acl_get_file(3) — Linux manual page

NAME | LIBRARY | SYNOPSIS | DESCRIPTION | RETURN VALUE | ERRORS | STANDARDS | SEE ALSO | AUTHOR | COLOPHON

ACL_GET_FILE(3)          Library Functions Manual         ACL_GET_FILE(3)

NAME         top

       acl_get_file, acl_get_file_at — get an ACL by filename

LIBRARY         top

       Linux Access Control Lists library (libacl, -lacl).

SYNOPSIS         top

       <sys/types.h> <sys/acl.h> acl_t acl_get_file(const char *path_p,
       acl_type_t type) acl_t acl_get_file_at(int dirfd,
       const char *path_p, int at_flags, acl_type_t type)

DESCRIPTION         top

       The acl_get_file() function retrieves the access ACL associated
       with a file or directory, or the default ACL associated with a
       directory. The pathname for the file or directory is given in the
       argument path_p.  If path_p is a symbolic link, acl_get_file()
       returns information about the file or directory the link refers
       to.

       The ACL is placed into working storage and acl_get_file() returns
       a pointer to that storage.

       In order to read an ACL from an object, a process must have read
       access to the object's attributes.

       The value of the argument type is used to indicate whether the
       access ACL or the default ACL associated with path_p is returned.
       If type is ACL_TYPE_ACCESS, the access ACL of path_p is returned.
       If type is ACL_TYPE_DEFAULT, the default ACL of path_p is
       returned. If type is ACL_TYPE_DEFAULT and no default ACL is
       associated with the directory path_p, then an ACL containing zero
       ACL entries is returned. If type specifies a type of ACL that
       cannot be associated with path_p, then the function fails.

       This function may cause memory to be allocated.  The caller should
       free any releasable memory, when the new ACL is no longer
       required, by calling acl_free(3) with the (void*)acl_t returned by
       acl_get_file() as an argument.

   acl_get_file_at()
       The acl_get_file_at() function operates in exactly the same way as
       acl_get_file(), except for the differences described here.

       If the pathname given in path_p is relative, then it is
       interpreted relative to the directory referred to by the file
       descriptor dirfd (rather than relative to the current working
       directory of the calling process, as is done by acl_get_file()).

       If path_p is relative and dirfd is the special value AT_FDCWD,
       then path_p is interpreted relative to the current working
       directory of the calling process (like acl_get_file()).

       If path_p is absolute, then dirfd is ignored.

       The at_flags argument can either be 0, or include one or more of
       the following flags ORed:

       AT_EMPTY_PATH
               If path_p is an empty string, operate on the file referred
               to by dirfd (which may have been obtained using the
               open(2) O_PATH flag). In this case, dirfd can refer to any
               type of file, not just a directory, and the behavior of
               acl_get_file_at() is similar to that of acl_get_fd().

       AT_SYMLINK_NOFOLLOW
               If path_p refers to a symbolic link, do not dereference
               it: instead, fail the operation and set the global
               variable errno to ENOTSUP.  This indicates that the
               symbolic link cannot have ACLs.

RETURN VALUE         top

       On success, the acl_get_file() and acl_get_file_at() functions
       return a pointer to the working storage.  On error, a value of
       (acl_t)NULL is returned, and errno is set appropriately.

ERRORS         top

       If any of the following conditions occur, the acl_get_file() and
       acl_get_file_at() functions return a value of (acl_t)NULL and set
       errno to the corresponding value:

       [EACCES]           Search permission is denied for a component of
                          the path prefix or the object exists and the
                          process does not have appropriate access
                          rights.

                          Argument type specifies a type of ACL that
                          cannot be associated with path_p.

       [EBADF]            The argument path_p is relative but the
                          argument dirfd is neither AT_FDCWD nor a valid
                          file descriptor.

       [EINVAL]           The argument type is not ACL_TYPE_ACCESS or
                          ACL_TYPE_DEFAULT.

                          An invalid flag was specified in the at_flags
                          argument.

       [ENAMETOOLONG]     The length of the argument path_p is too long.

       [ENOENT]           The named object does not exist or the argument
                          path_p points to an empty string.

       [ENOMEM]           The ACL working storage requires more memory
                          than is allowed by the hardware or system-
                          imposed memory management constraints.

       [ENOTDIR]          A component of the path prefix is not a
                          directory.

                          The argument path_p is relative and the
                          argument dirfd is a file descriptor referring
                          to a file other than a directory.

       [ENOTSUP]          The argument at_flags includes the flag
                          AT_SYMLINK_NOFOLLOW and path_p is a symbolic
                          link.

                          The file system on which the file identified by
                          path_p is located does not support ACLs, or
                          ACLs are disabled.

STANDARDS         top

       IEEE Std 1003.1e draft 17 (“POSIX.1e”, abandoned)

       Function acl_get_file_at() is a Linux specific extension.

SEE ALSO         top

       acl_free(3), acl_get_entry(3), acl_get_fd(3), acl_set_file(3),
       acl(5)

AUTHOR         top

       Derived from the FreeBSD manual pages written by Robert N M Watson
       <rwatson@FreeBSD.org>, and adapted for Linux by Andreas
       Gruenbacher <andreas.gruenbacher@gmail.com>.

COLOPHON         top

       This page is part of the acl (manipulating access control lists)
       project.  Information about the project can be found at
       http://savannah.nongnu.org/projects/acl.  If you have a bug report
       for this manual page, see
       ⟨http://savannah.nongnu.org/bugs/?group=acl⟩.  This page was
       obtained from the project's upstream Git repository
       ⟨git://git.savannah.nongnu.org/acl.git⟩ on 2026-08-03.  (At that
       time, the date of the most recent commit that was found in the
       repository was 2026-06-29.)  If you discover any rendering
       problems in this HTML version of the page, or you believe there is
       a better or more up-to-date source for the page, or you have
       corrections or improvements to the information in this COLOPHON
       (which is not part of the original manual page), send a mail to
       man-pages@man7.org

Linux ACL                      June 5, 2026               ACL_GET_FILE(3)