Nearly all user directories are now on AFS. The handling of permissions in AFS is significantly different from those of NFS. For information on how file permissions work in AFS, read the stock answer titled "How permissions work in AFS" under the "AFS" topic. However, there is some small similarity, which is outlined in the answer below. Even if you are only concerned about AFS, you will probably still want to read this answer, although not all of it will be applicable. The rest of the material listed here is primarily specific to NFS and UFS. Some non-user lockers, however, still operate under NFS. UFS controls directories that are local to your workstation, such as /tmp and /usr/tmp. Its permission handling mechanisms are the ones used by NFS. When dealing with Unix files in NFS or UFS, there are three ways you can specify WHO can access them, and three ways you can specify HOW someone can access them. First, the HOW: READ If someone has read permission on a file, he can look at its contents. This naturally also means he can copy it. Someone who has read permission on a directory can find out what files exist in that directory. He cannot find out detailed information about those files, or read their contents, unless he has execute access to the directory. The Athena default gives no one but you read access to your files and directories. WRITE Someone who has write access to a file can change its contents ONLY. If someone has write permission to a directory, he can change its contents. This includes creating new files, renaming files, and removing files in that directory. The Athena default gives no one but you write permission to your files and directories. EXECUTE Someone who has execute permission for a file can run it as a Unix program. That is, he can just type its name and it will be run, whether it is a shell script or compiled program. This is useful if you want other people to be able to run a program but not be able to copy it. If someone has execute access to a directory, then he can 'cd' to it and look at the contents of files in that directory, depending on their individual protections. He cannot find out WHAT files are in that directory, however, without read access. This is the Athena default. It lets you easily give files to friends by telling them the names of the shared files, provided you give them read access to the files first. But they can't find out what OTHER files you have in your directory. Now, the WHO: OWNER This is you, of course, for your own file or directory. Each file or directory has an OWNER. GROUP Every file or directory has a GROUP. By default, this group is probably 'mit' for your files IF you got your account before September of 1988. IF you got your account after September of 1988, the group will be the same name as your login name. Files and directories inherit their group from their 'parents', the directories above them, unless you specify otherwise. WORLD This is everybody else. **** In AFS, only the information for OWNER is relevant. Permission **** must be set for the OWNER to read, write, or execute the file if **** ANYONE is to be able to do it. All other information (GROUP and **** WORLD) is ignored. To see all of these protections for a file or directory, use 'ls -lg': ls -lg a.out -rwxr--r-- 1 oconsult olc_adm 1237 Feb 1 22:30 a.out ^ ^ ^ ^ ^ ^ ^ ^ | | | | | | | | USER | WORLD OWNER GROUP SIZE DATE NAME GROUP (in bytes) The 'chmod' ("change mode") and 'chgrp' ("change group") commands let you change the group and protection for a file. For more information on them, you can read the appropriate manual pages by using the 'man' command: man chmod man chgrp See also the answer "How to change permissions" under the "UNIX" topic.