Skip to content

chmod 444: read-only for everyone, including the owner

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 444 · r--r--r-- · file
Output
Octal444
Symbolicr--r--r--
ls -l-r--r--r--
Commandchmod 444 file

`chmod 444 file` sets `r--r--r--`: every account can read the file, and no class can write or execute it. It marks a file as read-only reference data.

What chmod 444 means

In 444 the first digit is the owner, the second the group and the third everyone else: the owner gets read only, the group gets read only, and others get read only.

ls -l shows -r--r--r--. Each 4 is read alone. Editors open such a file read-only, and shell redirection into it fails with "Permission denied" for any non-root user, the owner included.

Where it is useful

444 suits generated or reference files you want protected from casual edits: a checked-out lockfile you do not mean to change, a published dataset, or a config a tool should read but never rewrite. It signals intent, and editors will warn before you overwrite it.

It is not suitable for secrets, because it is world-readable. If only one user should read the file, use 400; for a sudoers-style file readable by a group, 440 is the conventional mode.

Why a 444 file can still be deleted

Deleting a file changes its directory, not the file, so rm needs write permission on the directory and ignores the file's own mode. GNU rm asks "remove write-protected regular file?" when run interactively, but rm -f deletes it without asking. Protect against deletion with a non-writable directory or the sticky bit, not with 444.

The owner can also undo it with chmod u+w, and root ignores it. Never use it on a directory: without execute, nobody can enter it, and a recursive chmod -R 444 locks you out of your own tree until you restore execute.

Related values

444 is 644 without the owner's write, and 555 without execute. If others should not read the file, the related modes are 440 for a group and 400 for the owner alone, neither covered here. To make the file editable again, return it to 644, or to 600 if it should also be private. For a directory you want to freeze, use 555, which keeps execute so the directory can still be entered.

FAQ

Questions, answered.

Tap a question to expand the answer.

Yes, if you have write permission on its directory. rm may prompt for confirmation, and rm -f skips the prompt. A file's mode does not control whether it can be removed.

444 lets everyone read the file; 400 lets only the owner read it. Both deny write and execute to every class.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.