English

Developer tools · Chmod calculator

How to read ls -l permissions and convert them to an octal mode

· How it works

chmod unix developer-workflow

ls-style mode strings shown as a distinct Unix permission-bit diagram
Original ToolAcre vector illustration

The ten-character string at the start of ls -l is a file type plus nine permission bits. This post shows how to decode it and produce the octal mode that chmod wants, including the special-bit letters.

A ticket with -rw-r-----+ pasted in — you need to know whether to tell the user to run chmod 640 or something else

A pasted string such as -rw-r-----+ contains more than this parser accepts. The recognized core is a nine-character permission body, optionally preceded by one supported file-type character. The trailing plus makes the input too long and is rejected. Removing that external marker leaves -rw-r-----, which converts to 640: owner read/write, group read, and no permissions for other.

That conversion does not decode what the plus represents beyond article 501's warning that a long listing may use it for ACLs. The calculator has no ACL entries or mask. It also does not inspect the ticket's machine, owner, group, or path. Mode 640 is therefore the base permission value represented by the accepted core, not a complete answer about effective access.

The first character is the type — dash, d, l, c, b, p and s, and why it is not part of the mode

The optional first character is treated as a type marker rather than a permission bit. The parser recognizes -, d, l, b, c, p, s, D, and ?. When one appears before nine valid permission positions, it is removed for arithmetic. The resulting owner, group, and other triples alone determine the octal value and matrix selections.

This behavior is easy to verify with equivalent inputs. Both rwxr-x--- and -rwxr-x--- produce 750 because the leading dash contributes no mode bit. A directory marker can precede the same body and still yield the same integer. The target selector controls explanatory wording separately, so accepting a type character does not mean the browser has discovered or opened that object.

Nine characters in three groups — owner, group, others, always in rwx order, with a dash for each bit that is off

The nine permission positions form three fixed triples in owner, group, and other order. Within each triple, read occupies the first position, write the second, and execute the third. A dash means the corresponding bit is off. Position-specific validation rejects a misplaced letter instead of guessing, so an r in a write position cannot silently become another permission.

Each accepted triple maps to one octal digit by the weights in article 501: read is 4, write is 2, and execute is 1. The matrix shows the same flags as checkboxes and rebuilds the integer when one changes. Special letters are accepted only in execute positions, preserving setuid, setgid, or sticky together with the underlying execute state.

Worked example: -rwxr-x--- to 750 — assigning 4, 2, 1 to each letter and summing per group

Convert -rwxr-x--- by ignoring the leading type marker and splitting the body into rwx, r-x, and ---. Owner has 4+2+1, producing 7. Group has 4+1, producing 5. Other has no enabled bit, producing 0. The calculator returns 750 and selects the matching nine ordinary permission boxes.

The reverse check should land on the same text body. Enter 750 and the symbolic field becomes rwxr-x---; choose a regular-file marker for the displayed form and it becomes -rwxr-x---. The assignment preview is different syntax: u=rwx,g=rx,o=. All three views describe one fixed mode, while ownership and the wisdom of applying it remain unresolved.

The trailing plus and at signs — the + meaning ACL entries exist, the @ meaning extended attributes on macOS, neither being part of the mode

Trailing plus and at signs are metadata markers in the outline, but the implemented fact is narrower: this parser rejects either because accepted input ends after the permission body. Article 501 specifically identifies a trailing plus with ACLs. CHMOD_SOURCES provides no equivalent interpretation for an at sign, so this section does not assign it an operating-system meaning unsupported by the repository.

Strip no marker blindly when effective access matters. Instead, separate the accepted nine or ten character core for base-mode conversion and investigate any remainder with evidence from the originating system. The calculator can show that rw-r----- means 640. It cannot explain additional metadata, read extended attributes, or determine whether another access-control mechanism changes what a user or process can do.

Trailing plus and at signs are metadata markers this parser rejects

External stat commands are not run by the browser calculator. The page has no command runner or filesystem access; its path field exists only to construct quoted chmod text for display. Consequently, it cannot fetch a current mode, compare platform-specific command output, or certify that a pasted string came from a particular utility. The user must supply the value to convert.

Once a trustworthy mode is supplied, the browser provides an independent representation check. Enter the symbolic core and compare its octal result, matrix, summary, and assignment preview. Agreement catches transcription and arithmetic errors within the supported format. It does not validate the external collection command, reveal ownership, or prove that the represented permissions are effective on the object from which the text was copied.

External stat commands are not run by the browser calculator

ACL decoding remains outside the route. Its model contains owner, group, other, and three special bits, with no named entries or ACL mask. Windows permission decoding is equally absent: there is no Windows identity model, access-control entry syntax, or platform discovery. A nine-position Unix-style core can be converted, but neither additional permission system can be reconstructed from that result.

This boundary also limits diagnosis. A base mode that appears sufficient does not prove an ACL or another policy is irrelevant, while a restrictive mode does not identify every possible grant. The calculator settles only the twelve represented bits. Use its output to state the ordinary mode precisely, then reserve claims about effective authorization for tools and documentation that actually expose the external permission system.

ACL and Windows permission decoding remain outside the route

Reading an ls-style mode becomes mechanical once the accepted core is isolated. Drop one recognized leading type character, divide the remaining nine positions into owner, group, and other, and total read 4, write 2, and execute 1 within each triple. The calculator performs that conversion and validates position-specific letters, including the implemented s, S, t, and T forms.

Keep the conclusion proportional to the input. A successful conversion proves that the accepted string maps consistently to an octal mode, matrix, summary, and generated assignment. It does not run stat, inspect the path, decode a trailing marker, identify ownership, or apply chmod. Those limits make the output useful: it is exact about base mode arithmetic and silent about evidence it never collected.