Overview of Special Permission Bits
In addition to standard Read, Write, and Execute bits, Linux supports three special permission modes. These bits occupy the leading 4th digit in 4-digit octal notation.
Setuid (Set User ID)
When set on an executable file, the program executes with the privileges of the file owner, rather than the privileges of the user running the command.
/usr/bin/passwd has Setuid enabled so regular users can temporarily run as root to update their own encrypted password in /etc/shadow.rws-r-xr-x (lowercase s if execute bit is set; uppercase S if execute is missing).Setgid (Set Group ID)
On executable files, the process runs with the file group's permissions. On directories, new files created inside automatically inherit the directory's group owner.
rwxr-sr-x (lowercase s if execute bit is set).Sticky Bit
When set on a directory, users can only delete or rename files that they own (or root), even if the directory is world-writable.
/tmp folder (permissions 1777 or drwxrwxrwt). Everyone can create temporary files, but no user can delete another user's temp file.rwxrwxrwt (lowercase t if execute bit is set).How to Apply Special Bits in Terminal
chmod 4755 /usr/local/bin/custom_toolchmod u+s /usr/local/bin/custom_tool# Set Setgid (2000) + 775 = 2775 on shared folderchmod 2775 /var/www/shared_projectchmod g+s /var/www/shared_project# Set Sticky Bit (1000) + 777 = 1777 on temp folderchmod 1777 /var/tmp/shared_uploadschmod +t /var/tmp/shared_uploads