Linux file permissions
chmod 644: what it means and when to use it
chmod 644 lets the owner read and write the file, while the group and everyone else can only read it.
644
rw-r--r--
| Who | Digit | Read | Write | Execute |
|---|---|---|---|---|
| Owner | 6 |
Yes | Yes | No |
| Group | 4 |
Yes | No | No |
| Everyone else | 4 |
Yes | No | No |
How chmod 644 works
The 6 is read plus write, 4 + 2, for the owner, and each 4 is read only, for the group and for everyone else. Nobody has execute permission, so the file cannot be run as a program.
644 is the default for most ordinary files: HTML, CSS, images, documents and configuration that is safe to read. A web server needs to read these files but should never be able to change them, which is exactly what 644 allows.
Where 644 belongs
- Web pages, stylesheets and images
- Configuration files without secrets
- Documents shared with other users on the machine
The command
Both of these set exactly the same permissions. The number is shorter; the letters are easier to read back later.
chmod 644 filename
chmod u=rw,g=r,o=r filename
Files that hold passwords or API keys should not be 644. Use 600 so only the owner can read them.