Module 5 · Users, groups and permissions
chown and chgrp
Change who owns a file and which group it belongs to, one file at a time or a whole tree, and understand why only root may give files away.
What you will learn
- Change the owner, the group or both with `chown` and `chgrp`.
- Apply ownership changes recursively with `-R` and verify them.
- Explain the rules: who may chown, who may chgrp, and what a numeric owner in `ls -l` means.
Owner and group are part of the file
Every file carries a UID and a GID in its inode, right next to the permission bits. ls -l shows them as names in columns three and four. Permissions only make sense relative to them: -rw-r----- protects a file *from others*, but who counts as "owner" and "group" is exactly what chown and chgrp change. Typical reasons: you unpacked a project as root and want alice to own it; a directory should belong to the devs group so the team can share it; a user was deleted and left files behind.
chown: user, user:group, :group
~% cd /root/lab/l48
l48% chown alice notes.txt
l48% chgrp devs shared.txt
l48% chown alice:devs report.txt
l48% chown -R alice:devs project
l48% ls -l
-rw-r--r-- 1 alice root 0 Oct 4 19:20 notes.txt
drwxr-xr-x 2 alice devs 0 Oct 4 19:20 project
-rw-r--r-- 1 alice devs 0 Oct 4 19:20 report.txt
-rw-r--r-- 1 root devs 0 Oct 4 19:20 shared.txt
l48% ls -l project
-rw-r--r-- 1 alice devs 0 Oct 4 19:20 a.c
-rw-r--r-- 1 alice devs 0 Oct 4 19:20 b.c
chown USER FILE changes only the owner. chown USER:GROUP FILE changes both at once. chown :GROUP FILE changes only the group, which makes chgrp GROUP FILE a convenience rather than a necessity; both exist because people think in both ways. A dot instead of the colon (alice.devs) is also accepted for historical reasons, but the colon is the portable spelling. -R recurses into directories; -c prints each file that changed, which is the right habit for recursive runs; -h changes a symbolic link itself instead of its target.
The rules
| Action | Who may do it | Why |
|---|---|---|
| Change the owner | root only | Giving files away would defeat disk quotas and let you plant files on others |
| Change the group | root, or the owner to a group they belong to | You may only share with groups you are in |
| Change permissions | root or the owner | Lesson 46 |
Since you are root in the lab you will never hit these limits; on a shared machine chown: Operation not permitted is what an ordinary user sees when trying to give a file to someone else. Note also that chown wipes the setuid and setgid bits on regular files as a safety measure, which you will appreciate after lesson 50.
When ls shows a number
The inode stores numbers; ls -l looks the names up in /etc/passwd and /etc/group at display time. If no entry matches, you see the raw number, as in drwxr-sr-x 2 1000 1000 … /home/bob after deluser bob. The files are intact; only the name is gone. Create a user with that UID, or chown -R the files to someone who exists, and the names come back. chown itself accepts numbers too: chown 1000:1000 file.
Commands in this lesson
| Command | What it does |
|---|---|
chown alice FILE | New owner, group unchanged. |
chown alice:devs FILE | New owner and group. |
chown :devs FILE | Only the group (same as chgrp). |
chgrp devs FILE | Change the group. |
chown -R alice:devs DIR | Whole tree, recursively. |
chown -c alice FILE | Report what changed. |
ls -l FILE | awk '{print $3, $4}' | Just owner and group. |
Quiz
What does `chown :devs report.txt` change?
- Only the owner
- Only the group
- Owner and group
Why can an ordinary user not `chown` their own file to another user?
- Because chown needs the `w` bit on the target's home
- Because giving files away would break quotas and accountability; only root may
- They can, as long as the file is world-readable
`ls -l` shows `1000 1000` instead of names. What happened?
- The file is corrupted
- No user or group with those ids exists in /etc/passwd and /etc/group
- ls was run with -n
Which command changes owner and group of a directory and everything inside?
- `chown -R alice:devs dir`
- `chown alice:devs dir/*`
- `chown -a alice:devs dir`
Practice
Make `alice` the owner of `/root/lab/l48/notes.txt` (leave the group as it is).
Change the group of `/root/lab/l48/shared.txt` to `devs` without changing its owner.
Give the whole directory `/root/lab/l48/project`, including the files inside, to owner `alice` and group `devs` with a single command.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.