Skip to content

chmod 744: an owner-only executable that everyone can read

Runs in your browser — nothing you paste leaves this page. How we prove that

chmod calculator playground

Examples
Permission bits
Read
Write
Exec
Owner
Group
Other
Enter a value

The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.

Results update as you type — press Enter to run now.

fig. 29 — chmod-calculator · utilities 744 · rwxr--r-- · file
Output
Octal744
Symbolicrwxr--r--
ls -l-rwxr--r--
Commandchmod 744 file

`chmod 744 file` sets `rwxr--r--`: the owner can edit and run the file, while the group and everyone else can read it but not execute it.

What chmod 744 means

In 744 the first digit is the owner, the second the group and the third everyone else: the owner gets read, write and execute, the group gets read only, and others get read only.

ls -l shows -rwxr--r--. Each 4 is read alone. Compared with 755, the group and others lose execute, so the owner is the only account that can run the file directly. Anyone can still copy it, or pass it to an interpreter with sh script.sh — execute permission does not stop that for scripts.

Where it fits

744 suits a personal maintenance script you want colleagues to be able to read and review but not run from your path by accident, such as a cleanup job in your home directory triggered by your own crontab.

It is not a security boundary. Since the content is readable, it must not contain passwords or tokens; for that, use 700. And if the script is harmless to run, 755 is simpler and conventional.

Why 744 is odd on a directory

On a directory, read without execute lets group and others list the entry names but not enter the directory or open anything in it. ls prints the names alongside "Permission denied" errors for their details, and cd fails. That half-open state is rarely intended; directories almost always want 755, 750 or 700.

This is the classic chmod -R trap: applying 744 recursively to a tree gives every subdirectory this broken mode for non-owners. Use find dir -type f -exec chmod 744 {} + to touch files only.

Related values

The nearest values each change one class. 755 gives group and others execute as well, which is the normal choice for a script anyone may run. 700 removes read from group and others, which is what you want once the script holds anything sensitive. 644 drops the owner's execute too, turning the file back into plain data, and 444 removes write so even the owner gets a read-only copy.

FAQ

Questions, answered.

Tap a question to expand the answer.

Not directly as ./script, because they lack execute. They can still read it, so they can run it with an interpreter such as bash script.sh or python3 script.py. 744 limits convenience, not access to the logic.

Yes. The owner digit is 7 in both. The difference is only for group and others, who keep read but lose execute in 744.

More free, private DevOps tools.

The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.

42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.

Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.

Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.