chmod 4755 rwsr-xr-x

chmod 4755 (rwsr-xr-x): the owner can read, write and execute; group and others can read and execute, with setuid. Commands, umask and security notes.

Octal
4755
Symbolic
rwsr-xr-x
ls -l shows
-rwsr-xr-x for a file, drwsr-xr-x for a directory
chmod letters
u=rwxs,g=rx,o=rx

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)7rwxRead the contents, change or empty the contents and run it as a programList the names inside, create, delete and rename entries and enter it and open files by name
Group (g)5r-xRead the contents and run it as a programList the names inside and enter it and open files by name
Others (o)5r-xRead the contents and run it as a programList the names inside and enter it and open files by name

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Special bits

Setuid (4)
On a program: it runs with the file owner's user ID, whoever starts it. Shown as s in the owner's execute place. Linux ignores it on scripts and directories.

Typical uses

Setuid plus 755: the program runs with its owner's privileges, whoever starts it. /usr/bin/passwd is -rwsr-xr-x root, which is how an ordinary user can update /etc/shadow. Linux ignores setuid on scripts and on directories.

Security notes

  • Setuid programs owned by root are a classic privilege escalation route if they have a bug. List them with find / -perm -4000 -type f and keep the set small.
  • Only the owner (and root) can change it; the group and others are limited to the read and execute rights shown above, which is the usual safe pattern for shared files and directories.
  • Every account on the machine can read it, so keep passwords, keys and tokens out of anything with this mode.

Commands

  • Numeric
    chmod 4755 file
  • Symbolic
    chmod u=rwxs,g=rx,o=rx file
  • Check the result
    stat -c '%a %A %n' file

The umask that gives 4755

No umask produces 4755: a umask only removes bits from 666 for files and 777 for directories, and it never sets setuid, setgid or the sticky bit. Set it with chmod after creating the file or directory.

Other common modes

Work out any other mode in the chmod calculator