Fixing “Permission denied” on /tmp After a Kernel Update Removed the Sticky Bit

The sticky bit in a nutshell

The sticky bit (+t) on a directory means that only the file’s owner, the directory’s owner, or root can delete or rename files inside it. /tmp is traditionally set to 1777 (octal) – owner root, group root, permissions rwxrwxrwt. That lets any user create files, but stops them from messing with each other’s data.

What happened after the update

Some kernel releases changed the default mount options for tmpfs or how tmpfs‑based /tmp is handled. If /tmp is mounted as tmpfs without the sticky bit, the kernel quietly clears the +t flag. The directory stays world‑writable, but the protection that stops users from deleting each other’s files disappears. Applications that expect the sticky bit now refuse to write, because they see the directory as insecure.

Quick fix

# Verify the current mode
ls -ld /tmp
#  drwxrwxrwx 2 root root 4096 Sep 30 12:00 /tmp

# Re‑apply the sticky bit
chmod +t /tmp
#  drwxrwxrwt 2 root root 4096 Sep 30 12:00 /tmp

# Ensure ownership is correct
chown root:root /tmp

After this, most services that were blocked by the missing sticky bit will resume normal operation.

Making the change permanent

If the kernel update mounts /tmp with noexec or other options that strip the sticky bit, you’ll need to enforce it at mount time.

1. Edit /etc/fstab

tmpfs   /tmp    tmpfs   defaults,mode=1777 0 0

Adding mode=1777 forces the sticky bit and the correct permissions on every boot.

2. Use systemd-tmpfiles

Create /etc/tmpfiles.d/tmp.conf:

d /tmp 1777 root root

systemd-tmpfiles runs at boot and on demand, ensuring /tmp always has the right mode. This method is preferred on systems that use systemd, as it integrates with the init system and respects tmpfs mount options.

systemd-tmpfiles --create /etc/tmpfiles.d/tmp.conf

Security checklist

CheckCommandWhy
Sticky bit presentls -ld /tmpPrevents accidental or malicious file deletion.
Correct ownershipstat -c "%U:%G %a %n" /tmpEnsures only root can change permissions.
No noexec unless needed`mountgrep /tmp`
tmpfs size limits`cat /proc/mountsgrep /tmp`

Common pitfalls

  • tmpfs with mode=755 – Some distros set /tmp to 755 by default. This removes write permission for non‑root users, causing “Permission denied” for normal users. Always use mode=1777.
  • systemd-tmpfiles override – If you have a custom /etc/tmpfiles.d/tmp.conf, make sure it isn’t overridden by a higher‑priority file. systemd-tmpfiles --test shows the effective configuration.
  • SELinux or AppArmor – On SELinux‑enabled systems, the context for /tmp must be tmp_t. After changing permissions, run restorecon -R /tmp to reapply the correct context.

Troubleshooting

  1. Check mount options

    mount | grep /tmp
    

    Look for mode= or noexec. If mode is missing, add it to /etc/fstab.

  2. Verify systemd‑tmpfiles

    systemd-tmpfiles --create --prefix /tmp
    

    If the command fails, inspect /var/log/messages or journalctl -u systemd-tmpfiles.

  3. Audit logs

    journalctl -b | grep -i "permission denied"
    

    Look for specific services that fail to write to /tmp. The error messages often point to the missing sticky bit.

  4. Reboot – After changing /etc/fstab or tmpfiles.d, a reboot guarantees the new settings are applied.



See also