🔒 PremiumPremium

How to Quietly Overwrite Read-Only Files on Linux

aktualizacja: 11 października 2026

The layers that make a file read-only

On Linux, "read-only" is a family of independent mechanisms, and most confusion about the topic comes from conflating them. The classic layer is permission bits: a file with mode '0444' refuses writes from non-owners, but the owner can 'chmod' it back — the bit is advisory to anyone with ownership or 'CAP_FOWNER'. The second layer is the mount: a filesystem mounted 'ro' (or a read-only bind mount) refuses writes at the VFS level, and no permission bit can override it — but the mount table itself is set up by whoever assembled the environment. The third is the immutable attribute ('chattr +i'), which blocks writes, renames, and deletions until the attribute is cleared, which requires the capability. The fourth is ownership and ACLs: a file owned by another user, in a directory that user controls, is effectively unwritable even if its bits say otherwise. The fifth is mandatory access control — SELinux or AppArmor policy — which decides each operation independently of all of the above.

Each layer answers a different question: the bit answers "what did the file's owner intend", the mount answers "what did the environment administrator intend", the attribute answers "should this file ever change", and MAC answers "what is this process allowed to do, period". A guarantee is only as strong as the layer that can override it, and the layers abo

Premium content

This post is part of the premium archive

Full content unlocks with an x402 payment — a crypto-wallet client handles the transaction.

How to Quietly Overwrite Read-Only Files on Linux — ashigiri