How chmod permissions work: 755, 644 and sticky bit
On Unix-like systems, chmod changes access permissions on files and directories. Read, write and execute permissions are set separately for the owner, the group and other users. Directory permissions have their own meaning: they affect listing names, creating or removing entries, and accessing a known path.
Numeric and symbolic modes
A symbolic command such as chmod u+x script.sh gives the owner permission to execute the file. In a numeric mode, read is 4, write is 2 and execute is 1. Thus 755 means rwxr-xr-x: the owner can read, write and execute, while the group and others can read and execute. Mode 644 is often suitable for an ordinary public file, but its suitability depends on the application. Do not treat a familiar number as a universal security setting.
Why directory permissions matter
On a directory, read allows listing names, write allows changing directory entries, and execute allows traversing a known path. Removing a file normally depends on permissions on its parent directory, not write permission on the file itself. A file set to 444 can therefore still be removed by someone with sufficient access to the directory. The GNU Coreutils manual explains this distinction. If access fails even when the final file looks readable, inspect every parent directory and the identity under which the service runs.
A web hosting example
Imagine a directory of HTML files that a web server must read, but only its owner may update. A starting point may be 755 for directories and 644 for ordinary files. You must still account for the service account, groups and hosting rules; private configuration files may need tighter access. Setting everything to 777 to silence an error grants local users broad modification rights and can introduce a security problem. Inspect the current owner and permissions with stat and ls -l before changing them.
Setuid, setgid and the sticky bit
An initial fourth octal digit specifies special bits: 4 for setuid, 2 for setgid and 1 for sticky. For example, 4755 enables setuid on an executable; 455 does not. Setuid must be used carefully because flaws in the programme may run with the owner’s privileges. On directories, setgid can make new entries inherit the directory group. A sticky bit on a shared directory, such as /tmp, restricts who may remove or rename another user’s files. Before chmod -R, review the exact tree: ordinary files, executables and directories rarely all need identical modes.
