You changed one permission with chacl and quietly wiped every other ACL entry on the file, because it replaces the list rather than adding to it. This guide gives you a safe routine: inspect an ACL, replace it, set a directory default ACL, and undo a test change.
The examples use chacl from the Debian acl package, version 2.3.2-1build1.1 on the machine used for this guide. Allow about fifteen minutes. You need a shell, a file or directory you are allowed to change, and the acl package.
sudo only when you do not own the target or its ACL cannot be read.chacl is an IRIX-compatibility command. Its list option, -l, is a Linux addition. It prints the access ACL, followed by a slash and the default ACL when a directory has one:
$ chacl -l /srv/example/report.txt
/srv/example/report.txt [u::rw-,g::r--,o::r--]
$ chacl -l /srv/example/incoming
/srv/example/incoming [u::rwx,g::r-x,o::---/u::rwx,g::r-x,o::---]
The entries mean owner, owning group and everyone else. Each permission string is read, write and execute in that order. A blank name, as in u::, refers to the file owner, and g:: refers to the owning group. The slash separates a directory's access ACL from its default ACL.
Checkpoint: Save the output before changing anything. chacl replaces the existing ACL when you set one. It does not merge a new entry into the current list.
A minimum ACL has owner, group and other entries. This command gives the owner read and write access, the group read access, and nobody else access:
$ chacl u::rw-,g::r--,o::--- /srv/example/report.txt
$ chacl -l /srv/example/report.txt
/srv/example/report.txt [u::rw-,g::r--,o::---]
Run this as the file owner or with the privilege needed to change the file. The command prints no success message, so the second command is your verification. For a directory, include x where users must traverse it, for example u::rwx,g::r-x,o::---.
Recovery: Undo with another complete ACL, not a guessed single-entry edit. If your saved listing was u::rw-,g::r--,o::r--, restore it with the command below.
$ chacl u::rw-,g::r--,o::r-- /srv/example/report.txt
To grant user alice read access while keeping the owner and group entries, specify the whole replacement ACL and add a mask:
$ chacl u::rw-,g::r--,o::---,u:alice:r--,m::r-- /srv/example/report.txt
$ chacl -l /srv/example/report.txt
/srv/example/report.txt [u::rw-,g::r--,o::---,u:alice:r--,m::r--]
The mask is required for an ACL that names an additional user or group. It limits the effective permissions of named users, named groups and the owning group. So u:alice:rwx,m::r-- still gives Alice at most read access.
Names are resolved by the ACL library when the text is parsed. Check that the account or group is the one you intend, and keep the original -l output so you can reconstruct the prior state. A partial list will not append: it replaces the access ACL.
A default ACL belongs to a directory and is inherited by new entries created underneath it. Set the directory's access and default ACL to the same values with -b:
$ chacl -b u::rwx,g::r-x,o::--- u::rwx,g::r-x,o::--- /srv/example/incoming
$ chacl -l /srv/example/incoming
/srv/example/incoming [u::rwx,g::r-x,o::---/u::rwx,g::r-x,o::---]
Use -d when you want to set only the default ACL. It applies to a directory, not to an ordinary file. A default ACL affects the creation of future children and does not retroactively change existing files.
Creating a child is a useful check:
$ touch /srv/example/incoming/check.txt
$ chacl -l /srv/example/incoming/check.txt
/srv/example/incoming/check.txt [u::rw-,g::r--,o::---]
The file creation mode supplied by the creating program can also shape the inherited result. Verify the actual child instead of inferring its ACL from the parent.
The lowercase -r sets the access ACL recursively for each subtree rooted at the supplied path:
$ chacl -r u::rw-,g::r--,o::--- /srv/example/staging
$ chacl -l /srv/example/staging/item.txt
Warning: This is a broad change. It replaces the access ACL on every reachable item and can fail part-way through when a directory cannot be traversed or a file cannot be read. It does not set default ACLs. Capture a listing and test on a disposable copy before using it on a shared tree. If it was too broad, restore each item from the saved ACLs or from a known-good backup, because there is no single automatic undo command.
Do not confuse -r with the uppercase options:
-R removes the file access ACL only.-D removes a directory default ACL only.-B removes all ACLs.Warning: These are destructive permission changes. Save chacl -l output first and verify the path before pressing Enter.
Changing ordinary mode bits with chmod also changes the file access ACL settings, so check the ACL again after a mode change. A directory default ACL is different from the process umask: the manpage specifically warns that umask does not affect access ACL settings of files created using directory default ACLs.
ACLs are filesystem extended attributes, and conventional archive tools do not typically preserve them. If these permissions matter during backup or migration, choose an ACL-aware backup process and test restoration. On XFS, the local documentation points to xfsdump for ACL-aware backup work.
For a new script or a POSIX-style ACL workflow, compare getfacl and setfacl before standardising on this IRIX-compatible interface. The installed manpage describes chacl as maintained for users familiar with XFS or IRIX, and identifies those tools as closer to the withdrawn POSIX 1003.1e draft.
chacl -l and recorded the original ACL.