Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

chmod changes a file’s or directory’s permission bits. On Ubuntu 16.04 and 18.04, you can use a numeric mode such as 644 to set permissions exactly, or a symbolic mode such as u+x to make a targeted change while preserving other permissions. Inspect the current mode first, make the smallest change that solves the problem, and verify the result.

The commands below apply to both releases’ GNU chmod; their Ubuntu manpages identify Coreutils versions 8.25-2ubuntu3~16.04 and 8.28-1ubuntu1, respectively. Ubuntu 16.04 chmod manual · Ubuntu 18.04 chmod manual. These are older releases: as of August 18, 2026, Canonical lists Ubuntu 18.04 ESM through April 2028 and Ubuntu 16.04 Legacy coverage through April 2031 for eligible Ubuntu Pro systems. Production users should confirm their system’s support arrangement or plan an upgrade. Canonical: Ubuntu 18.04 · Canonical: Ubuntu 16.04

Inspect permissions before changing them

Start by checking the target and its ownership:

ls -l file.txt
stat file.txt

An ls -l line might look like this:

-rw-r--r-- 1 alice developers 1234 Aug 18 12:00 file.txt

The first ten characters describe the object and its ordinary permissions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
- rw- r-- r--
│  │   │   └── others
│  │   └────── group
│  └────────── owner
└───────────── file type

The initial character is commonly - for a regular file, d for a directory, or l for a symbolic link. The next nine characters are three groups of read, write, and execute permissions: owner, group, then others. A dash means that permission is absent.

Read, write, and execute mean different things for files and directories:

Permission Regular file Directory
r Read the contents. List directory entries.
w Modify the contents. Create, delete, or rename entries, subject to applicable directory and ownership rules.
x Run the file as a program or script, if it is executable in the relevant environment. Traverse or search the directory, including access to known entries.

Directory x does not mean “run the directory.” A user generally needs execute/search permission on a directory to reach entries inside it; listing names also requires read permission.

When access fails despite apparently suitable permissions, inspect every directory in the path:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
namei -l /path/to/file.txt

stat gives a detailed view of one object. namei -l can reveal a parent directory that blocks traversal.

What chmod changes—and what it does not

The name means “change mode”: the command changes permission bits. It does not change ownership, group membership, file contents, or the permissions granted by every other security mechanism. The related tools have distinct jobs:

  • chmod changes permission bits.
  • chown changes the owner and/or group.
  • umask influences the default permissions of newly created files and directories.

ACLs, application security policies, read-only mounts, and filesystem-specific behavior can also affect access. Changing mode bits alone cannot fix every “Permission denied” problem.

Basic syntax and safe command-line use

The common forms are:

chmod [OPTION]... MODE FILE...
chmod [OPTION]... OCTAL-MODE FILE...
chmod [OPTION]... --reference=REFERENCE_FILE FILE...

MODE can be symbolic, such as u+x, or numeric, such as 644. A command can name more than one target. Quote a path containing spaces, and use -- before a filename that begins with a hyphen:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
chmod 640 "Quarterly Report.txt"
chmod 600 -- -strange-name.txt

Do not put spaces inside a symbolic mode. Use chmod u+r,g-w file.txt, not chmod u + x file.txt.

Use symbolic modes for targeted changes

Symbolic modes name a permission class, an operation, and permissions. The classes are u for owner, g for group, o for others, and a for all three classes. The operations are + to add, - to remove, and = to assign the selected class exactly the permissions specified.

Command Effect
chmod u+x script.sh Adds execute permission for the owner, leaving the owner’s other permissions unchanged.
chmod g+w shared.txt Adds group write permission.
chmod o-r secret.txt Removes read permission for others.
chmod a+r manual.txt Adds read permission for all classes.
chmod go-w report.txt Removes write permission for group and others.
chmod u=rw,g=r,o= private.txt Sets owner to read/write, group to read, and others to no permissions.
chmod g=u file.txt Copies the owner’s permissions to the group.

The difference between adding and assigning is important. chmod u+x file adds owner execute permission while preserving owner read and write permissions. chmod u=x file makes execute the owner’s only permission, removing the owner’s read and write bits.

Use numeric modes for an exact permission set

In an ordinary numeric mode, each digit represents owner, group, or others. Add the values for the permissions in that class: read is 4, write is 2, and execute is 1.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Digit Permissions
0 ---
1 --x
2 -w-
3 -wx
4 r--
5 r-x
6 rw-
7 rwx

For example, 6 means read plus write (4 + 2). In 644, the owner gets rw- and group and others each get r--. Numeric modes set the specified ordinary permissions; they can remove bits that a symbolic addition would preserve.

Mode Permission string Typical use
600 rw------- Owner-only read/write file, such as a private key.
640 rw-r----- Owner read/write; group read; others no access.
644 rw-r--r-- Ordinary non-sensitive file the owner can edit and others can read.
700 rwx------ Private directory accessible to its owner.
755 rwxr-xr-x Executable file or directory that others may read/traverse.

For example:

chmod 644 file.txt
chmod 600 private-key
chmod 700 private-directory/
chmod 755 program

Choose based on the object’s purpose. A script containing credentials or private configuration should not automatically be readable by everyone just because it is executable.

Common tasks: scripts, files, and directories

Make a script executable

If only its owner needs to execute the script, add just that permission:

chmod u+x script.sh
ls -l script.sh
./script.sh

Use chmod ug+x script.sh when the owner and group both need execute permission. The script also needs to be accessible through its parent directories, and it must be a valid executable script for the environment. Avoid using 777 as a shortcut.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set a file’s permissions

For a normal, non-sensitive text file that should be readable by other users:

chmod 644 file.txt

For an owner-only credential file:

chmod 600 credentials.txt

Restrict a directory

To make a directory private to its owner:

chmod 700 private/

That permits the owner to list and traverse it and to manage entries there, while denying those permissions to group and others. The files inside have their own modes; changing a directory does not automatically set the permissions of its contents unless you request a recursive change.

Set up a group-shared directory

A common administrative starting point is:

sudo chgrp developers shared/
sudo chmod 2770 shared/

The leading 2 sets the set-group-ID bit on the directory. New entries commonly inherit the directory’s group, which helps group collaboration. This pattern depends on correct group membership and ownership, and exact inheritance behavior can also depend on the process’s creation mode and filesystem or application behavior. Do not apply it as a universal setting.

Change permissions recursively without making every file executable

-R (or --recursive) applies a mode throughout a directory tree. A blanket command such as chmod -R 755 project/ makes every regular file executable, not just directories and actual programs. For a mixed tree where entries should be readable and directories traversable, conditional uppercase X is usually safer:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
chmod -R a+rX directory/

Uppercase X adds execute/search permission to directories and to regular files that already have an execute bit for at least one user. It does not indiscriminately make every regular file executable. GNU’s documentation describes this conditional behavior and recursive use: GNU Coreutils: chmod invocation.

When a project needs a deliberate policy by file type, set directories and files separately, then restore execute permission only for known scripts:

find project/ -type d -exec chmod 750 {} +
find project/ -type f -exec chmod 640 {} +
find project/ -type f -name '*.sh' -exec chmod 750 {} +

Review the target tree before running a broad change, and adapt these modes to the application, owner, and group. A web or application deployment may need a different balance of read and write access.

Be careful with symbolic links in recursive operations. A symlink passed directly as a command-line argument generally leads chmod to affect its target; symlinks encountered during recursive traversal are handled differently. Inspect a link before changing a path that might resolve through one:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
ls -l link-name
readlink -f link-name

When to use sudo, chown, or ACLs

Normally, a user can change the mode of a file they own. A system-owned file may require elevated privileges, for example:

sudo chmod 644 /etc/example.conf

Use sudo only when the change is intended and necessary. If the file belongs to the wrong user or group, changing its mode may not be the right fix; correct ownership or group instead:

sudo chown alice:developers file.txt

For a “Permission denied” problem, check the path, identity, ACLs, and mount before widening access:

id
ls -l file.txt
namei -l /path/to/file.txt
getfacl file.txt
findmnt -T /path/to/file.txt

An appended + in an ls -l mode, such as -rw-r-----+, indicates additional ACL entries. Inspect them with getfacl. If one additional user or group needs access, an ACL may be more precise than changing permissions for all group members or everyone.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other causes include a read-only filesystem, application confinement, container boundaries, or filesystem-specific permission semantics. If an otherwise privileged change reports “Operation not permitted,” an immutable attribute is one possible cause; inspect before changing it:

lsattr file

Only if the immutable flag is confirmed and the change is authorized should an administrator consider removing it with sudo chattr -i file.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Special permission bits: use with care

GNU chmod also accepts a leading octal digit for special bits, or symbolic forms. Their effect depends on the object and system policy, so they are not ordinary convenience flags.

Bit Example Purpose and caution
Set-user-ID chmod u+s program or chmod 4755 program A setuid executable may run with its owner’s effective privileges. This is security-sensitive; do not add it casually.
Set-group-ID chmod g+s directory/ or chmod 2770 shared/ On a directory, commonly supports group inheritance for collaboration. The exact behavior is context-dependent.
Sticky bit chmod +t shared/ or chmod 1777 shared/ On a world-writable directory, it restricts unprivileged users from removing or renaming entries they do not own, subject to ownership and privilege rules. It is commonly used for /tmp, not a general-purpose directory mode.

Use umask for defaults on new files

chmod changes existing objects; it does not set the default mode for future files. A process’s requested creation mode and the current umask influence those defaults. Inspect the mask with:

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
umask
umask -S

For example, umask 027 removes group write and all ordinary permissions for others from the permissions requested at creation time. The resulting mode still depends on what the creating application requests, and directories and files may request different starting modes.

Copy a known mode and verify changes

If an existing file already has the mode you want, copy its mode to another file:

chmod --reference=template.conf new.conf

This copies the reference file’s mode, not its ownership. To check the result of a change, use:

chmod 640 report.txt
ls -l report.txt
stat -c '%A %a %n' report.txt

For a multi-file operation, -v reports every processed file, while -c reports only files whose permissions changed:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
chmod -v 640 report.txt
chmod -c -R a+rX project/

For a directory tree, inspect representative entries and their path components with namei -l; for a script, test it as the user who needs to run it.

Common mistakes and recovery

Why chmod 777 is usually the wrong fix

777 grants read, write, and execute to owner, group, and others. It can expose contents or allow unintended modification, depending on who and what can access the system. If an application cannot write a file, first identify the service account and intended ownership; if a person cannot access it, check the parent path and group or ACL. Correct only the needed class and permission.

A file is readable but still inaccessible

One of its parent directories may lack execute/search permission for the relevant user. Run namei -l /full/path/to/file and inspect each component, not only the file’s own mode.

There is no universal undo command

For a small, known set of files, set the intended modes explicitly. If a recursive change affected a large tree, recovery requires a known policy, backup, deployment configuration, package metadata, or a reference system. There is no general command that reconstructs the old modes after they have been overwritten.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.