chmod 755 is a common way to make a script executable or a directory accessible to other users. But it also makes the file readable by everyone, so it isn't a safe default for every path.
The mode sets permissions to rwxr-xr-x: the owner can read, write, and execute; group members and other users can read and execute, but not write.
Reading the three digits
Linux permissions are grouped into three classes: the file's owner, its group, and everyone else. In numeric mode, read is 4, write is 2, and execute is 1. Add the values for each class:
| Digit | Calculation | Permissions |
|---|---|---|
7 |
4 + 2 + 1 | rwx |
5 |
4 + 1 | r-x |
So 755 means rwx for the owner, followed by r-x for the group and others. In ls -l output, you'll see this as -rwxr-xr-x for a regular file or drwxr-xr-x for a directory.
What the command changes
To set a script to mode 755:
chmod 755 script.sh
ls -l script.sh
This sets the permission bits explicitly; it doesn't just add execute permission. The owner, group, and others get the same permissions described above, regardless of the file's previous mode. It also doesn't change who owns the file.
For a directory, ls -ld shows the directory itself rather than listing its contents:
chmod 755 my-folder
ls -ld my-folder
A useful distinction: execute permission means different things for files and directories. On an executable file, it allows execution, subject to normal requirements—for example, a script run as ./script.sh normally needs a valid shebang. On a directory, execute means search or traverse: it lets a user access entries inside when they know their names. Read permission on a directory controls whether its contents can be listed.
When 755 fits
Use 755 when the owner should have full control and other users genuinely need to read and execute a file, or traverse a directory. That might be a shared utility script or a directory a service needs to access.
It is usually unnecessary for ordinary data files. A configuration file, image, or text document generally doesn't need an execute bit. If the content should be readable by everyone but writable only by its owner, 644 (rw-r--r--) is often a better fit.
And if a file contains credentials or other private data, don't grant group or others read access. SSH private keys are a useful example: the right permissions for SSH key files are much more restrictive than 755.
Adding execute is not the same as setting 755
If you only want to make a file executable for its owner, use:
chmod u+x script.sh
That adds the owner's execute bit and leaves the other existing permission bits alone. For example, a file at 644 becomes 744 (rwxr--r--). By contrast, chmod 755 script.sh also grants read and execute access to the group and everyone else.
This is a useful distinction when a script is meant to be run by just its owner. Choose the command that expresses the access you actually want, rather than applying a familiar number automatically.
Be careful with chmod -R 755
Recursive mode applies the permissions to every file and directory underneath the path:
chmod -R 755 my-project/
That gives regular files the execute bit too—including source code, configuration, and images that don't need it. A safer pattern for a tree where directories should be traversable and regular files should not be executable by default is to handle each type separately:
find my-project/ -type d -exec chmod 755 {} \;
find my-project/ -type f -exec chmod 644 {} \;
Then set the execute bit on any specific scripts or binaries that need it. For more on the risks and alternatives, see this guide to using recursive chmod safely.
A quick comparison
-
644— owner can read and write; others can read. A common fit for non-executable files. -
700— only the owner has access. -
755— owner can read, write, and execute; others can read and execute. -
775— like 755, but the group can also write. -
777— everyone can read, write, and execute. Avoid it unless unrestricted access is specifically intended.
Before changing permissions, ask who needs to read, modify, execute, or traverse the path. 755 is useful when its access pattern matches that answer—not simply because it isn't 777.
I originally published a more detailed version of this guide on the SSHFlow blog.
I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.
Top comments (0)