Skip to content

Chmod Calculator (Linux File Permissions)

Tick owner, group and others permissions to get the octal mode, symbolic mode and copy-ready chmod commands, including recursive find.

  • Free
  • No sign-up
  • Runs locally

Runs in your browser; what you enter is not uploaded to our servers.

Updated

What this chmod calculator does

This chmod calculator turns the nine permission checkboxes on a Linux or Unix file into the numbers and commands you type. Tick read, write and execute for the owner, the group and everyone else, and it shows the octal mode (755), the symbolic mode from ls -l (rwxr-xr-x), a plain-English sentence for each class and a copy-ready chmod command. Type into the octal or symbolic box and the checkboxes follow, so you can also decode a mode from a tutorial or a Dockerfile.

It supports setuid, setgid and the sticky bit, and warns about risky modes such as 777, setuid files that others can edit, or directories with read but no execute. It builds the find commands that give directories and files different modes across a tree, previews what chmod +x or g-w does to an existing mode, and works out the modes a umask produces.

How to use the calculator

  1. Optionally pick a preset: WordPress, wp-config.php, Laravel storage, an SSH key or folder, a script, a shared team folder or a shared temp folder. It loads a mode, an item type and an example path, with a note on why.
  2. Choose File or Directory. Execute means "run" on a file and "enter" on a directory, and the warnings change to match.
  3. Tick the boxes. Read is 4, write is 2 and execute is 1 for Owner, Group and Others, and the Digit column shows each row's sum. Setuid, Setgid and Sticky add a fourth leading digit.
  4. Or type a mode. Octal takes one to four digits (644, 4755). Symbolic takes nine characters such as rwxr-xr-x, or ten with a leading - or d. Invalid input gets a specific message and the last valid mode stays.
  5. Copy a command. Set the path under Copy-ready commands. Spaces are quoted, a leading ~/ still expands, and the sudo switch adds sudo.
  6. For a whole tree, the Directories and Files fields start from your mode: directories get execute wherever read is set, and files lose every execute bit. Edit either field to override it.
  7. Test a symbolic change or use the umask calculator further down. Your inputs stay in this tab, and Reset calculator returns to 755.

How permission bits become an octal number

Each class has three switches worth 4, 2 and 1, the place values of the binary digits 100, 010 and 001. The three bits form a binary number, and its value is one octal digit from 0 to 7. Worked example for rwxr-x---:

owner   rwx  =  111  =  4+2+1  =  7
group   r-x  =  101  =  4+0+1  =  5
others  ---  =  000  =  0+0+0  =  0
                                  =>  750

In reverse, 640 splits into 6, 4 and 0, which reads rw-r-----: the owner reads and writes, the group reads, everyone else is locked out.

DigitBinarySymbolicDigitBinarySymbolic
0000---4100r--
1001--x5101r-x
2010-w-6110rw-
3011-wx7111rwx

The fourth digit holds the special bits: 4 for setuid, 2 for setgid, 1 for sticky, added together when you need several. So 4755 is setuid plus 755, and ls -l shows it by replacing the owner's x with s: rwsr-xr-x. A capital S or T means the special bit is set but the matching execute bit is not. 1777 reads rwxrwxrwt, the mode of /tmp.

Common chmod modes and when to use them

OctalSymbolicUse it forWatch out for
777rwxrwxrwxNothing permanentAny user or compromised process can rewrite it
775rwxrwxr-xShared directories a team group writes toEvery group member can delete anything inside
755rwxr-xr-xDirectories, scripts, public programsPlain data files do not need execute
750rwxr-x---Programs or folders for one groupEveryone else gets "Permission denied"
700rwx------Private directories such as ~/.sshEven the web server cannot enter
644rw-r--r--Ordinary files: HTML, images, configNo execute, so scripts will not run directly
640rw-r-----Config secrets a service group must readThe service account must be in that group
600rw-------SSH private keys, credentialsServices running as another user cannot read it
400r--------Locked-down keys and strict configThe owner needs chmod u+w before editing

Three special modes come up often: 1777 for shared temp directories, 2775 for team directories where new files inherit the group, and 4755 for a setuid program, which belongs only on audited binaries.

What execute means on directories

On a directory the three bits mean something different from a file:

  • Read (r) lets you list the names inside, as ls does.
  • Execute (x) lets you enter with cd and reach anything inside by path. Opening /var/www/site/index.html needs execute on /var, /var/www and /var/www/site, whatever the file's own mode says.
  • Write (w) lets you create, rename and delete entries, but only when execute is also set.

A directory at 644 locks out everyone, its owner included, because nobody has execute. A directory at 711 lets others open files whose exact names they know without seeing what is there. And deleting a file depends on write permission for its directory, not on the file's own mode, so you can delete a read-only file you cannot edit. That is the gap the sticky bit closes on shared folders.

Symbolic mode: chmod +x, u=rw and the umask catch

Symbolic modes read as who, operator, permissions, with clauses separated by commas. Who is u (owner), g (group), o (others) or a (all). The operator is + to add, - to remove or = to set exactly. Permissions are r, w, x, plus X, s and t, or u, g, o to copy another class's bits.

chmod u+x deploy.sh          # owner may run it
chmod g-w,o-rwx notes.txt    # group loses write, others lose everything
chmod u=rw,go=r report.txt   # exactly rw-r--r--

The +x catch. With no who letters, GNU chmod acts like a except that bits set in your umask are left alone. With the usual umask of 022, chmod +x adds execute for all three classes, so 644 becomes 755. With umask 077 it adds execute for the owner only, giving 744. chmod a+x ignores the umask. Set the umask box in "Try a symbolic change" to 077 to see both results.

Capital X adds execute only to directories and to items that already have an execute bit, which suits trees. Symbolic modes change only the bits you name; a numeric mode replaces everything.

Recursive chmod without breaking your files

chmod -R 755 site/ gives every file the execute bit, and chmod -R 644 site/ makes every directory impossible to enter. Treat the two kinds separately:

find site -type d -exec chmod 755 {} +
find site -type f -exec chmod 644 {} +
chmod -R u=rwX,g=rX,o=rX site     # one command that keeps scripts executable

The find pair strips execute from every file, scripts included, so restore it on deploy.sh afterward. The capital-X command keeps already-executable files executable. If find prints "Permission denied" for a folder, that folder currently lacks execute for you: fix it with chmod u+x folder (or run the command with sudo) and repeat.

One GNU quirk: a numeric mode of up to four digits does not clear a directory's setuid or setgid bit, so chmod 755 dir on a 2775 directory leaves 2755. Use chmod g-s dir or a five-digit mode such as chmod 00755 dir to clear it.

umask: where default permissions come from

The umask lists the bits a new item does not get. Files start from 666, because programs are never created executable, and directories start from 777. The umask bits are then cleared. This is a bit mask, not subtraction: a file under umask 033 becomes 644, not 633.

umaskNew filesNew directories
022 (default on most distributions)644755
002 (common with per-user groups)664775
027640750
077600700

Set it for the current shell with umask 027, or in your shell profile to make it stick.

Practical fixes by role

System administrator: "Permission denied" on a script. ls -l deploy.sh shows -rw-r--r--, so nobody may execute it, and chmod u+x deploy.sh fixes that. If it still fails, run namei -l /full/path/to/deploy.sh to find a parent directory without execute, and check whether the filesystem is mounted noexec.

WordPress site owner. Use 755 for directories and 644 for files, with wp-config.php tighter at 640 or 600 (some hosts prefer 440 or 400). "Unable to create directory wp-content/uploads" is nearly always an ownership mismatch: PHP runs as a user that does not own the folder. Check with ls -ld wp-content/uploads, then fix the owner with chown instead of using 777.

Laravel developer. storage and bootstrap/cache must be writable by the web server user. Give that group ownership, then 775 for directories and 664 for files, with setgid so new files stay group-writable:

sudo chgrp -R www-data storage bootstrap/cache
sudo chmod -R ug+rwX storage bootstrap/cache
sudo find storage bootstrap/cache -type d -exec chmod g+s {} +

www-data is the web server group on Debian and Ubuntu; other distributions use apache or nginx.

Anyone using SSH. Use 700 for ~/.ssh, 600 for private keys and authorized_keys, and 644 for public keys. The client prints "WARNING: UNPROTECTED PRIVATE KEY FILE!" and refuses a key that group or others can read. On the server, sshd ignores authorized_keys if your home directory, .ssh or the file is writable by others, giving "Permission denied (publickey)". Protect the key with a passphrase from the password generator.

Tips and common mistakes

  • chmod does not change ownership. "Operation not permitted" means you do not own the item: use chown or sudo.
  • Never run chmod -R 777 on / or a system directory. It breaks sudo, ssh and package managers, with no undo.
  • Setuid is ignored on scripts. Linux honors it only on compiled binaries.
  • Git tracks one bit. It records only whether the owner execute bit is set (modes 100644 and 100755); restore it with git update-index --chmod=+x script.sh.
  • ACLs can override the mode. A + after the permission string in ls -l means one exists; inspect it with getfacl.
  • Verify the result. ls -ld path works everywhere, and on Linux stat -c '%a %A %U:%G %n' path shows octal, symbolic, owner and group together.
  • Quote spaces in file names. The calculator does it for you, but a hyphenated name from the slug generator avoids the problem.

Privacy and limitations

Everything runs in your browser. The path, modes and expressions you enter are not uploaded, and they stay in this tab's session storage until you close it. WordPress and Laravel are named only to describe common setups; this site is not affiliated with either project.

The symbolic-mode engine follows GNU coreutils chmod, used on most Linux systems. macOS and BSD agree on numeric and everyday symbolic modes, but corner cases can differ. The calculator cannot see ownership, ACLs, SELinux or AppArmor policy, or mount options such as noexec, all of which can block access a mode allows. Filesystems without Unix permissions, such as FAT and exFAT, ignore chmod. Test on a copy before a recursive change in production.

Frequently asked questions

How do I calculate chmod numbers?

Read is worth 4, write is worth 2 and execute is worth 1. Add up the ones you want for the owner, then the group, then everyone else, to get three digits. Read plus write plus execute is 4 + 2 + 1 = 7, read plus execute is 5, and read alone is 4, so rwxr-xr-x is 755 and rw-r--r-- is 644. A fourth leading digit adds setuid (4), setgid (2) or the sticky bit (1).

What does chmod 755 mean?

The owner gets 7 (read, write, execute), and the group and everyone else get 5 (read and execute), written rwxr-xr-x. Everyone can read the item and run or enter it, but only the owner can change it. It is the normal mode for directories, shell scripts and programs that other users must run. Ordinary files such as HTML or images do not need execute, so they usually get 644.

What is the difference between chmod 644 and 755?

They differ only in the execute bit. 644 (rw-r--r--) is for ordinary files that are read but not run. 755 (rwxr-xr-x) adds execute for everyone, which directories need so people can enter them and which scripts and programs need so they can run. Web roots typically use 755 for directories and 644 for files. Giving a directory 644 locks everyone out of it, including its owner.

Why is chmod 777 dangerous, and what should I use instead?

777 lets every user on the machine, and every process running as any user, read, change and execute the item. On a web server, a single vulnerable script can then overwrite your code. It usually seems to fix an error only because the owner or group was wrong. Correct that with chown or chgrp, then use 755 and 644, or 775 and 664 with a shared group. Shared temporary folders are the exception, and they use 1777 with the sticky bit.

How do I make a file executable with chmod +x?

Run chmod +x script.sh. With no u, g, o or a letters, GNU chmod leaves the bits in your umask alone. With the common umask of 022 that adds execute for the owner, group and others, so 644 becomes 755. With umask 077 it adds execute for the owner only, giving 744. To be explicit, use chmod u+x for just yourself or chmod a+x for everyone. Scripts also need read permission and a valid shebang line.

How do I change permissions recursively without making every file executable?

chmod -R 755 gives every file execute permission, and chmod -R 644 makes directories unusable. Set them separately: find . -type d -exec chmod 755 {} + for directories and find . -type f -exec chmod 644 {} + for files. Or use one command, chmod -R u=rwX,g=rX,o=rX ., where capital X adds execute only to directories and to files that already have an execute bit. The calculator builds all of these for you.

What are the right permissions for WordPress, Laravel and SSH keys?

WordPress uses 755 for directories and 644 for files, with wp-config.php tighter at 640 or 600 (some hosts prefer 440 or 400). Laravel needs storage and bootstrap/cache writable by the web server user, typically 775 and 664 with the right group. SSH wants ~/.ssh at 700, private keys at 600 and authorized_keys at 600, and OpenSSH rejects keys that others can read. None of these should be 777, and ownership matters as much as the mode.

What are setuid, setgid and the sticky bit?

They are three special bits in the optional leading octal digit. Setuid (4000) makes a program run as its owner, and setgid (2000) makes it run as its group. On a directory, setgid makes new files inherit the directory's group. The sticky bit (1000) on a directory lets only a file's owner, the directory's owner or root delete or rename entries, which is why /tmp is 1777. In ls output they appear as s and t, or S and T when the execute bit is missing.

Published · Updated

Found a bug or have an idea? Tell us