How chmod numbers work
Every file has three sets of permissions — for its owner, its group and everyone else — and each set is three bits: read (4), write (2) and execute (1). Add up the bits a set has and you get one octal digit, so 755 is owner 7 (4 + 2 + 1), group 5 (4 + 1) and others 5. Tick boxes above, type a number, or type the symbolic form that ls -l prints; the other two follow.
| Digit | Symbolic | Meaning |
|---|---|---|
| 0 | --- | No access |
| 1 | --x | Execute only |
| 2 | -w- | Write only |
| 3 | -wx | Write and execute |
| 4 | r-- | Read only |
| 5 | r-x | Read and execute |
| 6 | rw- | Read and write |
| 7 | rwx | Read, write and execute |
Files and directories read the bits differently
- On a file, read lets you open it, write lets you change it, and execute lets you run it as a program — a script without the execute bit fails with bash: Permission denied.
- On a directory, read lets you list the names in it, write lets you create, rename and delete files in it, and execute lets you enter it and reach anything inside. A directory needs execute to be usable at all, which is why directories are 755 where the files in them are 644.
- Deleting a file is a right on the directory, not on the file: anyone who may write to a directory can delete files in it, whatever the files’ own modes — unless the directory has the sticky bit.
Common modes and where they belong
| Mode | ls -l | Typical use |
|---|---|---|
| 644 | rw-r--r-- | Ordinary files: web pages, images, most configuration |
| 755 | rwxr-xr-x | Directories, and scripts or programs anyone may run |
| 600 | rw------- | Private keys, .env files, ~/.ssh/authorized_keys |
| 700 | rwx------ | ~/.ssh and other private directories |
| 640 | rw-r----- | Configuration a service reads through its group |
| 2775 | rwxrwsr-x | Shared project directory: new files keep the directory's group |
| 1777 | rwxrwxrwt | /tmp: anyone may create files, only the owner may delete them |
| 4755 | rwsr-xr-x | Setuid programs such as passwd — rarely something to set yourself |
SSH is strict about the first rows: it refuses a key whose file or directory others may write to, which is one of the causes of Permission denied (publickey). The usual fix is chmod 700 ~/.ssh and chmod 600 ~/.ssh/authorized_keys.
Changing a whole tree
chmod -R 755 gives every file the execute bit along with the directories. Give directories and files their own modes instead, and fix ownership first — most permission errors on a web server are a wrong owner, not a wrong mode. Let the account you deploy with own the code and the web server’s group read it, so a compromised app cannot rewrite its own files; only the directories the app writes to, such as uploads or a cache, get group write:
sudo chown -R deploy:www-data /var/www/site
sudo find /var/www/site -type d -exec chmod 750 {} +
sudo find /var/www/site -type f -exec chmod 640 {} +
sudo chmod -R g+w /var/www/site/uploadsdeploy stands for your own user; www-data is the group nginx, Apache and PHP-FPM run as on Debian and Ubuntu. Use 755 and 644 instead of 750 and 640 if other accounts on the server need to read the files.
chmod u+x deploy.sh, chmod g-w file and chmod o= file change one set without touching the others; the calculator’s symbolic command sets all three at once.
Frequently asked
What does chmod 755 mean?
The owner may read, write and execute (7 = 4 + 2 + 1); the group and everyone else may read and execute (5 = 4 + 1). It is the usual mode for directories and for programs or scripts that anyone may run but only the owner may change, and ls -l shows it as rwxr-xr-x.
What is the difference between chmod 644 and 755?
644 (rw-r--r--) lets the owner read and write and everyone else read, with no execute bit — the mode for ordinary files such as HTML, images and configuration. 755 adds execute for everyone, which a directory needs before anyone can enter it and a script needs before it can be run.
Why is chmod 777 a bad idea?
777 lets every account on the system — including a web server's, if one site on it is compromised — change, replace or delete the file, and on a directory create new files in it. Most advice that ends in 777 is really an ownership problem: hand the file to the right user with chown and keep the mode at 644 for files and 755 for directories.
What are setuid, setgid and the sticky bit?
They are the optional leading digit. 4 (setuid) runs an executable with its owner's rights — that is how passwd can write the password file. 2 (setgid) does the same for the group, and on a directory makes new files inherit the directory's group. 1 (sticky) on a directory lets only a file's owner delete it, which is why /tmp is 1777. ls -l shows them as s, s and t in the execute positions, as capital S or T when the execute bit underneath is off.
How do I set permissions recursively without making every file executable?
chmod -R gives everything below a path the same mode, so files end up with the execute bit that only directories need. Set the two separately: find /path -type d -exec chmod 755 {} + for the directories and find /path -type f -exec chmod 644 {} + for the files.
Related guides
bash: Permission denied — why your script will not run
Permission denied on a script usually means the execute bit is missing, or the file lives on a noexec mount. How to tell which, and fix both safely.
Permission denied (publickey) — every reason SSH rejects your key
The SSH connected but your key was refused. The four causes: wrong user, wrong key offered, bad file permissions, or the key was never installed.