Pygetfacl retrieves Access Control List (ACL) information provided by the Linux getfacl command and stores that information as a Python object.
- Linux distribution with the
aclpackage installed. - Python version 3.7 or higher
Pygetfacl may be useful any time you want to obtain a file path's ACL information from within a Python program.
From the command line:
$ pip install git+https://github.com/duanegoodner/pygetfaclNote If you want to test pygetfacl in Docker, you can build and run a container using files provided in the
demo_dockerdirectory. From the pygetfacl project root directory, run the following terminal commands to build/run the container and start abashshell inside it. Pygetfacl is installed during the image build process.$ docker build ./demo_docker -t pygetfacl_demo $ docker run -it -d --rm --name="pygetfacl_demo" pygetfacl_demo $ docker exec -it -w /home/user_a pygetfacl_demo /bin/bash
From the command line (either in your local environment, or a Docker container), run the following command to create a test directory with some interesting ACL settings, and start the Python interpreter in interactive mode.
$ mkdir test_dir \
&& sudo useradd user_b \
&& setfacl -bn test_dir \
&& setfacl -m u:user_b:rwx test_dir \
&& chmod g+s test_dir \
&& pythonThen, in the Python interpreter, run the following commands to get a feel for pygetfacl.getfacl() and the ACLData object that it returns:
>>> import pygetfacl
>>> acl_data = pygetfacl.getfacl("test_dir")
>>> import pprint
>>> pprint.pprint(acl_data)
ACLData(owning_user='user_a',
owning_group='user_a',
flags=-s-,
user=rwx,
special_users={'user_b': rwx},
group=r-x,
special_groups=None,
mask=rwx,
other=r-x,
default_user=None,
default_special_users=None,
default_group=None,
default_special_groups=None,
default_mask=None,
default_other=None)The effective permissions can be accessed via the .effective_permissions property of the ACLData object returned by pygetfacl.getfacl.
>>> print(acl_data.effective_permissions)
user: rwx
special_users: {'user_b': rwx}
group: r-x
special_groups: None
other: r-x
default_user: None
default_special_users: None
default_group: None
default_special_groups: None
default_other: None
Permissions and flags in an ACLData object have _repr_ methods defined so they print in the usual string form when printed (e. g. rwx or sst), but the value of each bit is stored as a boolean in a private data member that can be accessed with a public getter.
>>> special_user_effective = acl_data.effective_permissions.special_users
>>> user_b_effective = special_user_effective.get("user_b")
>>> print(user_b_effective)
rwx
>>> vars(user_b_effective)
{'_r': True, '_w': True, '_x': True}
>>> print(f"user_b effective permissions: r = {user_b_effective.r}, w = {user_b_effective.w}, x = {user_b_effective.x}")
user_b effective permissions: r = True, w = True, x = TruePygetfacl does not offer any methods for changing ACL settings (or even "regular" permission ). For that, you may want to look at:
- pylibacl
- miracle-acl
- trigger.acl
- the standard library
pathlib.Path.chmod()oros.chmod()methods (for "regular" permissions only) - calling the necessary system commands using the standard library subprocess module. This option usually works well for me, perhaps because my use cases tend to be simple.
Pygetfacl is a work-in-progress. Will use it as a dependency in other projects and modify as improvement opportunities arise.