Developer tools · Chmod calculator
The fourth chmod digit: how setuid, setgid and the sticky bit work
· How it works
chmod unix developer-workflow
Modes like 4755 and 2775 carry a leading digit that changes who a program runs as or who owns new files. This post explains the three special bits and how they show up in ls -l.
The s in drwxrwsr-x — a shared project directory behaves differently and the ls output has a letter that is not in the basic cheatsheet
The s in rwxrwsr-x records two facts in one position: setgid is enabled, and group execute is also enabled. The implementation stores setgid as octal 2000, then substitutes s for the group-execute character. With a directory type marker selected, mode 2775 appears as drwxrwsr-x while the four-digit summary preserves the leading special-bit digit.
That output is a conversion, not a filesystem observation. The target selector changes how the page explains the bits, but it never opens a directory or examines ownership. For a directory, the implemented explanation says newly created files inherit the directory's group. Whether a particular storage system applies that behavior, or another policy affects access, requires evidence beyond this calculator.
The fourth digit and its letters — 4, 2 and 1 as a prefix on the familiar mode, shown as s and t in the execute position, uppercase when the execute bit beneath is off
The leading octal digit combines three independent masks: setuid is 4000, setgid is 2000, and sticky is 1000. Their letters occupy existing execute positions rather than adding characters to the nine-position display. Setuid uses the owner position, setgid the group position, and sticky the other position. The matrix exposes all three separately from ordinary read, write, and execute.
Case reveals the underlying execute bit. Mode 4755 renders rwsr-xr-x because owner execute accompanies setuid; 4644 renders rwSr--r-- because it does not. The parser reads both forms back into the corresponding special and execute bits. The same lower-versus-upper rule produces s or S for setgid and t or T for sticky, preserving all combinations during round trips.
setuid on executables — how /usr/bin/passwd runs with the file owner's privileges and why Linux ignores setuid on interpreted scripts
For a regular file, the implemented setuid explanation depends on owner execute. When both bits are present, the page says running the file uses the file owner's identity rather than the caller's. When setuid is present without owner execute, the display uses capital S and explains that there is nothing to run. This is the corrected, source-backed scope of the section.
The calculator does not identify a particular executable, launch one, or inspect how a platform treats scripts. Its evidence is the supplied mode and target choice. Mode 4755 can be decomposed into setuid plus rwxr-xr-x, and the assignment preview appends u+s after the ordinary clauses. That verifies rendering and explanation only; program suitability and actual execution remain external questions.
setuid rendering and explanation for regular files
Setgid on a directory is represented independently from the ordinary group permissions. Mode 2775 combines the 2000 mask with owner and group 7 and other 5. The display rwxrwsr-x keeps group read, write, and execute while replacing the visible x with s. The directory explanation associates the special bit with inheritance of the directory's group for newly created files.
Removing group execute while retaining setgid changes the group-position letter to capital S. That visible warning follows directly from the renderer, regardless of target wording. The page can compare those completed values and show which checkbox changed, but it cannot inspect a shared directory, its current group, or the identities creating entries. Agreement among the views is arithmetic evidence, not operational approval.
The sticky bit on directories — restricted deletion in /tmp and why 1777 is not the same as 777
Sticky occupies the other-execute position and contributes octal 1000. For directory mode 1777, all ordinary permissions remain enabled and the final symbolic character becomes t. The implemented directory explanation adds a deletion and rename restriction, while the 777 explanation warns about a writable directory without sticky. Thus the converter makes the one-bit difference visible without changing the underlying rwx triples.
If sticky is present without other execute, the final character is uppercase T instead. The parser and renderer preserve that distinction in both directions. The page does not inspect a real shared directory, entry owners, or attempted deletion. Its reliable conclusion is narrower: the supplied integer contains sticky, its execute companion is visible through case, and directory-oriented explanatory text is selected.
Worked example: building 2775 for a shared directory — deriving the digits and the equivalent symbolic chmod g+s,a+rwx,o-w
Build 2775 as four visible components: special digit 2 for setgid, owner digit 7 for rwx, group digit 7 for rwx, and other digit 5 for r-x. Entering the completed value produces rwxrwsr-x. The matrix selects setgid separately, while the summary names owner, group, and other permissions alongside that special bit.
The generated assignment list is u=rwx,g=rwx,o=rx,g+s. This differs from the nine-character display but represents the same twelve-bit value. Choosing directory changes the explanation to the implemented group-inheritance wording; choosing file changes the wording without changing 2775. The calculator never verifies the target's group or creates a file, so the example remains a model rather than a deployment prescription.
Worked example: building and reading 2775 for a shared-directory model
Mount behavior, capabilities, and additional platform semantics are not modeled. The page has no mount input, capability set, kernel query, or filesystem probe. It can represent setuid, setgid, and sticky and can vary its explanation between regular files and directories. It cannot establish whether an external rule neutralizes, extends, or interprets those bits differently on an actual target.
Even the source's corner wording should not be generalized beyond the interface. A valid special-bit mode proves that the parser, renderer, matrix, summary, and generated assignments agree. It does not prove execution, inheritance, or deletion behavior occurred. Keep unsupported policy claims out of the diagnosis, and treat the copied command as inert text until a separately inspected environment supplies the missing context.
Mount policy, capabilities and unimplemented corner semantics remain external
The implemented takeaway is a round trip with positional meaning. Setuid maps to the owner execute position, setgid to group execute, and sticky to other execute. Lowercase means the associated execute bit is on; uppercase means it is off. The leading octal digit and dedicated checkboxes preserve the same information, so no special bit needs to be inferred from prose alone.
Test a special mode by comparing all representations. For 2775, expect the leading 2, group-position s, a checked setgid box, and a generated g+s addition. A mismatch would expose a conversion problem. Agreement establishes only one consistent mode. Ownership, mount policy, capabilities, application rules, and the consequences of running chmod remain beyond the browser calculator's evidence.