chmod 660 rw-rw----

chmod 660 (rw-rw----): the owner can read and write, the group read and write, others do nothing. Typical use: files shared by a group. Commands and umask.

Octal
660 (also written 0660)
Symbolic
rw-rw----
ls -l shows
-rw-rw---- for a file, drw-rw---- for a directory
chmod letters
u=rw,g=rw,o=

Who can do what

ClassDigitBitsOn a fileOn a directory
Owner (u)6rw-Read the contents and change or empty the contentsList the names inside, nothing more with write alone (it needs execute to work) and see names only, not open or inspect the files
Group (g)6rw-Read the contents and change or empty the contentsList the names inside, nothing more with write alone (it needs execute to work) and see names only, not open or inspect the files
Others (o)0---NothingNothing

Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.

Typical uses

The owner and the group read and write, others get nothing. Used for device files such as disks (/dev/sda is 660 root:disk) and serial ports (group dialout), shared data files edited by a team, and sockets a service shares with its group.

Security notes

  • The group can write, so check who is in the group; adding a user to it gives them write access.

Commands

  • Numeric
    chmod 660 file
  • Symbolic
    chmod u=rw,g=rw,o= file
  • Check the result
    stat -c '%a %A %n' file
  • Files only, recursively
    find /path -type f -exec chmod 660 {} +

The umask that gives 660

  • umask 007: new files are created as 660 (and directories as 770)

Programs create files with 666 and directories with 777, and the umask removes bits from those. A umask never adds execute to a new file, and it cannot set setuid, setgid or the sticky bit.

Its directory counterpart is chmod 770 (rwxrwx---).

Other common modes

Work out any other mode in the chmod calculator