Chmod Calculator
Work out chmod numbers, symbolic modes and umask results, with warnings for risky modes.
Permissions
3 or 4 digits such as 644, 755 or 2775
rwxr-xr-x, -rw-r--r-- or a whole ls -l line
| Who | Read4 | Write2 | Execute1 | Digit |
|---|---|---|---|---|
| Owner u | 7 | |||
| Group g | 5 | |||
| Others o | 5 |
drwxr-xr-x · u=rwx,go=rx
Common modes
chmod and find commands
Separate modes for directories and files — the safe way to fix a whole tree.
Apply a chmod change
See what a symbolic mode such as u+x or a pasted chmod command does to the permissions above.
Clauses without u, g, o or a respect the umask below (as chmod does).
umask: permissions of new files
Octal (022) or symbolic as umask -S prints it
Programs normally ask for 666 when they create a file and 777 for a directory; the umask removes bits from that. Run umask in a terminal to see yours.
Read ls -l output
About the Chmod Calculator
Tick what the owner, group and others may do — or type 755, 2775, rwxr-xr-x or a whole ls -l line — and get the octal number, the symbolic form and the chmod command, including the setuid, setgid and sticky bits. Every mode comes with a plain-language summary for files or directories and a warning when it is risky, such as 777 or a world-writable directory without the sticky bit.
Below the calculator you can try a relative change (u+x, go-w, a+X, g=u or a pasted chmod -R … command) exactly as GNU chmod on Linux applies it, see which modes your umask gives new files and directories, decode pasted ls -l output, and get find commands that give directories and files different modes. Nothing is uploaded and nothing touches your files.
How to use it
- Tick the read, write and execute boxes, or type a mode in either box:
644,0755,2775,rwxr-xr-x,-rw-r--r--or anls -lline. - Choose File or Directory: execute means “run” for a file and “enter” for a directory, and the explanation and warnings change with it.
- Copy the octal,
rwxor symbolic form, or enter a path under chmod and find commands to get commands that set directories and files separately. - Type a relative change such as
u+x,go-worchmod -R g+w dirunder Apply a chmod change to see the result step by step, then press Apply to keep it. - Enter your umask to see the modes of new files and directories, or paste
ls -loutput and press Use on a line to load its permissions.
Examples
Path /var/www/example.com · directories 755 · files 644
find /var/www/example.com -type d -exec chmod 755 {} +
find /var/www/example.com -type f -exec chmod 644 {} +
chmod -R u=rwX,go=rX /var/www/example.comThe last line does both in one go: capital X gives execute to directories, but only to files that already have an execute bit.
2775 (directory)
drwxrwsr-x · ug=rwx,o=rx,g+s
The setgid bit (the leading 2) makes new files take the folder’s group, so the whole team can edit them.
chmod -w on a 666 file, umask 022
466 (r--rw-rw-), not 444
With no u, g, o or a, chmod leaves alone the bits the umask masks (POSIX). a-w removes write for everyone.
600
-rw------- · u=rw,go=
OpenSSH ignores a private key file that the group or others have any access to.
Common uses
- Finding the right mode for web roots, upload folders, deploy scripts, SSH keys and config files.
- Fixing “Permission denied” errors without reaching for chmod 777.
- Decoding
ls -loutput orstatresults someone pasted in a ticket. - Writing chmod commands for Dockerfiles, CI scripts and Ansible tasks, and checking what a symbolic mode really does.
- Choosing a umask for a shared server or a service account.
How the numbers work
Each octal digit adds up read (4), write (2) and execute (1) for one class of user: the owner, the group, then everyone else. 754 is rwx (4+2+1) for the owner, r-x (4+1) for the group and r-- (4) for others.
An optional first digit holds the special bits: setuid (4), setgid (2) and the sticky bit (1), as in 4755, 2775 and 1777. ls -l shows them in the execute positions: s for setuid or setgid, t for sticky — and a capital S or T when the execute bit underneath is off, which usually means the special bit does nothing.
Files and directories are different
- Read a file to see its contents; read a directory to list the names in it.
- Write a file to change it; write a directory to create, rename or delete entries — which also needs execute.
- Execute a file to run it as a program (scripts also need read); execute (search) a directory to enter it and reach the files inside.
So directories almost always need r and x together: r-- lets you see names but open nothing, while --x lets you open a file only if you already know its name. Deleting a file depends on the directory’s permissions, not the file’s.
Symbolic modes, the umask and GNU chmod
A symbolic mode is who (u, g, o, a), an operator (+ add, - remove, = set exactly) and permissions (r, w, x, X, s, t), with clauses separated by commas: u=rwx,go=rx. g=u copies the owner’s permissions to the group. With no who letter, chmod works on everyone but treats the bits set in your umask differently (POSIX): + does not add them, - does not remove them and = clears them — which is why chmod +w usually only gives the owner write access.
The calculator follows GNU coreutils chmod, the one on Linux. It also accepts operator numeric modes such as =644, and on directories it keeps the setuid and setgid bits when a 3- or 4-digit mode, u=… or g=… does not set them — use 00755, =755 or g-s to clear them. macOS and BSD chmod differ in a few corner cases: they clear a directory’s setuid and setgid bits in those cases, o=… leaves the sticky bit alone, a copy such as g=u keeps a file’s setgid bit, =755 is rejected, and X looks at the mode before the whole change rather than after the earlier clauses.
Modes worth a second look
- 777 / 666 — anyone on the machine, including a compromised web application, can change the file. Fix ownership (
chown,chgrp) and use 755/644 or a group mode such as 775/664 instead. - World-writable directories without the sticky bit let any user delete anyone’s files; shared scratch space uses 1777, like
/tmp. - Setuid and setgid programs run with the privileges of the file’s owner or group. They belong on a handful of system programs such as
passwd, never on files others can write. - Owner with less access than group or others (for example 477) is almost always a typo.
Limitations
- It calculates permissions only: it never reads or changes your files. Check the path before you run a command, especially with
-Rorfind. - Access control lists (ACLs, the
+inls -l), SELinux or AppArmor policies, immutable attributes (chattr +i) and read-only mounts can allow or deny more than the mode bits show. - Symbolic changes follow GNU coreutils chmod on Linux; macOS and BSD chmod differ in the corner cases described above.
- umask results assume the program asks for 666 for files and 777 for directories, as most do; a program can ask for less, never more. A default ACL on the parent directory replaces the umask for files created in it.
Privacy
Everything happens in your browser. What you enter or open here is not uploaded or stored by MySmartCoPilot.
Frequently asked questions
What does chmod 755 mean?
The owner can read, write and execute (7 = 4 + 2 + 1); the group and everyone else can read and execute (5 = 4 + 1). Written out it is rwxr-xr-x. It is the usual mode for directories, scripts and programs.
What is the difference between 644 and 755?
644 (rw-r--r--) has no execute bits, which is right for ordinary files. 755 adds execute for everyone, which directories need (to be entered) and programs need (to be run). Giving every file 755 makes all of them executable — set directories and files separately with the find commands.
Why is chmod 777 a bad idea?
It lets every user and every process on the machine change or replace the file, or add and delete files in the directory. Permission errors are almost always better fixed by giving the right user or group ownership and using 755/644 (or 775/664 for a shared group).
What do s, S, t and T mean in ls -l?
s in the owner’s execute position means setuid plus execute; in the group’s, setgid plus execute. t in the last position is the sticky bit plus execute for others. A capital S or T means the special bit is set but the execute bit under it is not.
How does umask 022 work?
Programs ask for 666 when they create a file and 777 for a directory, and the umask removes bits from that. 022 removes write for the group and others, so new files are 644 and new directories 755. 002 gives 664 and 775; 077 gives 600 and 700.
Why did chmod +w not give everyone write permission?
When a symbolic mode has no u, g, o or a, chmod leaves alone the bits that are set in your umask. With the common umask 022, +w only adds write for the owner. Write a+w (or ugo+w) to really change everyone — the calculator shows both results when they differ.
Is anything uploaded or run on my server?
No. Everything is calculated in your browser; the page never sees your files and works offline once loaded. You copy the commands and run them yourself.