chmod Command Explained
chmod changes who can read, write, or execute a file. Between numeric and symbolic mode, there are two genuinely different ways to express the same change, and knowing both makes reading other people’s scripts and documentation much easier.
Numeric mode: the classic three-digit form
chmod 755 script.sh
chmod 644 document.txt
chmod 700 private_key
Each digit represents one of the three permission groups, owner, group, other, in that fixed order, and each digit is a sum of three values:
4 = read (r)
2 = write (w)
1 = execute (x)
7 = 4+2+1 = rwx (read, write, execute)
6 = 4+2 = rw- (read, write)
5 = 4+1 = r-x (read, execute)
4 = 4 = r-- (read only)
0 = 0 = --- (nothing)
chmod 755 breaks down as: owner gets 7 (rwx), group gets 5 (r-x), other gets 5 (r-x). This is the standard permission mode for executable scripts, since it lets the owner do everything while letting anyone else run or read it without being able to modify it.
Common numeric modes worth memorizing
chmod 755 script.sh # rwxr-xr-x: owner full, everyone else read+execute
chmod 644 document.txt # rw-r--r--: owner read+write, everyone else read only
chmod 700 private_key # rwx------: owner only, nobody else has any access
chmod 600 secrets.env # rw-------: owner read+write only, nobody else at all
chmod 777 shared_folder # rwxrwxrwx: everyone has full access (rarely appropriate)
755 and 644 cover the overwhelming majority of everyday cases: 755 for anything that needs to be executed or entered (scripts, directories), 644 for anything that is just data to be read (documents, configuration files that are not scripts). 777 is almost never the right answer in practice, since it grants write access to literally everyone on the system, and its presence in a permission audit is usually treated as a red flag worth investigating.
Symbolic mode: targeted changes
chmod u+x deploy.sh # add execute for the owner (u) only
chmod g-w shared.txt # remove write for the group (g)
chmod o=r public.txt # set exactly read-only for others (o), overwriting whatever was there
chmod a+r everyone-readable.txt # add read for everyone (a = owner+group+other combined)
Symbolic mode uses u (owner/user), g (group), o (other), and a (all three), combined with an operator, + to add a permission, - to remove one, = to set it exactly, discarding whatever was there before for that category.
# Multiple changes in a single command, comma-separated
chmod u+x,g-w,o-rwx script.sh
Symbolic mode is often the better choice when you want to change just one specific bit without needing to first work out or remember the complete numeric value for the rest of the permissions, since + and - only touch what you explicitly name and leave everything else exactly as it was.
Recursive changes with -R
chmod -R 755 project/
-R applies the change to a directory and every file and subdirectory nested inside it. This needs a bit of caution: blanket-applying the same numeric mode to both files and directories can produce results you did not intend, for example making ordinary data files executable when they should not be, since 755 includes execute permission that is appropriate for directories (execute lets you enter them) but usually unnecessary for a plain text file.
# A more careful recursive pattern using find, applying different
# modes to directories versus files
find project/ -type d -exec chmod 755 {} \;
find project/ -type f -exec chmod 644 {} \;
This two-step pattern with find sets directories to 755 (so they remain browsable) and regular files to 644 (read-write for the owner, read-only for everyone else), without indiscriminately marking every file executable.
Checking the result
ls -l script.sh
# -rwxr-xr-x 1 colton colton 850 Jul 9 10:00 script.sh
stat -c '%a %n' script.sh
# 755 script.sh
ls -l shows the symbolic representation directly; stat -c '%a' gives you the plain numeric value, which is often more convenient to check against an expected value in a script.
chmod and symbolic links
ln -s target.txt link.txt
chmod 600 link.txt
# by default, this changes the permissions of target.txt,
# the file the symlink POINTS TO, not the symlink itself
chmod -h 600 link.txt
# -h changes the symlink's own permissions instead, though
# on Linux, symlink permissions are largely a formality
# since the kernel generally ignores them and defers to
# the target file's actual permissions
By default, chmod follows a symbolic link to its target and changes the target’s permissions, which occasionally surprises people who expected the command to affect the link itself.
Frequently Asked Questions
What does the chmod command do?
chmod (change mode) sets the read, write, and execute permissions on a file or directory for the owner, group, and everyone else. It is the standard tool for controlling exactly who can read, modify, or run any given file on a Linux system.
How does numeric mode work in chmod, like chmod 755?
Numeric mode represents permissions as three digits, one each for owner, group, and other, where each digit is the sum of read (4), write (2), and execute (1). 7 means all three (4+2+1=rwx), 5 means read and execute (4+1=r-x), 6 means read and write (4+2=rw-), and so on. chmod 755 therefore sets rwx for the owner and r-x for both the group and everyone else.
What is symbolic mode in chmod and when should I use it instead of numeric mode?
Symbolic mode uses letters instead of numbers: u (owner), g (group), o (other), a (all three), combined with + (add), - (remove), or = (set exactly), followed by r, w, or x. For example, chmod u+x file.sh adds execute permission for the owner only, without touching any other permission bit. Symbolic mode is preferable when you want to change just one specific permission without needing to know or recalculate the full numeric value first.
What is the difference between chmod 755 and chmod 644?
755 (rwxr-xr-x) grants the owner full access and everyone else read plus execute, the standard mode for executable scripts and directories that should be publicly browsable. 644 (rw-r—r—) grants the owner read and write but no execute, and everyone else read only, the standard mode for regular data files and documents that are not meant to be run as programs.
How do I change permissions on a directory and everything inside it at once?
Add the -R (recursive) flag, such as chmod -R 755 mydirectory, which applies the change to the directory itself and every file and subdirectory nested inside it. This should be used carefully, since applying the same mode to both files and directories indiscriminately can accidentally make files executable that should not be, or strip execute permission from directories that need it to remain browsable.
Why does my chmod change not seem to take effect?
A few common causes: you may not own the file and lack the privileges to change its permissions without sudo, the change may have been applied to the wrong path due to a typo or an unexpected working directory, or you may be checking the permissions of a symbolic link rather than the file it points to, since chmod by default follows symlinks to their target rather than changing the symlink itself.