⇠ chan.dev / posts

Jellyfin Media Server Permissions on Arch Linux

🌱 This post is in the growth phase. It may still be useful as it grows up.

AI-generated note: this setup summary was generated by Google Gemini from my Jellyfin server setup.

Setting Up Jellyfin Media Server on Arch Linux with Proper Folder Permissions

A guide to installing Jellyfin on Arch Linux, or Arch-based distros like Omarchy, and configuring storage directories in /mnt so desktop file managers can drag and drop media files without “Permission Denied” blocks or Wayland security barriers.

1. Install and Start Jellyfin

Install the official server and web client packages from the Arch extra repositories, then enable the background service:

sudo pacman -Syu jellyfin-server jellyfin-web
sudo systemctl enable --now jellyfin

The server dashboard is now accessible at http://<your-server-ip>:8096.

2. Configure the Storage Gateway

By default, the jellyfin system user has no rights to view host paths. Open the top-level /mnt gateway so system processes can look inside it:

sudo chmod 755 /mnt

3. Fix Media Directory Permissions

If media directories, like movies and shows, inside /mnt/media are owned by root, desktop users and Jellyfin are locked out.

To fix this permanently, hand ownership over to the jellyfin group, add the missing group write permissions, and enable the SetGID bit. SetGID forces new folders and files dropped into the directory to inherit Jellyfin’s group permissions.

# 1. Take ownership away from root and assign it to jellyfin
sudo chown -R jellyfin:jellyfin /mnt/media/
# 2. Force folders to 2775 permissions (group write + SetGID)
sudo find /mnt/media/ -type d -exec chmod 2775 {} +
# 3. Force existing video files to 664 permissions
sudo find /mnt/media/ -type f -exec chmod 664 {} +

4. Grant Your Local User Access

To manage files, drag and drop, or copy movies into /mnt/media/ via a desktop file manager without using sudo, add your personal username to the jellyfin system group:

sudo usermod -aG jellyfin $USER

Log out of the desktop session and log back in for the group assignment to take effect.

5. Bypass Wayland Drag-and-Drop Limitations

Because Omarchy and Hyprland use Wayland, mouse-dragging files across different user permission tiers, like moving files from an external USB drive into a system directory, can trigger security blocks.

Use keyboard shortcuts instead of the mouse:

  1. Select files on the external drive.
  2. Hit Ctrl + C, or Super + C.
  3. Open the target directory.
  4. Hit Ctrl + V, or Super + V.

Because of the SetGID configuration, files pasted this way should inherit the correct Jellyfin group.

6. Refresh the Server

Once media files are copied over, map the target libraries inside the Jellyfin Web UI:

  1. Navigate to Dashboard -> Libraries.
  2. Add your paths, for example /mnt/media/movies and /mnt/media/shows.
  3. Click the three dots on the library card and select Scan Library to force a metadata and poster refresh.