Ravindra BagaleCourses & study guides मराठी Track your progress

chmod in depth: symbolic and numeric permissions, folder permissions and who can delete a file

Let's start. In the last class you met chmod u-w and chmod g+w. Today we go deeper. First, the full symbolic way: who, plus or minus, which permission, and how to change many things in one command. Then the numbers everyone uses on real servers, like 755, 644 and 600, and how to read and build them in your head. Then we look at folders, where r, w and x mean something different. We end with a puzzle: can ec2-user delete a file that root owns? Keep your server running and try every command with me.

What you'll learn in this class

  • Reading the ten characters of ls -l in one go
  • Symbolic chmod: u, g, o, a with +, - and =
  • Many changes in one command: commas, and several letters together
  • What chmod +w and chmod +x do when you don't say who
  • Numeric chmod: r = 4, w = 2, x = 1
  • Decoding numbers like 645, and building numbers like 714 from a need
  • 555, 000, 777 and 444, and why 777 is a bad habit
  • Root-owned files: sudo chmod, and why root still needs an x bit to run a file
  • The 766 vs 776 question, worked out properly
  • Which numbers to use for files, scripts, folders and keys
  • What r, w and x mean on a folder, with chmod 700, 600, 300, 555 and 200
  • The puzzle: deleting depends on the parent folder
  • The sticky bit on /tmp
  • Why ec2-user can use sudo and a new user can't
  • A real-life tip for when EC2 Instance Connect keeps failing
  • Tasks to try at home

1. Quick recap: the ten characters

Why. Every chmod you type changes some of these ten characters, so you need to read them in one glance.

What. On Amazon Linux, a new file and a new folder made by ec2-user look like this:

[ec2-user@ip-172-31-xx-xx ~]$ ls -l
total 4
-rw-rw-r--. 1 ec2-user ec2-user 6 Jan  5 10:15 my.txt
drwxrwxr-x. 2 ec2-user ec2-user 6 Jan  5 10:15 ravi

Reading -rw-rw-r-- from the left:

  1. -: the type. - is a file, d is a directory.
  2. rw-: the user (owner), the first name, ec2-user.
  3. rw-: the group, the second name. A group can have many members, for example ravi and ramesh.
  4. r--: others, every other user on the server.

The trailing . is Amazon Linux's SELinux marker; ignore it. Owners, groups, adduser and the first chmod u-w demo are in Linux users, groups, sudo and file permissions. This chapter goes deeper.

2. Symbolic chmod: who, + or -, and which permission

Why. Sometimes you want to change exactly one thing, like "let the group write", and leave everything else as it is. Letters do that.

What. A symbolic mode has three parts, written together with no spaces:

  1. who: u user (owner), g group, o others, a all three.
  2. what to do: + give, - take away, = set exactly (anything not listed is removed).
  3. which permission: r, w, x.

Classroom line

The permissions we're giving now use letters.

Symbolic chmod: who, + or -, and which permission 1. who uuser (owner) ggroup oothers aall = ugo 2. what to do +give -take away =set exactly 3. which permission rread wwrite xexecute $ chmod g+wx my.txt$ chmod u+x,g+w my.txt$ chmod go-r my.txt group: give w and x two changes: comma, no space group and others: take away r Pick from each column, write them together, then the file name. Several letters can go in one place: go, ug, wx.

Figure 1. Symbolic chmod: pick who (u, g, o or a), what to do (+, - or =) and which permission (r, w, x), then the file name.

Worked examples. Each one starts again from -rw-r--r--:

chmod u+x my.txt     →  -rwxr--r--
chmod g+w my.txt     →  -rw-rw-r--
chmod o-r my.txt     →  -rw-r-----
chmod a+x my.txt     →  -rwxr-xr-x
chmod u-w my.txt     →  -r--r--r--
chmod u=rw,go=r my.txt  →  -rw-r--r--
  1. u+x: the owner may now run it.
  2. g+w: group members may now change it.
  3. o-r: others can't even read it any more.
  4. a+x: everyone may run it.
  5. u-w: even the owner can't save changes (the owner can still chmod it back).
  6. =: sets those bits exactly. Handy to "reset" a file to rw-r--r--.

3. Many changes in one command

Why. Typing chmod three times for three small changes is slow. You can do them in one go.

How. Two ways:

  1. Commas between separate changes, with no space after the comma.
  2. Several letters in one place: go for group and others, wx for write and execute.

Again starting from -rw-r--r-- each time (checked on the box):

chmod u+x,g+w my.txt   →  -rwxrw-r--
chmod g+wx my.txt      →  -rw-rwxr--
chmod go+x my.txt      →  -rw-r-xr-x
chmod ug+x my.txt      →  -rwxr-xr--
chmod ugo+x my.txt     →  -rwxr-xr-x
chmod a+x my.txt       →  -rwxr-xr-x

ugo and a mean the same thing. And chmod 664 my.txt followed by chmod o-r,g-w my.txt gives -rw-r-----.

Classroom line

We can give permissions to many in one command.

A space after the comma breaks the command:

chmod u+x, g+w my.txt
chmod: invalid mode: ‘u+x,’
Try 'chmod --help' for more information.
Handwritten board: four lines, chmod ug+x my.txt, chmod u+x,g+w my.txt with a line under the comma part, chmod g+wx my.txt with wx underlined, and chmod go+x.

From the class board: Class board: chmod ug+x my.txt, chmod u+x,g+w my.txt (comma, no space), chmod g+wx my.txt and chmod go+x.

4. chmod +w and +x with no u, g or o

Why. You'll often see chmod +x script.sh with no letter before the +. Who gets the permission then?

What. With no u, g, o or a, chmod gives the permission to everyone except where your umask blocks it. The umask is the same setting that decides the permissions of new files (more in section 12).

See it. As ec2-user (umask 0002) on a read-only file:

umask
0002
chmod 444 my.txt
chmod +w my.txt
ls -l my.txt
-rw-rw-r--. 1 ec2-user ec2-user 6 Jan  5 10:15 my.txt

The umask 0002 blocks w only for others, so the owner and group got w. As root (umask 0022) the same chmod +w gives only -rw-r--r--, because 0022 blocks the group too.

To give w to everyone, say so with a:

chmod 444 my.txt
chmod a+w my.txt
ls -l my.txt
-rw-rw-rw-. 1 ec2-user ec2-user 6 Jan  5 10:15 my.txt

chmod +x follows the same rule, but these umasks only block w, so chmod +x my.txt on -rw-r--r-- gives -rwxr-xr-x, x for everyone.

Taking away works the same way, and chmod warns you when the umask kept some bits:

chmod 666 my.txt
chmod -w my.txt
chmod: my.txt: new permissions are r--r--rw-, not r--r--r--
chmod +w with no u, g or o follows the umask $ chmod 444 my.txt$ ls -l my.txt-r--r--r--. 1 ec2-user ec2-user 6 Jan 5 10:15 my.txtStart: read-only for everyone. $ umask0002$ chmod +w my.txt-rw-rw-r--. 1 ec2-user ec2-user 6 Jan 5 10:15 my.txtec2-user, umask 0002: the umask blocks only others, so owner and group get w. # umask0022# chmod 444 my.txt; chmod +w my.txt-rw-r--r--. 1 ec2-user ec2-user 6 Jan 5 10:15 my.txtroot, umask 0022: the group is blocked too, so only the owner gets w. $ chmod 444 my.txt$ chmod a+w my.txt-rw-rw-rw-. 1 ec2-user ec2-user 6 Jan 5 10:15 my.txta+w ignores the umask: everyone gets w, even others. Rarely what you want. +w as ec2-user (0002)rw-rw-r-- +w as root (0022)rw-r--r-- a+wrw-rw-rw-

Figure 2. Animation: on a read-only file, chmod +w as ec2-user (umask 0002) gives rw-rw-r--, as root (umask 0022) gives rw-r--r--, and chmod a+w gives rw-rw-rw-.

Correction

The class said a bare chmod +w "won't work" and that you must write a+w, as a safety lock. That's not right. chmod +w works: with no u/g/o it follows your umask, so as ec2-user (umask 0002) it gives w to the owner and group, and as root (umask 0022) only to the owner. chmod a+w forces w for everyone, others included, which you rarely want.

5. Numeric chmod: r = 4, w = 2, x = 1

Why. Letters change one thing at a time. A number sets all nine bits at once, exactly. That's why you'll see chmod 755, chmod 644 and chmod 600 in almost every guide.

What. Three digits: the first for the user, the second for the group, the third for others. Each digit is a sum:

  1. r = 4
  2. w = 2
  3. x = 1

So 7 = 4 + 2 + 1 = rwx, 6 = 4 + 2 = rw-, 5 = 4 + 1 = r-x, and 3 = 2 + 1 = -wx.

chmod 755: one digit each for user, group and others chmodmy.txt 7user 5group 5others r = 4 w = 2 x = 1 7= 4 + 2 + 1= rwxread, write, run 5= 4 + 0 + 1= r-xread, run 5= 4 + 0 + 1= r-xread, run $ chmod 755 my.txt; ls -l my.txt-rwxr-xr-x. 1 ec2-user ec2-user 6 Jan 5 10:15 my.txt

Figure 3. Animation: chmod 755 my.txt. 7 = 4 + 2 + 1 = rwx for the user, and each 5 = 4 + 1 = r-x for the group and others.

Handwritten board: chmod 755 my.txt with the 7 circled and arrows to user, group and other users; on the right r, w and x with 4, 2 and 1 next to them, brackets adding up to 6, 3 and 7, and a 5 joining r and x.

From the class board: Class board: in chmod 755 my.txt, the first digit is for the user, the second for the group, the third for other users. On the right: r = 4, w = 2, x = 1, so r + w = 6, w + x = 3, r + x = 5 and all three = 7.

Every digit from 0 to 7 0 - - - ---nothing 1 - - x --xrun only 2 - w - -w-write only 3 - w x -wxwrite, run 4 r - - r--read only 5 r - x r-xread, run 6 r w - rw-read, write 7 r w x rwxeverything Add the values of the letters you want: r = 4, w = 2, x = 1. Three digits = user, group, others.

Figure 4. All eight digits: 0 ---, 1 --x, 2 -w-, 3 -wx, 4 r--, 5 r-x, 6 rw-, 7 rwx.

6. Decoding a number

How. Take one digit at a time, and split it into 4, 2 and 1:

  1. Is 4 in it? Then r, else -.
  2. Is 2 in what's left? Then w, else -.
  3. Is 1 left? Then x, else -.

Worked example: 645.

  1. 6 = 4 + 2 → rw- for the user.
  2. 4 = 4 → r-- for the group.
  3. 5 = 4 + 1 → r-x for others.

So chmod 645 my.txt gives -rw-r--r-x. Here are more, each checked with chmod and ls -l on the box:

755 -> -rwxr-xr-x
645 -> -rw-r--r-x
714 -> -rwx--xr--
514 -> -r-x--xr--
555 -> -r-xr-xr-x
000 -> ----------
777 -> -rwxrwxrwx
444 -> -r--r--r--
644 -> -rw-r--r--
600 -> -rw-------
400 -> -r--------

7. Building a number from a need

Why. At work nobody says "chmod 714". They say "the owner needs everything, the group should only run it, others may only read it". You turn that into a number.

Worked example 1. The need: user rwx, group --x, others r--.

  1. User: 4 + 2 + 1 = 7.
  2. Group: 1.
  3. Others: 4.
  4. Answer: chmod 714 my.txt.

Worked example 2. Same as above, but take away the user's write.

  1. User: 4 + 1 = 5.
  2. Group and others don't change: 1 and 4.
  3. Answer: chmod 514 my.txt.
Handwritten board: chmod 645 my.txt at the top; lower down, rwx --x r-- written above chmod 714 my.txt.

From the class board: Class board: chmod 645 my.txt to decode, and below, the need rwx --x r-- written as chmod 714 my.txt.

Three quick ones to try in your head:

  1. "Only the owner may read and write" → 6, 0, 0 → 600.
  2. "Owner everything, group read and run, others nothing" → 7, 5, 0 → 750.
  3. "Everyone may read, nobody may change it" → 4, 4, 4 → 444.

8. Special numbers: 555, 000, 777 and 444

What.

  1. 555 = r-x for all: everyone may read and run, nobody may change it.
  2. 000 = nothing for anybody.
  3. 777 = everything for everybody.
  4. 444 = read-only for everybody.

000 is not a trap for the owner. The owner can't read the file, but can always chmod it back, and root still reads it:

chmod 000 my.txt
cat my.txt
cat: my.txt: Permission denied
sudo cat my.txt
hello
chmod 644 my.txt
cat my.txt
hello

777 is a bad habit on a server. Any user, or any program that gets broken into, can change a 777 file, for example a script that root runs later. If a file "doesn't work", find the bit that's missing instead of opening everything. A good repair after a 777 is chmod 644 (or chmod 444 if nobody should change it).

9. Numbers or letters?

When to use which:

  1. Numbers when you know the final result you want: chmod 644 index.html. All nine bits are set, whatever they were before.
  2. Letters when you want one change and want the rest left alone: chmod u+x my.sh.

For example, on a file that is -rw-rw-r--, chmod u+x gives -rwxrw-r--, but chmod 744 gives -rwxr--r--: the number also removed the group's w.

10. Root-owned files: sudo chmod

Why. A file made with sudo belongs to root, and that changes who may chmod it.

See it. Root writes a small script:

sudo nano a.txt
ls -l a.txt
-rw-r--r--. 1 root root 36 Jan  5 10:15 a.txt

The file holds two lines, #!/bin/bash and echo "Hello from a.txt". Now try it as ec2-user:

chmod 777 a.txt
chmod: changing permissions of 'a.txt': Operation not permitted
./a.txt
-bash: ./a.txt: Permission denied
  1. chmod is refused because only the owner (root) or root via sudo may change the mode.
  2. ./a.txt is refused because nobody has x yet.

Fix it the right way, with 755, not 777:

sudo chmod 755 a.txt
ls -l a.txt
-rwxr-xr-x. 1 root root 36 Jan  5 10:15 a.txt
./a.txt
Hello from a.txt

Root skips the r and w checks, but not this one: to run a file, at least one x bit must be set. On a 666 file even root gets Permission denied.

11. The 766 vs 776 question

Why. The board said that for this root-owned a.txt, 766 doesn't let ec2-user run it but 776 does. Let's work it out instead of believing it.

Who is ec2-user here? The file is root root. ec2-user isn't the owner, and isn't in the group root, so it gets the others bits, the last digit.

  1. 766: others = 6 = rw-. No x.
  2. 776: others = 6 = rw-. Still no x.

So both are denied. Tested on the box with a real root root file:

sudo chmod 766 a.txt
./a.txt
-bash: ./a.txt: Permission denied
sudo chmod 776 a.txt
./a.txt
-bash: ./a.txt: Permission denied

776 only works when the file's group is one that ec2-user belongs to, because then ec2-user gets the middle digit, 7:

sudo chown root:ec2-user a.txt
sudo chmod 776 a.txt
./a.txt
Hello from a.txt
sudo chmod 766 a.txt
./a.txt
-bash: ./a.txt: Permission denied

The same idea explains 700 and 770: 700 lets only root run it (sudo ./a.txt), and 770 works for ec2-user only if the group is ec2-user. One more detail: bash must also read a script. With 711 (x but no r for others) you get /bin/bash: ./a.txt: Permission denied.

A root-owned script: which three bits does ec2-user get? -rwxrwxrw-. 1 root root 36 a.txt (776) ec2-user is not the owner (root) and not in the group (root), so it gets the others bits. mode file root:root file root:ec2-user what ./a.txt does 766rw- (others)rw- (group) Permission denied 776rw- (others)rwx (group) works only if the group is ec2-user 770--- (others)rwx (group) works only if the group is ec2-user 700--- (others)--- (group) only root: sudo ./a.txt 755r-x (others)r-x (group) works for everyone To run a script you need x, and bash also needs r to read it. 755 is the usual answer; avoid 777.

Figure 5. For a root:root script, ec2-user gets the others bits: 766 and 776 are both denied. 776 and 770 work only when the group is ec2-user. 755 works for everyone.

Correction

The board marked 766 ✗ and 776 ✓ for ec2-user running a file made with sudo nano. That file is root:root, so ec2-user falls under others, and both 766 and 776 give others rw-, with no x. Both fail. 776 works only if the file's group is ec2-user (for example after sudo chown root:ec2-user a.txt). The simple answer is sudo chmod 755 a.txt.

12. Which numbers to use

A short list to remember:

What Number Bits
Normal files (web pages, configs) 644 rw-r--r--
Scripts and programs 755 rwxr-xr-x
Folders 755 rwxr-xr-x
Private files and SSH private keys 600 rw-------
A .pem key that never changes 400 r--------
Anything not 777

You met chmod 400 already in Inside an EC2 server, when you locked your .pem key on a Mac: SSH refuses a private key that others can read.

And your defaults on Amazon Linux? New files and folders made by ec2-user come out a bit more open for the group:

umask
0002
touch new.txt
mkdir newdir
ls -ld new.txt newdir
-rw-rw-r--. 1 ec2-user ec2-user 0 Jan  5 10:15 new.txt
drwxrwxr-x. 2 ec2-user ec2-user 6 Jan  5 10:15 newdir
  1. Files start from 666 and folders from 777.
  2. The umask 0002 removes w for others → 664 files and 775 folders.
  3. Root's umask 0022 also removes the group's w → 644 and 755.

This is safe on Amazon Linux because each user has a private group of their own.

Correction

The board showed new files as rw-r--r-- (644) and new folders as rwxr-xr-x (755). Those are root's defaults (umask 0022). For ec2-user on Amazon Linux 2023 the umask is 0002, so new files are rw-rw-r-- (664) and new folders rwxrwxr-x (775), as mkdir ravi showed in class.

13. Folder permissions: r, w and x mean something else

Why. A folder is a list of names. Its permissions protect that list, not the contents of the files in it. That's why the same letters mean different things.

What.

  1. r on a folder: list the names inside (ls).
  2. w on a folder: create, delete and rename entries inside (touch, mkdir, cp into it, mv, rm), and only together with x.
  3. x on a folder: enter it (cd) and use paths through it, like cat ravi/a.txt.
On a folder, r w x mean something different ravi/ drwxrwxr-x. rlist the names insidels ravi wcreate, delete, rename entries (needs x too)touch mkdir cp mv rm xenter it and use paths through itcd ravi cat ravi/a.txt Reading or editing a file that already exists: needs the file's own r or w, plus x on the folder. The folder's w is not needed.

Figure 6. On a folder, r = list the names, w = create, delete and rename entries (needs x too), x = enter and use paths. Reading or editing an existing file needs the file's own r or w plus x on the folder.

Reading or editing a file that already exists is about the file: cat needs the file's r, saving changes needs the file's w, and both need x on the folder to reach it. The folder's w isn't needed.

Correction

The board put cat, nano and vi under the folder's w. cat only reads, so it needs the file's r (plus x on the folder). Editing an existing file needs the file's w, not the folder's. The folder's w matters only when you create, delete or rename entries, like a new file from touch or nano, and it works only together with x.

14. One folder, five modes

How. Make a folder with two files, then change its mode and watch what breaks. All outputs below are from the box:

mkdir ravi
echo hello > ravi/a.txt
touch ravi/aa.txt

Example 1: 700 (rwx------). You can list it, enter it and create in it. Everything works.

Example 2: 600 (rw-------), no x.

chmod 600 ravi
cd ravi
-bash: cd: ravi: Permission denied
ls -l ravi
ls: cannot access 'ravi/a.txt': Permission denied
ls: cannot access 'ravi/aa.txt': Permission denied
total 0
-????????? ? ? ? ?            ? a.txt
-????????? ? ? ? ?            ? aa.txt

r lets ls read the names, but without x it can't look at the files, so you get question marks. cat ravi/a.txt fails too.

Example 3: 700 again.

chmod 700 ravi
cd ravi
pwd
/home/ec2-user/ravi

Classroom line

I could get in because execute permission is there.

Example 4: 300 (-wx------), no r.

chmod 300 ravi
cd ravi
ls
ls: cannot open directory '.': Permission denied
touch new.txt
cat a.txt
hello

cd works (x), ls fails (no r), but touch works (w + x) and a name you already know still opens.

Example 5: 200 (-w-------), w without x.

chmod 200 ravi
touch ravi/n2.txt
touch: cannot touch 'ravi/n2.txt': Permission denied
rm ravi/aa.txt
rm: cannot remove 'ravi/aa.txt': Permission denied

w alone does nothing. Creating and deleting need w and x. (With 100, x only, cat ravi/a.txt works but ls ravi and touch fail.)

Handwritten board: chmod 600 ravi, cd ravi underlined, chmod 700 ravi, and chmod 300 ravi with 300 underlined.

From the class board: Class board: chmod 600 ravi, then cd ravi, then chmod 700 ravi and chmod 300 ravi. 600 blocks cd, 700 allows it, and 300 allows cd but not ls.

Same folder, five modes $ chmod 700 ravi; ls -ld ravidrwx------. 2 ec2-user ec2-user 33 Jan 5 10:15 ravi$ cd ravi; ls; touch new.txta.txt aa.txt700 = rwx: list, enter, create. Everything works. $ chmod 600 ravi$ cd ravi-bash: cd: ravi: Permission denied$ ls -l ravi-????????? ? ? ? ? ? a.txt600 = rw-, no x: you cannot enter, and ls only sees names. $ chmod 300 ravi$ cd ravi$ lsls: cannot open directory '.': Permission denied$ touch new.txt; cat a.txthello300 = -wx, no r: cd works, ls fails, known names still work. $ chmod 555 ravi; cd ravitouch: cannot touch 'rr.txt': Permission deniedrm: cannot remove 'aa.txt': Permission deniedmv: cannot move 'a.txt' to 'c.txt': Permission denied555 = r-x, no w: nothing can be added, removed or renamed. $ chmod 200 ravi$ touch ravi/n2.txttouch: cannot touch 'ravi/n2.txt': Permission denied$ cd ravi-bash: cd: ravi: Permission denied200 = -w-, w without x: still nothing. Create and delete need w and x. modecdlscreate / delete 700 ✓ ✓ ✓ 600 ✗ names ✗ 300 ✓ ✗ ✓ 555 ✓ ✓ ✗ 200 ✗ ✗ ✗ r = list names, w = create and delete (only together with x), x = enter.

Figure 7. Animation: one folder in five modes. 700 everything works; 600 no cd; 300 no ls; 555 no create or delete; 200 nothing, because w needs x.

15. A folder without w: chmod 555

What. 555 (r-x for all) lets you enter and list, but nothing can be added, removed or renamed:

chmod 555 ravi
cd ravi
touch rr.txt
touch: cannot touch 'rr.txt': Permission denied
mkdir tata
mkdir: cannot create directory ‘tata’: Permission denied
rm aa.txt
rm: cannot remove 'aa.txt': Permission denied
cp a.txt b.txt
cp: cannot create regular file 'b.txt': Permission denied
mv a.txt c.txt
mv: cannot move 'a.txt' to 'c.txt': Permission denied

Classroom line

I removed the write permission.

But the files inside can still change. a.txt is rw-rw-r--, so its owner can edit it:

echo more >> a.txt
cat a.txt
hello
more

nano a.txt saves fine too ([ Wrote 2 lines ]). Only a new file fails: nano new.txt shows [ Error writing new.txt: Permission denied ] when you save.

16. The puzzle: can ec2-user delete root's file?

The question. Root makes a file inside /home/ec2-user. The file is root root, rw-r--r--. Can ec2-user delete it without sudo? Most of the class said no.

Classroom line

Will it come into my own house and beat me?

The answer: yes. Deleting doesn't touch the file's contents. It removes a name from the folder's list, so it's decided by the parent folder, and ec2-user owns its home with rwx.

Proof 1. In your home:

ls -ld /home/ec2-user
drwx------. 3 ec2-user ec2-user 74 Jan  5 10:15 /home/ec2-user
sudo nano rootwala.txt
ls -l rootwala.txt
-rw-r--r--. 1 root root 10 Jan  5 10:15 rootwala.txt

Changing what's inside is refused, because that's the file's w, and only root has it:

echo more >> rootwala.txt
-bash: rootwala.txt: Permission denied

But deleting works. rm asks first, because you can't write the file; answer y:

rm rootwala.txt
rm: remove write-protected regular file 'rootwala.txt'? y
ls rootwala.txt
ls: cannot access 'rootwala.txt': No such file or directory

(For an empty file the question says regular empty file. rm -f skips the question.)

Proof 2. Same thing in a folder you made:

mkdir myfolder
cd myfolder
sudo nano folderwala.txt
rm folderwala.txt
rm: remove write-protected regular file 'folderwala.txt'? y

Classroom line

It depends on the parent folder's write permission.

And a folder made by root? sudo mkdir rootwala makes a root root folder in your home. You can't create anything inside it (touch rootwala/x.txt → Permission denied), but while it's empty you can remove it with rmdir rootwala, because its name lives in your folder. If root has put a file inside, rm -r fails on that file.

Root's file in your home: edit no, delete yes /home/ec2-userdrwx------. ec2-user ec2-user ec2-user has w and x on this folder rootwala.txt-rw-r--r--. root root rootwala.txtdeleted 1. Root made a fileinside your home.$ sudo nano rootwala.txt$ ls -l rootwala.txt-rw-r--r--. 1 root root 10 Jan 5 10:15 rootwala.txt 2. Changing its content needsthe file's w. Only root has it.$ echo more >> rootwala.txt-bash: rootwala.txt: Permission denied 3. Deleting removes a name fromthe folder. The folder is yours.$ rm rootwala.txtrm: remove write-protected regular file 'rootwala.txt'? y$ ls rootwala.txtls: cannot access 'rootwala.txt': No such file or directory Delete, create and rename are decided by the parent folder (w and x). Read and edit are decided by the file.

Figure 8. Animation: root's rootwala.txt inside /home/ec2-user. Editing it is denied (the file's w is root's), but rm works after the write-protected question, because deleting depends on the parent folder.

Correction

The class said deleting depends on the parent folder's write permission. It needs w and x on the parent folder: w alone (chmod 200) still gives Permission denied, as section 14 showed. Also, ec2-user can delete root's file here, but still can't change its content; that's the file's own w.

17. The exception: the sticky bit on /tmp

Why. /tmp is a folder where every user may create files, so everyone has w and x on it. By the rule above, anyone could delete anyone's files there. The sticky bit stops that.

What. It shows as a t in place of the last x:

ls -ld /tmp
drwxrwxrwt. 25 root root 2220 Jan  5 10:15 /tmp

With the sticky bit, only the file's owner, the folder's owner or root may delete or rename a file, even if the file itself is rw-rw-rw-. Tested on the box with two users:

[ec2-user@ip-172-31-xx-xx ~]$ echo hi > /tmp/ec2.txt
[ec2-user@ip-172-31-xx-xx ~]$ chmod 666 /tmp/ec2.txt

[ravi@ip-172-31-xx-xx ~]$ rm /tmp/ec2.txt
rm: cannot remove '/tmp/ec2.txt': Operation not permitted

In a drwxrwxrwx folder without the t, the same rm by ravi works. You set the sticky bit with chmod +t folder or chmod 1777 folder.

The exception: the sticky bit (t) on /tmp drwxrwxrwt. root root /tmp everyone may create files here ec2.txt-rw-rw-rw-. ec2-user ravi $ rm /tmp/ec2.txtrm: cannot remove ... Operation not permitted drwxrwxrwx. root root /srv/share no t: anyone with w + x on the folder can delete anyone else's file ravi$ rm -f /srv/share/ec2.txt(gone, no error) With t, only the file's owner,the folder's owner or root may delete. Set it with chmod +t or chmod 1777. You will see it on /tmp and /var/tmp.

Figure 9. /tmp is drwxrwxrwt: ravi can't delete ec2-user's file there (Operation not permitted). Without the t, anyone with w and x on the folder could delete it.

Correction

The rule "deleting depends on the parent folder" has an exception that wasn't mentioned: folders with the sticky bit (t), like /tmp and /var/tmp. There, only the file's owner, the folder's owner or root can delete a file.

18. "I can use sudo anywhere": only if you're allowed

What. ec2-user can run sudo because Amazon Linux sets it up that way. It's in the wheel group, and cloud-init adds a rule with no password:

sudo cat /etc/sudoers.d/90-cloud-init-users
...
ec2-user ALL=(ALL) NOPASSWD:ALL

A new user gets nothing like that:

sudo -l -U ravi
User ravi is not allowed to run sudo on ip-172-31-xx-xx.

So ravi can't use sudo unless an admin allows it, for example with sudo usermod -aG wheel ravi. The wheel rule (%wheel ALL=(ALL) ALL) also asks for ravi's own password, which a new user doesn't have until someone sets one with sudo passwd ravi.

Correction

The class said "I can use sudo anywhere in Linux". That's true for ec2-user on EC2 only because it's in /etc/sudoers.d/90-cloud-init-users (and in wheel). A normal user like ravi gets User ravi is not allowed to run sudo until an admin gives that right.

Ravindra Bagale's Tip

Give sudo only to people who manage the server. Developers who only deploy code usually need write access to one project folder (a group, as in the last chapter), not root.

19. Real-life tip: when EC2 Instance Connect keeps failing

Ravindra Bagale's Tip

In class, EC2 Instance Connect kept showing "Error establishing SSH connection" even though the server was fine. The cause was the laptop's clock: it was wrong, and syncing it (on Windows: Settings → Time & language → Date & time → Sync now) fixed it at once. If a console connection fails for no clear reason, check these:

  1. The instance is running and both status checks have passed.
  2. The security group allows port 22 from the right source. For the browser-based Instance Connect, that's the EC2 Instance Connect IP range of your Region, not only your own IP.
  3. The AMI supports Instance Connect (Amazon Linux and Ubuntu do).
  4. Your computer's date, time and time zone are set automatically.

20. Try at home

Try at home

Task 1: symbolic

  1. echo hello > my.txt, then chmod 644 my.txt.
  2. Run chmod u+x,g+w my.txt and predict the result before ls -l.
  3. Run chmod go-r my.txt, then reset with chmod u=rw,go=r my.txt.
  4. Run chmod 444 my.txt, then chmod +w my.txt, and explain the result using umask.

Task 2: numbers

  1. Decode 640, 711 and 754 on paper, then check each with chmod and ls -l.
  2. Build the number for "owner read and write, group read, others nothing".
  3. Try chmod 000 my.txt, cat my.txt, then get it back with chmod 644 my.txt.

Task 3: folders

  1. Make ravi with two files. Try cd, ls -l and touch after chmod 700, 600, 300, 555 and 200.
  2. In the 555 folder, edit an existing file with nano, then try to save a new one.

Task 4: the puzzle

  1. sudo nano rootwala.txt in your home, then echo more >> rootwala.txt and rm rootwala.txt. Explain both results.
  2. Run ls -ld /tmp and find the t.

When you're done, put the folder back with chmod 755 ravi before deleting it with rm -r ravi, and stop the instance.

Recap

In short

  1. Ten characters: type, then r w x for user, group and others.
  2. Symbolic: who (u g o a), + - =, which (r w x). Combine with commas and no spaces: chmod u+x,g+w.
  3. ugo = a. chmod +w with no letter follows the umask; a+w forces it for everyone.
  4. Numbers: r = 4, w = 2, x = 1, one digit each for user, group and others. 645 = rw-r--r-x.
  5. Build from a need: rwx --x r-- = 714; take away the user's w → 514.
  6. 000 doesn't lock the owner out of chmod; root still reads. Avoid 777.
  7. Numbers set all nine bits; letters change only what you name.
  8. A sudo-made file is root root: ec2-user needs sudo chmod. Root needs at least one x bit to run a file.
  9. For a root:root file, ec2-user is "others": 766 and 776 both fail; 755 works.
  10. Use 644 files, 755 scripts and folders, 600/400 keys. Amazon Linux gives ec2-user 664 files and 775 folders (umask 0002).
  11. Folder: r = list, w = create/delete/rename (needs x), x = enter.
  12. Reading or editing an existing file = the file's own bits + folder x.
  13. Deleting depends on the parent folder (w + x), so ec2-user can delete root's file in its home, but can't edit it.
  14. Sticky bit (t, like /tmp): only the owner, folder owner or root may delete.
  15. ec2-user has sudo because of /etc/sudoers.d/90-cloud-init-users; ravi doesn't, until an admin allows it.

Samjla ka? Ghari ek folder banva, tyala 700, 600, 300 ani 555 deun bagha, ani root chi file delete karun bagha.


Ravindra Bagale, trainer: linkedin.com/in/ravindra-bagale. The user, folder and file names (ravi, ramesh, my.txt, a.txt, rootwala.txt and the rest) are examples for learning. Commands and messages were checked on the box with GNU coreutils, bash and nano using an ec2-user test account with umask 0002, and against the settings of an Amazon Linux 2023 server (umask 0002, home folder 700, /tmp drwxrwxrwt, the cloud-init sudoers rule, coreutils 8.32); the hostname in the prompt, the dates and the /tmp size in ls -l are illustrative.