Read

Module 5 · Users, groups and permissions

Directory permissions and special bits

What r, w and x really do on a directory, and the three extra bits, setuid, setgid and sticky, that explain /tmp, shared folders and why busybox is -rwsr-xr-x.

What you will learn

  • Predict what a user can do in a directory from its rwx bits.
  • Recognise `s`, `S`, `t` and `T` in a mode string and say what they mean.
  • Set the sticky and setgid bits on directories with symbolic and octal chmod.

Directories are lists of names

A directory is a file whose contents are pairs of *name → inode number*. Once you hold that picture, its permission bits stop being mysterious. r lets you read the list, so ls works. x lets you *use* an entry: pass through the directory to reach something inside by name, cd into it, open dir/file. w lets you change the list: create, delete and rename entries, and it only counts together with x, because you must reach the entry to modify it.

Directory mode`ls dir``cat dir/known-file``touch dir/new`, `rm dir/file`
r-xyesyesno
--xnoyes, if you know the nameno
r--names only, no detailsnono
rwxyesyesyes, any file, whoever owns it

The last row is the one that bites: with w on a directory you can delete *anyone's* file in it, because deletion is a change to the list, not to the file. That is what the sticky bit fixes.

The three special bits

BitOctalShown asOn a programOn a directory
setuid4000s in the owner's x slotRuns with the *owner's* UID, not the caller'sIgnored on Linux
setgid2000s in the group's x slotRuns with the file's groupNew files inherit the directory's group
sticky1000t in the others' x slotNothing todayOnly a file's owner (or root) may delete or rename it
~% ls -ld /tmp /bin/busybox
-rwsr-xr-x    1 root     root        592196 Jul 21  2018 /bin/busybox
drwxrwxrwt    2 root     root            60 Oct  4 18:51 /tmp
~% cd /root/lab/l50
l50% chmod +t dropbox; chmod g+s team
l50% ls -ld dropbox team
drwxrwxrwt    2 root     root             0 Oct  4 19:30 dropbox
drwxrwsr-x    2 root     root             0 Oct  4 19:30 team
l50% chmod 1777 dropbox; chmod 2775 team   # the same, in octal

/tmp is the textbook sticky directory: drwxrwxrwt, everyone may create files, nobody may remove anyone else's. /bin/busybox is setuid root in this image so that applets like passwd and su, which need to edit /etc/shadow or change identity, work for ordinary users; when alice runs passwd the process briefly has UID 0. That is powerful and dangerous, which is why chown strips these bits and why find / -perm -4000 is a standard security audit (lesson 36).

A setgid directory is the practical one for teams: make team belong to group devs, set g+s, and every file anyone creates inside gets group devs automatically instead of the creator's private group, so the 664/775 modes from the umask lesson actually let colleagues edit each other's work. Symbolically the bits are s (for u or g) and t; in octal they are the fourth, leading digit: chmod 1777, chmod 2775, chmod 4755.

Commands in this lesson

CommandWhat it does
ls -ld DIRSee a directory's own bits, including s and t.
chmod +t DIRSticky: only owners may delete their files.
chmod 1777 DIRWorld-writable sticky directory, like /tmp.
chmod g+s DIRSetgid: new files inherit the directory's group.
chmod 2775 DIRSetgid team directory, group-writable.
chmod o= DIRKeep others out entirely.
find / -perm -4000List setuid programs (audit).

Quiz

  1. A directory is `drwxrwxrwt`. alice created `a.txt` inside; can bob delete it?

    • Yes, the directory is world-writable
    • No, the sticky bit lets only the owner (or root) delete it
    • Only if a.txt is world-writable
  2. What does setgid do on a directory?

    • Files created inside inherit the directory's group
    • Programs inside run as root
    • Only the group may list it
  3. What does `-rwsr-xr-x` on /bin/busybox mean?

    • It is a shared library
    • It runs with its owner's (root's) UID whoever starts it
    • It is sticky
  4. Which octal command sets a sticky, world-writable directory?

    • `chmod 7777`
    • `chmod 1777`
    • `chmod 777t`
  5. A directory is `drwx--x--x`. What can other users do with it?

    • List its contents
    • Reach files inside if they already know the names
    • Nothing at all

Practice

  1. `/root/lab/l50/dropbox` is world-writable. Add the sticky bit so users can only delete their own files (it should show as `drwxrwxrwt`).

  2. Make `/root/lab/l50/team` a setgid directory, so new files inside inherit its group (result: `drwxrwsr-x`).

  3. `/root/lab/l50/private` is open to everyone. Remove *all* access for others, leaving owner and group untouched (`drwxrwx---`).

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.