Skip to content
← System engineer foundations

Learning bite

Build a permission diagnosis

Separate observation, hypothesis, repair, and verification.

Documentation reviewed2026-10-01 · 3 min read
On this page

Turn an error into a specific access question

“Permission denied” does not identify the failing check. A program may be unable to search a parent directory, read a file, write an existing file, or create a new directory entry. Start with four facts: the account, the path, the working directory, and the requested operation.

Use the Ubuntu learning machine as a regular user. This worked failure is deliberately limited to a new temporary directory; keep this terminal open through cleanup.

bash
study_access=$(mktemp -d)
mkdir "$study_access/config"
printf 'theme=plain\n' > "$study_access/config/settings.txt"
chmod 600 "$study_access/config/settings.txt"
chmod 600 "$study_access/config"
id
ls -ld "$study_access" "$study_access/config"
cat "$study_access/config/settings.txt"

The final read should fail under ordinary user permissions. The file has owner read access, but config is a directory with owner rw-: it lacks search permission. File lookup cannot reach settings.txt. A failed ls -l on the child is therefore useful evidence, not proof that the child is absent.

If available, namei -l "$study_access/config/settings.txt" displays each path component and its mode. It helps spot an inaccessible parent several levels above the file. This read-only tool may itself stop where your account cannot inspect further.

Predict a repair before making it

The owner needs to resolve a name within config. The smallest missing bit is owner search, so add that bit to that directory:

bash
chmod u+x "$study_access/config"
cat "$study_access/config/settings.txt"
ls -ld "$study_access/config"
ls -l "$study_access/config/settings.txt"

Expected content is theme=plain; expected directory owner mode is now rwx. The file remains private (600). Reading it with sudo would change the requesting identity and would not demonstrate that the original user can read it. Likewise, making every file world-writable would not test the hypothesis carefully.

When the ordinary bits do not explain it

Check the actual process identity, not just your login. Services may use another account, an older set of supplementary groups, or a different filesystem view. Resolve symbolic links and verify the final target. Then inspect the relevant extra layer:

ObservationNext question
A + follows the modeDoes getfacl PATH, if installed, show a named-user/group ACL or an ACL mask limiting effective rights?
Mode grants write, error says read-only filesystemDoes findmnt -T PATH show a read-only mount?
Access differs between shell and serviceWhat user, working directory, and service restrictions apply?
Modes and identity appear rightDo AppArmor/SELinux policy logs explain a denial?

An ACL is an access control list that can grant named users or groups additional rules; its mask can limit several entries. A default directory ACL affects newly created children. Do not start changing ACLs or security policy until there is evidence that they caused this failure. Those deeper administration exercises are optional here.

Explain the result without guessing

A useful note would say: “My regular user could not read this fixture because its config parent had no owner search bit. I added u+x to that directory and repeated the same read successfully.” Write that only if it matches your actual observations. If the read unexpectedly succeeds, check whether you used root or a different filesystem.

Why inspect the resulting file mode after a successful read? Success proves access now works; checking the mode also shows that the repair did not grant unnecessary access. The next lab repeats this reasoning with explicit before/after checks.

bash
rm -- "$study_access/config/settings.txt"
rmdir "$study_access/config" "$study_access"

Sources

For the permission model, consult GNU Coreutils↗.

Your notes and evidence

Record observations, questions, or links to your work. Keep credentials out of your notes.

Loading saved progress…

Back up or restore this path

Progress and notes stay in this browser. A backup contains only this learning path.