You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu Server 16.04.3特定目录组权限及公共目录权限配置问询

Hey there! Let's get those directory permissions configured exactly how you need them. I'll break this down into simple, actionable steps:

1. Lock Down /group1 and /group2 to Their Respective Groups

First, we need to make sure each directory is tied to the correct group, then set permissions so only group members can write to them:

  • Set the group ownership for each directory (this links the directory to your existing groups):
    sudo chown :group1 /group1
    sudo chown :group2 /group2
    
  • Next, set base permissions plus the setgid bit (this ensures any new files/directories created inside inherit the directory's group, making collaboration smoother):
    sudo chmod u=rwx,g=rwx,o=rx,g+s /group1
    sudo chmod u=rwx,g=rwx,o=rx,g+s /group2
    
    Let's break that down:
    • u=rwx: The directory owner has full access
    • g=rwx: Members of the directory's group can read, write, and access the directory
    • o=rx: Users not in the group can only read and enter the directory (no write permissions)
    • g+s: Enables the setgid bit for automatic group inheritance of new files
2. Configure /everyone for Shared Writing (No Deleting Others' Files)

The magic here is the sticky bit—a special permission that stops users from deleting or renaming files they don't own, even if they have write access to the directory.

Run these commands to set it up:

# Give everyone full access to the directory first
sudo chmod u=rwx,g=rwx,o=rwx /everyone
# Add the sticky bit to protect others' files
sudo chmod +t /everyone

Or combine them into one line for brevity:

sudo chmod u=rwx,g=rwx,o=rwx,+t /everyone

With the sticky bit enabled, any user can create files in /everyone, but they won't be able to delete or modify files owned by someone else—exactly what you need.

Quick Verification Tips

  • To check directory permissions, run ls -ld /group1 /group2 /everyone—you should see rwxrwxr-x with an s in the group section for /group1//group2, and rwxrwxrwx with a t at the end for /everyone.
  • Test with different users: Create a file in /everyone as user A, then try to delete it as user B—you should get a "Permission denied" error.

内容的提问来源于stack exchange,提问作者LeFou

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:30:53