Emergency server help: get in touch

chmod Calculator

Convert Linux file permissions between octal (755) and symbolic (rwxr-xr-x) notation, see what owner, group and others can do, and catch world-writable settings.

Status
Live
Last updated
October 7, 2026

Enter an octal mode such as 644 or a symbolic string such as rwxr-x— to convert between them and see the exact rights of owner, group and others.

Safe defaults for web hosting

Files 644, directories 755, wp-config.php 600 or 640, SSH private keys 600 and ~/.ssh 700. Under suPHP or PHP-FPM running as the account user, nothing in a web root needs 777 — if a plugin asks for it, fix ownership instead.

Fix a whole tree with: find public_html -type d -exec chmod 755 {} + and find public_html -type f -exec chmod 644 {} +

Chmod calculator at a glance

chmod Calculator summary card: Enter an octal mode such as 644 or a symbolic string such as rwxr-x--- to convert between them and see the exact rights…
In short: Enter an octal mode such as 644 or a symbolic string such as rwxr-x— to convert between them and see the exact rights of owner, group and others.
Chmod calculator – overview of the steps
Chmod calculator: the sections of this tool at a glance.
chmod Calculator questions answered: What does chmod 755 mean? Why is 777 dangerous?
Answers: What does chmod 755 mean? Why is 777 dangerous?

How to use this tool

  1. Enter three octal digits such as 644, or four such as 4755 or 1777 when you need setuid, setgid or the sticky bit.
  2. Or enter the nine permission letters such as rwxr-x---. You can paste the ten-character string from ls -l, such as drwxr-xr-x; the leading file-type letter (-, d, l, c, b, p or s) is ignored. Remove a trailing . (SELinux context) or + (ACL) that ls adds.
  3. Special bits go in the execute positions: s or S for owner and group, t or T for others.
  4. Press Convert. The calculation runs in your browser. Relative modes such as u+x or g-w are not accepted, because their result depends on the file’s current mode.

How to read the results

ResultWhat it shows
OctalThe numeric mode. Three digits, or four when a special bit is set (4755).
SymbolicThe nine letters as ls -l prints them, with s, S, t or T where special bits are set.
CommandA ready chmod command, for example chmod 640 filename.
Special bitsShown when the fourth digit is not 0: setuid (4) runs a program as its owner, setgid (2) runs it as its group or makes new files in a directory inherit the directory’s group, sticky (1) lets only owners delete or rename their files in a shared directory.
WarningRed when others have write permission. With the sticky bit set (as on /tmp) it is shown as information instead, because that is the intended setup for shared temporary directories.
BreakdownOne row each for Owner, Group and Others: the digit, the three letters and what they allow in words. A capital S or T is flagged as “without execute”, which is usually a mistake.

Each digit is the sum of read (4), write (2) and execute (1):

DigitLettersAllows
0—nothing
1–xexecute
2-w-write
3-wxwrite, execute
4r–read
5r-xread, execute
6rw-read, write
7rwxread, write, execute

Common problems and how to fix them

SSH: “Permissions 0644 for ‘/home/user/.ssh/id_ed25519’ are too open.”

The OpenSSH client refuses a private key that other users can read and prints “This private key will be ignored.” Make the key readable by you only:

chmod 600 ~/.ssh/id_ed25519

sshd: “Authentication refused: bad ownership or modes for directory /home/user/.ssh”

With StrictModes yes (the default), sshd ignores authorized_keys when the file, the .ssh directory or the home directory is writable by group or others, or owned by someone else. The message appears in /var/log/secure on AlmaLinux or in journalctl -u ssh on Ubuntu.

chown -R user:user /home/user/.ssh
chmod 700 /home/user/.ssh
chmod 600 /home/user/.ssh/authorized_keys
chmod go-w /home/user

500 error and “SoftException in Application.cpp” … “is writeable by group”

suPHP refuses to run a PHP file, or a file in a directory, that the group or others can write to. Set directories to 755 and PHP files to 644. The same rule makes 775 and 777 fail outright on suPHP servers.

Apache “AH00035: access to … denied … because search permissions are missing on a component of the path”

Every directory from / down to the file needs the execute (search) bit for the web server user, not only the last one. namei -l shows the mode of each component, so the one that is missing x stands out:

namei -l /home/user/public_html/index.html

nginx logs the same problem as open() "..." failed (13: Permission denied). On AlmaLinux with SELinux enforcing, correct modes can still be denied by a wrong SELinux label; check with ls -Z and restore the default labels with restorecon -Rv /var/www/html.

“chmod: changing permissions of ‘file’: Operation not permitted”

Only the file’s owner or root can change its mode. Check the owner with ls -l. If even root gets this error, the file has the immutable attribute, which malware sometimes sets on files it plants:

lsattr file
chattr -i file

Uploads or updates fail after files were copied as root

Files extracted or synced as root are owned by root, so PHP running as the account user cannot write them. This is an ownership problem; chmod 777 hides it and opens the site to other users. Fix the owner instead. On cPanel with FileProtect enabled, public_html itself is 0750 with group nobody, so change only what is inside it and do not reset public_html to 755:

chown -R user:user /home/user/public_html/*
find /home/user/public_html -mindepth 1 -type d -exec chmod 755 {} +
find /home/user/public_html -type f -exec chmod 644 {} +

Note that public_html/* skips hidden files such as .htaccess; check those separately. On Plesk, plesk repair fs -n -verbose example.com lists files with non-default permissions and plesk repair fs -y example.com resets them.

A directory keeps its setgid bit after chmod 755

GNU chmod preserves setuid and setgid on directories when given a plain numeric mode. Clear them explicitly with chmod u-s,g-s dir, or use a numeric mode with an extra leading zero such as chmod 00755 dir.

What read, write and execute mean on directories

On a file the three bits mean what they say. On a directory they behave differently, and most permission puzzles come from this:

  • r lets you list the names in the directory.
  • x lets you enter the directory and reach files inside it by name. Without x, even a readable file inside cannot be opened.
  • w (together with x) lets you create, delete and rename entries. Deleting a file depends on write permission on the directory, not on the file itself, unless the sticky bit is set.

New files get their mode from the creating program minus the umask. With the common umask 022, files are created as 644 and directories as 755; with 027 they become 640 and 750. Check yours with umask. For hardening the login side, see hardening SSH on AlmaLinux 9.

Official documentation: cPanel & WHM documentation, AlmaLinux wiki, Linux man pages.

Related guides: CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · KernelCare on cPanel and DirectAdmin servers: setup, verification and rollback.

Frequently asked questions

What does chmod 755 mean?

Owner can read, write and execute; group and others can read and execute.

Why is 777 dangerous?

Any user or process on the server can modify the file, which is how many shared-hosting compromises spread.

What about the fourth digit?

It sets setuid (4), setgid (2) and sticky (1) bits, as in 1777 for /tmp. The calculator reads all four digits and shows the special bits as s, S, t or T in the symbolic form, for example 4755 is rwsr-xr-x.

How do I convert rwxr-xr-x to a number?

Add read 4, write 2 and execute 1 for each group of three: rwx is 7, r-x is 5 and r-x is 5, so rwxr-xr-x is 755.

What does a capital S or T mean in ls -l output?

The setuid, setgid or sticky bit is set but the execute bit underneath it is not. On files that is almost always a mistake; a lowercase s or t means both are set.

Can I paste a line from ls -l?

Paste only the first column, for example -rw-r–r– or drwxr-x—, without the trailing dot or plus sign. The calculator ignores the file-type letter.

Why can I delete a file I am not allowed to write to?

Deleting changes the directory, not the file, so it needs write permission on the directory. The sticky bit, as on /tmp, limits deletion to the file owner.

Does the calculator accept chmod u+x or g-w?

No. Relative modes add or remove bits from whatever the file has now, so they have no fixed number. Run them with chmod directly, then check the result with ls -l.

What is umask?

A mask of bits removed from the mode of every new file and directory. A umask of 022 removes write for group and others, giving 644 files and 755 directories.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.