One grid, four notations
The checkbox matrix, the three-digit octal, the four-digit octal, the symbolic string, and the ls -l line are all views of the same nine bits, and every one of them redraws on the keystroke.
Turn read, write, and execute checkboxes into an octal mode, a symbolic string, and a chmod command, or paste a mode you already have and see, in plain words, exactly who it lets in.
Mode 755, symbolic rwxr-xr-x, on a file. chmod 755 script.sh. No warnings.
Each class gets its own octal digit, and each digit is just the ticked boxes added together.
| Class | Readr · 4 | Writew · 2 | Executex · 1 | Digit |
|---|---|---|---|---|
| Owneru · user | 4 + 2 + 17 | |||
| Groupg · group | 4 + 15 | |||
| Otherso · world | 4 + 15 |
Open the file and read its bytes, or copy it elsewhere.
Change or truncate the contents. Deleting the file is governed by its directory instead.
Run it as a program. A script also needs read, because the interpreter has to open it.
These three live in front of the mode, in a digit most people never write. Each one changes who a process becomes or what a directory allows; read the note before you set one.
The owner can read the file, change the file and run it as a program.
One account: the user id recorded on the inode, and the first of the two names in an ls -l line. Root bypasses these checks almost entirely, so a mode only ever constrains ordinary users.
Group members can read the file and run it as a program.
Every account in the file's group, which is the second name in an ls -l line. Membership is what lets a team share write access without opening it to the machine.
Everyone else can read the file and run it as a program.
Everyone the first two classes missed: other logins, and every daemon account such as www-data or nobody. This is the class attackers land in.
No world-writable bit, no special bit that cannot fire. That is not the same as correct: the mode still has to match what this file is for.
A single recursive chmod gives directories and documents the same mode: either the files come out executable or the directories come out impossible to enter. Split it in two and each kind gets what it needs.
find script.sh -type d -exec chmod 755 {} +find script.sh -type f -exec chmod 644 {} +A umask subtracts. The kernel offers 666 to a new file and 777 to a new directory, then clears every bit the mask names.
Under the usual 022 this is why a file you just created arrives as 644 rather than 666: the mask took the group and other write bits away before you ever saw it. Nothing here changes your shell; it is arithmetic on the value you typed.
Generate the credentials that belong in a 600 file, with entropy you can actually justify.
Check a downloaded binary against its published checksum before you give it an execute bit.
Read the epoch times in log lines and file metadata that sit next to these modes.
Unix records permissions as nine bits: read, write, and execute, repeated for the owner, the group, and everyone else. Group three bits together and each triple fits in a single octal digit from 0 to 7, which is the only reason chmod takes numbers like 755 instead of a sentence. The kernel checks the classes in order (owner first, then group, then others) and stops at the first one that matches you, so a mode that is generous to others cannot rescue an owner who was denied.
The same three bits mean different things on each. Flip the switch first and every explanation on the page follows it: execute stops meaning run and starts meaning enter.
Toggle read, write, and execute for owner, group, and others. Have a mode in front of you instead? Drop 0644 or the ten characters from an ls -l listing into the reverse field and the grid fills itself in.
Set the real target, then copy the octal command, the assignment form for scripting, or the pair of find commands that give directories and documents different modes in one pass.
The checkbox matrix, the three-digit octal, the four-digit octal, the symbolic string, and the ls -l line are all views of the same nine bits, and every one of them redraws on the keystroke.
Paste 700, 0755, rwxrwxr-x, or drwxr-xr-x. The ten-character listing form even sets the file-or-directory switch from its leading letter, and anything unparseable says so instead of quietly ignoring you.
Read lists names, write adds and removes entries, execute lets a lookup pass through. Those sentences are generated from the mode you have, not printed from a fixed table.
setuid, setgid, and sticky each get their own control and their own explanation, including the cases the kernel ignores entirely: setuid on a shell script, sticky on a plain file.
World-writable, a setuid bit sitting on a file nobody can execute, a script with execute but no read: each is called out in its own colour, with the reason rather than a scolding.
Octal, the u=rwx,g=rx,o=rx assignment form, and the two find commands for a mixed tree, with the target path you typed already in place. All of it is built in your browser.
Each digit is one class: owner, then group, then others. Within a digit, read is worth 4, write 2, and execute 1, so 7 is 4+2+1 (read, write, execute), 5 is 4+1 (read and execute) and 0 is nothing. 755 therefore lets the owner do everything, while the group and everyone else may read and execute but not modify. It is the usual mode for a program and for almost every directory on a system.
Only the execute bit. 644 grants the owner read and write and gives everyone else read; 755 adds execute for all three classes. Data files want 644; an executable bit on a PDF or a photo does nothing but confuse. Programs, shell scripts, and every directory want 755, because a directory without execute cannot be entered even by someone who can list it.
It grants write to every account on the machine, which includes the service accounts an attacker reaches first. A web server running as www-data that can rewrite the application it serves turns a small file-upload flaw into arbitrary code execution. Reaching for 777 also means the real cause (usually the wrong owner or group) is never found, so the exposure stays long after the original error is forgotten. Fix ownership with chown and grant the narrowest mode that works.
Only when you are setting setuid (4000), setgid (2000), or the sticky bit (1000). Writing 755 and 0755 does the same thing, because a missing leading digit is read as zero. Clearing those bits again is where the surprise is: GNU chmod deliberately leaves a directory's setuid and setgid alone unless you name them, so on Linux neither chmod 755 nor chmod 0755 takes setgid off a directory; that needs chmod g-s, chmod =755, or the five-digit chmod 00755. BSD chmod, macOS included, clears them from a plain three-digit mode instead. On a regular file every version clears them.
It means the special bit is set but the matching execute bit is not, so the special bit cannot fire. rwSr--r-- is a setuid file the owner cannot execute; drwxrwxrwT is a sticky directory with no execute for others. A lowercase s or t means both bits are set and the behaviour is live. A capital letter usually means the execute bit was cleared after the special bit was set, or that a four-digit mode was typed without the matching x; either way the mode does not do what it looks like it does.
Because deleting is not an operation on the file, it is an operation on the directory that holds the name. Write plus execute on the directory is enough to unlink any entry inside it, whatever the file itself says. That is precisely the hole the sticky bit closes: on a 1777 directory such as /tmp, only the owner of an entry, the owner of the directory, or root may remove it.
It grants traversal: the right to resolve a name inside it and reach anything deeper. Read and execute are independent: read without execute lets you list the names but not use them, so ls works and opening any of the results fails. Execute without read is the reverse, and is a real technique: mode 711 on a home directory lets a web server reach public_html without letting anyone list what else is in there. Every directory along a path needs execute, or the lookup fails at that level.
chmod sets a mode outright; umask only ever takes bits away, and only at the moment something is created. The kernel offers 666 for a new file and 777 for a new directory, then clears every bit the mask names, which is why the common umask of 022 produces 644 files and 755 directories, and why new files are never executable. It is a per-process setting, so changing it in a shell affects that shell and its children, and nothing that already exists.
Explore the growing collection for calculations, documents, writing, and everyday work.