English

Developer tools · Chmod calculator

How chmod octal digits map to rwx permission bits (4, 2, 1)

· How it works

chmod unix developer-workflow

Octal permission digits split into owner, group and other rwx bits
Original ToolAcre vector illustration

Each octal digit is three binary flags in disguise. This post shows the arithmetic that turns 7 into rwx and 5 into r-x, so you can read and write any mode without a lookup table.

The number you keep pasting — chmod 755 works, but you cannot say what the 5 grants or to whom

Running chmod 755 because a forum answer said so may grant more access than an application needs. A Unix mode is a compact encoding of who may read, write or execute a file; the number is not an arbitrary setting to paste whenever permission is denied. Before changing it, ask which identity owns the file, which group a process runs as, and which action actually failed. A syntactically valid mode does not solve a wrong owner or a missing parent-directory execute permission.

Three classes, three digits — owner, group and others each get one octal digit in a fixed order

Three octal digits describe three classes in order: owner, group, others. In 640, the owner gets 6, the group gets 4, and everyone else gets 0. “Other” does not mean root or a service account; it means identities matching neither the owner nor the file’s group under ordinary mode-bit checks. An optional leading fourth digit handles special modes such as setuid, setgid and sticky, which is a separate topic and should not be inferred from the trailing three.

Read 4, write 2, execute 1 — why the weights are powers of two and how they add to any value from 0 to 7

Each class has three bits with weights read=4, write=2 and execute=1. Add only the allowed weights: 7=4+2+1 (rwx), 6=4+2 (rw-), 5=4+1 (r-x), and 0=---. They are powers of two, so no combination of three independent flags produces the same total as another. Directory execute means traversal, not “run this folder”; a directory often needs it for users to access files inside even when the file itself has read permission.

Worked example: decoding 640 and 751 by hand — turning each digit into a binary triple and then into rwx letters

Decode 640 by class: 6 -> binary 110 -> rw-; 4 -> 100 -> r--; 0 -> 000 -> ---. The nine permission letters are rw-r-----. Decode 751: 7 -> rwx, 5 -> r-x, 1 -> --x, giving rwxr-x--x. Notice how “other” in 751 can traverse or execute without read or write. That may be intentional for a directory but merits review on a sensitive file. Use Chmod calculator to compare the octal and symbolic outputs rather than memorising examples.

Going the other way: from ls -l to octal — reading rwxr-x--- and adding the weights per class

Work backwards from a symbolic mode such as rwxr-x---. The owner has 4+2+1=7, the group 4+1=5, and others 0; the result is 750, not 755. A long ls -l display also has a leading file-type character and may show a trailing + for ACLs, so do not feed the whole display string into three-digit arithmetic. For a directory, plan read/write/execute separately for each class instead of copying the mode of a neighbouring file.

What this does not cover — the leading fourth digit for setuid, setgid and sticky, and ACLs that ls marks with a plus sign

This seven-section walkthrough covers the ordinary nine permission bits. It does not explain a leading 4, 2 or 1 for setuid, setgid and sticky; those bits change how a program or directory behaves and are represented by s/S or t/T in symbolic output. Access-control lists can grant or deny access beyond this simple picture. The ToolAcre calculator supports additional special bits, but you should read their separate explanation before enabling them on a production system.

Takeaway: a mode is nine bits you can compute — and the Chmod calculator lets you check the conversion in either direction in the browser

A mode is nine flags you can calculate, not an incantation. Chmod calculator converts octal and symbolic forms in your browser so you can test a proposed mode before executing any chmod command yourself. The tool does not change permissions on your computer: it provides the string and reasoning, while your shell and filesystem remain under your control.