The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| List permission strings | ls -l | View examples |
| Show a numeric mode | stat -c '%A %a %U %G %n' file | View examples |
| Show current identity | id | View examples |
| Add owner execute | chmod u+x script.sh | View examples |
| Remove group and other write | chmod go-w file | View examples |
| Assign exact symbolic modes | chmod u=rw,g=r,o= file | View examples |
| Set a private file mode | chmod 640 secrets.env | View examples |
| Set a directory mode | chmod 750 scripts | View examples |
| Apply a recursive mode | chmod -R --preserve-root u=rwX,g=rX,o= project | View examples |
| Change a file owner | sudo chown alice file | View examples |
| Change owner and group | sudo chown alice:developers path | View examples |
| Change the owning group | sudo chgrp developers path | View examples |
| Show the current umask | umask | View examples |
| Set a restrictive umask | umask 027 | View examples |
| Inherit a directory group | chmod g+s shared | View examples |
| Protect shared entries | chmod +t shared | View examples |
| Find world-writable files | find . -type f -perm -o=w -print | View examples |
| Find executable files | find . -type f -perm /111 -print | View examples |
Linux access is controlled by permission bits for the owning user, owning group, and everyone else. Inspect the current state first, change the narrowest scope possible, and verify recursive operations before running them.
Step by step
Detailed examples
Inspect modes, owners, and effective groups
The ten-character mode from ls -l starts with the file type and then shows read, write, and execute for user, group, and other. On directories, read lists names, write changes entries, and execute permits traversal. Access can also be affected by ACLs and security modules, so the basic mode is not always the whole policy.
ls -ld deploy.sh config/
stat -c '%A %a %U %G %n' deploy.sh config/ id
groups Note: Group membership changes may require a new login session before they affect running processes.
Change selected bits with symbolic modes
Symbolic chmod expressions combine a class (u, g, o, or a), an operation (+, -, or =), and permissions (r, w, x, or X). Use + or - for a narrow change. Use = when you intend to replace every permission in that class.
chmod u+x script.sh
chmod go-w script.sh
ls -l script.sh chmod u=rw,g=r,o= settings.ini
stat -c '%A %a %n' settings.ini Set complete modes with octal numbers
Each octal digit is the sum of read 4, write 2, and execute 1 for user, group, and other. Thus 640 means rw-r----- and 750 means rwxr-x---. Uppercase X in a recursive symbolic mode adds execute only to directories and to files that already have an execute bit.
chmod 640 secrets.env
chmod 750 scripts
stat -c '%A %a %n' secrets.env scripts find project -maxdepth 2 -printf '%M %p\n'
chmod -R --preserve-root u=rwX,g=rX,o= project
find project -maxdepth 2 -printf '%M %p\n' Note: Review the target before a recursive change. Recursive chmod can alter far more files than intended, and GNU --preserve-root only guards against operating recursively on /.
Manage owning users and groups
chown changes the owning user, optionally with the group after a colon. chgrp changes only the group. These operations commonly require elevated privileges; quote unusual path names and inspect a tree before using recursive ownership changes.
sudo chown alice:developers deploy.sh
stat -c '%U %G %n' deploy.sh sudo chgrp developers shared
ls -ld shared find project -maxdepth 2 -print
sudo chown -R --preserve-root alice:developers project Note: Avoid recursive ownership changes through untrusted symbolic links or against a path whose resolved location you have not checked.
Control defaults with umask
The umask removes permission bits from the modes requested by programs when they create files and directories. A common 027 mask yields at most 640 for ordinary files requested as 666 and 750 for directories requested as 777. It does not retroactively change existing paths.
umask
umask 027
touch report.txt
mkdir reports
stat -c '%A %a %n' report.txt reports Note: Applications can request different initial modes, and ACL defaults can also influence the final permissions.
Find permissions that deserve review
find can test exact bits, any matching bit, or all matching bits. Use -perm -mode when every bit in mode must be set and -perm /mode when any selected bit may be set. Review matches before piping them into a modifying command.
find . -type f -perm -o=w -printf '%M %u:%g %p\n' find . -type f -perm /111 -printf '%M %p\n' Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



