Ubuntu Server 16.04.3特定目录组权限及公共目录权限配置问询
Hey there! Let's get those directory permissions configured exactly how you need them. I'll break this down into simple, actionable steps:
First, we need to make sure each directory is tied to the correct group, then set permissions so only group members can write to them:
- Set the group ownership for each directory (this links the directory to your existing groups):
sudo chown :group1 /group1 sudo chown :group2 /group2 - Next, set base permissions plus the setgid bit (this ensures any new files/directories created inside inherit the directory's group, making collaboration smoother):
Let's break that down:sudo chmod u=rwx,g=rwx,o=rx,g+s /group1 sudo chmod u=rwx,g=rwx,o=rx,g+s /group2u=rwx: The directory owner has full accessg=rwx: Members of the directory's group can read, write, and access the directoryo=rx: Users not in the group can only read and enter the directory (no write permissions)g+s: Enables the setgid bit for automatic group inheritance of new files
The magic here is the sticky bit—a special permission that stops users from deleting or renaming files they don't own, even if they have write access to the directory.
Run these commands to set it up:
# Give everyone full access to the directory first sudo chmod u=rwx,g=rwx,o=rwx /everyone # Add the sticky bit to protect others' files sudo chmod +t /everyone
Or combine them into one line for brevity:
sudo chmod u=rwx,g=rwx,o=rwx,+t /everyone
With the sticky bit enabled, any user can create files in /everyone, but they won't be able to delete or modify files owned by someone else—exactly what you need.
Quick Verification Tips
- To check directory permissions, run
ls -ld /group1 /group2 /everyone—you should seerwxrwxr-xwith ansin the group section for/group1//group2, andrwxrwxrwxwith atat the end for/everyone. - Test with different users: Create a file in
/everyoneas user A, then try to delete it as user B—you should get a "Permission denied" error.
内容的提问来源于stack exchange,提问作者LeFou

