| Tested on | RHEL 10.2 |
|---|---|
| Package | coreutils (chmod, chgrp, ls, find) |
| Applies to | RHEL, Rocky Linux, AlmaLinux, CentOS Stream, Fedora, Ubuntu, Debian, and other Linux systems with POSIX permissions |
| Privilege | Normal user for demos under /tmp; sudo to create shared directories and groups outside your home |
| Scope | Setgid on directories (group inheritance) and executables (effective GID): chmod g+s, octal 2 prefix, 2775, s vs S, and find. Does not cover setuid, ACLs, or SELinux. |
| Related guides | Linux file permissions Setuid in Linux Sticky bit in Linux chown command find command |
Setgid does two related jobs. On a directory, new files inherit the
directory's group so a team shares one group owner. On an executable, the
process runs with the file's group ID instead of your login group. You will
see it as s in the group execute column of ls -l, for example drwxrwsr-x
on a project folder or rwxr-sr-x on /usr/bin/write.
Quick Reference: Setgid Commands
| Task | Command |
|---|---|
| Set setgid on a directory | chmod g+s directory or chmod 2775 directory |
| Set group owner first | chgrp team directory then chmod g+s directory |
| Remove setgid | chmod g-s directory or drop the 2 digit in octal |
| Find setgid directories | find /path -type d -perm -2000 |
| Find setgid executables | find /path -type f -perm -2000 |
| Inspect mode | ls -ld directory (look for s or S in group execute) |
1. What Is Setgid in Linux?
The setgid bit lives in the group execute position. What it does depends on whether the target is a directory or an executable.
On a directory, setgid is a team label. Every new file or subdirectory
created inside picks up the directory's group, even if the creator's primary
group is something else. That keeps a shared tree group-consistent without
everyone running chgrp after each save.
On an executable, setgid causes the process effective GID to become the
executable file's group when the kernel honors the setgid bit. Tools such as
write use that to reach the tty group safely.
Setgid does not grant root powers. It adjusts group context only. For root-level file access, see setuid.
Root, group members, and the "others" class
Behavior depends on whether setgid is on a directory or an executable.
On a directory, inheritance applies to every creator, including root.
If root writes a file into a setgid devteam folder, the new file's group is
devteam, not root. Members of devteam then share group permissions on
that file according to the mode bits.
On an executable, setgid causes the process effective GID to become the executable file's group when the kernel honors the setgid bit. If the resulting GID already matches the caller's, there is no practical privilege change. Root does not need that shortcut for ordinary administration.
The s appears in the group execute column (chmod g+s). Execute
permission is separate: users still need x through owner, group, or
others before the kernel will run the file. /usr/bin/write is group
setgid and world-executable (rwxr-sr-x), so any user with x in their
triplet can run it and pick up the tty group for that process.
2. The team folder: user1, user2, and setgid
Imagine a design team with a shared shelf labeled devteam. Without setgid,
user1 saves a draft and the file is owned by user1:user1. user2 saves
next door and gets user2:user2. The shelf is shared, but the paperwork still
belongs to separate personal stacks. Collaboration turns into a chain of
chgrp requests and "please fix the permissions" tickets.
Setgid on the directory is the label on the shelf that says everything
placed here belongs to devteam. user1 and user2 still own their own
files as individuals, but the group column reads devteam for both.
Either teammate can edit team files when group write is allowed, without
re-homing every upload.
That is different from setuid, which is the borrowed red badge for one root-owned kiosk. Setgid is the shared team stamp on a folder. Sticky bit is the "only remove your own mug from the break-room table" rule. All three are special permission bits; they solve different arguments.
When setgid on a directory helps
- Shared project trees where many users write files (
/srv/www,/data/project) - Git checkouts, build artifacts, or upload queues that should stay one group
- Any folder where the group name matters more than each user's primary group
When setgid on an executable helps
- Almost never on your own scripts; distro packages such as
writeship setgid when they must touch a device group
When you do not need it
- Personal home directories where only one user should own the tree
- Directories already managed with ACLs or a single service account
- World-writable paths where sticky bit is the real fix, not group inheritance
3. Setgid on a Shared Directory (2775)
Create a team directory, assign the shared group, then add setgid and
group-writable mode. The demo assumes a group devteam with members user1
and user2 (create them with groupadd and useradd if your host does not
have them yet):
mkdir /tmp/sgid-labPoint the directory at the team group:
chgrp devteam /tmp/sgid-labAdd setgid and group-writable mode (775 plus the 2 special digit):
chmod 2775 /tmp/sgid-labThe 2 prefix is setgid; 775 lets owner and group read, write, and enter.
ls should show s in the group execute slot:
ls -ld /tmp/sgid-labdrwxrwsr-x. 2 root devteam 6 Aug 15 19:19 /tmp/sgid-labHave two members of devteam create files:
su - user1 -c 'touch /tmp/sgid-lab/from_user1.txt'Switch to the second account and add another file:
su - user2 -c 'touch /tmp/sgid-lab/from_user2.txt'Both files should list devteam as the group even though owners differ:
ls -l /tmp/sgid-labtotal 0
-rw-r--r--. 1 user1 devteam 0 Aug 15 19:19 from_user1.txt
-rw-r--r--. 1 user2 devteam 0 Aug 15 19:19 from_user2.txtNeither user ran chgrp. The directory's setgid bit set the group at create
time.
Setgid controls the inherited group owner; it does not automatically add
group-write permission. With a typical umask 022, the files above are
644. If teammates must edit one another's files, use an appropriate umask
such as 002, ACLs, or another deliberate permission
policy. New subdirectories created inside a setgid directory can inherit the
setgid bit as well, keeping the whole tree on the same group.
4. Setgid on an Executable
Some programs need a specific group to open devices or sockets. write sends
messages to other terminals and runs with the tty group:
ls -l /usr/bin/write-rwxr-sr-x. 1 root tty 24160 Jan 15 2026 /usr/bin/writeThe s in group execute means setgid is active when the kernel honors it
during execve. Users run write as themselves, but the process GID matches
tty for the duration of the command. Linux ignores setgid on scripts the
same way it ignores setuid. Package maintainers decide when compiled binaries
need the bit.
5. Set Setgid with chmod g+s
When the rwx bits are already correct, add setgid symbolically:
chmod g+s /tmp/sgid-labg+s only touches the group triplet. u+s would be setuid;
o+t would be sticky.
6. Lowercase s vs Uppercase S
The same letter rules as setuid, but in the group execute column:
- lowercase
s— setgid and group execute are on - uppercase
S— setgid is on without group execute
Force uppercase S with mode 2740 (setgid without group execute):
chmod 2740 /tmp/sgid-labGroup execute is off, so ls prints capital S:
ls -ld /tmp/sgid-labdrwxr-S---. 2 root devteam 6 Aug 15 19:19 /tmp/sgid-labRestore group execute for a usable shared directory:
chmod 2775 /tmp/sgid-lab7. Remove Setgid
Prefer symbolic mode so you do not fight GNU chmod's special-bit preservation on directories:
chmod g-s /tmp/sgid-labA short numeric mode such as chmod 775 can leave setgid set on a directory.
GNU chmod preserves setuid and setgid on directories when the mode uses four
or fewer digits. To clear special bits explicitly with octal, include a leading
zero field or use = to set the mode exactly:
chmod =775 /tmp/sgid-labConfirm setgid is gone:
ls -ld /tmp/sgid-labdrwxrwxr-x. 2 root devteam 6 Aug 15 20:22 /tmp/sgid-labchmod 00775 /tmp/sgid-lab also clears the setgid bit. New files created
afterward follow the creator's primary group again.
8. Find Directories and Files with Setgid
Setgid is bit 2000 in octal:
find /tmp -maxdepth 1 -type d -perm -2000/tmp/sgid-labSearch executables separately:
find /usr/bin -maxdepth 1 -type f -perm -2000/usr/bin/write
/usr/bin/plocateAudit both lists after migrations. Unexpected setgid binaries deserve the same scrutiny as setuid files.
Setgid vs Setuid and Sticky Bit
| Bit | Target | Effect |
|---|---|---|
setgid (g+s, 2) |
directory | new entries inherit directory group |
setgid (g+s, 2) |
executable | process runs with file's GID |
setuid (u+s, 4) |
executable | process runs with file owner's UID |
sticky (+t, 1) |
directory | users delete only their own files |
Pick setgid when the problem is group sharing. Pick setuid when one program must act as another user. Pick sticky when the directory is world- writable but deletes must be per-owner.
Summary
Setgid on a directory makes new files inherit the folder's group, which keeps
shared project trees coherent for every member of that group. Setgid on an
executable switches the process group for the run, as with write and the
tty group.
Use chmod g+s or octal 2775 after chgrp sets the team name. Lowercase
s means group execute is set; uppercase S means it is not. Remove
setgid with g-s or by dropping the 2 prefix. Find setgid paths with
find … -perm -2000.
Reach for setgid when collaboration needs a common group owner. Reach for setuid when a program must cross a user-ID boundary, and sticky bit when a public directory must stay writable without letting users delete each other's files.
References
man chmodman 7 inode(set-group-ID on directories and executables)- GNU Coreutils chmod documentation

