chmod permission calculator
Developer tools
Loading
Loading tool
The tool is loaded only when you open it.
All processing for this tool happens in your browser. Your input is not sent to a server.
About this tool
Convert a Unix permission-bit pattern between octal and a nine-character display such as rw-r--r--, or build it with permission checkboxes. The result always includes four octal digits and preserves setuid, setgid and sticky bits, including uppercase S and T. Choose file or directory to change the explanations, not the bits. Everything is calculated locally; the page never examines or changes a real file.
Common uses
- Decode a copied permission value and see the owner, group and other-user bits individually.
- Compare execute/search permission with the independent setuid, setgid and sticky flags before reviewing a configuration.
- Explain why an identical bit pattern behaves differently on a regular file and a directory without running a command.
How to use it
- 1.Choose octal or symbolic input. Enter exactly three or four ASCII octal digits, such as 644 or 2750, or exactly nine permission characters, such as rwxr-s---. Enter only the permission value, with no spaces, filename or file-type prefix.
- 2.Convert the value and inspect the four-digit octal result, nine-character symbolic result and individual checkboxes. Use the checkboxes to explore another bit pattern. Choose file or directory to read the relevant access and special-bit explanations.
- 3.Review the warnings before copying a result or illustrative GNU command. For 0644, the examples are chmod =0644 -- example-file and chmod =0644 -- example-directory. The = operator requests the exact bit pattern. These fixed example names are placeholders; no command is executed.
Executable permission-bit examples
Normalize a three-digit mode
{
"format": "octal",
"value": "644"
}{
"octal": "0644",
"symbolic": "rw-r--r--"
}Read is 4 and write is 2, so the owner digit 6 means rw-. Each 4 gives read alone. The omitted special digit becomes 0; the output is 0644. The JSON describes the input fields: select its format and enter only its value.
Separate owner, group and other
{
"format": "octal",
"value": "0750"
}{
"octal": "0750",
"symbolic": "rwxr-x---"
}The owner has rwx, the group has r-x and other users have no ordinary permissions. Choosing directory changes x to search/traverse in the explanation, while the encoded result stays the same.
setuid with owner execute
{
"format": "octal",
"value": "4755"
}{
"octal": "4755",
"symbolic": "rwsr-xr-x"
}The leading 4 sets setuid. Owner digit 7 includes execute, so the owner’s third character is lowercase s. This demonstrates the encoding, not a recommendation to enable setuid.
setgid without group execute
{
"format": "octal",
"value": "2640"
}{
"octal": "2640",
"symbolic": "rw-r-S---"
}The special digit 2 sets setgid, while group digit 4 provides read but no execute. The group’s third character is uppercase S, and the owner remains rw-.
Sticky without other execute
{
"format": "octal",
"value": "1700"
}{
"octal": "1700",
"symbolic": "rwx-----T"
}The sticky bit is set, but the other-user execute bit is absent. The last character is uppercase T. The owner’s execute bit does not change T into t.
All special bits without ordinary permissions
{
"format": "octal",
"value": "7000"
}{
"octal": "7000",
"symbolic": "--S--S--T"
}The leading 7 combines 4 + 2 + 1. With all ordinary bits clear, the special positions display S, S and T. This bit pattern is valid even though it grants no ordinary permissions.
Reverse all lowercase special positions
{
"format": "symbolic",
"value": "--s--s--t"
}{
"octal": "7111",
"symbolic": "--s--s--t"
}Each lowercase special character carries its corresponding execute bit too. The three special flags produce the leading 7, and the three execute bits produce 111, giving 7111.
Reverse a setgid directory-style display
{
"format": "symbolic",
"value": "rwxr-s---"
}{
"octal": "2750",
"symbolic": "rwxr-s---"
}The display has owner rwx, group r-x plus setgid, and no other-user permissions. It converts to 2750. Directory group inheritance is a separate semantic explanation, not an additional encoded bit.
All bits clear
{
"format": "symbolic",
"value": "---------"
}{
"octal": "0000",
"symbolic": "---------"
}Nine hyphens encode zero ordinary permissions and zero special bits. The canonical result is 0000. This does not establish that privileged processes or other access-control mechanisms cannot access a real file.
Common permission-reading mistakes
- Pasting drwxr-x--- or -rw-r--r-- instead of the nine permission characters alone.
- Treating S or T as an error, or assuming every special bit also sets execute.
- Using u+x, 0o644, decimal digits 8/9 or extra whitespace as if they were supported input.
- Assuming directory read permission permits traversal, or that a file’s write bit controls deletion of its name.
- Expecting chmod 0644 on GNU to clear a directory’s existing setuid/setgid flags, or assuming GNU =mode syntax is portable.
- Treating a bit conversion as a security audit or using blanket broad permissions to suppress an access error.
Limits and notes
- Accepted octal input is exactly 3–4 digits from 0 to 7; output is always four digits from 0000 through 7777. Symbolic input is exactly nine characters in three rwx positions, with s/S allowed only in owner/group execute positions and t/T only in the other execute position. Whitespace, 0o prefixes, one/two/five-digit modes, full ls listings, file-type prefixes, ACL suffixes and symbolic operations such as u+x, a=rw or =0644 are rejected.
- This is a 12-bit representation calculator, not an effective-access check. It does not inspect ownership, group membership, ACLs, capabilities, security policies, mount flags, parent directories or symlinks. It does not apply umask or predict newly created file modes. Operating-system and filesystem rules may restrict, ignore or clear special bits.
- For files, r/w/x mean read content, change content and execute. For directories, they mean list names, change directory entries and search/traverse; entry creation or removal normally needs both write and search. A file’s own write bit does not decide whether its directory entry can be deleted. Directory 0644 has no search bits and is an illustration, not a suggested setting.
- GNU chmod can preserve existing directory setuid/setgid bits with ordinary numeric modes such as 0644. The directory command therefore uses =0644 to request an exact bit pattern. Operator numeric modes are a GNU extension; POSIX permits implementations to ignore directory setuid/setgid changes. Verify the target system and the resulting permissions yourself before relying on any command.
- Conversion uses only the value entered in this loaded browser page. It makes no filesystem, network or shell calls and does not persist permission inputs. Copying places the selected output in your clipboard, outside the page’s control. Examples are educational bit patterns, not permission recommendations; granting access broadly is not a general fix for permission errors.
Frequently asked questions
Why are s and t sometimes uppercase?
The third character of each permission group carries two independent bits. In the owner or group position, s means setuid or setgid plus execute; S means the special bit is set while execute is absent. In the other-user position, t means sticky plus execute and T means sticky without execute. Uppercase is meaningful and does not make the input invalid.
Does x mean the same thing for files and directories?
For a regular file, x is an execute permission bit; it does not guarantee the file is a runnable program. For a directory, x means search/traverse and is needed to resolve entries beneath it. Reading names and changing entries are separate permissions. Selecting directory changes the explanation and command example without adding execute bits automatically.
What do setuid, setgid and sticky actually do?
On supported executable files, setuid/setgid affect the process’s effective user/group ID, subject to system restrictions. Directory setgid commonly makes new entries inherit the directory’s group and new subdirectories inherit setgid; directory setuid is not portable. Sticky restricts removal or renaming of directory entries by unprivileged users to the entry’s owner or directory’s owner, in addition to normal checks. Sticky does not prevent writing file contents, and its effect on regular files is system-specific.
Can I paste a complete chmod command or an ls -l line?
No. Symbolic here means only the nine displayed permission characters, not chmod’s operation grammar. Remove the leading file-type character from a copied ls mode and leave out ACL markers and all other columns. The calculator cannot detect a real file’s current mode or guarantee that applying the displayed command will succeed.
- GNU Coreutils: numeric mode bit values
- GNU Coreutils: ls permission display and s/S/t/T
- GNU Coreutils: file and directory permission meanings
- GNU Coreutils: directory setuid/setgid and portability
- GNU Coreutils: operator numeric modes
- GNU Coreutils: chmod behavior and system restrictions