Linux Chmod Permissions Calculator

Interactively calculate Linux file and directory permissions in octal (numeric) and symbolic formats. Generate ready-to-use terminal commands with instant presets and special bit support.

Numeric / Octal755
Symbolic Notation-rwxr-xr-x
File Permissions Matrix
Direct Octal Input:
Permission ClassRead (r = 4)Write (w = 2)Execute (x = 1)
Owner (User)7
Group5
Others (Public)5
Special Permissions
Generated Linux Chmod Command
chmod 755 filename.txt
chmod u=rwx,g=rx,o=rx filename.txt
Popular Permission Presets

Comprehensive Guide to Unix & Linux File Permission Architecture

In Unix-like operating systems (including GNU/Linux distributions like Ubuntu, Debian, Red Hat, CentOS, Arch, and macOS), file system security is anchored around the Discretionary Access Control (DAC) model. Every single file, directory, symlink, device node, and named pipe stored on an ext4, XFS, Btrfs, or ZFS volume is tagged with metadata in its file system inode that governs who may inspect, modify, or execute its contents.

This model compartmentalizes all operating system users into three distinct permission categories:

1. Owner (User - u)

The individual user account that created the file or was assigned ownership via the chown command. The owner typically retains the authority to modify the file's permission flags and grant or restrict rights to other entities.

2. Group (g)

A collection of user accounts managed in /etc/group that share common collaborative responsibilities (for example, the developers group, docker group, or web server daemon group www-data).

3. Others (Public - o)

Any user or process on the machine that is neither the file owner nor a member of the designated group. Permissions assigned to 'Others' represent the baseline public access level on the server.

The Mathematics of Octal Notation: How Binary Bits Sum to Permissions

The Unix kernel views permissions as a 9-bit binary array (or 12-bit when including special flags). Each triplet of bits maps directly to a single base-8 (octal) digit from 0 to 7:

4Read (r)
Binary: 100

Permits viewing file content or listing filenames inside a folder.

2Write (w)
Binary: 010

Permits modifying, appending, truncating, or creating new files in a directory.

1Execute (x)
Binary: 001

Permits executing binaries/scripts or traversing into a folder path.

By combining these flags:
• 7 (4 + 2 + 1) = Read, Write, and Execute (rwx)
• 6 (4 + 2 + 0) = Read and Write (rw-)
• 5 (4 + 0 + 1) = Read and Execute (r-x)
• 4 (4 + 0 + 0) = Read Only (r--)
• 0 (0 + 0 + 0) = No Permissions (---)

Production Web Server & Security Best Practices

Security misconfigurations are among the top OWASP vulnerabilities in web infrastructure. Apply these battle-tested standards:

WordPress & CMS Deployments

Never grant 777 to wp-content/uploads even if installation plugins complain about upload write failures. Instead, retain 755 on directories and 644 on files, while transferring ownership to the web daemon:

sudo chown -R www-data:www-data /var/www/html
find /var/www/html -type d -exec chmod 755 {} +
find /var/www/html -type f -exec chmod 644 {} +
SSH Keys & Cloud Server Credentials

OpenSSH client rejects private keys if they are accessible by group members or others, failing with the warning "Permissions are too open":

chmod 700 ~/.ssh
chmod 600 ~/.ssh/id_rsa ~/.ssh/id_ed25519
chmod 644 ~/.ssh/authorized_keys ~/.ssh/*.pub

Linux File Permissions Reference Table

OctalSymbolicBinaryDescriptionBest For
777rwxrwxrwx111 111 111Read, write, & execute for everyone (Dangerous)Temporary local sandbox testing only
755rwxr-xr-x111 101 101Owner full; group and others read/executeWeb directories, CGI scripts, executables
644rw-r--r--110 100 100Owner read/write; others read-onlyStandard web files (.html, .css, .js, .png)
600rw-------110 000 000Only owner can read & writePrivate SSH keys (id_rsa, .pem), credentials
700rwx------111 000 000Only owner can enter & modifyPersonal user folders, ~/.ssh directory
444r--r--r--100 100 100Read-only for all classesProtected archives, read-only logs

Frequently Asked Questions

The 'chmod' command is an abbreviation for 'change mode'. In Unix, Linux, and POSIX-compliant operating systems, it is a core system utility used by system administrators and developers to define or alter file system access modes (permissions) on files and directories for three distinct user classes: the file owner (user), group members, and everyone else (others).

In Unix file systems, permissions are represented mathematically by three fundamental binary bits: Read (r) worth 4, Write (w) worth 2, and Execute (x) worth 1. By summing these values together, each user class receives a single octal digit between 0 and 7. For example, Read + Write (4+2) equals 6. Read + Execute (4+1) equals 5. Full access (4+2+1) equals 7. A permission string of 755 signifies that the Owner has 7 (rwx), the Group has 5 (r-x), and Others have 5 (r-x). When a four-digit octal notation is used (such as 0755 or 1777), the leading digit represents special flags: SetUID (4), SetGID (2), and the Sticky Bit (1).

Setting permissions to 777 grants Read, Write, and Execute rights to every single user, guest account, automated bot, and compromised process operating on the server. If an attacker discovers an arbitrary file upload vulnerability or remote code execution flaw in any web application hosted on that machine, 777 permissions permit them to overwrite critical scripts, plant persistent web shells, delete databases, and escalate system privileges. Production systems should always adhere to the Principle of Least Privilege (PoLP).

For standard PHP, WordPress, Laravel, or Node.js web applications, the industry security consensus is: 755 for all directories (allowing the web server daemon like www-data or nginx to traverse folders), 644 for all standard files (HTML, CSS, JS, images, allowing reading without unauthorized modifications), 600 or 400 for sensitive environment configuration files like .env or wp-config.php (only accessible by the process owner), and 700 for the user's private ~/.ssh directory.

For a regular file, the Execute permission allows the operating system kernel to run the file as a compiled binary or shell script. However, for a directory, the Execute permission has a completely different meaning: it grants 'search' or 'traversal' permission. Without execute permission on a directory, a user cannot 'cd' into it, nor can they access or execute files stored inside it, even if they possess read permissions on the files themselves.

SetUID (octal 4000) is a special permission bit applied to executable binaries. When an executable with SUID enabled is run by a regular user, the operating system executes the process with the permissions of the file's owner rather than the user who launched it. A classic example is the '/usr/bin/passwd' utility: standard users need to change their own passwords, which requires updating the root-owned '/etc/shadow' file. SUID allows passwd to temporarily operate with elevated root privileges.

The Sticky Bit is primarily applied to shared world-writable directories such as '/tmp'. When the sticky bit is active (indicated by a 't' in the permissions string, like drwxrwxrwt), only the root administrator or the specific user who originally created a file inside that directory is permitted to rename or delete it. This prevents malicious users on shared hosting servers from deleting or tampering with temporary files belonging to other processes.

To change all directories to 755 recursively without altering file permissions, run: 'find /path/to/folder -type d -exec chmod 755 {} +'. To change all files to 644 recursively without altering directory permissions, run: 'find /path/to/folder -type f -exec chmod 644 {} +'.

Explore Related Tools

Hand-picked utilities and calculators related to this tool.

Developer Tools