More
More
chmod 666 rw-rw-rw-
chmod 666 (rw-rw-rw-): the owner can read and write; group and others can read and write. Typical use: device files like /dev/null. Commands and umask.
- Octal
666(also written0666)- Symbolic
rw-rw-rw-- ls -l shows
-rw-rw-rw-for a file,drw-rw-rw-for a directory- chmod letters
u=rw,g=rw,o=rw
Who can do what
| Class | Digit | Bits | On a file | On a directory |
|---|---|---|---|---|
| Owner (u) | 6 | rw- | Read the contents and change or empty the contents | List the names inside, nothing more with write alone (it needs execute to work) and see names only, not open or inspect the files |
| Group (g) | 6 | rw- | Read the contents and change or empty the contents | List the names inside, nothing more with write alone (it needs execute to work) and see names only, not open or inspect the files |
| Others (o) | 6 | rw- | Read the contents and change or empty the contents | List the names inside, nothing more with write alone (it needs execute to work) and see names only, not open or inspect the files |
Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.
Typical uses
Read and write for everyone. That is right for a few special device files: /dev/null, /dev/zero and /dev/tty are 666. On a regular file it lets every user and process on the machine change the contents.
Security notes
- Others can write: every user and every process on the machine, including a compromised web application, can change or replace this. For a directory, they can delete or swap any file inside it.
Commands
- Numeric
- Symbolic
- Check the result
- Files only, recursively
The umask that gives 666
umask 000: new files are created as 666 (and directories as 777)
Programs create files with 666 and directories with 777, and the umask removes bits from those. A umask never adds execute to a new file, and it cannot set setuid, setgid or the sticky bit.
Its directory counterpart is chmod 777 (rwxrwxrwx).
Other common modes
400r--------, private keys that must not change440r--r-----, read-only config such as sudoers444r--r--r--, read-only files for everyone500r-x------, private read-only scripts550r-xr-x---, read-only programs shared with a group555r-xr-xr-x, read-only programs and directories600rw-------, SSH keys and private files640rw-r-----, config files and logs read by a group644rw-r--r--, web files and normal documents655rw-r-xr-x, a likely typo for 755660rw-rw----, files shared by a group664rw-rw-r--, team files under umask 002666rw-rw-rw-, device files like /dev/null700rwx------, ~/.ssh and private directories710rwx--x---, directories a group may pass through711rwx--x--x, home directories on shared hosting750rwxr-x---, home and app directories for a group755rwxr-xr-x, directories, programs and scripts770rwxrwx---, shared team directories775rwxrwxr-x, shared directories under umask 002777rwxrwxrwx, nothing, almost always a mistake1777rwxrwxrwt, shared temporary directories like /tmp2755rwxr-sr-x, setgid programs and group directories2775rwxrwsr-x, shared team directories that keep a group4755rwsr-xr-x, setuid programs like passwd