Decode a permission string
The familiar rwx groups represent read, write and execute permissions for the owner, group and everyone else. The first character in ls -l identifies the file type. Directory execute permission means permission to traverse/search the directory, not execute it like a programme.
Permissions work alongside ownership, access-control lists, mount options and other security controls. A short permission string is not the entire access decision on every system.
Create a disposable exercise
practice_dir=$(mktemp -d)
printf 'A harmless practice note\n' > "$practice_dir/note.txt"
ls -l "$practice_dir/note.txt"The temporary directory avoids overwriting an existing note. Keep the variable in this shell for the remaining commands.
Restrict the file to its owner
chmod 600 "$practice_dir/note.txt"
ls -l "$practice_dir/note.txt"The numeric values come from read 4, write 2 and execute 1. Mode 600 gives the owner read and write while removing group and other access. A directory normally needs execute permission for useful traversal, so blindly applying file modes to directories can break access.
Practise a symbolic change
chmod u-w "$practice_dir/note.txt"
ls -l "$practice_dir/note.txt"
chmod u+w "$practice_dir/note.txt"This removes and restores the owner's write bit on your test file. A process with sufficient privilege can bypass ordinary access restrictions, so this is not a guarantee against an administrator or a compromised root account.
Verify understanding
Explain the before-and-after permission string in your own words. Check ownership as well as the mode. Remove the exact practice file and directory when finished:
rm -- "$practice_dir/note.txt"
rmdir -- "$practice_dir"Common mistakes
chmod 777 grants broad access and is not a standard fix for application errors. Recursive permission changes over /etc, a home directory or a shared application tree can create serious faults. If an application cannot read a file, identify the actual service user and minimum necessary access first.
Apply the lesson carefully
A private SSH key usually needs tighter access than a public web asset. A shared directory may need group-based access rather than everyone-writable permissions. Practise the model here, then follow the application's documented ownership and permission requirements for real changes.
Official references
Consult the current vendor documentation if your version or screen differs.
Documentation-based draft. Commands have not all been executed against the named products in a lab. Validate configuration examples against your installed version before changing a working system.