Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Stop Users From Deleting Important Files on a DirectAdmin Server

You can lock a file so nobody can delete, rename or change it, even the file owner. This guide shows how with the immutable flag. You need root access.

DirectAdmin2 min read7 steps

What is the immutable flag?

Normal file permissions say who can read or write a file. But the owner of a file can still delete it. The immutable flag is a stronger lock. When it is on, no one can delete, rename or edit the file. Not even the root user can, until the flag is removed. It is like putting an item in a glass case.

The command is chattr, which means "change attribute". It works on Linux file systems such as ext4 and XFS.

Warning

A locked file cannot be updated. If an app needs to write to that file, it will stop working. Do not lock log files, cache files or anything that changes. Back up the file first.

Steps to lock a file

  1. Log in to your server over SSH as root.
  2. Check the file exists.
ls -l /home/username/domains/example.com/public_html/index.php

Replace the path with your real file. This shows the file and its owner.

  1. Lock the file.
chattr +i /home/username/domains/example.com/public_html/index.php

The +i adds the immutable flag.

  1. Check the flag is set.
lsattr /home/username/domains/example.com/public_html/index.php

You should see an i in the first column.

  1. Try to delete the file as the user, or from the DirectAdmin File Manager. It should say the operation is not permitted.

Lock a whole folder

Use chattr -R +i foldername. The -R makes it work on everything inside. The folder then cannot get new files either.

Steps to unlock

  1. Log in as root.
  2. Run the command below.
chattr -i /home/username/domains/example.com/public_html/index.php

The -i removes the lock. You can now edit or delete the file.

Tip: Backups are still the best safety net. A locked file protects against deleting, not against a hacked server.

Quick recap

  • Use chattr +i to lock a file so it cannot be deleted or changed.
  • Use lsattr to see the lock and chattr -i to remove it.
  • Do not lock files that apps need to write to.
  • Only root can set or remove the flag.