Files, folders and permissions
You create folders with mkdir, copy with cp, move or rename with mv, and delete with rm, which has no recycle bin. Every file has an owner, a group and three sets of permissions (read, write and execute) for the owner, the group and everyone else.
Making, copying, moving and deleting
| Command | What it does |
|---|---|
mkdir reports | Create a folder. mkdir -p a/b/c creates the whole chain if needed |
touch notes.txt | Create an empty file, or update the time stamp of an existing one |
cp app.conf app.conf.bak | Copy a file. cp -r copies a folder and everything in it |
mv draft.txt final.txt | Rename a file, or move it to another folder: mv final.txt ~/done/ |
rm old.log | Delete a file. rm -r folder deletes a folder and everything inside it |
rmdir empty | Delete a folder, but only if it is already empty |
Reading a permission string
ls -l starts every line with ten characters such as -rwxr-x---. The first says what the entry is: - for a file, d for a directory, l for a link. The next nine are three groups of three: what the owner may do, what members of the file's group may do, and what others (everyone else) may do.
On a directory the letters mean slightly different things: r lets you list the names inside, w lets you create and delete files in it, and x lets you enter it with cd.
Changing permissions with chmod
chmod (change mode) sets permissions in two styles. The symbolic style adds or removes letters: chmod u+x deploy.sh gives the owner (u) execute permission, and chmod o-r secret.txt takes read away from others. The numeric style adds up read = 4, write = 2 and execute = 1 for each of owner, group and others.
| Number | Letters | Typical use |
|---|---|---|
| 755 | rwxr-xr-x | Scripts and programs everyone may run, only the owner may change |
| 644 | rw-r--r-- | Ordinary files: owner edits, everyone else reads |
| 700 | rwx------ | A private folder or script |
| 600 | rw------- | Private keys and other secrets. ssh refuses keys that others can read |
chown changes who owns a file, for example chown asha:devs report.txt. Ordinary users cannot give their files away, so chown is normally run with sudo, which runs one command with administrator (root) rights after checking that you are allowed to.
Which chmod number gives the owner read, write and execute, and gives the group and others read and execute only?
Show a hint
Add read 4, write 2 and execute 1 for each of the three groups.
Show the solution
755: owner 4+2+1 = 7, group 4+1 = 5, others 4+1 = 5.
Common mistakes
One wrong space or variable can delete far more than you meant. List the path first and keep the command as narrow as possible.
It hides the real problem and opens the file to everyone. Grant the one permission the one user needs.
A script without x fails with 'Permission denied'. Run chmod u+x script.sh, or run it with bash script.sh.
What you will see at work
- Pipelines often fail with 'Permission denied' because the agent runs as a service user, not as you. Check the owner and permissions for that user.
- Take a copy before you edit configuration (
cp app.conf app.conf.bak). It is the quickest rollback there is. - On z/OS UNIX the same permission bits exist, and RACF decides which user ID and group a process runs under.
Key terms
Check your understanding.
Take this lesson's quiz and save your progress. Free.