Linux Permission Calculator
Permissions like drwxr-x--- are easy to read but hard to apply: what can www-data actually do with this folder? Paste lines from ls -l, enter a user and their groups, and the calculator explains for every entry which permission class applies to that user and what they can do, with directory rules, special bits and dangerous settings spelled out. It also turns a umask into the default permissions of new files and folders.
- Runs in your browser
- No sign-up
- Free to use
How to use Linux Permission Calculator
- Run ls -l and paste the lines.
- Enter a user and the groups they belong to (from id).
- Optionally enter the umask.
- Read the access report for each entry.
Linux Permission Calculator features
Effective access
Owner, group or others: the class that applies to the user.
Directory rules
List, enter, create and delete explained separately.
Special bits
setuid, setgid, sticky and capital S/T explained.
Risk warnings
World-writable files and folders, setuid scripts.
umask
Default modes for new files and directories.
Octal
Each entry’s mode in octal, ready for chmod.
When to use Linux Permission Calculator
- Finding out why the web server cannot write to a folder.
- Checking whether other users can read a configuration file.
- Understanding permissions on a shared team folder.
- Auditing a directory for risky permissions.
Linux Permission Calculator FAQ
How does Linux choose which permissions apply?
It checks whether you are the owner, then whether you are in the group, then uses the others permissions. Only the first matching class counts, even if another class has more rights.
Why can I not open a file in a folder I can list?
Listing needs read on the folder; opening files inside needs execute (search) permission on every folder in the path.
Who can delete a file?
Anyone with write and execute permission on the folder containing it, regardless of the file’s own permissions, unless the folder has the sticky bit.
What do s, S, t and T mean?
s means setuid or setgid with execute, t means sticky with execute; capital letters mean the special bit is set without execute, which is usually a mistake.
What is the umask?
A mask of permissions removed from new files and folders. With 022, files get 644 and folders 755.
Is anything uploaded?
No. The listing is analysed in your browser.
How Linux decides access
Every file and directory has an owner, a group and three sets of permissions: for the owner, for members of the group and for everyone else. ls -l shows them as ten characters, the type followed by rwx for each class. Reading them is easy; working out what one particular user can do takes a few rules that are easy to forget.
The first rule is that only one class applies. If you are the owner, the owner permissions decide, even if the group or others have more rights. Otherwise, if you are in the file’s group, the group permissions decide; otherwise the others permissions. The calculator determines the class for the user and groups you enter, and the root user bypasses read and write checks entirely.
Directories interpret the bits differently. Read allows listing names, execute allows entering the folder and reaching files inside, and write together with execute allows creating, renaming and deleting entries. That is why deleting a file depends on the folder, not the file, and why a folder with read but no execute is nearly useless.
Special bits change behaviour further. setuid runs an executable as its owner, which is how passwd can update system files; setgid on a folder makes new files inherit the folder’s group, ideal for shared team folders; and the sticky bit on a world-writable folder such as /tmp stops users from deleting each other’s files.
The umask sets the defaults for new files and folders by removing bits from 666 and 777. The calculator shows the resulting modes and warns about umasks that make new files writable by everyone.