Read

Module 5 · Users, groups and permissions

Reading permissions: the rwx triplets

Decode the ten characters at the start of every ls -l line: file type, and read, write and execute for owner, group and others.

What you will learn

  • Split the mode string into type plus three rwx triplets.
  • Decide which triplet applies to a given user and what it lets them do.
  • Inspect a directory itself, not its contents, with `ls -ld`.

Ten characters

You have been looking at the output of ls -l since module 1. Now the first column gets its due. It is always ten characters: one for the type of the entry and nine for its permissions, in three groups of three. The owner and group named in columns three and four decide which group of three applies to whom.

~% ls -l /root/lab/l45
-rw-r--r--    1 root     root             0 Oct  4 19:02 notes.txt
-rwxr-xr-x    1 root     root             0 Oct  4 19:02 run.sh
-rw-------    1 root     root             0 Oct  4 19:02 secret.key
drwxr-x---    2 root     root             0 Oct  4 19:02 data

  - rwx r-x r-x
  │  │   │   └── others: everybody else
  │  │   └────── group: members of the file's group
  │  └────────── user: the owner
  └───────────── type: - file, d directory, l symlink

The type character is - for a regular file, d for a directory, l for a symbolic link, and c or b for character and block devices such as /dev/ttyS0 or /dev/sda. Then come the triplets, always in the order user, group, others (remember *ugo*). Within each triplet the order is always r, w, x; a dash means that permission is absent. So -rwxr-xr-x is a file whose owner may read, write and execute, while its group and everyone else may read and execute but not write.

What r, w and x mean

BitOn a fileOn a directory
r readOpen and read the contents (cat, less)List the names inside (ls)
w writeChange the contents (edit, truncate, append)Create, delete and rename entries inside
x executeRun it as a programEnter it (cd) and reach things inside by name

The directory column surprises people. Deleting a file is a change to the *directory*, so it needs w on the directory, not on the file: you can delete a read-only file in a folder you own, and you cannot delete your own file in a folder you may not write. Lesson 50 goes deeper into directory bits.

Which triplet applies to me?

The kernel picks exactly one triplet and stops. If your UID is the file's owner, the user triplet applies, full stop. Otherwise, if any of your groups is the file's group, the group triplet applies. Otherwise, the others triplet. There is no "best of": a file ----rwxrwx owned by alice is unreadable *by alice*, even though everybody else can read it. And root ignores r and w entirely, though it still needs at least one x somewhere to execute a file.

In the listing above, secret.key is -rw-------: only root can read or write it, nobody else can even open it. data is drwxr-x---: root has full control, members of group root can list and enter but not create files, and everyone else is kept out entirely. To see a directory's own permissions rather than those of its contents, add -d: ls -ld /root/lab/l45/data. Other systems also offer stat, which prints the mode in several formats; BusyBox here does not include it, and ls -l tells you everything you need.

Commands in this lesson

CommandWhat it does
ls -lMode, links, owner, group, size, date, name.
ls -ld DIRThe directory's own line, not its contents.
ls -laInclude hidden entries, `.` and `..`.
ls -l FILE | cut -c1-10Just the mode string.
su bob -c 'cat FILE'Test a permission as another user.

Quiz

  1. In `-rwxr-x---`, what can members of the file's group do?

    • Read and execute
    • Read, write and execute
    • Nothing
  2. What does the first character `d` in `drwxr-xr-x` mean?

    • The entry is deletable
    • The entry is a directory
    • The entry is a device
  3. alice owns a file with mode `----rw-rw-` and belongs to its group. Can she read it?

    • Yes, through the group triplet
    • No: as owner, only the user triplet applies, and it is empty
    • Only with sudo
  4. Which permission do you need on a directory to delete a file inside it?

    • `w` on the file
    • `w` (and `x`) on the directory
    • `r` on the directory
  5. How do you see the permissions of `/root/lab` itself, not of what is inside?

    • `ls -l /root/lab`
    • `ls -ld /root/lab`
    • `ls -a /root/lab`

Practice

  1. Save the long listing of `/root/lab/l45` into `/root/lab/l45/listing.txt`.

  2. Look at `/root/lab/l45`. One file can be read by its owner only. Write its name (just the name) into `/root/lab/l45/answer.txt`.

  3. Write the `ls` line describing the directory `/root/lab/l45/data` *itself* into `/root/lab/l45/dir.txt`.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.