chmod 755, chmod 644, chmod 600. You've probably typed these from a Stack Overflow answer without being sure what the numbers mean. They're simpler than they look: three digits, each built from three permission bits. Once you can read them, you can pick the right one for any file in a few seconds.
Who and what: the permission model
Every file on Linux and macOS has three sets of permissions, one for each class of user:
| Class | Who |
|---|---|
| User (u) | The file's owner |
| Group (g) | Members of the file's group |
| Others (o) | Everyone else |
Each class can have three permissions:
| Permission | On a file | On a directory |
|---|---|---|
| Read (r) | View the contents | List the files inside |
| Write (w) | Change the contents | Create, delete and rename files inside |
| Execute (x) | Run it as a program | Enter it (cd) and reach files inside |
Directory permissions catch people out. Without x on a directory, you can't open the files in it even if those files are readable.
Reading octal: 4, 2 and 1
Each permission has a value, and you add them up per class:
| Permission | Value |
|---|---|
| Read | 4 |
| Write | 2 |
| Execute | 1 |
So each digit runs from 0 to 7:
| Digit | Sum | Symbolic | Meaning |
|---|---|---|---|
| 7 | 4+2+1 | rwx | Read, write, execute |
| 6 | 4+2 | rw- | Read, write |
| 5 | 4+1 | r-x | Read, execute |
| 4 | 4 | r-- | Read only |
| 0 | 0 | --- | Nothing |
The three digits are user, group and others, in that order. 754 means the owner gets 7 (rwx), the group gets 5 (r-x) and others get 4 (r--).
If you'd rather click checkboxes, the chmod calculator converts between checkboxes, octal, symbolic notation and the ready-to-run command.
The common modes
| Mode | Symbolic | Typical use |
|---|---|---|
755 | rwxr-xr-x | Scripts, programs and directories: everyone can run or enter, only the owner can change |
644 | rw-r--r-- | Ordinary files: web pages, config, source code |
700 | rwx------ | Private directories, such as ~/.ssh |
600 | rw------- | Private files: SSH private keys, .env files, credentials |
664 / 775 | rw-rw-r-- / rwxrwxr-x | Files and directories a team edits together through a shared group |
444 | r--r--r-- | Files nobody should change, including the owner without a chmod first |
777 | rwxrwxrwx | Almost never. Anyone on the machine can change or replace the file |
Why 777 is a bad fix
When something fails with "Permission denied", chmod 777 makes the error go away, which is why it gets suggested so often. It also lets every user and every process on the machine rewrite the file. On a web server, that can mean an attacker who gets in through one site can change another site's code. Find out which user needs access, then grant that user access, usually by fixing ownership with chown rather than opening permissions to everyone.
Symbolic mode: changing one thing at a time
Octal sets all nine bits at once. Symbolic mode changes only what you name:
chmod u+x deploy.sh # let the owner run it
chmod g-w report.csv # take write away from the group
chmod o= secrets.txt # remove every permission for others
chmod a+r index.html # let everyone read it (a = all three classes)
chmod u=rw,go=r notes.md # same as 644Use + to add, - to remove and = to set exactly.
Reading ls -l
$ ls -l
-rwxr-xr-x 1 ada staff 1204 Aug 20 10:12 deploy.sh
-rw------- 1 ada staff 411 Aug 20 10:12 id_ed25519
drwx------ 4 ada staff 128 Aug 20 10:12 .sshThe first character is the type: - for a file, d for a directory, l for a symbolic link. The next nine are the permissions in user, group, others order. So deploy.sh is 755, the key is 600, and .ssh is a 700 directory.
Setting permissions on a whole tree
chmod -R applies one mode to everything under a directory. Be careful with it: chmod -R 755 site/ makes every file executable, which you rarely want. Set directories and files separately instead:
find site/ -type d -exec chmod 755 {} +
find site/ -type f -exec chmod 644 {} +SSH key permissions
SSH refuses to use a private key that other users can read, and fails with "UNPROTECTED PRIVATE KEY FILE". The usual fix:
chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_ed25519
chmod 644 ~/.ssh/id_ed25519.pub
chmod 600 ~/.ssh/authorized_keysSpecial bits: the fourth digit
You'll sometimes see four digits, like 2775 or 1777. The leading digit holds three special bits:
| Value | Bit | Effect |
|---|---|---|
| 4 | setuid | An executable runs as its owner rather than as whoever started it |
| 2 | setgid | On a directory, new files inherit the directory's group, which helps shared folders |
| 1 | sticky | On a directory, only a file's owner can delete it. /tmp is 1777 for this reason |
Avoid setting setuid yourself. A setuid program owned by root runs with root's power, so any bug in it becomes a security hole.
Quick reference
- Digits are user, group, others. Read = 4, write = 2, execute = 1.
755for scripts and directories,644for normal files,600for secrets.- Directories need
xfor anyone to reach the files inside. - Fix ownership with
chowninstead of reaching for777.
Working out a mode? The chmod calculator shows the octal, symbolic and command forms side by side.