Keep users from trashing shared project files

Permissions & Security (Chmod/Chown/ACLs/SELinux/AppArmor)

Keep users from trashing shared project files

🧩 The Challenge

Ever set up a shared directory for a dev team, made it `777` (don’t lie, we’ve all done it), and then watched in horror as someone accidentally `rm -rf`’d half the project? Or maybe just deleted a critical config file because they thought it was theirs. It’s a mess, and it’s always “whoops.”

💡 The Fix

There’s a super simple permission bit that fixes this by making sure only the file owner (or root) can actually delete files in a shared, writable directory. It lets everyone create files, but keeps them from nuking other people’s stuff. Stops a lot of grief.

chmod +t /path/to/your/shared/directory
# Or, if you prefer octal:
# chmod 1777 /path/to/your/shared/directory

⚙️ Why It Works

Adding the sticky bit (`+t` or the `1` in `1777`) to a directory tells the kernel: “Yeah, anyone can write files here. But only the owner of a file, or the directory owner, or root, can delete or rename that file.” It’s a small change with a huge impact on team sanity.

🚀 Pro-Tip: Set this on `/tmp` too; it’s why you can’t `rm` other people’s temporary files in there.

Linux Tips & Tricks | © ngelinux.com | 10/6/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted