Start with the failing process
In a fictional batch incident, reading works as administrator but fails in the service. Before changing permissions, identify effective UID, groups, path, and operation: reading contents, creating a name, removing an entry, or executing a program. This lesson isolates DAC when the stem excludes ACLs, MAC, capabilities, and mount restrictions. Those controls still matter on a real system. Testing as root does not establish service access. Record observed identity and context so another operator can reproduce the check without relying on your session.
Traverse every component
Reading a file through its full path requires search permission on the necessary directories. File r does not grant x on parents. If /srv/report denies process search, result.csv can remain inaccessible despite apparently correct file mode. Also distinguish listing names from traversing a known directory. Check each component and effective identity before a recursive change. An overbroad fix can expose other data in the same branch. The objective is to allow the approved operation on the correct path and also check access that should remain denied.
Select the class, then evaluate rights
Owner, group, and other classes are not added to select the most permissive combination. If effective UID matches the owner, the owner entry is evaluated. In the 0460 example, the owner has r-- and cannot write even when belonging to the rw- group. An ownership change can therefore unexpectedly alter access. With named ACLs, follow the specific algorithm: the matching entry can be limited by the mask. Do not assume fallback to other after an applicable entry denies the request. Explain the selected class when justifying the decision.
Intersect ACL entry and mask
For a named non-owner user, r-x intersected with mask::rw- becomes r--. The mask removes x and does not create w missing from the entry. On a directory, this may allow observing names under suitable conditions without traversing the path to open a file. Before increasing the mask, review other covered entries because they can also gain effective rights. Default ACLs concern object creation rather than retroactively fixing every existing object. Confirm effective ACL after change and test with the identity needing access.
Separate group inheritance and mode creation
Setgid on a Linux directory can make new objects inherit its group. It does not itself grant group write. A file created as 0640 with group ops remains only group-readable. Without a default ACL, requested mode is limited by umask: 0666 & ~0027 gives 0640. This is neither decimal subtraction nor a calculation always starting from 0777. With a default ACL, creation rules differ and requested mode still limits rights. In the runbook, identify the mechanism actually controlling application-created files.
Distinguish contents, name, and inode
Removing a name operates on its containing directory. In the exercise without sticky bit or other restrictions, directory w+x can allow unlink of a 0444 file. Conversely, two hard links on one filesystem share an inode: content and mode changed through one name are observed through the other. A hard link called backup does not retain a former version. Recovery requires an independent copy or mechanism with verified consistency. File independence alone does not guarantee consistency during concurrent writes.
Respond to the observed error
Read-only file system points to a condition different from simply lacking mode write permission. Inspect the effective mount and kernel or storage events before broadening permissions. An automatic remount after errors can require integrity investigation rather than blind write retries. Preserve evidence and coordinate recovery with application owners. After fixing the cause, verify reading, writing, and restrictions with the real identity. This lesson’s bit models explain bounded decisions; they do not execute Linux ACLs or validate a production filesystem.
Owner r-- with group rw- does not grant owner write; 0666 with umask 0027 creates 0640 when no default ACL exists.
Common pitfalls
Adding classes, confusing a mask with a grant, setgid with write permission, or a hard link with a historical version.
Related topics: Identities and ACLs · Storage recovery
Access decisions depend on process, path, and operation; the filename does not tell the whole story.
Reference: acl(5) · LFCS current five-domain outline; exact edition date unconfirmed