chmod 2775 rwxrwsr-x

chmod 2775 (rwxrwsr-x): the owner can read, write and execute, the group read, write and execute, others read and execute, with setgid. Commands and umask.

Octal
2775
Symbolic
rwxrwsr-x
ls -l shows
-rwxrwsr-x for a file, drwxrwsr-x for a directory
chmod letters
u=rwx,g=rwxs,o=rx

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)7rwxRead the contents, change or empty the contents and run it as a programList the names inside, create, delete and rename entries and enter it and open files by name
Group (g)7rwxRead the contents, change or empty the contents and run it as a programList the names inside, create, delete and rename entries and enter it and open files by name
Others (o)5r-xRead the contents and run it as a programList the names inside and enter it and open files by name

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Special bits

Setgid (2)
On a program: it runs with the file's group. On a directory: new files and subdirectories take the directory's group, and new subdirectories inherit setgid. Shown as s in the group's execute place.

Typical uses

Setgid plus 775: the classic shared team directory. Group members can create files, and every new file and subdirectory belongs to the directory's group, so the team keeps access. Pair it with umask 002 so new files are group-writable.

Security notes

  • The group can write, so check who is in the group; adding a user to it gives them write access.
  • Setgid on a program lets anyone run it with the file's group; on a directory it only changes group ownership of new files, which is harmless.
  • Every account on the machine can read it, so keep passwords, keys and tokens out of anything with this mode.

Commands

  • Numeric
    chmod 2775 file
  • Symbolic
    chmod u=rwx,g=rwxs,o=rx file
  • Check the result
    stat -c '%a %A %n' file
  • Directories only, recursively
    find /path -type d -exec chmod 2775 {} +

Avoid chmod -R 2775 on a tree that holds files as well as folders: it makes every file executable. Use the find command above for directories and a file mode such as 644 for the files.

The umask that gives 2775

No umask produces 2775: a umask only removes bits from 666 for files and 777 for directories, and it never sets setuid, setgid or the sticky bit. Set it with chmod after creating the file or directory.

Other common modes

Work out any other mode in the chmod calculator