Resize my Image Blog

Chmod -R: chmod vs chown for Managing Linux File Permissions

chmod -R should be used to change permissions, while chown -R should be used to change ownership. Mixing them up is one of the fastest ways to break a Linux site, expose private files, or cause a service to stop writing logs. A careful admin treats recursive permission changes as a sharp tool, not a quick fix.

TLDR: chmod -R changes what users can do with files, such as read, write, or execute them. chown -R changes who owns those files and which group controls them. For example, after deploying 18,000 website files, an admin might run chown -R www-data:www-data /var/www/site, then set directories to 755 and files to 644. In one common hosting case, correcting ownership first can remove most 403 Forbidden errors without making files dangerously writable.

What chmod -R Actually Does

chmod means change mode. It controls file permissions. The -R flag means recursive, so the command applies to a directory and everything inside it.

A command like this changes permissions across an entire directory tree:

chmod -R 755 /var/www/html

That command gives the owner full access, while the group and others get read and execute access. For directories, execute means a user can enter the directory. For files, execute means the file can be run as a program or script.

The catch is that files and directories usually need different permissions. Applying 755 to every file may mark plain text, images, and PHP files as executable. It may not break the app, but it is messy and risky. Honestly, it feels like Linux lets one short command create a half-hour cleanup job far too easily.

What chown -R Actually Does

chown means change owner. It changes the user and group assigned to files or directories. The -R flag makes it recursive, just like with chmod.

A typical web server command looks like this:

chown -R www-data:www-data /var/www/html

This sets both the owner and group to www-data. That user is often used by Apache or Nginx on Debian and Ubuntu systems. On CentOS, AlmaLinux, or Rocky Linux, the web user may be apache or nginx.

chown does not grant read, write, or execute rights by itself. It only changes who the permission rules apply to. If a file has mode 600, only the owner can read and write it. Changing the owner changes which user gets that access.

chmod vs chown: The Core Difference

A simple way to think about it is this: chown decides who holds the key, and chmod decides what the key can open.

Common Permission Numbers

Linux numeric permissions use three digits. The digits represent the owner, group, and others. Each digit is built from these values:

So 755 means:

Common safe defaults include:

Why Recursive Commands Are Risky

-R is useful, but it is not forgiving. A small typo can affect thousands of files in seconds. A command meant for /var/www/site can become a disaster if it is run against /var/www, /home, or worse, /.

Expect to waste time on repairs if recursive commands are fired off without checking the target path. On a server with 250,000 files, even a wrong command that runs for 10 seconds can change enough data to cause login failures, broken uploads, or exposed config files.

Admins should inspect before changing:

ls -la /var/www/html
find /var/www/html -maxdepth 2 -ls

Safer Ways to Use chmod -R

Applying one permission to everything is rarely ideal. A better pattern is to set directories and files separately:

find /var/www/html -type d -exec chmod 755 {} \;
find /var/www/html -type f -exec chmod 644 {} \;

This keeps directories accessible and files non-executable. It also avoids the common mistake of making every CSS, JPG, and PHP file executable.

For upload folders, write access may be needed:

chown -R www-data:www-data /var/www/html/uploads
find /var/www/html/uploads -type d -exec chmod 755 {} \;
find /var/www/html/uploads -type f -exec chmod 644 {} \;

If the app needs group write access, 775 for directories and 664 for files may be used. That should happen only when group membership is controlled.

When to Use chown -R

chown -R is the right tool when files belong to the wrong user. This often happens after copying files as root, extracting a backup, deploying from CI, or moving a site between servers.

Common examples include:

A safer ownership pattern may separate code from writable content:

chown -R deploy:deploy /var/www/app
chown -R www-data:www-data /var/www/app/storage
chown -R www-data:www-data /var/www/app/cache

This limits the web server’s write access. If the site is compromised, the attacker has less room to alter application code.

A Practical Web Server Example

Suppose a Laravel, WordPress, or custom PHP site has been copied to /var/www/app. The files are owned by root. The web server throws errors when writing cache files.

An admin might fix ownership for writable areas:

chown -R www-data:www-data /var/www/app/storage
chown -R www-data:www-data /var/www/app/bootstrap/cache

Then set clean permissions:

find /var/www/app -type d -exec chmod 755 {} \;
find /var/www/app -type f -exec chmod 644 {} \;

If write access is still needed in selected folders:

chmod -R 775 /var/www/app/storage

This is much safer than running:

chmod -R 777 /var/www/app

777 is almost always a bad fix. It gives every local user read, write, and execute access. It may hide the real issue for a few minutes, but it creates a security problem that can bite later.

Best Practices for Managing Linux Permissions

FAQ

What is the difference between chmod -R and chown -R?

chmod -R changes permissions recursively. chown -R changes ownership recursively. One controls access rights, while the other controls which user and group own the files.

Is chmod -R 777 safe?

No. 777 allows everyone to read, write, and execute. It may make an error disappear, but it can expose files and allow unwanted changes.

Should ownership be fixed before permissions?

Usually, yes. If the wrong user owns the files, changing mode values may not solve the real problem. Correct ownership often fixes access errors with fewer permission changes.

What permissions should website files use?

A common setup is 755 for directories and 644 for files. Writable folders may need special handling, depending on the app and server user.

Can chmod change the file owner?

No. chmod only changes permission modes. chown is required to change the owner or group.

Why does -R need extra care?

-R applies changes to every nested item. A wrong path or broad command can damage many files at once, so admins should inspect paths before running it.

Exit mobile version