More
More
chmod 1777 rwxrwxrwt
chmod 1777 (rwxrwxrwt): the owner can read, write and execute; group and others can read, write and execute, with the sticky bit. Commands and umask.
- Octal
1777- Symbolic
rwxrwxrwt- ls -l shows
-rwxrwxrwtfor a file,drwxrwxrwtfor a directory- chmod letters
u=rwx,g=rwx,o=rwx,+t
Who can do what
| Class | Digit | Bits | On a file | On a directory |
|---|---|---|---|---|
| Owner (u) | 7 | rwx | Read the contents, change or empty the contents and run it as a program | List the names inside, create, delete and rename entries and enter it and open files by name |
| Group (g) | 7 | rwx | Read the contents, change or empty the contents and run it as a program | List the names inside, create, delete and rename entries and enter it and open files by name |
| Others (o) | 7 | rwx | Read the contents, change or empty the contents and run it as a program | List the names inside, create, delete and rename entries and enter it and open files by name |
Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.
Special bits
- Sticky bit (1)
- On a directory: only a file's owner, the directory's owner or root can delete or rename entries, even though others can write. Linux ignores it on files. Shown as t in the others' execute place.
Typical uses
The sticky bit plus 777: anyone can create files, but only a file's owner, the directory's owner or root can delete or rename it. /tmp and /var/tmp are 1777 on Linux and macOS, shown as drwxrwxrwt.
Security notes
- Everyone can write here, which the sticky bit makes safe for a shared directory: users cannot delete or rename each other's files.
Commands
- Numeric
- Symbolic
- Check the result
The umask that gives 1777
No umask produces 1777: a umask only removes bits from 666 for files and 777 for directories, and it never sets setuid, setgid or the sticky bit. Set it with chmod after creating the file or directory.
Other common modes
400r--------, private keys that must not change440r--r-----, read-only config such as sudoers444r--r--r--, read-only files for everyone500r-x------, private read-only scripts550r-xr-x---, read-only programs shared with a group555r-xr-xr-x, read-only programs and directories600rw-------, SSH keys and private files640rw-r-----, config files and logs read by a group644rw-r--r--, web files and normal documents655rw-r-xr-x, a likely typo for 755660rw-rw----, files shared by a group664rw-rw-r--, team files under umask 002666rw-rw-rw-, device files like /dev/null700rwx------, ~/.ssh and private directories710rwx--x---, directories a group may pass through711rwx--x--x, home directories on shared hosting750rwxr-x---, home and app directories for a group755rwxr-xr-x, directories, programs and scripts770rwxrwx---, shared team directories775rwxrwxr-x, shared directories under umask 002777rwxrwxrwx, nothing, almost always a mistake1777rwxrwxrwt, shared temporary directories like /tmp2755rwxr-sr-x, setgid programs and group directories2775rwxrwsr-x, shared team directories that keep a group4755rwsr-xr-x, setuid programs like passwd