Developer tools · Chmod calculator
The Unix permission model: from 1970s chmod to POSIX mode bits
· Background
chmod unix access-control
The owner/group/others model has survived for decades with remarkably few changes. This post traces where it came from, what POSIX standardised, and why it still fits most jobs.
A 1970s design in your 2020s deployment — every container and CI runner still speaks rwx, and it helps to know why
Current deployments still present modes such as 0644 and symbolic strings such as rw-r--r--, but this repository is not a historical archive. Its evidence is the implemented representation: twelve bits, deterministic conversion, and validation of octal and symbolic input. Dates, inventors, patents, and claims about every Unix-derived system require sources not supplied here.
The calculator therefore offers a present-tense view of a compact permission model. One integer drives owner, group, and other controls plus setuid, setgid, and sticky. The output can be checked in octal, symbolic, and matrix form. Agreement proves a consistent conversion, not the origin, universality, or enforcement of the model.
A long-lived notation appears in current deployments, but this repository is not a history source
Nine ordinary bits form three equal classes. Owner, group, and other each receive read, write, and execute positions with weights 4, 2, and 1. The calculator keeps that order everywhere: in the trailing three octal digits, the nine-character symbolic row, the checkbox matrix, and the plain-English description generated for a file or directory.
A mode of 640 demonstrates the structure without a lineage claim. Owner 6 means read and write, group 4 means read, and other 0 means no ordinary permissions, producing rw-r-----. As article 501 explains, these are calculable flags; identifying the actual owner, group, or process remains outside the conversion.
The implemented model has nine ordinary bits in three classes
Setuid is implemented as the 4000 mask. On a regular file, the renderer places s in the owner execute position when both setuid and owner execute are present. If setuid is present without owner execute, it places S there instead, preserving the important difference between a special bit and the ordinary execute bit beneath it.
The file description explains the lower-case case as execution with the file owner's identity and flags the upper-case combination as having nothing to run. Those statements describe this implementation's output. The repository supplies no patent record or primary history, so this section does not attribute the mechanism or date its introduction.
setuid behavior is implemented; patent history is not sourced
Directory explanations use the same numeric value but different verbs for ordinary bits. Read lists entries, write covers creating, renaming, and deleting entries, and execute covers entering the directory and reaching named contents. The implementation also describes setgid on a directory as causing newly created files to inherit that directory's group.
Sticky is represented by 1000 and occupies the other execute position as t or T. For a directory, the tool describes restricted deletion for shared entries. These are implemented semantics presented by the calculator; no branch history or cross-system lineage is established, and no live filesystem is queried to confirm local behavior.
Directory special-bit behavior is described without a lineage claim
The source names every mask directly: 0400, 0200, and 0100 for owner; 0040, 0020, and 0010 for group; 0004, 0002, and 0001 for other. Setuid, setgid, and sticky add 4000, 2000, and 1000. Conversion is bit testing and bitwise combination rather than an appeal to an external standard.
Input rules are similarly concrete. Octal accepts one to four digits from 0 through 7, with optional 0 or 0o-style leading forms. Symbolic input accepts nine positions or ten with a recognized file-type character. The repository does not establish that every implementation or standard accepts precisely the same surface grammar.
Named bit masks and conversion semantics are verified; universal standards claims are not
The compact model has deliberate limits. It provides one owner class, one group class, and one other class, but no named-user entry, named-group entry, ACL mask, or default ACL. It also has no capability set. Those mechanisms cannot be inferred from an apparently ordinary rwx string or a successful octal conversion.
Command generation does not expand the model. It emits an octal argument or explicit u=, g=, and o= clauses, adding u+s, g+s, or +t when required. The result remains displayed text. A responsible review gathers any ACL, capability, ownership, and enforcement evidence separately before treating the mode as a complete access-control account.
ACLs and capabilities sit outside the implemented mode model
This source set contains no supported comparison with Windows, VMS, Plan 9, or other operating-system permission histories. Omitting those narratives is more accurate than presenting remembered contrasts as fact. The calculator only demonstrates the mode representation it implements, and its tests can establish conversion behavior rather than the evolution of unrelated systems.
The same caution applies to broad compatibility language. A recognized leading file-type character may be parsed before the nine permission positions, but that does not prove universal ls formatting. Use the output as a precise reading of this tool's accepted notation, then consult authoritative platform documentation for behavior beyond these source-backed boundaries.
Other operating-system permission histories are omitted without sources
What survives scrutiny here is the compactness of the implemented model. Twelve named bits cover three ordinary permission classes and three special flags, while octal and symbolic views expose the same integer in different forms. Invalid digits or misplaced symbolic letters are rejected rather than silently repaired, making errors visible during conversion.
That is enough for a practical takeaway without a history lesson. Decode the mode, inspect each class, and notice whether s, S, t, or T replaces an execute position. Then stop where the evidence stops: the calculator explains representation and generated text, while ownership, policy, filesystem behavior, and historical provenance require other sources.