Skip to content

chmod 711: others can pass through, but not look around

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 711 · rwx--x--x · file
Output
Octal711
Symbolicrwx--x--x
ls -l-rwx--x--x
Commandchmod 711 file

`chmod 711 file` sets `rwx--x--x`: the owner has full control, and every other account gets execute only. On a directory that means others can pass through it to a path they already know, but cannot list what is inside.

What chmod 711 means

In 711 the first digit is the owner, the second the group and the third everyone else: the owner gets read, write and execute, the group gets execute only, and others get execute only.

ls -l shows -rwx--x--x. Each 1 is the execute bit alone. On a directory, read and execute are separate rights: read lets you list the names, execute lets you traverse the directory and open an entry by name. 711 hands out the second without the first.

Home directories

711 is a common compromise for home directories on shared hosts. Other users cannot run ls on your home and see what is there, yet a web server can still reach ~/public_html when that subdirectory is itself readable, and a shared file can be opened if someone gives out its full path and the file's own mode allows it. Some hosting control panels and distributions use exactly this mode for that reason.

Compared with 755, it hides file names. Compared with 700 and 750, it still allows traversal, which is what makes per-user web directories and similar setups work.

Hiding is not protecting

711 relies on names being hard to guess. Well-known paths such as .bashrc, .ssh or .config are trivial to guess, so every file and subdirectory below needs its own sensible mode: 700 on ~/.ssh, 600 on secrets, and so on. If nothing inside needs to be reachable by other accounts, 700 is simpler and stricter. Root, as always, is not limited by any of these bits.

On a file

On a compiled binary, 711 lets everyone run it while only the owner can read its bytes. On a script it does much less: an interpreter has to read the file to run it, so a user without read permission gets "Permission denied" from the shell. Use 755 for scripts others should run.

FAQ

Questions, answered.

Tap a question to expand the answer.

Only if they know the exact name and the file itself grants them read. They cannot list the directory to find names, which is why 711 hides contents without blocking access to known paths.

700 if nothing in it needs to be reachable by other accounts. 711 if a service such as a web server must traverse it to reach a subdirectory like public_html.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.