SSH, Security & Permissions

An ACL mask restricts access despite an explicit grant

A named ACL entry can show write permission while its mask removes effective write access. Inspect effective rights and parent traversal.

On this page
  1. Symptoms & scope
  2. Possible causes
  3. Diagnose safely
  4. Evidence-guided next steps
  5. References & review
  6. Related problems

Symptoms & scope

  • A shared file denies access to a specifically granted user.
  • getfacl shows an effective permission narrower than the entry.

Relevant environment

Linux filesystem with POSIX ACL support; getfacl and namei must be installed. Replace the example file path.

Possible causes

These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.

  • The ACL mask may cap named-user and group-class permissions.
  • A parent directory may lack search permission even when the file ACL is correct.

Diagnose safely

Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.

Check 1

Replace the absolute path; reads named entries, mask and effective-right comments.

getfacl -p /path/to/shared-file

Interpret the result: An entry like user:example:rw- with effective:r-- identifies the mask as a limiter. The owning user is not limited by this mask.

Check 2

Shows mode and owner of each parent directory without modifying access.

namei -l /path/to/shared-file

Interpret the result: The affected account needs directory search permission along the whole path; if extended ACLs are present, inspect those parents with getfacl too.

Evidence-guided next steps

Adjust the mask after reviewing every affected entry

If the mask is the confirmed restriction, save getfacl -p output and set a mask sufficient for the intended access on that one file with setfacl. Review all named-user and group entries because widening the mask can activate their previously hidden permissions.

Precautions: Do not use chmod 777 or recursive ACL removal. Preserve shared-directory defaults separately from access ACLs.

Recovery / rollback: Restore the saved ACL with setfacl --restore=/path/to/acl-backup using the authorized file owner or administrator.

Did this solution help you?

Share this solution#

References & review

This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.