.\" Access Control Lists manual pages .\" .\" (C) 2002-2026 Andreas Gruenbacher .\" .\" This is free documentation; you can redistribute it and/or .\" modify it under the terms of the GNU General Public License as .\" published by the Free Software Foundation; either version 2 of .\" the License, or (at your option) any later version. .\" .\" The GNU General Public License's references to "object code" .\" and "executables" are to be interpreted as the output of any .\" document formatting or typesetting system, including .\" intermediate and printed output. .\" .\" This manual is distributed in the hope that it will be useful, .\" but WITHOUT ANY WARRANTY; without even the implied warranty of .\" MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the .\" GNU General Public License for more details. .\" .\" You should have received a copy of the GNU General Public .\" License along with this manual. If not, see .\" . .\" .Dd June 5, 2026 .Dt ACL_EXTENDED_FILE 3 .Os "Linux ACL" .Sh NAME .Nm acl_extended_file , .Nm acl_extended_file_at , .Nm acl_extended_file_nofollow .Nd test for information in ACLs by file name .Sh LIBRARY Linux Access Control Lists library (libacl, \-lacl). .Sh SYNOPSIS .In sys/types.h .In acl/libacl.h .Ft int .Fo acl_extended_file .Fa "const char *path_p" .Fc .Ft int .Fo acl_extended_file_at .Fa "int dirfd" .Fa "const char *path_p" .Fa "int at_flags" .Fc .Ft int .Fo acl_extended_file_nofollow .Fa "const char *path_p" .Fc .Sh DESCRIPTION The .Fn acl_extended_file function returns .Li 1 if the file or directory whose pathname is given in .Va path_p is associated with an extended access ACL, or if the directory referred to by .Va path_p is associated with a default ACL. The function returns .Li 0 if the file has neither an extended access ACL nor a default ACL. If .Va path_p is a symbolic link, .Fn acl_extended_file returns information about the file or directory the link refers to. .Pp An extended ACL is an ACL that contains entries other than the three required entries of tag types ACL_USER_OBJ, ACL_GROUP_OBJ and ACL_OTHER. If the result of the .Fn acl_extended_file function for a file object is .Li 0 , then ACLs define no discretionary access rights other than those already defined by the traditional file permission bits. .Pp Access to the file object may be further restricted by other mechanisms, such as Mandatory Access Control schemes. The .Xr access 2 system call can be used to check whether a given type of access to a file object would be granted. .Ss Fn acl_extended_file_at The .Fn acl_extended_file_at function operates in exactly the same way as .Fn acl_extended_file , except for the differences described here. .Pp If the pathname given in .Va path_p is relative, then it is interpreted relative to the directory referred to by the file descriptor .Va dirfd (rather than relative to the current working directory of the calling process, as is done by .Fn acl_extended_file ) . .Pp If .Va path_p is relative and .Va dirfd is the special value .Dv AT_FDCWD , then .Va path_p is interpreted relative to the current working directory of the calling process (like .Fn acl_extended_file ) . .Pp If .Va path_p is absolute, then .Va dirfd is ignored. .Pp The .Va at_flags argument can either be 0, or include one or more of the following flags ORed: .Bl -tag .It Dv AT_EMPTY_PATH If .Va path_p is an empty string, operate on the file referred to by .Va dirfd (which may have been obtained using the .Xr open 2 .Dv O_PATH flag). In this case, .Va dirfd can refer to any type of file, not just a directory. .It Dv AT_SYMLINK_NOFOLLOW If .Va path_p refers to a symbolic link, do not dereference it: instead, fail the operation and set the global variable .Va errno to .Er ENOTSUP . This indicates that the symbolic link cannot have ACLs. .El .Ss Fn acl_extended_nofollow The .Fn acl_extended_file_at function operates in exactly the same way as .Fn acl_extended_file with a .Va dirfd value of .Dv AT_FDCWD and an .Va at_flags value of .Dv AT_SYMLINK_NOFOLLOW . .Sh RETURN VALUE If successful, these functions return .Li 1 if the file object referred to by .Va path_p has an extended access ACL or a default ACL, and .Li 0 if the file object referred to by .Va path_p has neither an extended access ACL nor a default ACL. Otherwise, the value .Li -1 is returned and the global variable .Va errno is set to indicate the error. .Sh ERRORS If any of the following conditions occur, these functions return .Li -1 and set .Va errno to the corresponding value: .Bl -tag -width Er .It Bq Er EACCES Search permission is denied for a component of the path prefix. .It Bq Er EBADF The argument .Va path_p is relative but the argument .Va dirfd is neither .Dv AT_FDCWD nor a valid file descriptor. .It Bq Er EINVAL An invalid flag was specified in the .Va at_flags argument. .It Bq Er ENAMETOOLONG The length of the argument .Va path_p is too long. .It Bq Er ENOENT The named object does not exist or the argument .Va path_p points to an empty string. .It Bq Er ENOTDIR A component of the path prefix is not a directory. .Pp The argument .Va path_p is relative and the argument .Va dirfd is a file descriptor referring to a file other than a directory. .It Bq Er ENOTSUP The argument .Va at_flags includes the flag .Dv AT_SYMLINK_NOFOLLOW and .Va path_p is a symbolic link. .Pp The file system on which the file identified by .Va path_p is located does not support ACLs, or ACLs are disabled. .El .Sh STANDARDS This is a non-portable, Linux specific extension to the ACL manipulation functions defined in IEEE Std 1003.1e draft 17 (\(lqPOSIX.1e\(rq, abandoned). .Sh SEE ALSO .Xr access 2 , .Xr acl_get_file 3 , .Xr acl 5 .Sh AUTHOR Written by .An "Andreas Gruenbacher" Aq andreas.gruenbacher@gmail.com .