acl_extended_file(3) — Linux manual page

NAME | LIBRARY | SYNOPSIS | DESCRIPTION | RETURN VALUE | ERRORS | STANDARDS | SEE ALSO | AUTHOR | COLOPHON

ACL_EXTENDED_FILE(3)     Library Functions Manual    ACL_EXTENDED_FILE(3)

NAME         top

       acl_extended_file, acl_extended_file_at,
       acl_extended_file_nofollow — test for information in ACLs by file
       name

LIBRARY         top

       Linux Access Control Lists library (libacl, -lacl).

SYNOPSIS         top

       <sys/types.h> <acl/libacl.h> int
       acl_extended_file(const char *path_p) int
       acl_extended_file_at(int dirfd, const char *path_p, int at_flags)
       int acl_extended_file_nofollow(const char *path_p)

DESCRIPTION         top

       The acl_extended_file() function returns 1 if the file or
       directory whose pathname is given in path_p is associated with an
       extended access ACL, or if the directory referred to by path_p is
       associated with a default ACL. The function returns 0 if the file
       has neither an extended access ACL nor a default ACL.  If path_p
       is a symbolic link, acl_extended_file() returns information about
       the file or directory the link refers to.

       An extended ACL is an ACL that contains entries other than the
       three required entries of tag types ACL_USER_OBJ, ACL_GROUP_OBJ
       and ACL_OTHER.  If the result of the acl_extended_file() function
       for a file object is 0, then ACLs define no discretionary access
       rights other than those already defined by the traditional file
       permission bits.

       Access to the file object may be further restricted by other
       mechanisms, such as Mandatory Access Control schemes. The
       access(2) system call can be used to check whether a given type of
       access to a file object would be granted.

   acl_extended_file_at()
       The acl_extended_file_at() function operates in exactly the same
       way as acl_extended_file(), except for the differences described
       here.

       If the pathname given in path_p is relative, then it is
       interpreted relative to the directory referred to by the file
       descriptor dirfd (rather than relative to the current working
       directory of the calling process, as is done by
       acl_extended_file()).

       If path_p is relative and dirfd is the special value AT_FDCWD,
       then path_p is interpreted relative to the current working
       directory of the calling process (like acl_extended_file()).

       If path_p is absolute, then dirfd is ignored.

       The at_flags argument can either be 0, or include one or more of
       the following flags ORed:

       AT_EMPTY_PATH
               If path_p is an empty string, operate on the file referred
               to by dirfd (which may have been obtained using the
               open(2) O_PATH flag). In this case, dirfd can refer to any
               type of file, not just a directory.

       AT_SYMLINK_NOFOLLOW
               If path_p refers to a symbolic link, do not dereference
               it: instead, fail the operation and set the global
               variable errno to ENOTSUP.  This indicates that the
               symbolic link cannot have ACLs.

   acl_extended_nofollow()
       The acl_extended_file_at() function operates in exactly the same
       way as acl_extended_file() with a dirfd value of AT_FDCWD and an
       at_flags value of AT_SYMLINK_NOFOLLOW.

RETURN VALUE         top

       If successful, these functions return 1 if the file object
       referred to by path_p has an extended access ACL or a default ACL,
       and 0 if the file object referred to by path_p has neither an
       extended access ACL nor a default ACL. Otherwise, the value -1 is
       returned and the global variable errno is set to indicate the
       error.

ERRORS         top

       If any of the following conditions occur, these functions return
       -1 and set errno to the corresponding value:

       [EACCES]           Search permission is denied for a component of
                          the path prefix.

       [EBADF]            The argument path_p is relative but the
                          argument dirfd is neither AT_FDCWD nor a valid
                          file descriptor.

       [EINVAL]           An invalid flag was specified in the at_flags
                          argument.

       [ENAMETOOLONG]     The length of the argument path_p is too long.

       [ENOENT]           The named object does not exist or the argument
                          path_p points to an empty string.

       [ENOTDIR]          A component of the path prefix is not a
                          directory.

                          The argument path_p is relative and the
                          argument dirfd is a file descriptor referring
                          to a file other than a directory.

       [ENOTSUP]          The argument at_flags includes the flag
                          AT_SYMLINK_NOFOLLOW and path_p is a symbolic
                          link.

                          The file system on which the file identified by
                          path_p is located does not support ACLs, or
                          ACLs are disabled.

STANDARDS         top

       This is a non-portable, Linux specific extension to the ACL
       manipulation functions defined in IEEE Std 1003.1e draft 17
       (“POSIX.1e”, abandoned).

SEE ALSO         top

       access(2), acl_get_file(3), acl(5)

AUTHOR         top

       Written by Andreas Gruenbacher <andreas.gruenbacher@gmail.com>.

COLOPHON         top

       This page is part of the acl (manipulating access control lists)
       project.  Information about the project can be found at
       http://savannah.nongnu.org/projects/acl.  If you have a bug report
       for this manual page, see
       ⟨http://savannah.nongnu.org/bugs/?group=acl⟩.  This page was
       obtained from the project's upstream Git repository
       ⟨git://git.savannah.nongnu.org/acl.git⟩ on 2026-08-03.  (At that
       time, the date of the most recent commit that was found in the
       repository was 2026-06-29.)  If you discover any rendering
       problems in this HTML version of the page, or you believe there is
       a better or more up-to-date source for the page, or you have
       corrections or improvements to the information in this COLOPHON
       (which is not part of the original manual page), send a mail to
       man-pages@man7.org

Linux ACL                      June 5, 2026          ACL_EXTENDED_FILE(3)