Files, Links & Permissions
Files, Links & Permissions
8 interactive questions
Explain `chmod 755` and `chmod 644` in plain English.
Each octal digit is owner / group / other, summed from read=4, write=2, execute=1.
755 = owner rwx, group r-x, other r-x → scripts, binaries, and directories you
cdinto. 644 = owner rw-, group r--, other r-- → config and data files not meant to run. ⚠️ On a directory,xmeans "can traverse/enter,"rmeans "can list names" — they're separate.
Hard link vs soft (symbolic) link?
A hard link is another directory entry pointing at the same inode (same data). It can't cross filesystems or link directories, and the data survives until the last link is gone. A symlink is a small file holding a path to the target — it can cross filesystems and link directories but dangles if the target is deleted. 🎯 The key insight: a filename is just a pointer to an inode, not the data itself. Check with ls -li (same inode = hard links).
What is an inode?
A structure holding a file's metadata — permissions, owner, timestamps, size, and pointers to its data blocks. ⚠️ The name is not in the inode; the directory maps names → inode numbers. That's why hard links work and why you can be "out of space" with free disk via inode exhaustion (df -i).
atime vs mtime vs ctime?
mtime = file content last changed; ctime = metadata changed (permissions/owner, also changes on content change); atime = last accessed/read (often relaxed via relatime mounts). See all three with stat. 🎯 Backups usually key off mtime.
setuid, setgid, sticky bit?
setuid on an executable makes it run as the file's owner (that's how passwd edits /etc/shadow as root). setgid does the same for group, and on a directory makes new files inherit that group. Sticky bit on a world-writable dir (e.g. /tmp) means only a file's owner can delete it. In ls -l they show as s/s/t replacing the execute bit. 🎯 setuid is a real privilege-escalation surface — audit find / -perm -4000.
What does `umask` do?
It masks permission bits off new files. umask 022 → new files 644, new dirs 755 (files start from 666, dirs from 777, minus the mask). ⚠️ It's a mask, not the resulting permission.
How do you make a file immutable so even root can't change it accidentally?
sudo chattr +i file — blocks writes, deletes, renames until cleared with chattr -i; check with lsattr. ⚠️ It's a safety guard, not an authorization boundary — root can remove the flag. Not a substitute for version control.
You own a file but can't write to it. Possible reasons?
Walk the layers: the file's own perms lack write; the parent directory lacks write+execute (needed to modify entries); the immutable bit (chattr +i) is set; the filesystem is mounted read-only (often after it detected errors); or the disk/inodes are full. 🎯 Listing permissions → immutable → read-only mount shows field experience.