English

Developer tools · Chmod calculator

Common chmod modes explained: 644, 755, 600, 700, 2775 and 1777

· Background

chmod unix access-control

preset modes shown as a distinct Unix permission-bit diagram
Original ToolAcre vector illustration

A handful of modes cover almost every file you will ever set. This post explains each one's rwx meaning, the convention behind it, and the situation where it is the right choice.

The same six numbers everywhere — tutorials say 644 or 755 without ever explaining the choice

Familiar chmod numbers become useful when their bits are visible. The preset list includes 644, 600, 755, 700, 775, 1777, 4755, and 2775, each with a short label. Selecting one drives the standard renderer, updating symbolic output, the permission matrix, four-digit summary, explanation, and command previews from one inspectable value.

A preset is not a policy decision. The page knows neither target ownership nor process groups, ACL entries, parent-directory access, or filesystem behavior. Article 501 supplies the better discipline: begin with the identity and failed action. A preset offers a reproducible starting value, but the actual object and environment determine whether that mode is suitable.

644 and 755: the defaults — rw-r--r-- for data, rwxr-xr-x for directories and programs, and why umask 022 produces exactly these

The shipped list presents 644 for an ordinary file and 755 for a program or directory, not as universal defaults. Mode 644 is rw-r--r--: owner reads and writes, while group and other read. Mode 755 is rwxr-xr-x: owner has rwx, while group and other receive read and execute. Both follow 4-2-1 arithmetic.

Target type explains why a number lacks complete operational meaning. On files, execute means running a program; on directories, it means entering and reaching named entries. The mode stays 755 while the prose changes. No supplied source computes umask or predicts newly created modes, so these values should remain described as shipped presets rather than inevitable defaults.

644 and 755 are shipped presets, not universal defaults

The list labels 600 a private file and 700 a private directory. Mode 600 renders rw-------, giving only the owner read and write; its example is an SSH private key. Mode 700 renders rwx------, granting only the owner all ordinary permissions. On directories, absent group and other bits prevent those classes from listing or entering.

Private describes owner-only bits, not verified security. The calculator never checks ownership, parent directories, ACLs, mount rules, mandatory policy, or application requirements. Confirm in the matrix that group and other boxes are clear, then inspect the environment separately. The quoted chmod preview is only browser text and does not execute against the displayed path.

600 and 700 are labelled private by the preset list

Two presets address group sharing. Mode 775 renders rwxrwxr-x, granting owner and group rwx while other receives read and execute. Mode 2775 adds setgid without changing those ordinary triples. For directories, the explanation says new files inherit the directory's group. Because group execute remains set, setgid appears as lowercase s in rwxrwsr-x.

Neither preset chooses an owner or group. The page accepts a mode and display path but performs no identity lookup or chown operation. Its 775 note suggests pairing writable group access with setgid, while 2775 is labeled a setgid directory. Actual collaboration still depends on group membership and any additional rules enforced by the target system.

775 and 2775 model group sharing without selecting ownership

Preset 1777 represents a world-writable sticky directory, illustrated by the /tmp pattern. Its ordinary permissions are rwxrwxrwx, so every class may list, modify, and enter. The leading 1 enables sticky, replacing the final x with t and adding a restricted-deletion explanation. This differentiates 1777 from 777 without altering the base rwx grants.

The directory explanation remains deliberately narrow. Sticky permits creation while limiting deletion or rename to a file's owner or root. The calculator identifies neither identity, inspects no directory, and observes no attempted operation, ACL, or storage policy. Treat 1777 as a recognizable pattern to decode, not automatic approval for every shared location.

1777 is presented as the sticky shared-directory pattern

Mode 4755 is the shipped setuid-program preset. Its base is 755, and leading 4 enables setuid. Since owner execute is present, the result is rwsr-xr-x with lowercase s. The file explanation says execution uses the owner's identity rather than the caller's, and both it and the preset label caution that this rare privilege change deserves review.

The display can expose a suspicious combination without judging a program. If setuid remains while owner execute is cleared, uppercase S appears, as in 4644, and the explanation notes there is nothing to run. Tests verify both forms and every round trip. No code review, ownership check, capability analysis, or execution occurs.

4755 exposes a setuid program and a reason-to-review warning

Mode 777 is absent from the shipped presets, though the library can parse it. A 777 file triggers a warning because any account can change its contents. A 777 directory grants every class rwx and, without sticky, allows deletion of entries users do not own. Nothing in the sources presents 777 as a generic permission-error remedy.

ACL sharing and other permission models are separate. This converter represents one owner, one group, everyone else, and three special bits. It has no named ACL entries, masks, Windows syntax, platform detection, or filesystem query. Accurate rwx conversion can inform diagnosis, but platform-specific evidence must establish access granted outside the traditional mode.

777, ACL sharing and other platforms remain separate questions

The useful cheatsheet is the evidence behind the numbers, not magic values. Select any shipped preset and inspect the owner, group, other, and special boxes it activates. Compare the nine-character symbolic form with the four-digit summary. That exposes setuid, setgid, and sticky, while target selection keeps file execution distinct from directory traversal in the explanation.

Apply only the conclusion the page supports. A preset supplies an exact bit pattern and a short purpose label, not knowledge of ownership, workload, ACLs, parent directories, mounts, or threats. Its command preview never runs. Following article 501, start with identity and action, verify representation here, then review the real system before changing anything.