More
More
chmod 440 r--r-----
chmod 440 (r--r-----): the owner can read, the group read, others do nothing. Typical use: read-only config such as sudoers. Commands and umask.
- Octal
440(also written0440)- Symbolic
r--r------ ls -l shows
-r--r-----for a file,dr--r-----for a directory- chmod letters
u=r,g=r,o=
Who can do what
| Class | Digit | Bits | On a file | On a directory |
|---|---|---|---|---|
| Owner (u) | 4 | r-- | Read the contents | List the names inside and see names only, not open or inspect the files |
| Group (g) | 4 | r-- | Read the contents | List the names inside and see names only, not open or inspect the files |
| Others (o) | 0 | --- | Nothing | Nothing |
Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.
Typical uses
The owner and the group can read, nobody can write. /etc/sudoers ships as 0440 on most Linux distributions, and visudo keeps it that way. It also suits a config file holding secrets that a service reads through its group, and WordPress suggests 440 or 400 for wp-config.php.
Security notes
- Only the owner (and root) can change it; the group and others are limited to the read and execute rights shown above, which is the usual safe pattern for shared files and directories.
Commands
- Numeric
- Symbolic
- Check the result
- Files only, recursively
The umask that gives 440
No umask produces 440: a umask only removes bits from 666 for files and 777 for directories, and it never sets execute on a new file. Set it with chmod after creating the file or directory.
Its directory counterpart is chmod 550 (r-xr-x---).
Other common modes
400r--------, private keys that must not change440r--r-----, read-only config such as sudoers444r--r--r--, read-only files for everyone500r-x------, private read-only scripts550r-xr-x---, read-only programs shared with a group555r-xr-xr-x, read-only programs and directories600rw-------, SSH keys and private files640rw-r-----, config files and logs read by a group644rw-r--r--, web files and normal documents655rw-r-xr-x, a likely typo for 755660rw-rw----, files shared by a group664rw-rw-r--, team files under umask 002666rw-rw-rw-, device files like /dev/null700rwx------, ~/.ssh and private directories710rwx--x---, directories a group may pass through711rwx--x--x, home directories on shared hosting750rwxr-x---, home and app directories for a group755rwxr-xr-x, directories, programs and scripts770rwxrwx---, shared team directories775rwxrwxr-x, shared directories under umask 002777rwxrwxrwx, nothing, almost always a mistake1777rwxrwxrwt, shared temporary directories like /tmp2755rwxr-sr-x, setgid programs and group directories2775rwxrwsr-x, shared team directories that keep a group4755rwsr-xr-x, setuid programs like passwd