chmod 555 r-xr-xr-x

chmod 555 (r-xr-xr-x): the owner can read and execute; group and others can read and execute. Typical use: read-only programs and directories.

Octal
555 (also written 0555)
Symbolic
r-xr-xr-x
ls -l shows
-r-xr-xr-x for a file, dr-xr-xr-x for a directory
chmod letters
u=rx,g=rx,o=rx

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)5r-xRead the contents and run it as a programList the names inside and enter it and open files by name
Group (g)5r-xRead the contents and run it as a programList the names inside and enter it and open files by name
Others (o)5r-xRead the contents and run it as a programList the names inside and enter it and open files by name

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Typical uses

Read and execute for everyone, write for no one. Linux shows /proc as dr-xr-xr-x, and some distributions ship system directories this way. Installed programs are more often 755, so root can update them without changing the mode.

Security notes

  • Only the owner (and root) can change it; the group and others are limited to the read and execute rights shown above, which is the usual safe pattern for shared files and directories.
  • Every account on the machine can read it, so keep passwords, keys and tokens out of anything with this mode.

Commands

  • Numeric
    chmod 555 file
  • Symbolic
    chmod u=rx,g=rx,o=rx file
  • Check the result
    stat -c '%a %A %n' file
  • Directories only, recursively
    find /path -type d -exec chmod 555 {} +

Avoid chmod -R 555 on a tree that holds files as well as folders: it makes every file executable. Use the find command above for directories and a file mode such as 444 for the files.

The umask that gives 555

  • umask 222: new directories are created as 555 (and files as 444)

Programs create files with 666 and directories with 777, and the umask removes bits from those. A umask never adds execute to a new file, and it cannot set setuid, setgid or the sticky bit.

Its file counterpart is chmod 444 (r--r--r--).

Other common modes

Work out any other mode in the chmod calculator