Permission Bits

Reading and Setting the Permission Bits

Each file has an owner, a group and nine bits: read, write and execute for owner, group and other. The kernel uses one triad, the first that applies, and never falls through: an owner whose triad is r-- cannot write even if the group could. chmod 754 equals chmod u=rwx,g=rx,o=r; symbolic notation changes only the bits you name.

The anatomy of an ls -l line and the mode field it starts with
The anatomy of an ls -l line and the mode field it starts with

On a directory, r lists names, x lets you use a name inside (Apache 129 's user needs x on every directory from / down to the file), and w lets you create, rename and delete entries: deletion depends on the directory's mode, not the file's.

Octal modes, first match wins, and capital XShell
touch config.php; chmod 640 config.php; stat -c '%a %A %n' config.php
chmod 460 config.php; echo '<?php' >> config.php   # owner triad is r--: first match wins
mkdir -p site/img; touch site/index.php site/img/logo.png
chmod -R u=rwX,g=rX,o=rX site      # capital X: execute on directories only
find site -printf '%m %y %p\n'
Output
640 -rw-r----- config.php
bash: config.php: Permission denied
755 d site
644 f site/index.php
755 d site/img
644 f site/img/logo.png

Capital X sets execute only on directories (and files already executable), so one command yields 755 directories and 644 files where chmod -R 755 would mark every .php executable. A + after the mode in ls -l means an ACL (Web Server Permissions).