More
More
chmod 750 rwxr-x---
chmod 750 (rwxr-x---): the owner can read, write and execute, the group read and execute, others do nothing. Commands, umask and security notes.
- Octal
750(also written0750)- Symbolic
rwxr-x---- ls -l shows
-rwxr-x---for a file,drwxr-x---for a directory- chmod letters
u=rwx,g=rx,o=
Who can do what
| Class | Digit | Bits | On a file | On a directory |
|---|---|---|---|---|
| Owner (u) | 7 | rwx | Read the contents, change or empty the contents and run it as a program | List the names inside, create, delete and rename entries and enter it and open files by name |
| Group (g) | 5 | r-x | Read the contents and run it as a program | List the names inside and enter it and open files by name |
| Others (o) | 0 | --- | Nothing | Nothing |
Each digit adds read (4), write (2) and execute (1). Deleting or renaming a file depends on write and execute on the directory that holds it, not on the file's own mode. Root bypasses read and write checks.
Typical uses
The owner has full access, the group can list and enter, others get nothing. Ubuntu has created new home directories as 750 since 21.04, and it suits application directories a service group needs to read. WordPress lists 750 or 755 for directories.
Security notes
- Only the owner (and root) can change it; the group and others are limited to the read and execute rights shown above, which is the usual safe pattern for shared files and directories.
Commands
- Numeric
- Symbolic
- Check the result
- Directories only, recursively
Avoid chmod -R 750 on a tree that holds files as well as folders: it makes every file executable. Use the find command above for directories and a file mode such as 640 for the files.
The umask that gives 750
umask 027: new directories are created as 750 (and files as 640)
Programs create files with 666 and directories with 777, and the umask removes bits from those. A umask never adds execute to a new file, and it cannot set setuid, setgid or the sticky bit.
Its file counterpart is chmod 640 (rw-r-----).
Other common modes
400r--------, private keys that must not change440r--r-----, read-only config such as sudoers444r--r--r--, read-only files for everyone500r-x------, private read-only scripts550r-xr-x---, read-only programs shared with a group555r-xr-xr-x, read-only programs and directories600rw-------, SSH keys and private files640rw-r-----, config files and logs read by a group644rw-r--r--, web files and normal documents655rw-r-xr-x, a likely typo for 755660rw-rw----, files shared by a group664rw-rw-r--, team files under umask 002666rw-rw-rw-, device files like /dev/null700rwx------, ~/.ssh and private directories710rwx--x---, directories a group may pass through711rwx--x--x, home directories on shared hosting750rwxr-x---, home and app directories for a group755rwxr-xr-x, directories, programs and scripts770rwxrwx---, shared team directories775rwxrwxr-x, shared directories under umask 002777rwxrwxrwx, nothing, almost always a mistake1777rwxrwxrwt, shared temporary directories like /tmp2755rwxr-sr-x, setgid programs and group directories2775rwxrwsr-x, shared team directories that keep a group4755rwsr-xr-x, setuid programs like passwd