chmod 1777: world-writable with the sticky bit, the /tmp mode
Runs in your browser — nothing you paste leaves this page. How we prove that
chmod calculator playground
The matrix, octal and symbolic fields all stay in sync — edit any one and the others follow.
Results update as you type — press Enter to run now.
`chmod 1777 file` sets `rwxrwxrwt`: every account can create files in the directory, but the sticky bit means only the owner of an entry, the directory's owner or root can delete or rename it. It is the mode of `/tmp` and `/var/tmp`.
What chmod 1777 means
In 1777 the first digit is the special-bits digit (4 = setuid, 2 = setgid, 1 = sticky; the values add up to combine them), so 1 sets sticky. The next three digits are owner, group and others: the owner gets read, write and execute, the group gets read, write and execute, and others get read, write and execute.
On a directory such as /tmp, ls -ld prints drwxrwxrwt. The t in the last position is the sticky bit sitting on top of the others' execute bit; a capital T would mean sticky without execute, which is almost always a mistake.
Why /tmp needs the sticky bit
Normally, deleting or renaming a file is decided by write permission on the directory, not on the file. In a plain 777 directory any user could therefore remove or replace another user's temporary files, which breaks programs and opens the door to swapping a file another process is about to use. The sticky bit narrows that: in a sticky directory, unlinking or renaming an entry also requires owning the entry or the directory.
Linux adds further protections for these directories, such as the fs.protected_symlinks setting (enabled by default on most systemd distributions), which stops a process from following a symlink in a sticky world-writable directory unless it owns the link or the link's owner also owns the directory. They complement the sticky bit rather than replace it.
Creating your own shared scratch space
For a drop folder every user must write to, use chmod 1777 dir or chmod +t dir on an existing 777 directory, never a bare 777. If only one team should write there, a group-owned 1770 or 3770 directory is tighter still. On a regular file the sticky bit has no effect on Linux, so 1777 only makes sense on directories.
Pitfalls
The sticky bit stops deletion, not reading. Files created in /tmp get whatever mode the creating process chooses, so a program writing secrets there must create them as 600, ideally with mktemp to avoid guessable names. And a numeric chmod 777 on /tmp itself clears the sticky bit; if a system starts misbehaving after a careless recursive chmod, check that /tmp still shows a trailing t.
FAQ
Questions, answered.
Tap a question to expand the answer.
What is the difference between 777 and 1777?
The leading 1 is the sticky bit. Both let everyone create files, but in a 1777 directory only a file's owner, the directory owner or root can delete or rename it. In a plain 777 directory anyone can.
How do I restore the correct permissions on /tmp?
Run chmod 1777 /tmp as root and make sure it is owned by root. ls -ld /tmp should then end in a lowercase t.
More free, private DevOps tools.
The chmod Calculator is one tool in OpsCanopy — a growing canopy of browser-based validators, converters and testers that never touch a server.
More in Utilities
Read more about this
- chown command in Linux: change file owner and group The chown command in Linux explained: user:group syntax, chown -R and symlinks, --reference, chgrp, chmod vs chown, and fixing Docker volume permission errors with numeric IDs.
- chmod command in Linux: syntax, examples and common mistakes The chmod command in Linux explained: octal and symbolic modes, chmod +x, chmod -R and its traps, setuid, setgid and sticky bits, umask, and how to fix Permission denied.
42 free tools, every one offline-capable — opscanopy.com works with no signup and nothing uploaded.
Related utilities: the UUID / ULID Generator, the Case Converter and the Slugify tool — or browse the full tools directory.
Provided as-is for convenience; always double-check permission changes on production systems. OpsCanopy is free and open.