chattr Command in Linux: Change File Attributes

By 

•

Updated on

•

8 min read

Linux chattr Command

Many Linux filesystems support special file attributes that control how the kernel and system tools handle a file. You can mark a file as immutable so it cannot be changed or removed by mistake, or set a log file to append-only so new entries can be added without allowing old ones to be overwritten. These attributes work separately from standard permission bits , and support depends on the filesystem.

The chattr command sets or removes supported attributes, and its companion lsattr displays them. This guide explains the most useful flags with practical examples.

chattr Syntax

The chattr command takes the following general form:

txt
chattr [OPTIONS] [OPERATOR][ATTRIBUTES] FILE...

The [OPERATOR] is one of three symbols:

  • + - Add the specified attributes to the existing ones.
  • - - Remove the specified attributes from the existing ones.
  • = - Set the specified attributes as the only attributes, replacing all others.

The operator is followed by one or more [ATTRIBUTES] flags. The most useful flags are:

  • i - Immutable. The file cannot be modified, deleted, renamed, or linked to. Only root or a process with the required capability can set or clear this flag.
  • a - Append only. The file can only be opened in append mode for writing. Existing content cannot be overwritten or truncated. Only root or a process with the required capability can set or clear this flag.
  • A - No atime updates. The kernel will not update the access time (atime) when the file is read.
  • d - No dump. The file is skipped by the dump backup program.
  • e - Extents. The file uses extents for mapping blocks on disk. ext4 sets this flag by default, and you should not change it with chattr.
  • s - Secure deletion. This flag is documented by chattr, but current ext2, ext3, and ext4 kernels do not honor it.
  • S - Synchronous updates. Changes to the file are written to disk immediately.
  • j - Data journaling. File data is written to the ext3 or ext4 journal before being written to the file itself.
  • u - Undeletable. This flag is documented by chattr, but current ext2, ext3, and ext4 kernels do not honor it.

For the full list, run man chattr.

The most commonly used option is:

  • -R - Apply attribute changes recursively to directories and their contents.

Viewing Attributes with lsattr

Before changing attributes, you need to see what is already set. The lsattr command shows the current attribute flags for one or more files:

Terminal
lsattr todo.txt
output
--------------e------- todo.txt

Each position in the output corresponds to an attribute flag. In this case only the e (extents) flag is set, which is the default on ext4 filesystems.

If you prefer descriptive names instead of single-letter flags, use -l:

Terminal
lsattr -l todo.txt
output
todo.txt                     Extents

You can also pass a directory to lsattr to see the attributes of every file inside it. This is helpful when auditing a configuration directory like /etc/:

Terminal
lsattr /etc/

When you run it as a regular user, lsattr prints an error for every file it cannot read:

output
lsattr: Permission denied While reading flags on /etc/gshadow-
lsattr: Operation not supported While reading flags on /etc/os-release

The Permission denied lines come from protected files such as /etc/gshadow-. Run the command with sudo to read them. The Operation not supported lines come from symbolic links, and you can ignore them.

By default this skips hidden files. Add -a to include dot files in the listing:

Terminal
lsattr -a /etc/

If you want to see the attributes of the directory itself rather than its contents, use -d:

Terminal
lsattr -d /etc/

For a full recursive listing of a directory tree, use -R:

Terminal
lsattr -R /etc/

By default, file attributes are not preserved when copying a file with commands like cp or rsync .

Making a File Immutable

One of the most common uses of chattr is making a file immutable so it cannot be modified, deleted, or renamed.

Create a test file and set the immutable flag with +i:

Terminal
touch ~/demo.txt
sudo chattr +i ~/demo.txt

We use sudo because changing the immutable flag requires elevated privileges.

Verify the change:

Terminal
lsattr ~/demo.txt
output
----i---------e------- /home/user/demo.txt

The i flag now appears in the output. If you try to remove the file, the operation will fail:

Terminal
rm ~/demo.txt
output
rm: cannot remove '/home/user/demo.txt': Operation not permitted

The flag applies to root as well. Running sudo rm ~/demo.txt fails with the same error.

To remove the immutable flag when you need to edit or delete the file again:

Terminal
sudo chattr -i ~/demo.txt

After clearing the flag, you can modify or remove the file normally.

Setting Append-Only Mode

The a (append-only) attribute is useful for log files. It allows new data to be appended but prevents existing content from being overwritten or truncated.

Create a test file in your home directory and enable append-only mode:

Terminal
touch ~/app.log
sudo chattr +a ~/app.log

After setting this flag, you can still append to the file with the >> operator:

Terminal
echo "new entry" >> ~/app.log

But attempting to overwrite it with > will fail:

Terminal
echo "overwrite" > ~/app.log
output
bash: /home/user/app.log: Operation not permitted

The shell cannot truncate the file, and the new entry line stays in place.

This restriction applies to new write attempts. As the chattr manual notes, existing open file descriptors are not affected retroactively.

The a flag also works on directories. In an append-only directory, you can create new files, but you cannot delete them.

To remove the append-only flag:

Terminal
sudo chattr -a ~/app.log

Combining Multiple Attributes

You can set or remove multiple attributes in a single command. For example, to make a file immutable and disable atime updates:

Terminal
sudo chattr +iA todo.txt

Verify:

Terminal
lsattr todo.txt
output
----i--A------e------- todo.txt

To remove both at once:

Terminal
sudo chattr -iA todo.txt

Using the = Operator

The = operator replaces the current user-settable attributes with exactly the ones you specify. For example, on an empty ext4 test file named todo.txt, the following command leaves only the A flag set:

Terminal
sudo chattr =A todo.txt

This clears other changeable flags such as i or a and keeps A. Check the result with lsattr:

Terminal
lsattr todo.txt
output
-------A-------------- todo.txt

In this empty-file example, the e flag is cleared too. Ext4 can only convert certain simple block layouts away from extents, so =A may fail with Operation not supported on larger or more complex files. For everyday changes, use + and - to preserve unrelated attributes.

Applying Attributes Recursively

The -R flag applies attribute changes to a directory and everything inside it. Start with a test directory before you use it on system paths:

Terminal
mkdir -p ~/demo-config/subdir
touch ~/demo-config/app.conf ~/demo-config/subdir/site.conf
sudo chattr -R +i ~/demo-config/

Every file and subdirectory under ~/demo-config/ is now immutable. The directories are locked too, and you cannot create new files inside them:

Terminal
touch ~/demo-config/new.conf
output
touch: cannot touch '/home/user/demo-config/new.conf': Permission denied

To reverse it:

Terminal
sudo chattr -R -i ~/demo-config/
Warning
Be careful with recursive immutable flags. If you apply them to a system directory such as /etc/nginx/, package managers and configuration tools will fail to update files there. Remove the flag before running updates.

Quick Reference

TaskCommand
View attributeslsattr file
View attributes recursivelylsattr -R /path/
Make file immutablesudo chattr +i file
Remove immutable flagsudo chattr -i file
Set append-onlysudo chattr +a file
Remove append-onlysudo chattr -a file
Disable atime updatessudo chattr +A file
Skip dump backupssudo chattr +d file
Apply recursivelysudo chattr -R +i /dir/
Set exact attributessudo chattr =A file

Troubleshooting

“Operation not permitted” when setting attributes
Only root can set the i and a flags. Run the command with sudo.

“Operation not supported while reading flags”
The path may be a symbolic link or a special file, or the filesystem may not support these attributes. Pseudo-filesystems such as /proc are one example. Check that the path points to a regular file or directory, then check the filesystem type with df -T /path/to/file.

“Permission denied” when writing to a file in /tmp with sudo
Most modern distributions enable fs.protected_regular, which can block even root from opening another user’s existing regular file with O_CREAT in a shared sticky directory such as /tmp. Commands such as tee and shell output redirects use this flag even when the file already exists. This restriction does not block every write to the file, and it is separate from chattr attributes. Test with a file in your home directory, or run the command as the file owner.

Cannot delete or modify a file, even with sudo
Someone may have set the immutable flag. Check with lsattr file and look for the i flag. Remove it with sudo chattr -i file.

Package updates fail with “Operation not permitted”
If you applied chattr +i recursively to a system directory like /etc/, package managers will not be able to update configuration files. Remove the flag with sudo chattr -R -i /etc/directory/ before running updates.

Conclusion

The chattr and lsattr commands give you filesystem-level control over how files can be modified, deleted, or backed up. For related file permission management, see the chmod and chown guides.

Linuxize Weekly Newsletter

A quick weekly roundup of new tutorials, news, and tips.

About the authors

Dejan Panovski

Dejan Panovski

Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.

View author page