Keep users from trashing shared project files
Permissions & Security (Chmod/Chown/ACLs/SELinux/AppArmor)
Keep users from trashing shared project files
🧩 The Challenge
Ever set up a shared directory for a dev team, made it `777` (don’t lie, we’ve all done it), and then watched in horror as someone accidentally `rm -rf`’d half the project? Or maybe just deleted a critical config file because they thought it was theirs. It’s a mess, and it’s always “whoops.”
💡 The Fix
There’s a super simple permission bit that fixes this by making sure only the file owner (or root) can actually delete files in a shared, writable directory. It lets everyone create files, but keeps them from nuking other people’s stuff. Stops a lot of grief.
chmod +t /path/to/your/shared/directory
# Or, if you prefer octal:
# chmod 1777 /path/to/your/shared/directory
⚙️ Why It Works
Adding the sticky bit (`+t` or the `1` in `1777`) to a directory tells the kernel: “Yeah, anyone can write files here. But only the owner of a file, or the directory owner, or root, can delete or rename that file.” It’s a small change with a huge impact on team sanity.
🚀 Pro-Tip: Set this on `/tmp` too; it’s why you can’t `rm` other people’s temporary files in there.
Linux Tips & Tricks | © ngelinux.com | 10/6/2026
