chmod Calculator
Convert between octal and symbolic Unix permissions, with every bit explained and dangerous combinations flagged.
| Read (4) | Write (2) | Execute (1) | |
|---|---|---|---|
| Owner | |||
| Group | |||
| Everyone else | |||
| Special bits |
What this allows
About this mode
Everything is calculated in your browser. Permissions are only half the picture — ownership decides who the owner and group actually are, so check both.
What It Does
Unix permissions are three bits repeated three times, written in octal — which makes them compact, easy to type, and completely opaque until you have memorised the arithmetic. This converts between the forms in every direction: tick the boxes and get the number, type 755 and see the symbolic string, or paste the rwxr-xr-x you got from ls and get the octal back. Alongside the conversion it says in plain language what each group can actually do, which matters more than the notation. It also flags the combinations that are usually mistakes rather than choices — world-writable files, setuid on something that should not have it — because 777 is what people reach for when a permission error appears, and it solves the error by removing the protection.
When to Use It
- A deployment guide specifies permissions in octal and you want to check what they actually grant before applying them.
- ls -l shows a symbolic string and you need the number for a chmod command or a Dockerfile.
- An upload directory is failing to write and you need to work out which bit is missing rather than reaching for 777.
- You are reviewing infrastructure code and want to confirm the permissions it sets are not more permissive than intended.
- You are learning Unix permissions and want to see the arithmetic connect to what each group can do.
Worked Examples
644
The standard for an ordinary file. The owner can read and write, everyone else can only read. Note there is no execute anywhere, which is correct for a document or a configuration file but would stop a script running.
755
The standard for a directory or an executable. Adds execute for all three groups — which on a directory means the right to enter it, not to run anything, and is why directories that are only 644 produce such confusing errors.
777
Everything to everyone. The tool flags this because it is almost never the right answer — it is what gets applied when a permission error appears, and it fixes the error by removing the protection rather than correcting the ownership.
Features
How to Use
1. Type an octal value like 755, or a symbolic string like rwxr-xr-x, or tick the boxes directly. 2. Every other representation updates immediately. 3. Read the plain-language summary of what each group can do. 4. Check any warnings before applying a permissive mode. 5. Copy the ready-made chmod command.
Common Mistakes
- Using 777 to make a permission error go away. It works by removing the protection; the error was almost certainly telling you the owner or group was wrong, which chown fixes properly.
- Removing execute from a directory. On a directory execute means the right to enter it, so without it the contents become inaccessible even though the names are still listable.
- Leaving configuration files world-readable. A file holding database credentials at 644 can be read by every account on the machine — those belong at 600 or 640.
- Setting setuid without understanding it. A setuid program runs as its owner rather than the person invoking it, which is a well-trodden route to privilege escalation.
- Expecting chmod to explain new files. Newly created files are shaped by umask, not by any chmod you ran, which is why they arrive with permissions nobody appears to have chosen.