The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
List permission stringsls -lView examples
Show a numeric modestat -c '%A %a %U %G %n' fileView examples
Show current identityidView examples
Add owner executechmod u+x script.shView examples
Remove group and other writechmod go-w fileView examples
Assign exact symbolic modeschmod u=rw,g=r,o= fileView examples
Set a private file modechmod 640 secrets.envView examples
Set a directory modechmod 750 scriptsView examples
Apply a recursive modechmod -R --preserve-root u=rwX,g=rX,o= projectView examples
Change a file ownersudo chown alice fileView examples
Change owner and groupsudo chown alice:developers pathView examples
Change the owning groupsudo chgrp developers pathView examples
Show the current umaskumaskView examples
Set a restrictive umaskumask 027View examples
Inherit a directory groupchmod g+s sharedView examples
Protect shared entrieschmod +t sharedView examples
Find world-writable filesfind . -type f -perm -o=w -printView examples
Find executable filesfind . -type f -perm /111 -printView examples

Linux access is controlled by permission bits for the owning user, owning group, and everyone else. Inspect the current state first, change the narrowest scope possible, and verify recursive operations before running them.

Step by step

Detailed examples

01

Inspect modes, owners, and effective groups

The ten-character mode from ls -l starts with the file type and then shows read, write, and execute for user, group, and other. On directories, read lists names, write changes entries, and execute permits traversal. Access can also be affected by ACLs and security modules, so the basic mode is not always the whole policy.

Compare symbolic and numeric permissions
ls -ld deploy.sh config/
stat -c '%A %a %U %G %n' deploy.sh config/
Check the current user's groups
id
groups

Note: Group membership changes may require a new login session before they affect running processes.

Back to quick reference ↑
02

Change selected bits with symbolic modes

Symbolic chmod expressions combine a class (u, g, o, or a), an operation (+, -, or =), and permissions (r, w, x, or X). Use + or - for a narrow change. Use = when you intend to replace every permission in that class.

Make a script executable without broadening other access
chmod u+x script.sh
chmod go-w script.sh
ls -l script.sh
Assign an exact file policy
chmod u=rw,g=r,o= settings.ini
stat -c '%A %a %n' settings.ini
Back to quick reference ↑
03

Set complete modes with octal numbers

Each octal digit is the sum of read 4, write 2, and execute 1 for user, group, and other. Thus 640 means rw-r----- and 750 means rwxr-x---. Uppercase X in a recursive symbolic mode adds execute only to directories and to files that already have an execute bit.

Protect a file and a directory
chmod 640 secrets.env
chmod 750 scripts
stat -c '%A %a %n' secrets.env scripts
Normalize a project tree carefully
find project -maxdepth 2 -printf '%M %p\n'
chmod -R --preserve-root u=rwX,g=rX,o= project
find project -maxdepth 2 -printf '%M %p\n'

Note: Review the target before a recursive change. Recursive chmod can alter far more files than intended, and GNU --preserve-root only guards against operating recursively on /.

Back to quick reference ↑
04

Manage owning users and groups

chown changes the owning user, optionally with the group after a colon. chgrp changes only the group. These operations commonly require elevated privileges; quote unusual path names and inspect a tree before using recursive ownership changes.

Assign a deployment file
sudo chown alice:developers deploy.sh
stat -c '%U %G %n' deploy.sh
Change only group ownership
sudo chgrp developers shared
ls -ld shared
Apply ownership to a reviewed tree
find project -maxdepth 2 -print
sudo chown -R --preserve-root alice:developers project

Note: Avoid recursive ownership changes through untrusted symbolic links or against a path whose resolved location you have not checked.

Back to quick reference ↑
05

Control defaults with umask

The umask removes permission bits from the modes requested by programs when they create files and directories. A common 027 mask yields at most 640 for ordinary files requested as 666 and 750 for directories requested as 777. It does not retroactively change existing paths.

Create paths under a restrictive mask
umask
umask 027
touch report.txt
mkdir reports
stat -c '%A %a %n' report.txt reports

Note: Applications can request different initial modes, and ACL defaults can also influence the final permissions.

Back to quick reference ↑
06

Configure collaborative directories

The set-group-ID bit on a directory makes newly created entries inherit that directory's group. The restricted deletion flag, commonly called the sticky bit, prevents users from deleting or renaming entries they do not own in an otherwise writable directory.

Create a group-shared workspace
sudo chgrp developers shared
chmod 2770 shared
ls -ld shared

Note: Members still need an appropriate umask or default ACL if newly created files should remain group-writable.

Protect a public drop directory
chmod 1777 dropbox
ls -ld dropbox

Note: A world-writable directory should be intentional and monitored even when the sticky bit is set.

Back to quick reference ↑
07

Find permissions that deserve review

find can test exact bits, any matching bit, or all matching bits. Use -perm -mode when every bit in mode must be set and -perm /mode when any selected bit may be set. Review matches before piping them into a modifying command.

Report world-writable regular files
find . -type f -perm -o=w -printf '%M %u:%g %p\n'
Report executable regular files
find . -type f -perm /111 -printf '%M %p\n'
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. GNU ProjectGNU Coreutils Manualgnu.org
  2. GNU ProjectFile permissionsgnu.org
  3. GNU ProjectSetting Permissionsgnu.org
  4. GNU ProjectUmask and Protectiongnu.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback