Cheat Sheets Development

chmod and File Permissions Cheat Sheet

Octal and symbolic chmod modes, what each digit means, how to read ls -l, special bits and umask, on one page.

Last reviewed:

AdSense Placeholder
Slot: header_reference_page
On this page

A file's permissions say who may read (r), write (w) or execute (x) it, separately for three audiences: the user that owns it (u), the owner's group (g) and others (o). chmod changes them. The Chmod Calculator does the arithmetic for you.

Reading ls -l

-rwxr-xr--  1 ana  staff  1024 Oct  3 10:00 deploy.sh

The first character is the type (- file, d directory, l symbolic link). The next nine are three groups of three: rwx for the owner, r-x for the group and r-- for others. So this script is 754: the owner can do everything, the group can read and run it, others can only read it.

Octal digits

Each audience gets one digit that is the sum of read = 4, write = 2 and execute = 1.

Digit Binary Permissions
7 111 rwx read + write + execute
6 110 rw- read + write
5 101 r-x read + execute
4 100 r-- read
3 011 -wx write + execute
2 010 -w- write
1 001 --x execute
0 000 --- none

Common modes

Octal Symbolic Meaning
644 -rw-r--r-- Normal file: you read and write, everyone else reads
600 -rw------- Private file: only you (SSH keys, secrets)
640 -rw-r----- You read and write, your group reads, others get nothing
664 -rw-rw-r-- You and your group write, others read
755 -rwxr-xr-x Program or directory: you do everything, others read and run
700 -rwx------ Private program or directory: only you
750 -rwxr-x--- You do everything, your group reads and runs, others nothing
775 -rwxrwxr-x Shared directory: you and your group do everything
444 -r--r--r-- Read-only for everyone
400 -r-------- Read-only, and only for you
777 -rwxrwxrwx Everyone can do everything: avoid it

For a directory, r means you can list its contents, w means you can create and delete entries in it, and x means you can enter it and reach what is inside. A directory without x is effectively locked, which is why directories are usually 755 or 700 rather than 644.

Symbolic mode

Describe the change instead of the final value: who (u, g, o or a for all), an operator (+ add, - remove, = set exactly) and the permissions.

chmod u+x script.sh        # let the owner run it
chmod go-w notes.txt       # remove write from group and others
chmod a=r readme.txt       # everyone: read only, nothing else
chmod u=rwx,g=rx,o= tool   # same as 750
chmod -R u+rwX,go-rwx dir  # recursive; capital X adds execute only to directories

Setting many files at once

find . -type d -exec chmod 755 {} +     # every directory
find . -type f -exec chmod 644 {} +     # every regular file

Setting 755 on everything makes data files executable, and chmod -R 777 is almost never the right fix for a "permission denied" error. Find out which user needs access and grant exactly that.

Special bits

A fourth leading digit sets three special bits.

Bit Octal On a file On a directory
setuid 4000 runs as the file's owner no effect on most systems
setgid 2000 runs as the file's group new files inherit the directory's group
sticky 1000 ignored only a file's owner can delete it (as in /tmp)

chmod 1777 shared/ makes a world-writable directory with the sticky bit, and chmod 2775 project/ keeps a team directory's files in one group.

Default permissions and umask

New files start from 666 and new directories from 777, then the umask removes bits. With the common umask 022, new files are 644 and new directories 755. With 077 they are 600 and 700. Check yours with umask.

Try these tools

AdSense Placeholder
Slot: footer_leaderboard