DevKitHub

Programming

Chmod Calculator — Octal, Symbolic and ls -l Permissions

Type a mode as octal, as ls -l prints it, or as a symbolic change like u+x — or click the grid — to see it in every notation, with the command to run and what it allows.

Owner
Group
Others
Special

Mode

Octalor 0755
755
Symbolicas ls -l shows it
rwxr-xr-x
Command
chmod 755 file
Symbolic modethe same, spelled out
u=rwx,go=rx
Decimalwhat os.chmod gets from 0o755
493
Meaning
The owner can read, change and run it; the group and everyone else can read and run it.

This tool runs entirely in your browser. Your input is never uploaded, stored or logged.

How it works

A permission mode is twelve bits, and octal is those bits written three at a time. Each digit is one class — owner, group, everyone else — and within a digit read counts 4, write 2 and execute 1, so 7 is all three and 5 is read and execute: 755 is rwxr-xr-x. An optional digit in front carries the special bits, 4 for setuid, 2 for setgid and 1 for sticky, so 4755 is rwsr-xr-x. ls -l folds each special bit into an execute position, lower case when execute is also set and capital when it is not, and a capital S almost always means a special bit was set on something nobody can execute. A mode shorter than three digits is padded on the left, so chmod 55 means 0055, not 550.

A symbolic mode is a different kind of thing: a change, not a mode. u+x means add owner execute to whatever is already there, so it has no answer until you say what it is applied to, which is what the base field is for. Two letters depend on the target as well. X adds execute only to a directory or to a file someone can already execute, which is why chmod -R a+rX is the safe way to open up a tree. And a clause with no who-letter goes through the umask: under the usual 022, chmod +w adds write for the owner only, while chmod a+w adds it for everyone. The engine is a port of the one GNU chmod uses, so copies like g=u, the numeric form =755 and the POSIX examples behave as they do on Linux.

Where Linux and macOS disagree, the result follows Linux and the difference is stated. macOS ignores o+t, which GNU treats as +t. macOS decides X from the mode before any clause runs, so u+x,a+X on a 644 file gives 744 there and 755 on Linux. And GNU chmod keeps a directory’s setgid bit through chmod 755, where macOS clears it. The meaning is written separately for files and directories, because the same bits mean different things: on a directory r lists the names, x lets you enter, and r without x shows names you cannot open. Access control lists and SELinux can allow or refuse what the mode bits say, and they are not read here — an ls -l marker of +, . or @ is recognised and explained.

Common problems

Every example below is run against this tool in our test suite, so what it says here is what the tool actually does.

8 and 9 are not octal digits.

758
Why:
Each digit of a mode is a sum of read 4, write 2 and execute 1, so no digit can be larger than 7. An 8 or 9 is a typo, or a decimal number mistaken for a mode.
Fix:
Add up read, write and execute for each class separately. 7 is the most any one class can have.

That octal mode has too many digits.

75555
Why:
A mode is at most four octal digits: the special bits, then owner, group and others. A fifth significant digit has nowhere to go. Leading zeros are harmless, so 00755 is accepted.
Fix:
Remove the extra digit. Setuid, setgid and sticky go in the single digit in front, as in 4755, 2755 or 1777.

A mode cannot contain spaces.

u+x, g+w
Why:
chmod takes the whole mode as one argument, so a space after the comma splits it in two, and chmod rejects "u+x," as an invalid mode because of the trailing comma.
Fix:
Write the clauses as one word with commas between them: u+x,g+w.

os.chmod(path, 755) left the file as --wxrw--wt.

Why:
Inside a program, 755 is a decimal number, and decimal 755 is octal 1363: sticky, owner write and execute, group read and write. The chmod command reads its argument as octal; Python’s os.chmod and Node’s fs.chmod given a number do not.
Fix:
Write the literal in octal — 0o755 in Python and JavaScript — or pass 493, its decimal value. The Decimal row shows it for any mode.

After chmod -R 644, nothing inside the subdirectories can be opened.

Why:
On a directory, x is permission to enter it and reach what is inside. A recursive 644 removes x from every directory in the tree, so ls still lists the names but every file inside is refused.
Fix:
Use chmod -R a+rX, which gives x to directories and to files that already had it, or set directories and files separately with find -type d and find -type f.

Frequently asked questions

What does chmod 755 mean?
The owner can read, write and execute; the group and everyone else can read and execute but not write. ls -l shows it as rwxr-xr-x. It is the usual mode for a directory or a program, and 644 (rw-r--r--) is the usual one for an ordinary file.
What is the difference between chmod +x and chmod a+x?
With no u, g, o or a, chmod applies the change through your umask and leaves alone any bit the umask blocks. Under the common umask 022 the two give the same result for x, but +w adds write for the owner only while a+w adds it for everyone.
What do s, S, t and T mean in ls -l output?
An s in the owner or group position is setuid or setgid with execute also set; S is the same bit without execute, which is almost always a mistake. A t in the last position is the sticky bit with execute for others, and T is sticky without it. On a directory the sticky bit stops users deleting each other’s files, which is why /tmp is 1777.
How do I make a directory tree readable without making every file executable?
Use chmod -R a+rX. The capital X adds execute only to directories and to files that were already executable, so directories can be entered and scripts keep working, while plain files do not become runnable.

Last updated