whatis acl

Access Control List (ACL)

Also known as: ACL, POSIX ACL, getfacl, setfacl

Extended permissions that grant specific users or groups access to a file beyond the basic owner, group, and other bits.

What Is an Access Control List (ACL) in Linux?

Standard permissions only allow one owning group. ACLs let you say "user bob can also read this" or "group auditors gets read-only" without changing ownership. A + at the end of ls -l permissions means an ACL is present.

Default ACLs on a directory are inherited by new files created inside it, which solves many shared-folder permission headaches.

Example

setfacl -m u:bob:rX /srv/reports
getfacl /srv/reports