← index

Redis ACL Simulator

Modelled on src/acl.c, Redis 7.2.14. Command categories and key specs are generated from that release's src/commands/*.json.

ACL rules are applied in the order you write them and the last rule that touches a command wins. +@all and -@all are not ordinary rules: each one rewrites the whole permission bitmap and discards every rule stated before it (acl.c:1030, acl.c:1037). Type a rule set on the left, then dry-run a command to see the replay that produced the answer.

ACL command

acl.c:2764 aclCommand

Supported: SETUSER · GETUSER · DELUSER · LIST · USERS · CAT · DRYRUN

Permission check (DRYRUN)

acl.c:3022

Rule replay

acl.c:1010 ACLSetSelector · acl.c:1668

Run a check to see how each rule, in order, moved the verdict for that one command.

Users

acl.c:2862 ACL LIST

Rule builder

+@all / -@all is always emitted first: placed later it would erase every category rule before it (acl.c:1030).

Log

What this models, and what it does not

Order of checkscommand bit, then keys, then channels — acl.c:1662 ACLSelectorCheckCmd.
SelectorsEach (…) becomes a selector. Selectors are tried in order, the root selector first, and the first one that passes wins — acl.c:1839. The reported error is the command if no selector could run it, otherwise the last key or channel no selector matched — acl.c:1828.
+@all / -@allFills or clears the whole bitmap and drops accumulated command rules and first-args — acl.c:1030, acl.c:1037.
Container commandsAllowing or blocking a container also applies to its subcommands — acl.c:608. A category rule additionally walks subcommands on their own categories — acl.c:629.
Commands exempt from the bitmapCommands flagged NO_AUTH skip the command check entirely — acl.c:1665. In 7.2.14 those are AUTH, HELLO, RESET and QUIT.
offBlocks authentication only. DRYRUN and already-authenticated connections are unaffected — acl.c:1191, and the DRYRUN path never reads the enabled flag.
PSUBSCRIBEIts argument is compared to ACL channel patterns as a literal string, not glob-matched — acl.c:1630.
SETUSER is atomicIf any rule is invalid nothing is applied and no user is created — acl.c:2057.
Not modelled: SORT, SORT_RO, MIGRATETheir later key specs are marked incomplete in the command table; real Redis resolves them with a command-specific function. Only the keys their complete specs describe are checked here.
Not modelled: BITFIELDIts key spec carries VARIABLE_FLAGS and the read/write decision is made by a C helper this page has not reproduced, so its key is not checked. SET's variable flags are modelled, from db.c:2501.
Not modelledACL LOG, ACL SAVE/LOAD, modules, and cluster or sentinel specifics.