The sticky bit in a nutshell
The sticky bit (+t) on a directory means that only the file’s owner, the directory’s owner, or root can delete or rename files inside it. /tmp is traditionally set to 1777 (octal) – owner root, group root, permissions rwxrwxrwt. That lets any user create files, but stops them from messing with each other’s data.
What happened after the update
Some kernel releases changed the default mount options for tmpfs or how tmpfs‑based /tmp is handled. If /tmp is mounted as tmpfs without the sticky bit, the kernel quietly clears the +t flag. The directory stays world‑writable, but the protection that stops users from deleting each other’s files disappears. Applications that expect the sticky bit now refuse to write, because they see the directory as insecure.
Quick fix
# Verify the current mode
ls -ld /tmp
# drwxrwxrwx 2 root root 4096 Sep 30 12:00 /tmp
# Re‑apply the sticky bit
chmod +t /tmp
# drwxrwxrwt 2 root root 4096 Sep 30 12:00 /tmp
# Ensure ownership is correct
chown root:root /tmp
After this, most services that were blocked by the missing sticky bit will resume normal operation.
Making the change permanent
If the kernel update mounts /tmp with noexec or other options that strip the sticky bit, you’ll need to enforce it at mount time.
1. Edit /etc/fstab
tmpfs /tmp tmpfs defaults,mode=1777 0 0
Adding mode=1777 forces the sticky bit and the correct permissions on every boot.
2. Use systemd-tmpfiles
Create /etc/tmpfiles.d/tmp.conf:
d /tmp 1777 root root
systemd-tmpfiles runs at boot and on demand, ensuring /tmp always has the right mode. This method is preferred on systems that use systemd, as it integrates with the init system and respects tmpfs mount options.
systemd-tmpfiles --create /etc/tmpfiles.d/tmp.conf
Security checklist
| Check | Command | Why |
|---|---|---|
| Sticky bit present | ls -ld /tmp | Prevents accidental or malicious file deletion. |
| Correct ownership | stat -c "%U:%G %a %n" /tmp | Ensures only root can change permissions. |
No noexec unless needed | `mount | grep /tmp` |
tmpfs size limits | `cat /proc/mounts | grep /tmp` |
Common pitfalls
tmpfswithmode=755– Some distros set/tmpto755by default. This removes write permission for non‑root users, causing “Permission denied” for normal users. Always usemode=1777.systemd-tmpfilesoverride – If you have a custom/etc/tmpfiles.d/tmp.conf, make sure it isn’t overridden by a higher‑priority file.systemd-tmpfiles --testshows the effective configuration.- SELinux or AppArmor – On SELinux‑enabled systems, the context for
/tmpmust betmp_t. After changing permissions, runrestorecon -R /tmpto reapply the correct context.
Troubleshooting
Check mount options
mount | grep /tmpLook for
mode=ornoexec. Ifmodeis missing, add it to/etc/fstab.Verify systemd‑tmpfiles
systemd-tmpfiles --create --prefix /tmpIf the command fails, inspect
/var/log/messagesorjournalctl -u systemd-tmpfiles.Audit logs
journalctl -b | grep -i "permission denied"Look for specific services that fail to write to
/tmp. The error messages often point to the missing sticky bit.Reboot – After changing
/etc/fstabortmpfiles.d, a reboot guarantees the new settings are applied.
See also
- Free Your Root Partition by Moving /var/log to a tmpfs: A Step‑by‑Step Guide
- Fixing a Failed /boot Mount in Emergency Mode on Ubuntu 24.04 LTS After a Kernel Update
- Easily Run a Docker‑Compose‑Style Stack with Podman Rootless Containers in One Command
- How to Re‑run the Last Failed Command with Its Original Environment in Bash
- Recovering a Deleted /etc Directory on a VPS with Borg Snapshot Restore