A file's permissions say who may read (r), write (w) or execute (x) it, separately for three audiences: the user that owns it (u), the owner's group (g) and others (o). chmod changes them. The Chmod Calculator does the arithmetic for you.
Reading ls -l
-rwxr-xr-- 1 ana staff 1024 Oct 3 10:00 deploy.sh
The first character is the type (- file, d directory, l symbolic link). The next nine are three groups of three: rwx for the owner, r-x for the group and r-- for others. So this script is 754: the owner can do everything, the group can read and run it, others can only read it.
Octal digits
Each audience gets one digit that is the sum of read = 4, write = 2 and execute = 1.
| Digit | Binary | Permissions |
|---|---|---|
7 |
111 |
rwx read + write + execute |
6 |
110 |
rw- read + write |
5 |
101 |
r-x read + execute |
4 |
100 |
r-- read |
3 |
011 |
-wx write + execute |
2 |
010 |
-w- write |
1 |
001 |
--x execute |
0 |
000 |
--- none |
Common modes
| Octal | Symbolic | Meaning |
|---|---|---|
644 |
-rw-r--r-- |
Normal file: you read and write, everyone else reads |
600 |
-rw------- |
Private file: only you (SSH keys, secrets) |
640 |
-rw-r----- |
You read and write, your group reads, others get nothing |
664 |
-rw-rw-r-- |
You and your group write, others read |
755 |
-rwxr-xr-x |
Program or directory: you do everything, others read and run |
700 |
-rwx------ |
Private program or directory: only you |
750 |
-rwxr-x--- |
You do everything, your group reads and runs, others nothing |
775 |
-rwxrwxr-x |
Shared directory: you and your group do everything |
444 |
-r--r--r-- |
Read-only for everyone |
400 |
-r-------- |
Read-only, and only for you |
777 |
-rwxrwxrwx |
Everyone can do everything: avoid it |
For a directory, r means you can list its contents, w means you can create and delete entries in it, and x means you can enter it and reach what is inside. A directory without x is effectively locked, which is why directories are usually 755 or 700 rather than 644.
Symbolic mode
Describe the change instead of the final value: who (u, g, o or a for all), an operator (+ add, - remove, = set exactly) and the permissions.
chmod u+x script.sh # let the owner run it
chmod go-w notes.txt # remove write from group and others
chmod a=r readme.txt # everyone: read only, nothing else
chmod u=rwx,g=rx,o= tool # same as 750
chmod -R u+rwX,go-rwx dir # recursive; capital X adds execute only to directories
Setting many files at once
find . -type d -exec chmod 755 {} + # every directory
find . -type f -exec chmod 644 {} + # every regular file
Setting 755 on everything makes data files executable, and chmod -R 777 is almost never the right fix for a "permission denied" error. Find out which user needs access and grant exactly that.
Special bits
A fourth leading digit sets three special bits.
| Bit | Octal | On a file | On a directory |
|---|---|---|---|
| setuid | 4000 |
runs as the file's owner | no effect on most systems |
| setgid | 2000 |
runs as the file's group | new files inherit the directory's group |
| sticky | 1000 |
ignored | only a file's owner can delete it (as in /tmp) |
chmod 1777 shared/ makes a world-writable directory with the sticky bit, and chmod 2775 project/ keeps a team directory's files in one group.
Default permissions and umask
New files start from 666 and new directories from 777, then the umask removes bits. With the common umask 022, new files are 644 and new directories 755. With 077 they are 600 and 700. Check yours with umask.