Post

Who Are You?, I Cannot Let You In

Figure out how Linux decides who gets in and what they can do once inside: users, groups, sudo, and rwx permissions.

Who Are You?, I Cannot Let You In
Pre-test
Answer all 5 questions, then press Check answers.
1. Which file holds the list of user accounts on a Linux system (name, UID, home directory, shell)?
2. What does the read (r) permission allow on a directory?
3. Which command changes the permissions of a file?
4. What does sudo do?
5. How many primary groups can a Linux user have?
0 of 5 answered

Who Is on This Machine?

Linux was built as a multi-user system. Many people (and many services) can be logged in at once, so the OS needs a way to keep them out of each other’s stuff. That’s the whole job of users, groups, and permissions.

There are three kinds of accounts you’ll run into:

TypeUID (usually)Notes
root0The superuser. Can do anything, no questions asked.
System users1 to 999Created for services like www-data or postfix. They normally can’t log in (/usr/sbin/nologin).
Regular users1000 and upReal people. These are the accounts you create.

Account info lives in three plain text files:

FileContains
/etc/passwdOne line per user: name, UID, GID, home, shell
/etc/shadowThe password hashes (readable by root only)
/etc/groupOne line per group and its members

Here is one line from /etc/passwd, split by colons:

1
alice:x:1001:1001:Alice:/home/alice:/bin/bash
FieldValueMeaning
1aliceUsername
2xPassword placeholder, the real hash is in /etc/shadow
31001UID
41001GID of the primary group
5AliceComment / full name
6/home/aliceHome directory
7/bin/bashLogin shell
1
2
3
4
5
6
7
# Who am I, and what groups do I have?
whoami
id

# Look up another user
id alice
getent passwd alice

Managing Users

CommandWhat it does
sudo adduser aliceFriendly wrapper on Debian/Ubuntu. Asks questions, creates the home directory and a group with the same name.
sudo useradd -m -s /bin/bash aliceThe low-level, works-everywhere version. Forget -m and you may end up with no home directory.
sudo passwd aliceSet or change a password (run passwd alone to change your own).
sudo usermod -s /bin/zsh aliceModify an existing account (shell, home, groups, and more).
sudo passwd -l aliceLock an account without deleting it.
sudo userdel aliceDelete the account only. The home directory stays behind.
sudo userdel -r aliceDelete the account and its home directory.

Good to know: on Debian/Ubuntu use adduser, on RHEL/Rocky use useradd. Both end up in the same files, they just ask different amounts of questions.


Groups

A group is simply a named list of users. Instead of giving access to five people one by one, you give it to a group once and then move people in and out.

  • Primary group: the one stored in /etc/passwd. Every user has exactly one, and every new file they create is tagged with it.
  • Secondary groups: extras you add later. A user can have none, one, or many.
CommandWhat it does
groups aliceShow all groups for a user
id aliceSame, but with the numeric IDs too
sudo groupadd webteamCreate a group
sudo usermod -aG webteam aliceAdd alice to a secondary group
sudo gpasswd -d alice webteamRemove alice from a group
sudo groupdel webteamDelete a group
newgrp webteamStart a shell that uses webteam as the active group

Watch out: usermod -G without -a replaces all secondary groups. It’s an easy way to accidentally remove yourself from sudo. Always type -aG.

Group changes don’t reach sessions that are already open. Log out and back in (or use newgrp) before testing.


Sudo, Not Root

Doing everything as a root all day is risky. One typo and there’s no safety net. The usual approach is to work as a normal user and use admin power only when you need it, with sudo.

1
2
sudo apt update          # one command as root
sudo -l                  # list what you're allowed to run

Who gets to use sudo is decided by group membership:

Distro familyAdmin group
Debian / Ubuntusudo
RHEL / Rocky / Fedorawheel
1
2
sudo usermod -aG sudo alice      # Debian/Ubuntu
sudo usermod -aG wheel alice     # RHEL family

For finer rules, edit the sudoers file, only with visudo. It checks the syntax before saving, so a typo can’t lock you out.

1
sudo visudo -f /etc/sudoers.d/alice
1
2
# alice may restart nginx and nothing else
alice ALL=(ALL) /usr/bin/systemctl restart nginx

Best practice: give people the smallest set of commands they need (least privilege), and use full paths in sudoers (which systemctl tells you the path).


Reading Permissions

Run ls -l and look at the first column:

1
-rwxr-xr-- 1 alice webteam 220 Oct  4 10:00 deploy.sh
Chars-rwxr-xr--
MeaningType (- file, d directory, l link)Owner (alice)Group (webteam)Others (everyone else)

Then comes the link count, owner, group, size, date, and name.

The same three letters mean different things on files and directories:

 FileDirectory
r readView the contentsList the names inside
w writeChange the contentsCreate, rename, or delete entries inside (needs x too)
x executeRun it as a programEnter it with cd and reach what’s inside

Changing Permissions

chmod

You can describe the change with letters or with numbers.

1
2
3
4
5
6
7
# Letters: who (u g o a) + operator (+ - =) + permission (r w x)
chmod u+x deploy.sh        # let the owner run it
chmod g+w,o-rwx notes.txt  # group can write, others get nothing
chmod -R g+rX project/     # recursive; capital X only adds x on directories

# Numbers (octal)
chmod 640 notes.txt

For the numeric style, each permission has a value, and you add them per column:

PermissionValue
r4
w2
x1

So rwx = 4+2+1 = 7, r-x = 4+1 = 5, rw- = 4+2 = 6, r-- = 4.

ModeLooks likeTypical use
644rw-r--r--Normal files
755rwxr-xr-xScripts, public directories
600rw-------Private files like SSH keys
640rw-r-----Configs the group may read
770rwxrwx---Shared team folder

Don’t reach for 777. It means every user on the box can change the file. If something “needs 777 to work”, the real fix is almost always the right owner or group.

chown and chgrp

1
2
3
4
sudo chown alice file.txt              # change owner
sudo chown alice:webteam file.txt      # owner and group together
sudo chown -R alice:webteam /srv/site  # whole tree
sudo chgrp webteam file.txt            # group only

umask: Default Permissions

Brand new file is 644 and a new folder is 755, without you ever running chmod? That’s the umask at work.

Think of it as a list of things to take away from every new file or folder. Linux starts with the maximum, then the umask crosses permissions out.

New itemStarts as
File666 (rw-rw-rw-), files never start with x
Directory777 (rwxrwxrwx)

The most common umask is 022. Read it as three digits, one each for owner, group, and others. A 2 means “remove write”.

 OwnerGroupOthers
umask 022remove nothingremove wremove w
New filerw-r--r--
New directoryrwxr-xr-x

That gives you 644 for files and 755 for directories.

For the usual umask values, a quick shortcut works: subtract the umask from the starting mode. File: 666 - 022 = 644. Directory: 777 - 022 = 755.

umaskFilesDirectoriesUse it when
022644755Default. Others can look but not touch
002664775Team folders where the group edits together
077600700Private. Only the owner gets in
1
2
umask          # show the current value
umask 002      # change it for this terminal session only

The umask only affects files created after you set it. Existing files keep their permissions, and closing the terminal resets it. To keep it, add the umask line to ~/.bashrc.


Special Bits

Three extra flags that show up in multi-user setups:

BitSet withOn a fileOn a directory
setuidchmod u+s (4xxx)Runs with the owner’s rights (that’s how passwd can edit /etc/shadow)Ignored
setgidchmod g+s (2xxx)Runs with the group’s rightsNew files inherit the directory’s group
stickychmod +t (1xxx)IgnoredOnly the file’s owner (or root) can delete or rename it

You’ve already seen the sticky bit: ls -ld /tmp shows drwxrwxrwt. Everybody can write there, but you can’t delete someone else’s files.

setuid on your own scripts is a security risk. Leave it to system tools unless you really know why you need it.


Good Habits

Do thisBecause
One account per personFiles stay separated and logs show who did what
Never share passwordsShared logins can’t be audited or revoked cleanly
Use groups for teamworkOne change to the group, instead of editing every file
Use sudo instead of rootFewer mistakes, better logging
Give the least access neededA compromised account can only do so much
Review with ls -l and idCheck before you assume

Key Commands Cheat Sheet

CommandWhat it does
id, whoami, groupsWho am I and what groups do I belong to
adduser, useradd -m, userdel -rCreate or remove a user
passwdSet a password
groupadd, usermod -aG, gpasswd -dCreate a group, add or remove members
sudo, visudoRun as admin, safely edit sudo rules
ls -l, ls -ldRead permissions (use -d for a directory itself)
chmod, chown, chgrpChange permissions, owner, group
getent passwd, getent groupLook up accounts and groups

Hands-On Case

Scenario: A small web team (Alice and Bob) needs one shared folder at /srv/webteam. They should both be able to edit each other’s files. Carol works in another department and must stay out.

Try it yourself first, then open the solution to check.

Goal:

  1. Create the group webteam and the users alice, bob, carol
  2. Put only Alice and Bob in the group
  3. Make /srv/webteam owned by root:webteam, with group-shared files and no access for others
  4. Prove it works for Alice and Bob, and fails for Carol
Show solution
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
# 1. Create the group and the users
sudo groupadd webteam
sudo useradd -m -s /bin/bash alice
sudo useradd -m -s /bin/bash bob
sudo useradd -m -s /bin/bash carol

# 2. Add Alice and Bob (Carol stays out)
sudo usermod -aG webteam alice
sudo usermod -aG webteam bob

# 3. Build the shared directory
sudo mkdir /srv/webteam
sudo chown root:webteam /srv/webteam
sudo chmod 2770 /srv/webteam

# 4. Check the setup
ls -ld /srv/webteam      # drwxrws---  (the "s" is the setgid bit)
id alice
id bob
1
2
3
4
5
6
7
8
9
# 5. Test it, one user at a time
 
# --- Alice creates a file ---
sudo su - alice                              # switch to Alice
whoami                                       # should print: alice
umask 002                                    # let the group edit new files
echo "<h1>Hello</h1>" > /srv/webteam/index.html
ls -l /srv/webteam                           # group is webteam, even though Alice's primary group is alice
exit                                         # go back to your own user
1
2
3
4
5
6
# --- Bob edits the same file ---
sudo su - bob                                # switch to Bob
whoami                                       # should print: bob
echo "<p>Bob was here</p>" >> /srv/webteam/index.html
cat /srv/webteam/index.html                  # you should see both lines
exit
1
2
3
4
5
# --- Carol tries to peek ---
sudo su - carol                              # switch to Carol
whoami                                       # should print: carol
ls /srv/webteam                              # Permission denied
exit

Command Explanation

PartWhat it does
useradd -m -s /bin/bashCreate the user with a home directory and a bash shell
usermod -aG webteamAppend the group, don’t overwrite existing ones
chown root:webteamRoot owns the folder, the team group controls it
chmod 27702 = setgid, then rwx owner, rwx group, --- others
sudo -u aliceRun the command as Alice without needing her password
umask 002Make new files group-writable (see the note below)

Why the umask 002? The default umask 022 creates files as 644, so the group could read Alice’s file but not edit it. Setting 002 gives new files 664. In real setups you’d put this in the users’ shell profile.

1
2
3
4
5
6
# cleanup
sudo userdel -r alice
sudo userdel -r bob
sudo userdel -r carol
sudo groupdel webteam
sudo rm -rf /srv/webteam

Going further: add the sticky bit (chmod 3770 /srv/webteam) so Bob can edit Alice’s files but can’t delete them.


Glossary

TermDetail
UIDNumeric ID of a user. root is always 0
GIDNumeric ID of a group
Primary groupThe one group stored in /etc/passwd; new files get tagged with it
Secondary groupAny extra group a user is added to
sudoTool that runs one command with elevated privileges
Octal modePermissions written as numbers (4=r, 2=w, 1=x), like 750
setgidBit that makes new files in a directory inherit its group
Sticky bitBit that stops users from deleting each other’s files in a shared directory
umaskThe default “subtract these permissions” mask applied to new files

Finish

Thanks for following along. Before moving on, run through the post-test below and see how far you’ve come.


Post-test
Answer all 5 questions, then press Check answers.
1. What does chmod 750 report.sh do?
2. You run sudo usermod -G developers dave and Dave suddenly loses his sudo rights. What happened?
3. What does the setgid bit do on a shared directory?
4. You have r-- but no x on a directory. What happens when you run cd into it?
5. What is the safest way to give a coworker admin rights?
0 of 5 answered
This post is licensed under CC BY 4.0 by the author.