Skip to content

Linux File Permissions Explained

Octal and symbolic modes for chmod, plus setuid, setgid, and sticky bits.

Every file has three classes: owner, group, and other. Each class sums three bits: read is 4, write is 2, execute is 1. Three octal digits form the mode.

Reference table · 42 entries
42 of 42 rows
Numeric (octal)
Owner full access; group and others read and execute.chmod 755 script.sh
Owner read and write; group and others read only.chmod 644 notes.txt
Owner read and write only; no access for others.chmod 600 ~/.ssh/id_rsa
Owner full access only; no access for others.chmod 700 ~/.ssh
Everyone full access. A security risk.chmod 777 shared/
Everyone read and write. No execute bit set.chmod 666 log.txt
Owner full access; group read and execute; others none.chmod 750 app/
Execute only, for all classes. A directory can be traversed but not listed.chmod 111 dir/
No access for any class. Root can still read the file.chmod 000 private.key
Owner and group full access plus setgid; the shared-team directory pattern.chmod 2775 /srv/team
umask results
Default mask. New files get 644; new directories get 755.umask 022
Private mask. New files get 600; new directories get 700.umask 077
Symbolic
Add execute for the owner.chmod u+x deploy.sh
Remove write from the group.chmod g-w config.yml
Remove read from others.chmod o-r secret.env
Set read-only for all classes.chmod a=r readme.md
Grant all permissions to all classes.chmod ugo+rwx public/
Special bits
Setuid bit set. Binary runs as the file owner.chmod 4755 /usr/bin/passwd
Setgid bit set. New files and subdirectories inherit the directory group.chmod 2755 /shared
Sticky bit set. Only the file owner can delete.chmod 1777 /tmp
Sticky bit on a regular file. A legacy keep-in-swap hint that modern Linux ignores.chmod 1755 legacy.sh
Commands
Change file mode bits.chmod 755 file
Change file owner and group.chown user:group file
Change the owning group of a file.chgrp devs file
Set default permission mask for new files.umask 022
List files with permissions in long form.ls -l /etc
Show POSIX ACL entries for a file.getfacl report.pdf
Set or modify POSIX ACL entries.setfacl -m u:alice:rw report.pdf
Find files whose permission bits match a mode.find / -perm /4000
Print file metadata, including the octal mode.stat -c '%a %n' file
List the permissions of every component in a path.namei -l /var/www/index.html
Change a file attribute, such as immutable.chattr +i /etc/resolv.conf
List file attributes.lsattr /etc/resolv.conf
Show the capabilities granted to a file.getcap /usr/bin/ping
Grant a file capability, without setuid.setcap 'cap_net_raw=+ep' /usr/bin/ping
List the capabilities in effect for the current shell.capsh --print
Show the user id, group id, and group memberships of a user.id alice
List the groups a user belongs to.groups alice
Run a command as another user under the sudoers policy.sudo systemctl restart nginx
Edit the sudoers file with syntax checking.visudo
Switch to another user account.su - deploy
Start a shell with a different primary group.newgrp developers