Module 5 · Users, groups and permissions
Reading permissions: the rwx triplets
Decode the ten characters at the start of every ls -l line: file type, and read, write and execute for owner, group and others.
What you will learn
- Split the mode string into type plus three rwx triplets.
- Decide which triplet applies to a given user and what it lets them do.
- Inspect a directory itself, not its contents, with `ls -ld`.
Ten characters
You have been looking at the output of ls -l since module 1. Now the first column gets its due. It is always ten characters: one for the type of the entry and nine for its permissions, in three groups of three. The owner and group named in columns three and four decide which group of three applies to whom.
~% ls -l /root/lab/l45
-rw-r--r-- 1 root root 0 Oct 4 19:02 notes.txt
-rwxr-xr-x 1 root root 0 Oct 4 19:02 run.sh
-rw------- 1 root root 0 Oct 4 19:02 secret.key
drwxr-x--- 2 root root 0 Oct 4 19:02 data
- rwx r-x r-x
│ │ │ └── others: everybody else
│ │ └────── group: members of the file's group
│ └────────── user: the owner
└───────────── type: - file, d directory, l symlink
The type character is - for a regular file, d for a directory, l for a symbolic link, and c or b for character and block devices such as /dev/ttyS0 or /dev/sda. Then come the triplets, always in the order user, group, others (remember *ugo*). Within each triplet the order is always r, w, x; a dash means that permission is absent. So -rwxr-xr-x is a file whose owner may read, write and execute, while its group and everyone else may read and execute but not write.
What r, w and x mean
| Bit | On a file | On a directory |
|---|---|---|
r read | Open and read the contents (cat, less) | List the names inside (ls) |
w write | Change the contents (edit, truncate, append) | Create, delete and rename entries inside |
x execute | Run it as a program | Enter it (cd) and reach things inside by name |
The directory column surprises people. Deleting a file is a change to the *directory*, so it needs w on the directory, not on the file: you can delete a read-only file in a folder you own, and you cannot delete your own file in a folder you may not write. Lesson 50 goes deeper into directory bits.
Which triplet applies to me?
The kernel picks exactly one triplet and stops. If your UID is the file's owner, the user triplet applies, full stop. Otherwise, if any of your groups is the file's group, the group triplet applies. Otherwise, the others triplet. There is no "best of": a file ----rwxrwx owned by alice is unreadable *by alice*, even though everybody else can read it. And root ignores r and w entirely, though it still needs at least one x somewhere to execute a file.
In the listing above, secret.key is -rw-------: only root can read or write it, nobody else can even open it. data is drwxr-x---: root has full control, members of group root can list and enter but not create files, and everyone else is kept out entirely. To see a directory's own permissions rather than those of its contents, add -d: ls -ld /root/lab/l45/data. Other systems also offer stat, which prints the mode in several formats; BusyBox here does not include it, and ls -l tells you everything you need.
Commands in this lesson
| Command | What it does |
|---|---|
ls -l | Mode, links, owner, group, size, date, name. |
ls -ld DIR | The directory's own line, not its contents. |
ls -la | Include hidden entries, `.` and `..`. |
ls -l FILE | cut -c1-10 | Just the mode string. |
su bob -c 'cat FILE' | Test a permission as another user. |
Quiz
In `-rwxr-x---`, what can members of the file's group do?
- Read and execute
- Read, write and execute
- Nothing
What does the first character `d` in `drwxr-xr-x` mean?
- The entry is deletable
- The entry is a directory
- The entry is a device
alice owns a file with mode `----rw-rw-` and belongs to its group. Can she read it?
- Yes, through the group triplet
- No: as owner, only the user triplet applies, and it is empty
- Only with sudo
Which permission do you need on a directory to delete a file inside it?
- `w` on the file
- `w` (and `x`) on the directory
- `r` on the directory
How do you see the permissions of `/root/lab` itself, not of what is inside?
- `ls -l /root/lab`
- `ls -ld /root/lab`
- `ls -a /root/lab`
Practice
Save the long listing of `/root/lab/l45` into `/root/lab/l45/listing.txt`.
Look at `/root/lab/l45`. One file can be read by its owner only. Write its name (just the name) into `/root/lab/l45/answer.txt`.
Write the `ls` line describing the directory `/root/lab/l45/data` *itself* into `/root/lab/l45/dir.txt`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.