Reading the nine characters
ls -l shows -rwxr-xr--: the first character is the type (d, l, -), then three triplets for owner, group, and others — read (4), write (2), execute (1). So 754 means owner rwx, group r-x, others r--. Execute on a directory means traverse (enter and access known names), not list — listing needs read too.
Octal shorthand
| Octal | Meaning | Common use |
|---|---|---|
| 755 | rwxr-xr-x | dirs, executables |
| 644 | rw-r--r-- | ordinary files |
| 600 | rw------- | private files (SSH keys) |
| 700 | rwx------ | private dirs (~/.ssh) |
Symbolic form edits what octal replaces: chmod g+w file adds group write; chmod o-r file removes other-read; chmod u+x script.sh makes it runnable. Use -R carefully, and prefer X (execute only for directories) when recursing: chmod -R u+rwX,go+rX ..
The three special bits
- setuid (4000) — run executable as its owner:
passwdruns as root this way. Rare, audited, and a classic privilege-escalation vector when misplaced. - setgid (2000) — on directories, new files inherit the directory's group: the collaboration pattern for shared team folders.
- sticky bit (1000) — on a world-writable dir, users can delete only their own files:
/tmpis 1777 for exactly this reason.
umask: permissions at creation
New files start 666 and directories 777, minus the umask. The common 022 yields 644/755; private setups use 077 (600/700). It's per-shell: set it in ~/.bashrc or ~/.zshrc, not once and forgotten.
Pitfalls
- SSH refuses keys that are too open —
~/.ssh/id_ed25519must be 600; the cryptic error is "UNPROTECTED PRIVATE KEY". - Execute-without-read on a script fails: the interpreter can't open it. Binaries can run r-x; shell scripts can't run --x.
- Directories need x for access — r without x lets you list names but not open anything inside.
Compute permission sets interactively with the Chmod Calculator.