Symptoms & scope
- A shared file denies access to a specifically granted user.
- getfacl shows an effective permission narrower than the entry.
Relevant environment
Linux filesystem with POSIX ACL support; getfacl and namei must be installed. Replace the example file path.
Possible causes
These are possible explanations, not a confirmed diagnosis. Several independent faults can coexist.
- The ACL mask may cap named-user and group-class permissions.
- A parent directory may lack search permission even when the file ACL is correct.
Diagnose safely
Run one command at a time in the relevant session. Read the explanation first. Uppercase placeholders need your own values; tools and privileges vary by distribution. These commands are displayed here and never executed by the website.
Check 1
Replace the absolute path; reads named entries, mask and effective-right comments.
getfacl -p /path/to/shared-fileInterpret the result: An entry like user:example:rw- with effective:r-- identifies the mask as a limiter. The owning user is not limited by this mask.
Check 2
Shows mode and owner of each parent directory without modifying access.
namei -l /path/to/shared-fileInterpret the result: The affected account needs directory search permission along the whole path; if extended ACLs are present, inspect those parents with getfacl too.
Evidence-guided next steps
Adjust the mask after reviewing every affected entry
If the mask is the confirmed restriction, save getfacl -p output and set a mask sufficient for the intended access on that one file with setfacl. Review all named-user and group entries because widening the mask can activate their previously hidden permissions.
Precautions: Do not use chmod 777 or recursive ACL removal. Preserve shared-directory defaults separately from access ACLs.
Recovery / rollback: Restore the saved ACL with setfacl --restore=/path/to/acl-backup using the authorized file owner or administrator.
Did this solution help you?
Grant only required search access on the blocking parent
If the file ACL is correct but a parent blocks traversal, the owner can add a narrowly targeted search ACL for the intended account on that parent. Add directory read access only if listing filenames is also required. Record existing ACLs first.
Precautions: Check the parent’s mask too; granting search access can expose reachable files further down the path.
Recovery / rollback: Restore the saved parent ACL or remove only the newly added named-user entry.
Did this solution help you?
References & review
This guide was prepared from primary project or distribution sources and reviewed on the date shown. This is an editorial source check, not evidence that a fix was reproduced on your hardware. Diagnostic log examples are synthetic fixtures. Version-dependent details must be checked against your installed release.
- ACL getfacl: effective rights and mask (project or distribution documentation)
- ACL setfacl: mask calculation and restoring ACLs (project or distribution documentation)