The Sticky Bit Explained
The sticky bit solves a specific, narrow problem: how do you have a directory that everyone can write to, without letting everyone delete each other’s files inside it? Without it, standard Unix permissions cannot express that distinction at all.
The problem it solves
ls -ld /tmp
# drwxrwxrwt 12 root root 4096 Jul 9 09:00 /tmp
/tmp needs to be writable by every user and process on the system, since anyone might need to create a temporary file there. But under ordinary Unix permission rules, if a directory is writable by everyone, any user with write access to that directory can also delete or rename any file inside it, regardless of who actually created that file, because deletion is governed by permission on the containing directory, not by the file’s own ownership.
Without some additional mechanism, a world-writable /tmp would mean any user could delete or tamper with any other user’s temporary files. This is precisely the gap the sticky bit closes.
What the sticky bit actually does
ls -ld /tmp
# drwxrwxrwt
# └── the sticky bit, shown as 't' in the final position
On a directory with the sticky bit set, deleting or renaming a file inside it is only allowed for:
- the file’s own owner
- the directory’s owner
- the root user
Everyone else retains their normal write access to the directory (they can still create new files), but they lose the ability to delete or rename files they did not create themselves, even though the directory’s regular permission bits would otherwise allow it.
Setting and removing the sticky bit
chmod +t shared_uploads/
ls -ld shared_uploads/
# drwxrwxrwt ... shared_uploads/
chmod -t shared_uploads/
ls -ld shared_uploads/
# drwxrwxrwx ... shared_uploads/ (sticky bit removed, t is gone)
Symbolic mode with +t and -t is the most direct way to toggle it. In numeric mode, the sticky bit is represented as a leading fourth digit:
chmod 1777 shared_uploads/
# equivalent to: rwxrwxrwx PLUS the sticky bit
# the leading 1 specifically represents the sticky bit
The standard three-digit numeric mode you would normally use for chmod 755 becomes four digits when a special bit like sticky is involved, with the special bit represented by that leading digit: 1 for sticky, and (covered in other special-permission articles) 2 for SGID and 4 for SUID.
Reading t vs T in ls -l output
ls -ld dir_with_execute
# drwxrwxrwt ... (lowercase t: sticky bit set, AND execute is present for others)
ls -ld dir_without_execute
# drwxrwxrwT ... (uppercase T: sticky bit set, but execute is NOT present for others)
The case of the final character carries extra information: lowercase t means the sticky bit is set and execute permission for “others” is also present (the normal, expected combination for a directory). Uppercase T means the sticky bit is set but execute permission for others is missing, an unusual combination since it would mean others cannot even enter the directory in the first place, making the sticky bit’s deletion restriction somewhat moot for them.
Where else the sticky bit shows up
ls -ld /var/tmp
# drwxrwxrwt ... /var/tmp
ls -ld /tmp
# drwxrwxrwt ... /tmp
/tmp and /var/tmp are the two most common default examples on virtually every Linux distribution, for exactly the reason described above: both are meant to be world-writable scratch directories, and both need protection against users deleting each other’s temporary files.
The same pattern is worth applying manually to any custom shared directory you create where multiple users need write access but should not be able to delete each other’s files:
sudo mkdir /srv/shared-drop
sudo chmod 1777 /srv/shared-drop
Why it is called the “sticky” bit at all
The name is a historical artifact. On very old Unix systems, this same permission bit had a completely different purpose: it told the kernel to keep a program’s executable image “stuck” in swap space after it exited, speeding up the next time that same program launched. Modern Linux does not use this original behavior at all; the bit was repurposed entirely for its current, unrelated deletion-restriction meaning on directories. The formal POSIX name, “restricted deletion flag,” describes its actual modern function far more directly, but “sticky bit” remains the name almost everyone uses in practice.
Frequently Asked Questions
What is the sticky bit in Linux?
The sticky bit is a special permission that can be set on a directory to restrict file deletion within it. In a directory with the sticky bit set, a user can only delete or rename a file if they are the file’s owner, the directory’s owner, or root, even if the directory itself is writable by everyone. Without the sticky bit, standard Unix permissions would let anyone with write access to the directory delete any file inside it, regardless of who created that specific file.
Where is the sticky bit commonly used by default?
/tmp is the most common example. It is world-writable, since any user or process needs to be able to create temporary files there, but it also has the sticky bit set, so that one user cannot delete or tamper with another user’s temporary files even though everyone shares write access to the same directory. Check it yourself with ls -ld /tmp, which shows a t at the end of the permission string.
How do I set or remove the sticky bit on a directory?
Use chmod +t directoryname to add the sticky bit, or chmod -t directoryname to remove it. In numeric mode, the sticky bit is represented by a leading fourth digit of 1, so chmod 1777 sets full rwx for everyone plus the sticky bit, equivalent to chmod 777 followed by chmod +t.
How can I tell if a directory has the sticky bit set just by looking at ls -l output?
The final character of the permission string will be a lowercase t if the sticky bit is set and execute permission for others is also present, or an uppercase T if the sticky bit is set but execute permission for others is not present. A directory without the sticky bit shows a regular x or - in that final position instead.
Does the sticky bit affect anything other than deletion?
No, the sticky bit specifically and only affects the ability to delete or rename files within the directory it is set on. It does not restrict reading, writing to the contents of an existing file you already have access to, or creating new files, all of which are still governed entirely by the normal rwx permission bits on the directory and the individual files themselves.
Why is the sticky bit sometimes called a “restricted deletion flag”?
This is its formal, more descriptive name in POSIX documentation, since “sticky bit” is a historical name inherited from an older, unrelated original use case on early Unix systems (where it affected how program executables were cached in memory, a behavior modern Linux no longer uses at all). The name stuck even though its actual modern function on Linux, restricting who can delete files in a shared directory, is what “restricted deletion flag” describes directly.