The Linux Permission Model
Linux is a multi-user operating system. Every file and directory on a Linux filesystem belongs to a specific Owner (User) and an assigned Group. Access control is enforced through three distinct user classes and three access permission types.
The 3 User Classes
Owner (User)
The account that owns the file. By default, this is usually the user who created it.
Group
A collection of user accounts sharing common access rights to the file.
Others (World)
All other authenticated user accounts on the operating system.
The 3 Access Modes
- Read (r / 4): View file contents or list directory entries.
- Write (w / 2): Modify file contents, create files in a folder, or delete existing files.
- Execute (x / 1): Run a file as an executable process or enter (cd) into a directory.
How Linux Evaluates Permissions
When a user or process attempts to read, write, or execute a file, the Linux kernel checks credentials in a strict hierarchy:
- If the user matches the File Owner, owner permissions apply (group and others bits are ignored).
- If the user belongs to the File Group, group permissions apply.
- Otherwise, Others permissions apply.
Viewing Permissions with ls -l
$ ls -l /var/www/html-rw-r--r-- 1 www-data www-data 1024 Jan 15 10:00 index.htmldrwxr-xr-x 2 www-data www-data 4096 Jan 15 10:00 images/The leading character indicates file type (- for regular file, d for directory). The following 9 characters represent the 3 permission triads: rw- (Owner), r-- (Group), and r-- (Others).