you know the name | no |
r-- | names only, no details | no | no |
rwx | yes | yes | yes, any file, whoever owns it |
The last row is the one that bites: with w on a directory you can delete *anyone's* file in it, because deletion is a change to the list, not to the file. That is what the sticky bit fixes.
The three special bits
| Bit | Octal | Shown as | On a program | On a directory |
|---|---|---|---|---|
| setuid | 4000 | s in the owner's x slot | Runs with the *owner's* UID, not the caller's | Ignored on Linux |
| setgid | 2000 | s in the group's x slot | Runs with the file's group | New files inherit the directory's group |
| sticky | 1000 | t in the others' x slot | Nothing today | Only a file's owner (or root) may delete or rename it |
~% ls -ld /tmp /bin/busybox
-rwsr-xr-x 1 root root 592196 Jul 21 2018 /bin/busybox
drwxrwxrwt 2 root root 60 Oct 4 18:51 /tmp
~% cd /root/lab/l50
l50% chmod +t dropbox; chmod g+s team
l50% ls -ld dropbox team
drwxrwxrwt 2 root root 0 Oct 4 19:30 dropbox
drwxrwsr-x 2 root root 0 Oct 4 19:30 team
l50% chmod 1777 dropbox; chmod 2775 team # the same, in octal
/tmp is the textbook sticky directory: drwxrwxrwt, everyone may create files, nobody may remove anyone else's. /bin/busybox is setuid root in this image so that applets like passwd and su, which need to edit /etc/shadow or change identity, work for ordinary users; when alice runs passwd the process briefly has UID 0. That is powerful and dangerous, which is why chown strips these bits and why find / -perm -4000 is a standard security audit (lesson 36).
A setgid directory is the practical one for teams: make team belong to group devs, set g+s, and every file anyone creates inside gets group devs automatically instead of the creator's private group, so the 664/775 modes from the umask lesson actually let colleagues edit each other's work. Symbolically the bits are s (for u or g) and t; in octal they are the fourth, leading digit: chmod 1777, chmod 2775, chmod 4755.
Commands in this lesson
| Command | What it does |
|---|---|
ls -ld DIR | See a directory's own bits, including s and t. |
chmod +t DIR | Sticky: only owners may delete their files. |
chmod 1777 DIR | World-writable sticky directory, like /tmp. |
chmod g+s DIR | Setgid: new files inherit the directory's group. |
chmod 2775 DIR | Setgid team directory, group-writable. |
chmod o= DIR | Keep others out entirely. |
find / -perm -4000 | List setuid programs (audit). |
Quiz
A directory is `drwxrwxrwt`. alice created `a.txt` inside; can bob delete it?
- Yes, the directory is world-writable
- No, the sticky bit lets only the owner (or root) delete it
- Only if a.txt is world-writable
What does setgid do on a directory?
- Files created inside inherit the directory's group
- Programs inside run as root
- Only the group may list it
What does `-rwsr-xr-x` on /bin/busybox mean?
- It is a shared library
- It runs with its owner's (root's) UID whoever starts it
- It is sticky
Which octal command sets a sticky, world-writable directory?
- `chmod 7777`
- `chmod 1777`
- `chmod 777t`
A directory is `drwx--x--x`. What can other users do with it?
- List its contents
- Reach files inside if they already know the names
- Nothing at all
Practice
`/root/lab/l50/dropbox` is world-writable. Add the sticky bit so users can only delete their own files (it should show as `drwxrwxrwt`).
Make `/root/lab/l50/team` a setgid directory, so new files inside inherit its group (result: `drwxrwsr-x`).
`/root/lab/l50/private` is open to everyone. Remove *all* access for others, leaving owner and group untouched (`drwxrwx---`).
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.