Stop fighting over complex permission sets with setfacl

Permissions & Security (Chmod/Chown/ACLs/SELinux/AppArmor)

Stop fighting over complex permission sets with setfacl

🧩 The Challenge

You’ve got a web app that needs read-write access to a directory, but you don’t want to blow up security by just doing a chmod 777. Nobody wants to deal with groups for every single shared folder.

💡 The Fix

Use Access Control Lists instead of messing with standard Unix permissions. It lets you grant specific access to a single user or group without needing to overhaul your entire directory ownership structure.

setfacl -R -m u:www-data:rwX /path/to/shared/storage
getfacl /path/to/shared/storage

⚙️ Why It Works

Adding an ACL entry modifies the filesystem metadata to include fine-grained access rules that the standard user-group-other triplet simply can’t represent. It stays stuck to those files even if you move them around within the same partition, which saves you from chasing ghosts later.

🚀 Pro-Tip: Toss the -d flag in there to set default ACLs, so any new files created in that directory automatically inherit the same permissions.

Linux Tips & Tricks | © ngelinux.com | 9/8/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted