chmod 777: what it means and when to use it
Runs in your browser — nothing you paste leaves this page. How we prove that
chmod calculator playground
The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.
Results update as you type — press Enter to run now.
`chmod 777 file` sets the mode to `rwxrwxrwx`: every user on the system can read, modify and execute the file. It is almost never the right fix, and the safer value is usually 755 or 644.
What chmod 777 means
In 777 the first digit is the owner, the second the group and the third everyone else: the owner gets read, write and execute, the group gets read, write and execute, and others get read, write and execute.
ls -l shows it as -rwxrwxrwx. Each 7 is 4 + 2 + 1 — read plus write plus execute — so there is no class left out. On a directory the same bits mean any account can list it, enter it, and create, rename or delete entries inside it, including files that belong to somebody else.
Why 777 is a security problem
A world-writable file can be replaced by any local process, including a compromised web server running as www-data or nginx. If that file is a script run by cron or a deploy hook, whoever can write it can run code as the account that executes it. A world-writable directory lets any user drop files into a path another program trusts.
Shared scratch space such as /tmp is world-writable on purpose, but it is mode 1777, not 777: the extra sticky bit means users can only delete their own files. A plain 777 directory has no such protection.
When people reach for it, and what to do instead
777 usually appears after a "permission denied" from a web app or a container volume. The real cause is almost always ownership: the process runs as a different user from the one that owns the files. Fix it with chown to the service account, or by putting that account in the file's group and granting group write, rather than opening the file to every user.
For code and directories that a server only needs to read, 755 for directories and 644 for files is the conventional pair. For a directory two accounts must both write, give it a shared group and use 775 or 770 with the setgid bit, so new files inherit the group.
Undoing a recursive 777
After chmod -R 777 every file is also executable, which a single recursive command cannot cleanly undo: chmod -R 644 would strip execute from directories and make them impossible to enter. Split the repair by type: find dir -type d -exec chmod 755 {} + for directories and find dir -type f -exec chmod 644 {} + for files, then restore execute on the scripts that need it.
FAQ
Questions, answered.
Tap a question to expand the answer.
Is chmod 777 ever acceptable?
Rarely, and only on a throwaway single-user machine or a scratch directory nobody else can reach. For shared scratch space use 1777 so the sticky bit stops users deleting each other's files. On a server or in a container image, fix ownership instead.
Does chmod 777 make a file executable for everyone?
Yes. All three classes get the execute bit, so any user can run the file as a program if its contents are a valid binary or a script with a shebang line. That is one more reason not to apply it to a whole tree.
More free, private DevOps tools.
The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Utilities
Read more about this
- chown command in Linux: change file owner and group The chown command in Linux explained: user:group syntax, chown -R and symlinks, --reference, chgrp, chmod vs chown, and fixing Docker volume permission errors with numeric IDs.
- chmod command in Linux: syntax, examples and common mistakes The chmod command in Linux explained: octal and symbolic modes, chmod +x, chmod -R and its traps, setuid, setgid and sticky bits, umask, and how to fix Permission denied.
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.
Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.