grep -rl "permissions" ./blog

Linux File Permissions and Ownership

The rwx model and everything layered on it: chmod and chown, umask, the special bits, and access control lists for cases the classic model cannot express.

13 articles

run0 vs sudo-rs vs sudo: The Three Ways to Get Root on Modern Linux sudo is being rewritten in Rust, and systemd now ships run0, which gets root without a setuid binary at all. How each one works, what they do differently, what sudo-rs leaves out, and which to use. chattr and Extended Attributes: File Properties Beyond Permissions A file root cannot delete, a directory where files can only be appended to, and where SELinux labels and capabilities actually live. Two different mechanisms people conflate, and what each is genuinely useful for. Flatpak Permissions Explained: What the Sandbox Actually Confines How Flatpak sandboxing works, why filesystem=home makes it decorative, how to inspect and tighten what an app can reach, and what portals do. Linux ACLs Explained: getfacl and setfacl Beyond rwx Permissions Standard permissions give you one owner, one group, and everyone else. Access control lists let you grant specific users and groups their own permissions on a file, and getfacl and setfacl are how you manage them. chmod Command Explained chmod changes the read, write, and execute permissions on files and directories. This guide covers numeric mode, symbolic mode, recursive changes, and the most common chmod values used in practice. chown Command Explained chown changes which user and group own a file or directory. This guide covers the user:group syntax, recursive ownership changes, and common patterns for web servers and shared directories. The groups Command Explained The groups command shows which groups a user belongs to, the basis for a large part of Linux's access control model. This guide covers primary vs supplementary groups, /etc/group, and managing group membership. rwx Permissions Explained Every file and directory in Linux carries a read, write, and execute permission for the owner, group, and everyone else. This guide breaks down exactly what r, w, and x mean, especially the surprising difference on directories. SGID Explained The SGID bit behaves differently on files versus directories, most commonly used to keep every new file in a shared team folder consistently owned by the same group. This guide explains both behaviors clearly. The Sticky Bit Explained The sticky bit restricts file deletion in shared, world-writable directories so only the file owner can remove their own files. This guide explains how it works, where it is used by default, and how to set it. SUID Explained The SUID bit lets a program run with the permissions of its file owner instead of the user who launched it. This guide explains how SUID works, why it exists, and why it is a common security concern. umask Explained umask controls the default permissions given to every new file and directory you create. This guide explains how umask subtracts from the maximum possible permissions and how to set it permanently. How Linux Permissions Work Linux permissions control who can read, write, and execute every file and directory on the system. This guide explains the permission model from the basics through to special bits, umask, and ACLs.