Chmod Examples
Common Unix permission modes, what they allow and when to use them.
About Chmod examples
Unix permissions control who can read, write and execute a file. There are three classes of user, the owner, the file's group and everyone else, and each gets three bits: read (4), write (2) and execute (1). Adding the bits gives one octal digit per class, which is why permissions are written as three digits such as 644. ls -l shows the same thing symbolically, as rwxr-xr-x.
For directories the bits mean something slightly different: read lets you list the names inside, write lets you create, rename and delete entries, and execute lets you enter the directory and reach the files in it. A fourth, leading digit sets special bits: 4 for setuid, 2 for setgid and 1 for the sticky bit. Use the chmod calculator to build any combination.
Common modes
| Mode | Symbolic | Who can do what | Typical use |
|---|---|---|---|
| 400 | r-------- | Owner can read; nobody else has access | Read-only secrets, such as a cloud SSH key file |
| 444 | r--r--r-- | Everyone can read; nobody can write | Files that must not be changed by accident |
| 600 | rw------- | Owner can read and write; nobody else has access | SSH private keys, .env files, ~/.ssh/config |
| 640 | rw-r----- | Owner reads and writes, group reads, others nothing | Config files read by a service's group |
| 644 | rw-r--r-- | Owner reads and writes, everyone else reads | Regular files, web pages, public SSH keys |
| 660 | rw-rw---- | Owner and group read and write, others nothing | Files shared within a team's group |
| 664 | rw-rw-r-- | Owner and group write, everyone reads | Shared project files |
| 666 | rw-rw-rw- | Everyone can read and write | Rarely appropriate; avoid |
| 700 | rwx------ | Owner has full access; nobody else has any | ~/.ssh and other private directories |
| 711 | rwx--x--x | Others can enter but not list the directory | Home directories on some systems |
| 750 | rwxr-x--- | Owner full, group can read and enter, others nothing | Directories shared with a group |
| 755 | rwxr-xr-x | Owner full access, everyone else reads and executes | Directories, scripts and programs |
| 775 | rwxrwxr-x | Owner and group full access, others read and execute | Group-writable project directories |
| 777 | rwxrwxrwx | Everyone can read, write and execute | Almost never: anyone can change or replace the file |
| 1777 | rwxrwxrwt | World-writable with the sticky bit: only owners can delete their files | /tmp |
| 2775 | rwxrwsr-x | Setgid directory: new files inherit the directory's group | Shared team directories |
| 4755 | rwsr-xr-x | Setuid: the program runs with the owner's privileges | System programs such as passwd; avoid on your own scripts |
What each digit means
| Digit | Symbolic | Permission |
|---|---|---|
| 0 | --- | No permission |
| 1 | --x | Execute (enter, for a directory) |
| 2 | -w- | Write |
| 3 | -wx | Write and execute |
| 4 | r-- | Read (list, for a directory) |
| 5 | r-x | Read and execute |
| 6 | rw- | Read and write |
| 7 | rwx | Read, write and execute |
chmod commands
| Command | What it does |
|---|---|
| chmod 644 file.txt | Set exact permissions in octal |
| chmod u+x script.sh | Add execute for the owner (u) |
| chmod +x script.sh | Add execute for everyone, minus the umask |
| chmod go-w file.txt | Remove write from group (g) and others (o) |
| chmod a+r file.txt | Add read for all (a = u, g and o) |
| chmod u=rw,go=r file.txt | Set exactly: same as 644 |
| chmod -R 755 dir/ | Apply recursively to a directory and everything in it |
| find dir -type f -exec chmod 644 {} + | Set files only to 644 (leave directories alone) |
| find dir -type d -exec chmod 755 {} + | Set directories only to 755 |
| stat -c '%a %n' file.txt | Show the octal mode (GNU stat; on macOS: stat -f '%Lp %N') |
Good to know
Permission denied?
Check ownership before widening permissions: ls -l shows the owner and group, and chown fixes them. chmod 777 makes the error go away by letting every user on the system change the file, which is rarely what you want, especially on a web server.
More references
- HTTP status codesEvery HTTP status code and what it means
- MIME typesCommon MIME types by file extension
- ASCII tableAll 128 ASCII codes in dec, hex, octal and binary
- HTML entitiesNamed HTML entities with their codes
- Regex cheat sheetRegular expression syntax at a glance
- Cron examples30 common cron schedules explained
- Unix timestamp referenceNotable epochs, the 2038 problem and code
- Git cheat sheetEveryday Git commands in one place
- Markdown cheat sheetMarkdown and GitHub Flavored syntax