Skip to content

chmod calculator

Convert between 755, rwxr-xr-x and the chmod command — including setuid and the sticky bit.

Runs in your browser — nothing is sent anywhere.

Both directions, including the bits most calculators drop

Type 755 and get rwxr-xr-x. Type rwxr-xr-x and get 755. That much every calculator does. The part they routinely miss is the fourth octal digit — setuid, setgid and the sticky bit — which is where the interesting behaviour lives and where the security problems are.

Reading s, S, t and T

The special bits do not get their own column. They overwrite the execute character of the class they belong to, and the case tells you whether execute is also set. So in rwsr-xr-x the lower-case s means setuid and owner-execute; in rwSr--r-- the capital S means setuid without execute, which is almost always a mistake. Same pattern for setgid in the group triple, and for the sticky bit in the others triple as t and T.

A parser that only reads r, w and x throws all of that away and converts rwsr-xr-x to 755, losing the setuid bit entirely. This one round-trips all 4096 possible modes, and that is checked on every build against Python's own stat.filemode.

What the special bits actually do

setuid on an executable makes it run as the file's owner rather than as you — that is how passwd can edit the shadow file. It is also why a setuid binary with a bug is a privilege-escalation vulnerability, and why it is worth noticing when one appears.

setgid on a directory is quietly the most useful of the three: files created inside inherit the directory's group rather than the creator's, which is how shared project directories are made to work without everyone remembering to run chgrp.

The sticky bit on a directory means only a file's owner can delete it, regardless of the directory's write permission. That is what makes /tmp — mode 1777 — world-writable without users being able to delete each other's files.

777 is almost never the answer

It is the standard advice on forums and it is standard because it makes the symptom go away, not because it is correct. Most web servers refuse to execute a script that is group- or world-writable, so 777 can be the thing that breaks the site people are trying to fix. The result flags it.

Directories need execute

Worth knowing if permissions are behaving strangely: on a directory, the execute bit means "may traverse into", not "may run". A directory with read but not execute lets you list the names in it and not open anything inside, which produces a very confusing set of errors. Directories usually want 755 or 750; ordinary files usually want 644 or 640.

01

Common questions

What does 755 mean?

The owner can read, write and execute; group and others can read and execute. It is the normal mode for a directory or an executable script.

What is the fourth digit for?

The special bits: 4 is setuid, 2 is setgid, 1 is the sticky bit. So 4755 is setuid plus 755, and 1777 is the sticky bit plus 777, which is how /tmp is set.

Why does my symbolic string have an s or a t in it?

They replace the execute character when a special bit is set. Lower case means the special bit and execute; upper case means the special bit without execute, which is usually a mistake.

Should I use 777?

Almost never. It lets any user on the machine modify the file, and many web servers refuse to execute anything group- or world-writable — so it often breaks the very thing it was meant to fix.

What permissions do directories need?

755 or 750 in most cases. On a directory the execute bit means "can enter", so removing it makes the contents unreachable even when read is granted.

Does it handle ls -l output?

Yes — paste the ten-character string including the leading file-type character and it is ignored.