Removing a specific permission by using an ACL mask
You can remove an ACL from a file or directory with the -x
option. Let’s go back to the acl_demo.txt
file that I created earlier, and remove the ACL for Maggie:
[donnie@localhost ~]$ setfacl -x u:maggie acl_demo.txt
[donnie@localhost ~]$ getfacl acl_demo.txt
# file: acl_demo.txt
# owner: Donnie
# group: Donnie
user::rw-
user:frank:rw-
group::---
mask::rw-
other::---
[donnie@localhost ~]$
So, Maggie’s ACL is gone. But, the -x
option removes the entire ACL, even if that’s not what you really want. If you have an ACL with multiple permissions set, you might just want to remove one permission, leaving the others. Here, we see that Frank still has his ACL that grants him read/write access. Let’s now say that we want to remove the write permission, while still allowing him the read permission. For that, we’ll need to apply a mask:
[donnie@localhost ~]$ setfacl -m m::r acl_demo.txt
[donnie...