Linux ACLs and Extended Attributes: Finer Permission Control
Standard permissions are too coarse when one user needs access without changing ownership. ACLs and xattrs solve that, and the syntax is less scary than it looks. Standard Linux permissions give you owner, group, and others, each with read, write, and execute. That model covers most cases, but it breaks down when you need to grant a specific user access without changing ownership or widening group permissions. Access Control Lists, or ACLs, solve this, and extended attributes add metadata that the standard permission model cannot express. After years of avoiding them because the syntax felt obscure, I now reach for ACLs whenever the standard model is too coarse. When Standard Permissions Are Not Enough Suppose a log file owned by root and group adm needs to be readable by a monitoring user that is not in the adm group. With standard permissions, your options are to add the user to adm, change the group, or make the file world-readable. All three are wrong: they grant more access than needed. An ACL lets you grant read access to that one user without touching anything else. Reading and Setting ACLs The getfacl command shows the ACL on a file,…