Concept and mechanism
On local systems, file ownership is represented by numeric IDs. An account with the same name on two hosts can have different UIDs, so migration requires mapping identity and ownership. Use configured system sources, including directories where applicable, and check groups and caches without creating conflicting local accounts to bypass unavailability. Before recursive chown, scope data and owners that should change. Authorization should follow the intended service account, with directory traversal and file permissions. Running everything as root can hide the issue and widen an error’s impact.
Guided application
An access ACL applies to an object; a directory default ACL guides new-object inheritance, also subject to creation mode. It does not automatically fix existing files. The mask limits the covered group class and named entries: user:svc_reports:rw- with mask::r-- can give only effective read access. When expanding the mask, review other entries that also gain permissions. setfacl may recalculate the mask, so confirm the complete result. For Too many open files in a service, inspect effective process limits and descriptors. ulimit in the operator shell does not retroactively change another process. A LimitNOFILE change needs assessment of consumption, potential leaks, application compatibility, and controlled startup of new processes.
The named entry has rw but effective:r--: the mask is part of the decision, not only the user entry.
Common pitfalls
Identical name as identical UID; default ACL as retroactive modification; mask without side effects; shell limit as service limit.
Related topics: Services, scheduling, and persistent configuration · Packages, VMs, containers, and SELinux
Validate effective identity and all applicable controls in the context of the process doing the work.
Reference: setfacl(1) · LFCS current five-domain outline; exact edition date unconfirmed