Skip to content

chmod 555: read and execute for all, write for nobody

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 555 · r-xr-xr-x · file
Output
Octal555
Symbolicr-xr-xr-x
ls -l-r-xr-xr-x
Commandchmod 555 file

`chmod 555 file` sets `r-xr-xr-x`: every account can read and run the file or enter the directory, but no class has write. It is a read-only version of 755.

What chmod 555 means

In 555 the first digit is the owner, the second the group and the third everyone else: the owner gets read and execute, the group gets read and execute, and others get read and execute.

ls -l shows -r-xr-xr-x. Each 5 is 4 + 1, read plus execute. Compared with 755 only the owner's write bit is gone, and that changes more than it looks.

What removing write does

On a directory, write is what allows creating, renaming and deleting entries. A 555 directory therefore freezes its contents: even the owner cannot add or remove files in it until write comes back, although files inside can still be edited if their own modes allow it. /proc is mounted dr-xr-xr-x for this reason.

On an executable file, 555 stops accidental edits, for example a vendored binary or a release script you do not want a tool to rewrite in place.

Limits

It is a guard rail, not a lock. The owner can always run chmod u+w again, because changing the mode depends on ownership, not on the write bit. Root ignores read and write bits entirely. For a file that really must not change, use a read-only mount or, on ext4 and similar filesystems, chattr +i.

Some tools fail in confusing ways in a 555 tree — package managers, git and editors that write a temporary file next to the original all need directory write. If a build suddenly reports "Permission denied" on a file you own, check the directory mode.

Related values

555 is 755 without the owner's write. Add write back and you have the ordinary mode for directories and programs. Remove execute and you get 444, read-only data. For a private equivalent, 500 (not covered here) keeps read and execute for the owner only. 777 is the opposite end: every bit, for everyone, including the write that 555 removes.

FAQ

Questions, answered.

Tap a question to expand the answer.

Not directly, since there is no write bit. But the owner can restore it with chmod u+w at any time, so 555 prevents accidents rather than deliberate changes.

Execute. 555 keeps the execute bit for everyone, so it suits programs and directories that must still be entered. 444 is read-only data with no execute, which makes it unusable on a directory.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.