A Unix file has three sets of permissions: for its owner, for its group, and for everyone else. Each set says whether the file can be read, written, and run. The same facts are written in three ways: as a number such as 755, as a string such as rwxr-xr-x, and as a symbolic change such as u+x. This page converts between all three, and it says in plain words what a mode allows, because 755 on a file and 755 on a directory mean different things.
It also does what chmod does with a symbolic mode. Give it a starting mode and an expression such as go-w or a=rX, and it shows the mode that results, following the rules of GNU chmod, including the parts that surprise people: the execute bit that X sets only on directories and files that already have it, the way a missing class letter makes chmod obey the umask, and the way setuid and setgid are left alone on directories. Nothing is sent anywhere, and the code behind the page makes no network requests.
How to use the Chmod Permissions: Convert 755 to rwx, Explained
- Type a mode or tick the boxesType a number such as 644, a string such as rw-r--r-- or -rwxr-xr-x, or a symbolic mode such as u+x,go-w. Or tick the read, write, and execute boxes for the owner, the group, and others. Say whether it is a file or a directory.
- Read what it allowsThe page shows the mode as a number, as a string, as ls -l prints it, and as a command. It then says what the owner, the group, and everyone else can and cannot do, and warns about risky modes.
- Apply a symbolic modeIf you typed something like u+x, the page asks for a starting mode and a umask, and shows the mode that chmod would give. The umask matters only when no class letter is written, as in +x.
- Copy the commandAdd the path and choose whether the change reaches everything inside. If directories and files should have different modes, use the find commands in the page, because chmod -R gives both the same mode.
How the number works
Each permission has a value: read is 4, write is 2, and execute is 1. The three values of a class are added, so read and write is 6, read and execute is 5, and all three is 7. A mode is the three sums in the order owner, group, others. In 754 the owner has 7 (read, write, execute), the group has 5 (read, execute), and others have 4 (read only). Written as a string, 754 is rwxr-xr--.
A fourth digit in front holds the special bits: setuid is 4, setgid is 2, and the sticky bit is 1. So 4755 is a mode with setuid, and 1777 is the mode of /tmp. ls -l shows the special bits in place of the execute letter: s for setuid or setgid with execute, S when the execute permission is missing, and t or T for the sticky bit. The page converts every one of the 4,096 possible modes.
Files and directories are not the same
On a file, read means reading its contents, write means changing them, and execute means running it as a program or script. On a directory the same letters mean something else. Read lets you list the names in it. Execute lets you pass through it, so that you can open a file inside by name and use the directory in a path. Write lets you create, rename, and delete files in it, but only together with execute, so a directory with write and no execute permission is useless for that.
This is why 755 is the usual mode for directories and 644 for files. A directory needs execute for people to use it at all, and a plain file does not need it. The page words its explanation for the kind you choose, and it warns about a directory that can be read but not entered, and about a file that can be run but not read.
Symbolic modes
A symbolic mode has three parts: who, an operator, and what. Who is u for the owner, g for the group, o for others, and a for all, and several can be combined. The operator is + to add, - to remove, and = to set exactly. What is any of r, w, x, X, s, and t, or one of u, g, and o to copy the permissions that the file has for that class. Changes can be chained with commas, so u=rwx,g=rx,o= sets 750.
Three details cause most surprises. The capital X sets execute only if the file is a directory or already has execute for someone, which is what you want for chmod -R a=rX. When who is left out, as in +x, chmod acts as if a were given but leaves out the bits of the umask, so +w with a umask of 022 adds write for the owner only. And on a directory, the setuid and setgid bits are not changed by a number of up to four digits or by a letter that does not mention them, so that shared directories keep their group. The GNU coreutils manual describes all three, and the page follows them.
The umask
When a program creates a file it asks for a mode, usually 666 for a file and 777 for a directory, and the umask removes bits from it. With the common umask of 022, new files are 644 and new directories are 755. With 002, which many systems use for users with their own group, they are 664 and 775. With 077 they are 600 and 700, which is private. The page shows this for any umask, and gives the umask that produces a wanted directory mode.
Why chmod -R is often wrong
chmod -R 755 folder gives every file inside the execute permission, which a document or an image does not need, and chmod -R 644 folder removes the execute permission from every directory, which makes them impossible to enter. The usual fix is two commands with find, one for directories and one for files, and the page writes them for the modes that you choose. Writing a=rX with -R is the shorter way to give read to everyone and execute only where it already exists.
How it was tested
The symbolic and numeric rules were compared with the real GNU chmod, version 8.32 from the coreutils, which was run from Git Bash. chmod -v prints the mode that it works out, even on a file system that does not keep permissions, so 660 modes were run for a plain file, a read-only file, a script, and a directory under five different umasks, with 460 more runs for special cases, and the mode that chmod reported was compared with the page's. The modes included random symbolic modes with every combination of classes, operators, and letters, numbers of one to five digits, and strings that chmod refuses. That made 13,680 runs, of which 440 were strings that chmod refuses, and the page refused every one of them. For the 8,720 runs where chmod reported the mode that it started from, the page gave the same result every time, using that starting mode. In the other 4,520 runs chmod said that the mode was retained, which happens when the file system of Windows cannot keep the change, and then the report does not say what the starting mode was. For those, the result of the page was the same for at least one of the starting modes that had been seen, which is a weaker check, and it is stated here for that reason.
The strings that ls prints were checked against Python's stat.filemode for every mode from 0 to 7777, for a file, a directory, and a link, and each string was read back to the same mode. The numbers that start with an operator, such as =755 and +7, were checked in a separate run.
Limits and accuracy
- The page follows GNU chmod, the one on Linux. The chmod of macOS and the BSDs is close but not the same in every corner, so the result of a symbolic mode with X or with no class letter may differ there.
- The setuid and setgid bits of a directory, which GNU chmod leaves alone, were tested only for directories that started without them. The rule itself is taken from the GNU documentation.
- A mode is only part of what decides access. Access control lists, extended attributes, file system flags, mount options such as noexec, and security modules can allow or refuse more.
- The permissions of a symbolic link are not used on Linux. The page explains a link as a link and does not apply it.
- The page works out modes and does not look at a real file. It cannot tell you who the owner and the group of a file are, or whether you are one of them.
- The setuid and setgid bits on a script are ignored by Linux and are a risk on other systems. The page warns about them and does not remove them.
Frequently asked questions
What does chmod 755 mean?
The owner can read, write, and run the file, and the group and everyone else can read and run it but not change it. As a string it is rwxr-xr-x. It is the usual mode for directories and for programs that everyone may run.
What is the difference between 644 and 755?
The execute permission. 644 is rw-r--r--: the owner can read and write, and others can read. 755 adds execute for all three classes. Use 644 for ordinary files, and 755 for directories and for scripts and programs that must be run.
Is chmod 777 safe?
Usually not. It lets every user on the system change or replace the file, or add and delete files in a directory. If a program needs write access, give the specific user or group that needs it, for example with 775 and the right group, not everyone.
How do I give a file execute permission?
Use chmod +x file to add it, which follows the umask, or chmod u+x file to give it to the owner only. Type either on this page with a starting mode to see the number it gives. A script also needs read permission to be run.
What do the s, S, t, and T mean in ls -l?
They are the special bits written in place of the execute letter. A lower case s or t means that the bit is set and the execute permission is set too. A capital S or T means that the bit is set and execute is not, which usually means a mistake.
How do I give directories and files different modes?
Use find, which can select by kind: one command with -type d for the directories, and one with -type f for the files. chmod -R gives both the same mode. The page writes both commands for the modes that you choose.
Is anything I type sent to a server?
No. The modes are worked out in your browser, and the code behind the page makes no network requests. Nothing is saved.
Research and references
This page was written and checked against the sources below.

