chmod 755 vs 644: What's the Difference?

chmod 755 vs 644 explained in one line each — what the x bit does on files vs directories, the common modes table, and which to use on your files.

Published 2026-10-06

The short answer: 644 is rw-r--r-- and 755 is rwxr-xr-x — identical except 755 adds the execute bit for owner, group and others. Use 644 for ordinary files (documents, code, images, configs) and 755 for directories and for files meant to be run (scripts, binaries). The one-bit difference means “may execute” on a file and “may enter” on a directory.

What each digit buys

Each digit is one class — owner, group, others — and each is a sum of read 4 + write 2 + execute 1:

Mode ls -l Meaning in practice
644 rw-r--r-- owner edits, everyone reads — the web default for files
755 rwxr-xr-x owner edits+executes, everyone reads+executes — directories, scripts
600 rw------- owner only — secrets, ~/.ssh/id_rsa, .env
664 / 775 rw-rw-r-- / rwxrwxr-x group-writable variants for shared work
400 r-------- read-only even for the owner — accidental-deletion speed bump
700 rwx------ private directory — only the owner may enter
777 rwxrwxrwx world-writable — almost never right (why)

Paste any mode into the chmod calculator to see the ls -l string, the checkbox matrix and the equivalent symbolic command before you run it.

The execute bit does different jobs on files vs directories

On a file, x means “the kernel may exec this” — needed for ./deploy.sh or a CGI script, meaningless decoration on index.html. On a directory, x means “may traverse”: reach a file you already know the name of, cd into it, stat children. This is why the standard web layout is asymmetric:

find site/ -type d -exec chmod 755 {} +   # dirs: everyone may enter
find site/ -type f -exec chmod 644 {} +   # files: readable, not runnable

If a site shows “Forbidden” while every file is 644, the missing x is almost always on a directory somewhere in the path — namei -l /full/path/file checks every link in the chain. The full model is in Unix permissions explained.

When you actually want 755 on a file

  • Shell scripts and binaries invoked directly (./script.sh needs x plus a valid #!/bin/bash shebang).
  • cgi-bin executables on old-school hosting.
  • Anything a process must exec rather than merely read.

And when 755 is too generous on a directory: shared hosting home directories, anything holding secrets (700), and dirs that should let outsiders reach named files but not list (711 — x without r allows traversal without listing; obscure but real).

Frequently asked questions

What does chmod 755 actually do?

755 is rwxr-xr-x: the owner may read, write and execute; group and others may only read and execute — not write. It's the standard mode for directories (x = may enter) and for executable files like scripts and binaries.

Should HTML, CSS and image files be 644 or 755?

644 — they're read, not executed. A web server only needs read on .html/.css/.png files; the execute bit does nothing for them and marks them runnable for no reason. The directories containing them need 755 (or at least 711) so the server can reach inside.

Is 755 dangerous? When is it too much?

On a single-user machine it's harmless. The risk cases: a 755 writable-data file invites nothing directly, but an executable file you didn't intend to be runnable (an uploaded archive, a config) is sloppy hygiene; and 755 on a private directory lets everyone traverse it. The genuinely dangerous mode is 777 — see why 777 is never the answer.

What about 664 and 775 — when do I need the group write bit?

When several accounts share work through a common group: 664 files / 775 directories let every group member edit while outsiders only read. Typical for a shared /srv/team or a deploy group. Combine with setgid on the directory (chmod g+s) so new files inherit the group — explained in special bits.

Why do my directories need execute but my files don't?

Because x means different things: on a file it's "may run as a program"; on a directory it's "may enter and reach files inside". Read on a directory only lets you list names. So a directory is almost never useful without x, while a data file almost never needs it.

How do I set 644 on files and 755 on directories in one command?

Split the find: find dir/ -type f -exec chmod 644 {} + then find dir/ -type d -exec chmod 755 {} +. Or in one pass: chmod -R u+rwX,go+rX-w dir/ — capital X sets execute only on directories and files that already have it.