Chmod calculator

Tick read, write and execute, or type 755 or rwxr-xr-x. Shows the octal mode, symbolic form and the chmod command.

How it works

  1. Pick an input mode: toggles, octal or symbolic
  2. Set the permissions for owner, group and others
  3. Copy the octal mode or the chmod command

How the mode is built

A Unix file mode has three groups of permissions, for the owner, the group and everyone else (others). Each group can have read (4), write (2) and execute (1), and the digit is their sum: 7 is read, write and execute, 6 is read and write, 5 is read and execute, 4 is read only. 755 therefore means rwx for the owner and r-x for the group and others, and 644 means rw-r--r--. The page opens on 755 and shows the octal mode, the symbolic form, the command chmod 755 filename and a plain-words line for each class. When no special bit is set it also shows the same command in the symbolic form, chmod u=rwx,g=rx,o=rx filename.

Three ways to enter a mode

Input mode decides which control sets the mode, because the page does not link the controls both ways: each mode keeps its own value when you switch. In Toggles you tick nine boxes in three rows and, under Special bits (advanced), setuid, setgid and sticky. In Octal you type 3 digits, or 4 with a leading special digit, such as 755 or 4755; each digit is 0 to 7, and 0755 is the same as 755. In Symbolic you type nine characters such as rwxr-xr-x. A ten-character ls -l string beginning with - or d is accepted and the first character is ignored. Anything else shows a fixed message under the box.

setuid, setgid and the sticky bit

The leading octal digit holds three special bits: 4 is setuid, 2 is setgid and 1 is sticky. In the symbolic form they replace an x: s in the owner place for setuid, s in the group place for setgid, and t in the others place for the sticky bit. If the matching execute bit is off, the letter is capital: rwSr--r-- is setuid without owner execute, which has no effect on a file. 4755 reads rwsr-xr-x, 2755 reads rwxr-sr-x and 1777 reads rwxrwxrwt, the usual mode of a shared temporary directory. When special bits are set, the page gives only the octal command, because a symbolic command with = does not state them reliably.

Directories and warnings

Execute on a directory means the right to enter it and reach the files inside, so a directory usually needs x wherever a file would need only r. A mode where others can write, such as 777, gets a warning. The page does not know which file you mean, does not run anything and cannot say whether a mode is right for your system.

Frequently asked questions

What does chmod 755 mean?

The owner can read, write and execute; the group and others can read and execute. In symbols that is rwxr-xr-x. It is the usual mode for scripts, programs and directories that everyone may enter but only the owner may change.

What is the difference between chmod 644 and 600?

644 is rw-r--r--: the owner reads and writes, everyone else only reads. 600 is rw-------: only the owner has any access. Private keys and credential files are commonly set to 600 because tools such as ssh refuse keys that others can read.

What does the 4 in chmod 4755 do?

It sets the setuid bit. A program with setuid runs with the rights of the file owner instead of the user who started it. The symbolic form is rwsr-xr-x. Setuid on a script is ignored by most systems, and setuid on a directory has no effect on Linux.

Why does my symbolic string show a capital S or T?

A capital S or T means the special bit is set but the matching execute bit is not. rwSr--r-- is setuid with no owner execute. The lower case s or t means the bit and execute are both on.

Can I type a mode like u+x or a+rw?

No. This page takes toggles, an octal number or a nine-character string. Relative changes such as u+x depend on the file's current mode, which the page does not know, so it cannot work them out.

Does chmod -R need a different mode?

The page gives the mode, not the options. With -R the same mode is applied to every file and directory below, so a mode that suits files may stop people entering directories. Check what you are changing before you run it.