A chmod calculator translates a Unix permission bit pattern between strict 3- or 4-digit octal notation and a complete 9-character symbolic snapshot, with explicit handling for setuid, setgid, and the sticky bit. In each octal position, read contributes 4, write contributes 2, and execute (or directory search) contributes 1, so 7 represents read, write, and execute, 6 represents read and write, 5 represents read and execute, and 0 represents none. The three ordinary positions cover owner, group, and others in that order. When a 4-digit value is entered, the leading digit combines setuid as 4, setgid as 2, and sticky as 1, which means 6755 carries two special bits at once while 7755 carries all three. Symbolic output preserves those special bits in shared instances: a lowercase s in the owner position means both setuid and owner execute are set, an uppercase S means setuid is set but owner execute is absent, and the same lowercase and uppercase rule applies to setgid on the group position and sticky on the others position. The complete 12-bit mode space contains 4,096 distinct values from octal 0000 through 7777, and any trustworthy calculator covers the full range rather than a handful of familiar presets.

chmod calculator explained
Chmod Calculator Explained: Decoding Unix Permissions

What a Chmod Calculator Does and Does Not Do

A chmod calculator is a small, deterministic translator for one specific Unix data type: the 12-bit file mode. It accepts exactly one strict input snapshot, plus a direction flag of octal-to-symbolic or symbolic-to-octal, and produces the canonical octal value, a 9-character symbolic string, and a readable permission table for owner, group, and others. The Chmod Calculator performs this translation entirely in the current browser tab, without sending any path, permission value, or command to a remote server. It is not a file editor: it never asks for a real file path, never invokes chmod, never recurses through directories, never inspects current permissions, and never consults an umask. Its only job is to describe a requested set of mode bits accurately enough that you can review the value before applying it on the command line, which is why its copy action writes a chmod OCTAL FILE template rather than a finished script.

The 4-2-1 Math Behind Octal Digits

Each ordinary octal position covers one principal, namely owner, group, or others, and each position is a 3-bit field. The bits are weighted powers of two: read is 4, write is 2, and execute (or directory search) is 1. Adding the enabled bits yields one digit from 0 through 7. That single line is the entire foundation of chmod numeric notation, and any reliable calculator implements it with explicit bitwise masks rather than a small table of familiar examples. The pattern is identical to the way other Unix flags are stored, and the underlying mechanism is just a bitwise AND against a mask as described in the Mozilla Developer Network reference.

DigitRead (4)Write (2)Execute (1)Symbolic
0———---
1——set--x
2—set—-w-
3—setset-wx
4set——r--
5set—setr-x
6setset—rw-
7setsetsetrwx

Reading right to left matches the chmod tradition: the rightmost bit is execute, then write, then read. The same mapping applies whether the field belongs to a file, where execute means the file may be invoked, or a directory, where execute means the directory may be traversed and is often labeled search instead. If you are decoding a value from an ls -l listing, the three-position table is enough, and a leading zero such as 0755 simply means no special bits and describes the same mode as 755.

Reading the 9-Character Symbolic Output

Symbolic output always contains exactly nine characters: three for owner, three for group, and three for others, in that order. Each position accepts r or a hyphen for read, w or a hyphen for write, and x or a hyphen for ordinary execute. A calculator that accepts the full snapshot, for example rwxr-xr-x or rwsr-xr-x, gives you a round-trip-friendly value that you can paste back into the tool and recover the original octal digits without loss. By contrast, a leading file-type character such as the dash in -rwxr-xr-x belongs to ls -l, not to chmod, and a modification expression such as u+x carries different information and should not be fed into a calculator that converts mode snapshots.

The case of the special bits, setuid, setgid, and sticky, encodes two pieces of information in one character: whether the special bit is set, and whether the corresponding execute bit is set. Lowercase means both, uppercase means the special bit is set but that execute position is absent. The owner position uses s and S for setuid, the others position uses t and T for sticky, and setgid follows the same lowercase and uppercase rule in the group position.

Special bitExecute also setCharacter
setuid (owner)Yess
setuid (owner)NoS
setgid (group)Yess
setgid (group)NoS
sticky (others)Yest
sticky (others)NoT

Preserving that case distinction matters because chmod 4755 and chmod 4655 describe genuinely different file states: only the second has setuid without owner execute, so a calculator that flattened both to S would lose state during a round trip.

How to Use the Chmod Calculator

  1. Open the Chmod Calculator and pick a direction: octal-to-symbolic if you have digits such as 754 or 4755, or symbolic-to-octal if you have a string such as rwxr-xr-x or rwsr-xr-x.
  2. Enter exactly one complete permission snapshot in the strict form the tool expects: three ASCII octal digits for ordinary modes, four ASCII octal digits when special bits are present, or nine position-valid symbolic characters in the other direction. Do not add a 0o prefix, a sign, a space, a separator, an underscore, or a leading file-type dash.
  3. Read the canonical octal value, the 9-character symbolic value, and the owner, group, and others table the calculator renders for review. The table separates read, write, and execute (or search), and labels any setuid, setgid, or sticky bit that is set.
  4. Before using the copy button, double-check the target file, its current ownership, and whether the request actually reflects least privilege. The copy action writes a chmod OCTAL FILE template; FILE is a placeholder that you must replace with the real path before running the command.
  5. Apply the command on the command line only after this review. The calculator describes requested mode bits and does not promise that the filesystem will retain or honor every bit once the command runs.

Special Bits: setuid, setgid, and Sticky in 4-Digit Modes

Three octal positions cover the ordinary permissions, and a fourth leading position combines three independent flags. Setuid contributes 4, setgid contributes 2, and sticky contributes 1. Adding the enabled special flags yields a leading digit from 0 through 7, which is why 6755 carries setuid and setgid at once, 4755 carries setuid alone, 1755 carries sticky alone, and 7755 carries all three. A 3-digit input such as 755 explicitly means none of those special flags is set, and a calculator that quietly promotes a 3-digit input to a 4-digit one without warning would be changing the meaning. The GNU chmod manual page documents the same bit positions and is worth keeping open while reviewing an unusual value.

Special bits deserve operational care. Setuid and setgid on executable files can alter the effective identity of a running process, and many systems clear or ignore them when the file's owner does not match the requested effective identity. Setgid on a directory commonly forces the group of new children to match the directory's group, which is a useful pattern for shared working trees. Sticky on a directory, often seen as the t on /tmp, restricts deletion and renaming to the owner of the entry, the owner of the directory, or root, which is the practical mechanism that lets many users share a world-writable scratch directory without stepping on each other.

Strict Input Rules and Common Rejections

A trustworthy calculator enforces a strict input grammar so the result is unambiguous. Octal input must be exactly three or four ASCII octal digits, with no 0o prefix, no sign, no leading whitespace, no separator, no decimal point, no underscore, and no Unicode lookalike digit. A leading zero such as 0755 is accepted and represents the same mode as 755, because canonical output simply omits the redundant zero when no special bit is set. A 3-digit input explicitly carries no setuid, setgid, or sticky bit; that is not a forbidden quantity, it is information about the value. Symbolic input must contain exactly nine position-valid characters, with no leading file-type dash from ls -l, and no modification expression such as u+x or g-w. Both directions share a 32-UTF-16-code-unit budget on raw input, so a degenerate value at the boundary receives an explicit syntax error and the next code unit receives an explicit budget error rather than a silent HTML truncation. Common reasons a calculator refuses a snapshot, then, include a leading minus, a 0o prefix, a decimal point, embedded whitespace, and a symbolic value with a leading dash from ls -l.

The Chmod Calculator also refuses to validate a snapshot that would have changed the result anyway: editing the input clears any earlier result, error, and copy status, and clipboard completion is generation-guarded so a late asynchronous copy cannot publish a stale success after the input or mode has changed.

Modes Are Bits, Not Authorization

The chmod bit pattern is a request to the filesystem, and the operating system is allowed to refuse parts of it. POSIX defines the bit positions, but actual access can still be affected by ownership, access control lists, capabilities, mount options (a read-only filesystem will not accept write regardless of mode), read-only file flags, application sandboxing, and other policy. A process also needs permission to traverse every parent directory in the path before it reaches the target file, which is why chmod 777 on a file inside a directory the user cannot traverse is a no-op rather than a fix. Umask affects permissions requested when files are created, but it is not an extra digit applied by the converter, and a calculator that quietly subtracted umask from your input would be lying about what the bits mean.

For a deeper walk through concrete values such as 6755 and 7755, see the setuid, sticky, and rwx example guide, or keep the octal and rwx cheat sheet open in a second tab while you convert. Treat the calculator's output as a check before applying the command, prefer the least privilege the actual user and service need, and avoid copying broad examples such as 777 to bypass an access problem; diagnose ownership, groups, directory traversal, ACLs, and service identity first.