chmod 444 r--r--r--

chmod 444 (r--r--r--): the owner can read; group and others can read. Typical use: read-only files for everyone. Commands, umask and security notes.

Octal
444 (also written 0444)
Symbolic
r--r--r--
ls -l shows
-r--r--r-- for a file, dr--r--r-- for a directory
chmod letters
u=r,g=r,o=r

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)4r--Read the contentsList the names inside and see names only, not open or inspect the files
Group (g)4r--Read the contentsList the names inside and see names only, not open or inspect the files
Others (o)4r--Read the contentsList the names inside and see names only, not open or inspect the files

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Typical uses

Read-only for everyone. Use it for published files that must not be edited in place. Root ignores file permissions and the owner can change the mode back, so it prevents accidents rather than deliberate changes.

Security notes

  • Only the owner (and root) can change it; the group and others are limited to the read and execute rights shown above, which is the usual safe pattern for shared files and directories.
  • Every account on the machine can read it, so keep passwords, keys and tokens out of anything with this mode.

Commands

  • Numeric
    chmod 444 file
  • Symbolic
    chmod u=r,g=r,o=r file
  • Check the result
    stat -c '%a %A %n' file
  • Files only, recursively
    find /path -type f -exec chmod 444 {} +

The umask that gives 444

No umask produces 444: a umask only removes bits from 666 for files and 777 for directories, and it never sets execute on a new file. Set it with chmod after creating the file or directory.

Its directory counterpart is chmod 555 (r-xr-xr-x).

Other common modes

Work out any other mode in the chmod calculator