Module 5 · Users, groups and permissions
chmod with octal modes
Permissions as three digits: r=4, w=2, x=1, add them up per triplet, and learn the handful of modes you will type for the rest of your life.
What you will learn
- Convert between an rwx triplet and its octal digit in both directions.
- Recognise and apply the common modes 644, 600, 755, 700, 750 and 775.
- Choose between octal and symbolic for a given change.
Three bits make one digit
Each triplet is three yes/no bits, and three bits are exactly one octal digit, 0 to 7. Give the bits their binary weights, r=4, w=2, x=1, and add up whatever is present: rwx is 4+2+1=7, r-x is 5, rw- is 6, r-- is 4, --- is 0. Do that for user, group and others and you get the whole mode as a three-digit number: -rwxr-xr-x is 755, -rw-r--r-- is 644. Going back is just as mechanical: 6 can only be 4+2, so rw-.
| Digit | Bits | Sum |
|---|---|---|
| 0 | --- | nothing |
| 1 | --x | 1 |
| 2 | -w- | 2 |
| 3 | -wx | 2+1 |
| 4 | r-- | 4 |
| 5 | r-x | 4+1 |
| 6 | rw- | 4+2 |
| 7 | rwx | 4+2+1 |
~% cd /root/lab/l47
l47% chmod 755 script.sh
l47% chmod 600 id_key
l47% chmod 640 report.txt
l47% ls -l
-rw------- 1 root root 0 Oct 4 19:15 id_key
-rw-r----- 1 root root 0 Oct 4 19:15 report.txt
-rwxr-xr-x 1 root root 0 Oct 4 19:15 script.sh
l47% chmod -c 644 report.txt
mode of 'report.txt' changed to 0644 (rw-r--r--)
The modes you will actually use
| Mode | Looks like | Typical use |
|---|---|---|
644 | -rw-r--r-- | Ordinary file: you edit, everyone reads. The default for new files |
600 | -rw------- | Private file: keys, passwords, mail |
755 | -rwxr-xr-x | Programs and scripts; also the default for directories |
700 | -rwx------ | Private script or private directory (/root is 700) |
750 | -rwxr-x--- | Shared with the group, hidden from others |
664 / 775 | -rw-rw-r-- / -rwxrwxr-x | Group-writable file / directory for a team |
777 | -rwxrwxrwx | Everyone may do everything. Almost always a mistake |
Octal is absolute: chmod 644 f sets all nine bits regardless of what they were. That is its strength, you know the final state without looking, and its risk, because chmod -R 644 dir also strips x from every directory inside and locks you out of them. Use octal when you want to *state* a mode, symbolic when you want to *adjust* one. The two forms are interchangeable: 755 is u=rwx,go=rx.
A fourth digit
You will sometimes see four digits, 0644 or 4755. The leading digit holds the three special bits, setuid (4), setgid (2) and sticky (1), which lesson 50 explains; chmod -c prints modes that way. A leading 0 just means none of them is set, and chmod 644 is the same as chmod 0644.
Commands in this lesson
| Command | What it does |
|---|---|
chmod 644 FILE | rw-r--r--: owner edits, everyone reads. |
chmod 600 FILE | rw-------: private file. |
chmod 755 FILE | rwxr-xr-x: program or public directory. |
chmod 700 DIR | rwx------: private directory. |
chmod 750 DIR | rwxr-x---: group may enter, others may not. |
chmod -c 640 FILE | Set and print the resulting mode. |
Quiz
What mode string does `chmod 640` produce?
- `-rw-r-----`
- `-rw-rw----`
- `-rwxr-----`
Which octal mode is `-rwxr-x--x`?
- `751`
- `761`
- `741`
Why is `chmod -R 644 project/` usually a bad idea?
- Because 644 is not a valid mode for files
- Because it removes `x` from the directories too, so nobody can enter them
- Because -R only works with symbolic modes
What is the symbolic equivalent of `755`?
- `u=rwx,go=rx`
- `a=rwx`
- `u=rw,go=r`
In `4755`, what does the leading 4 mean?
- Read permission for everyone
- The setuid special bit
- Four hard links
Practice
Set `/root/lab/l47/script.sh` to the standard mode for a program: owner rwx, everyone else r-x.
Make `/root/lab/l47/id_key` private: readable and writable by its owner, nothing for anyone else.
`/root/lab/l47/report.txt` is currently world-writable. Set it so the owner can read and write, the group can only read, and others get nothing.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.