chmod Permission Calculator
Convert between 755 and rwxr-xr-x, special bits included, in both directions.
Tick the boxes, or type a mode.
How it works
Read is 4, write is 2, execute is 1, and the three digits of a mode are owner, group and others in that order. So
7 is 4+2+1 and 5 is 4+1, which makes 755 mean the owner can do everything and everyone else can read
and execute. Everything on this page is that arithmetic in both directions, plus the two things the arithmetic
leaves out.
The first thing it leaves out: directories read differently
The same three bits mean something else on a directory. Read lists the names inside. Write creates, renames and deletes entries — which means write on a directory lets you delete a file inside it that you cannot write to. Execute means traverse: enter the directory and reach entries by name. A directory with read and no execute gives you a list of names you cannot open, which is the most common source of a permission error that looks impossible.
The second: the fourth digit
setuid (4), setgid (2) and the sticky bit (1) sit in a leading digit and overwrite the execute position in
symbolic notation. rwsr-xr-x is setuid with execute; rwSr-xr-x is setuid without it, and
the capital letter almost always means someone set a bit on something that cannot run. A setuid binary runs with
its owner’s privileges rather than the caller’s, so every one on a system is a privilege boundary worth knowing
about deliberately.
Why this page describes rather than scores
A mode is only right or wrong relative to what the file is for. 777 on a scratch path inside a
container is unremarkable; on anything a privileged process reads it means any account on the machine can change
what that process runs. So each observation says what the bits permit and leaves the judgement where it belongs.
Example
644 is rw-r--r--: the ordinary mode for a file. 600 is what an SSH private
key needs — OpenSSH refuses a key any other account can read. 1777 is rwxrwxrwt, the
mode of /tmp, where the sticky bit is what stops one user deleting another’s files in a directory
everyone can write to. Paste -rw-r----- 1 root adm 4096 auth.log and only the first field is read.
Frequently asked questions
What does 755 actually mean?
Read is 4, write 2, execute 1, and the three digits are owner, group and others. 7 is 4+2+1, 5 is 4+1 — so the owner can read, write and execute, and everyone else can read and execute. That is the standard mode for a directory or a program file.
Why does execute mean something different on a directory?
On a file it means run this as a program. On a directory it means traverse — enter it and reach entries by name. A directory with read but not execute lets you list the names inside and open none of them, which is the single most confusing thing the octal alone does not tell you.
What is the fourth digit?
setuid (4), setgid (2) and the sticky bit (1). They occupy the execute position in symbolic notation: rwsr-xr-x is setuid with execute, rwSr-xr-x is setuid without it. Uppercase almost always means a mistake, because the special bit is set on something that cannot be run.
Why did my new file come out 644 when I did not ask for that?
The umask. A process creating a file asks for 666 and a directory for 777, and the umask removes bits from that request — 022 leaves 644 and 755. It applies to the base mode a program requests, never to a mode you set explicitly with chmod. New files are never created executable, which is why the file and directory results differ.
What permissions does an SSH private key need?
600, or 400 if you want it read-only. OpenSSH refuses to use a key any other account can read and reports it as an unprotected private key file rather than failing quietly. The ~/.ssh directory itself wants 700.
Is 777 ever acceptable?
It depends entirely on what the file is, which is why this page describes what the bits permit instead of scoring the mode. On a throwaway path inside a container it is unremarkable. On anything a privileged process reads it means any account on the system can change what that process executes.
Related tools
Binary, Decimal & Hex Converter
Convert a number between binary, octal, decimal and hexadecimal.
LocalHash Generator
Produce SHA-1, SHA-256, SHA-384 and SHA-512 digests of text or a file.
LocalSAML Response Decoder
Decode a SAMLResponse and read its issuer, subject, conditions and attributes.
LocalJSON Diff
Compare two JSON documents and see what actually changed, independent of formatting.
LocalJSON to TypeScript
Infer a TypeScript interface from a JSON example, with optional fields worked out from an array.
LocalJSON to Zod Schema
Infer a runtime-checkable Zod schema from a JSON example.
Local