English

Developer tools · Chmod calculator

What the execute bit does on a directory, and why 644 folders break

· How it works

chmod unix developer-workflow

directory traversal shown as a distinct Unix permission-bit diagram
Original ToolAcre vector illustration

On a directory, x is not about running anything; it grants the right to traverse. This post explains the read/search split, the odd cases it produces, and the modes that avoid them.

Permission denied on a file you can read — the file is 644, the directory is 644, and cat still fails

A readable file can remain unreachable when its directory lacks execute for the relevant class. Article 501 calls directory execute traversal rather than running a folder. The calculator's directory explanation is more explicit: read lists entries, write permits entry changes, and execute permits entering the directory and reaching files inside by name. Mode 644 has no execute bit for any class.

Compare 644 with 755 while the target is set to directory. The first renders rw-r--r--; the second renders rwxr-xr-x. Every class gains execute, while only the owner retains write in both modes. That contrast explains the represented permission difference. The page does not inspect the file, identify the accessing process, or test whether an ancestor directory blocks the actual path.

Read lists, execute traverses — how directory r shows names while x lets you open entries by name and stat them

Directory read and execute are separate flags with separate explanations. Read corresponds to listing entries. Execute corresponds to entering the directory and reaching named files inside. A class can therefore have one without the other in the numeric model. The matrix keeps that distinction visible by placing read at weight 4 and execute at weight 1 within each class digit.

Changing an other-class digit from 4 to 5 is a focused demonstration. The symbolic triple moves from r-- to r-x, and the directory explanation adds name-based reachability while retaining listing. This is a conversion fact, not a live access test. Ownership, identity, ACL entries, and mandatory policy are absent, so the calculator cannot say which class governs a real request.

The four combinations — r without x, x without r, both and neither, and what each lets a user actually do

The four read-and-execute combinations are representable without assigning broader system behavior. Digit 4 is r--, digit 1 is --x, digit 5 is r-x, and digit 0 is ---. For a directory target, the generated prose associates those selected bits with listing and name-based reachability. Write remains an independent flag and is not implied by either read or execute.

Use the matrix to isolate one class at a time rather than treating a three-digit mode as a label. The page rebuilds the integer whenever a box changes, so the matching digit and symbolic position move together. It cannot open a directory or attempt a lookup. The four combinations are exact modeled permissions, while any effective result depends on separately observed target context.

Traversal applies to every ancestor — why one restrictive directory higher up the path breaks access to everything beneath

Article 501 identifies a missing parent-directory execute permission as a reason a valid file mode may not solve access. Each directory component in a path presents its own mode question. The calculator can decode each supplied value independently and show whether owner, group, or other execute is present. It cannot walk the path or determine which class applies to the requesting identity.

This makes ancestor analysis an external inspection workflow rather than a calculator feature. If a parent is reported as 750, the page shows rwxr-x---; if another is 700, it shows rwx------. That difference is concrete, but no conclusion follows until ownership and process membership are known. The command preview remains inert and offers no evidence that changing either directory is appropriate.

Worked example: fixing a web root — checking each directory from / to the served file and choosing 755 or 750

For a web-root example, inspect supplied modes component by component instead of prescribing one value for the tree. Mode 755 grants owner rwx and group and other r-x; mode 750 removes all other permissions while retaining group r-x. The converter makes that difference visible. It cannot identify a web process, discover the path, or choose which class needs traversal.

Check the served file separately from its directories. A supplied file mode such as 644 renders rw-r--r--, while the same number selected as a directory describes different actions and lacks execute everywhere. This target-sensitive wording prevents file reading from being confused with directory traversal. Suitability still depends on actual ownership, process identity, ancestors, and any access-control layers absent from the page.

Recursion done right — why chmod -R 644 on a tree is the classic mistake and how capital X or find -type d avoids it

Recursive display is intentionally modest. Selecting it only inserts -R into the generated chmod command; the calculator does not enumerate a tree or distinguish files from directories. Applying a completed 644 mode everywhere would leave directory execute clear in every class. The page can reveal that result, but it does not implement capital X or a file-type selection workflow.

Generated symbolic assignments also remain fixed. For 644 they are u=rw,g=r,o=r, not a relative command that conditionally preserves traversal. The ls-style field shows rw-r--r-- and should not be confused with that assignment list. Any external recursion strategy must be verified outside this route, including target selection, link handling, and the final modes placed on different object types.

What this does not cover — sticky and setgid behaviour on directories, and ACL masks, which are covered in their own posts

Sticky, setgid, and ACL masks are separate from the ordinary traversal question. The calculator does implement sticky and setgid representation and target-sensitive explanations, but this article's core comparison needs only read and execute. ACL masks are not represented at all. A correct base-mode conversion cannot establish whether additional entries grant or limit access for a particular identity.

Umask is also outside the test. The page accepts a completed mode, not the process settings that may have preceded it. If a directory appears with 644, the converter can show the missing execute positions and generate a candidate command for another supplied value. It cannot say why the mode arose, whether ownership is wrong, or whether changing it addresses the real failure.

Takeaway: directories need x to be usable — and the calculator makes the difference between 644 and 755 visible as r-- versus r-x

The durable takeaway is that directory x represents entry and name-based reachability in this calculator's explanation. Mode 644 displays r-- for group and other, whereas 755 displays r-x for both and adds owner execute as well. The synchronized octal field, symbolic field, matrix, and prose make that distinction inspectable without treating either familiar number as universally correct.

Diagnose beyond the arithmetic before applying anything. Confirm the relevant identity, ownership, each ancestor's supplied mode, and the target type. Then use the calculator to verify any completed candidate value. It will reject malformed notation and show exactly which bits change, but it never opens the path, executes chmod, evaluates application policy, or proves that traditional mode bits are the only authority.