chmod Explained: What 755, 644 and 600 Actually Mean

Read Unix file permissions in octal and symbolic form, see what chmod 755, 644, 600 and 777 allow, and pick safe modes for scripts, web files and SSH keys.

· 4 min read

chmod 755, chmod 644, chmod 600. You've probably typed these from a Stack Overflow answer without being sure what the numbers mean. They're simpler than they look: three digits, each built from three permission bits. Once you can read them, you can pick the right one for any file in a few seconds.

Who and what: the permission model

Every file on Linux and macOS has three sets of permissions, one for each class of user:

ClassWho
User (u)The file's owner
Group (g)Members of the file's group
Others (o)Everyone else

Each class can have three permissions:

PermissionOn a fileOn a directory
Read (r)View the contentsList the files inside
Write (w)Change the contentsCreate, delete and rename files inside
Execute (x)Run it as a programEnter it (cd) and reach files inside

Directory permissions catch people out. Without x on a directory, you can't open the files in it even if those files are readable.

Reading octal: 4, 2 and 1

Each permission has a value, and you add them up per class:

PermissionValue
Read4
Write2
Execute1

So each digit runs from 0 to 7:

DigitSumSymbolicMeaning
74+2+1rwxRead, write, execute
64+2rw-Read, write
54+1r-xRead, execute
44r--Read only
00---Nothing

The three digits are user, group and others, in that order. 754 means the owner gets 7 (rwx), the group gets 5 (r-x) and others get 4 (r--).

If you'd rather click checkboxes, the chmod calculator converts between checkboxes, octal, symbolic notation and the ready-to-run command.

The common modes

ModeSymbolicTypical use
755rwxr-xr-xScripts, programs and directories: everyone can run or enter, only the owner can change
644rw-r--r--Ordinary files: web pages, config, source code
700rwx------Private directories, such as ~/.ssh
600rw-------Private files: SSH private keys, .env files, credentials
664 / 775rw-rw-r-- / rwxrwxr-xFiles and directories a team edits together through a shared group
444r--r--r--Files nobody should change, including the owner without a chmod first
777rwxrwxrwxAlmost never. Anyone on the machine can change or replace the file

Why 777 is a bad fix

When something fails with "Permission denied", chmod 777 makes the error go away, which is why it gets suggested so often. It also lets every user and every process on the machine rewrite the file. On a web server, that can mean an attacker who gets in through one site can change another site's code. Find out which user needs access, then grant that user access, usually by fixing ownership with chown rather than opening permissions to everyone.

Symbolic mode: changing one thing at a time

Octal sets all nine bits at once. Symbolic mode changes only what you name:

chmod u+x deploy.sh        # let the owner run it
chmod g-w report.csv       # take write away from the group
chmod o= secrets.txt       # remove every permission for others
chmod a+r index.html       # let everyone read it (a = all three classes)
chmod u=rw,go=r notes.md   # same as 644

Use + to add, - to remove and = to set exactly.

Reading ls -l

$ ls -l
-rwxr-xr-x  1 ada  staff  1204 Aug 20 10:12 deploy.sh
-rw-------  1 ada  staff   411 Aug 20 10:12 id_ed25519
drwx------  4 ada  staff   128 Aug 20 10:12 .ssh

The first character is the type: - for a file, d for a directory, l for a symbolic link. The next nine are the permissions in user, group, others order. So deploy.sh is 755, the key is 600, and .ssh is a 700 directory.

Setting permissions on a whole tree

chmod -R applies one mode to everything under a directory. Be careful with it: chmod -R 755 site/ makes every file executable, which you rarely want. Set directories and files separately instead:

find site/ -type d -exec chmod 755 {} +
find site/ -type f -exec chmod 644 {} +

SSH key permissions

SSH refuses to use a private key that other users can read, and fails with "UNPROTECTED PRIVATE KEY FILE". The usual fix:

chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519
chmod 644 ~/.ssh/id_ed25519.pub
chmod 600 ~/.ssh/authorized_keys

Special bits: the fourth digit

You'll sometimes see four digits, like 2775 or 1777. The leading digit holds three special bits:

ValueBitEffect
4setuidAn executable runs as its owner rather than as whoever started it
2setgidOn a directory, new files inherit the directory's group, which helps shared folders
1stickyOn a directory, only a file's owner can delete it. /tmp is 1777 for this reason

Avoid setting setuid yourself. A setuid program owned by root runs with root's power, so any bug in it becomes a security hole.

Quick reference

  • Digits are user, group, others. Read = 4, write = 2, execute = 1.
  • 755 for scripts and directories, 644 for normal files, 600 for secrets.
  • Directories need x for anyone to reach the files inside.
  • Fix ownership with chown instead of reaching for 777.

Working out a mode? The chmod calculator shows the octal, symbolic and command forms side by side.