Skip to content

Chmod Examples

Common Unix permission modes, what they allow and when to use them.

About Chmod examples

Unix permissions control who can read, write and execute a file. There are three classes of user, the owner, the file's group and everyone else, and each gets three bits: read (4), write (2) and execute (1). Adding the bits gives one octal digit per class, which is why permissions are written as three digits such as 644. ls -l shows the same thing symbolically, as rwxr-xr-x.

For directories the bits mean something slightly different: read lets you list the names inside, write lets you create, rename and delete entries, and execute lets you enter the directory and reach the files in it. A fourth, leading digit sets special bits: 4 for setuid, 2 for setgid and 1 for the sticky bit. Use the chmod calculator to build any combination.

Common modes

ModeSymbolicWho can do whatTypical use
400r--------Owner can read; nobody else has accessRead-only secrets, such as a cloud SSH key file
444r--r--r--Everyone can read; nobody can writeFiles that must not be changed by accident
600rw-------Owner can read and write; nobody else has accessSSH private keys, .env files, ~/.ssh/config
640rw-r-----Owner reads and writes, group reads, others nothingConfig files read by a service's group
644rw-r--r--Owner reads and writes, everyone else readsRegular files, web pages, public SSH keys
660rw-rw----Owner and group read and write, others nothingFiles shared within a team's group
664rw-rw-r--Owner and group write, everyone readsShared project files
666rw-rw-rw-Everyone can read and writeRarely appropriate; avoid
700rwx------Owner has full access; nobody else has any~/.ssh and other private directories
711rwx--x--xOthers can enter but not list the directoryHome directories on some systems
750rwxr-x---Owner full, group can read and enter, others nothingDirectories shared with a group
755rwxr-xr-xOwner full access, everyone else reads and executesDirectories, scripts and programs
775rwxrwxr-xOwner and group full access, others read and executeGroup-writable project directories
777rwxrwxrwxEveryone can read, write and executeAlmost never: anyone can change or replace the file
1777rwxrwxrwtWorld-writable with the sticky bit: only owners can delete their files/tmp
2775rwxrwsr-xSetgid directory: new files inherit the directory's groupShared team directories
4755rwsr-xr-xSetuid: the program runs with the owner's privilegesSystem programs such as passwd; avoid on your own scripts

What each digit means

DigitSymbolicPermission
0---No permission
1--xExecute (enter, for a directory)
2-w-Write
3-wxWrite and execute
4r--Read (list, for a directory)
5r-xRead and execute
6rw-Read and write
7rwxRead, write and execute

chmod commands

CommandWhat it does
chmod 644 file.txtSet exact permissions in octal
chmod u+x script.shAdd execute for the owner (u)
chmod +x script.shAdd execute for everyone, minus the umask
chmod go-w file.txtRemove write from group (g) and others (o)
chmod a+r file.txtAdd read for all (a = u, g and o)
chmod u=rw,go=r file.txtSet exactly: same as 644
chmod -R 755 dir/Apply recursively to a directory and everything in it
find dir -type f -exec chmod 644 {} +Set files only to 644 (leave directories alone)
find dir -type d -exec chmod 755 {} +Set directories only to 755
stat -c '%a %n' file.txtShow the octal mode (GNU stat; on macOS: stat -f '%Lp %N')

Good to know

Permission denied?

Check ownership before widening permissions: ls -l shows the owner and group, and chown fixes them. chmod 777 makes the error go away by letting every user on the system change the file, which is rarely what you want, especially on a web server.

More references