Site icon New Generation Enterprise Linux

Stop letting stray ACLs hide inside your file permissions

Permissions & Security (Chmod/Chown/ACLs/SELinux/AppArmor)

Stop letting stray ACLs hide inside your file permissions

đź§© The Challenge

You ever run an ls -l and see a little plus sign at the end of the permissions string, only to realize your chmod commands are doing absolutely nothing to stop unauthorized access? I’ve spent way too long debugging “but I set the permissions to 644!” just to find a hidden ACL acting as a back door.

đź’ˇ The Fix

Use getfacl to actually see what’s going on under the surface, then wipe the extra noise away with setfacl so standard unix permissions can finally do their job again.

getfacl filename
setfacl -b filename

⚙️ Why It Works

That trailing plus sign indicates an Access Control List is active, which overrides the traditional mode bits you see in your standard directory listings. By running the remove-all flag, you strip out those invisible overrides and force the system back to the basic owner/group/world model you’re actually expecting.

🚀 Pro-Tip: Check directories recursively with -R if you suspect a rogue ACL is propagating through your app deployment folders.

Linux Tips & Tricks | © ngelinux.com | 10/8/2026

0 0 votes
Article Rating
Exit mobile version