A file refuses to open, a script will not run, or a shared folder blocks the wrong person. Linux handles those problems through owner, group, other-user permissions, ACLs, ownership, defaults, and mount rules. Start with the file manager for a single item, then use the terminal paths when you need precision or admin-level control.
Start in your file manager
For a single file or folder you own, the graphical Properties window is the cleanest first stop.
- 1.Open Files.
- 2.Right-click the file or folder and choose Properties.
- 3.Open Permissions.
- 4.Adjust the owner, group, and other-user permission controls.
- 5.Close the window after the permissions are set.
Make a script executable
When a downloaded script or program will not run, give that regular file execute permission. In GNOME Files, right-click the file, open Properties, open Permissions, and switch on Executable as Program.
If this method fails, open a terminal in the folder that contains the file and run chmod u+x script.sh.
Use Thunar or Dolphin on other desktops
This method applies when your Linux desktop uses Xfce Thunar or KDE Dolphin instead of GNOME Files. Both use the same basic route: select the item, open Properties, and adjust permissions from there.
In Xfce Thunar, select the file or folder, open File, and choose Properties....
You can also right-click the item and choose Properties..., or press Alt-Return.
Open Permissions and change the UNIX file permissions.
In KDE Dolphin, select the item, open File, and choose Properties, or press Alt+Return.
Open the Permissions tab, adjust the permissions or ownership controls, then choose Apply or OK.
Run chmod for faster changes
Use chmod when the terminal is faster than clicking through a permissions window.
- 1.Open a terminal in the folder that contains the file.
- 2.Run chmod u+x script.sh to give yourself execute permission on a script.
- 3.Run chmod go-rw private.txt to remove read and write access from group and other users.
- 4.Run chmod 644 notes.txt for a document-style mode.
- 5.Run chmod 755 script.sh for an executable-style mode.
Change a folder tree with care
Folder-wide changes help when many contained files and folders have the wrong permissions at once. In GNOME Files, right-click the folder, open Properties, open Permissions, choose Change Permissions for Enclosed Files..., set the drop-down options for contained files and folders, then choose Change.
From a terminal, chmod -R MODE FOLDER applies a mode through a folder tree. Use -H, -L, or -P when you need to control symlink traversal.
If this method fails, check ownership next; changing ownership requires sudo chown OWNER:GROUP FILE or sudo chown -R OWNER:GROUP FOLDER on systems where your account has sudo permission.
Give one user or group special access
Use ACLs when the normal owner, group, and everyone-else permissions are too broad. This route needs the setfacl utility and a filesystem that stores POSIX ACLs, such as ext4, XFS, or btrfs. On a filesystem without ACL support, setfacl falls back to the file mode permission bits, and when the ACL cannot be represented there it writes an error and exits with a non-zero status.
Run setfacl -m u:USERNAME:rwx FILE to add or modify access for one named user.
Run setfacl -m g:GROUP:rx FILE to give a group read and execute access.
Run setfacl -x u:USERNAME FILE to remove a named user ACL.
Run setfacl -b FILE to clear all extended ACL entries.
Run setfacl -d -m u:USERNAME:rwx FOLDER or setfacl -d -m g:GROUP:rwx FOLDER to set default ACLs for new items inside a folder.
Default ACLs apply to newly created files and folders, so change existing items separately when they already sit inside the folder.
Fix ownership and admin blocks
This fixes files that have the right permission pattern but belong to the wrong user or group.
Run chown OWNER FILE to change the owner of a file.
Run chown OWNER:GROUP FILE to change both owner and group.
Run chgrp GROUP FILE to change only the group.
Add -R only when the ownership or group change must apply through a folder tree.
Run the exact command with sudo when Linux denies the change, such as sudo chmod MODE FILE, sudo chown OWNER:GROUP FILE, or sudo setfacl ... FILE, then authenticate when prompted.
Set defaults and removable drive permissions
When the parent folder carries no default ACL, the umask command controls permissions assigned to newly created files and folders by the current shell and its child processes. A default ACL on the parent folder overrides umask: the mask is ignored and the new item inherits that ACL instead. Run umask to view the current mask, then run umask 022 or umask 002 before creating new items.
umask does not rewrite existing files. To make it persistent, place the shell's umask command in the user's shell startup files according to your distribution and shell policy.
For Windows-style filesystems such as NTFS, VFAT, and exFAT, normal per-file Unix ownership is not stored the same way as on ext4 or btrfs. Set behavior through mount options such as uid=1000, gid=1000, umask=022, dmask=022, or fmask=133, then unmount and remount the drive.
On systems that use UDisks 2.9.0 or later for desktop or removable-drive mounting, administrators set auto-mount policy in /etc/udisks2/mount_options.conf with entries such as vfat_defaults=uid=$UID,gid=$GID,... and vfat_allow=uid=$UID,gid=$GID,umask,dmask,fmask,... under the matching config section. Write each set out in full, because a _defaults or _allow set fully replaces the built-in set for that filesystem, and keep every option you put in _defaults permitted by _allow. These overrides cover only drives UDisks mounts itself; a device listed in /etc/fstab takes its options from that file instead. UDisks recomputes the options on every mount call, so no daemon reload is needed: unmount an already-mounted drive and mount it again to pick up the change.
Remove attributes that block changes
This fixes files that still refuse editing or deletion after the permission bits look right.
Run lsattr FILE to inspect file attributes on an ext2, ext3, or ext4 filesystem. Not every filesystem supports or uses these attributes, so on other filesystems check the filesystem-specific documentation, such as btrfs(5) or xfs(5).
Run sudo chattr -i FILE to remove the immutable attribute.
Run sudo chattr -a FILE to remove the append-only attribute.
Run sudo chattr +i FILE to make a file immutable when that lock is intentional.
Run sudo chattr +a FILE to make a file append-only when that behavior is intentional.
If this method fails on a work, school, or managed computer, contact the device administrator. Policy, account permissions, filesystem support, or mount rules block changes even when the command syntax is correct.
Frequently Asked Questions
How do I copy permissions from one Linux file to another?
Run chmod --reference=RFILE FILE, replacing RFILE with the file whose mode you want to copy and FILE with the target file.
Do I need sudo or su to change permissions?
Use sudo on the specific chmod, chown, or setfacl command when your account is authorized. su works only on systems where the root account has an enabled password and system policy permits it.
Why does chmod not work on my USB drive?
NTFS, VFAT, and exFAT drives use mount options for Linux ownership and permission behavior. Set uid, gid, umask, dmask, or fmask and remount the drive.
Do default ACLs change files already inside a folder?
No. Default ACLs apply to newly created files and folders inside that folder; existing items need their own chmod or setfacl change.