Safely update Linux account details with chfn
You will change the full name, room number, office phone, or home phone stored for a Linux account, then verify the result without editing /etc/passwd by hand. Allow about ten minutes. You need the passwd package and a shell account whose details you are authorised to change. The examples use the chfn from shadow-utils 4.13, installed here as package version 1:4.13+dfsg1-4ubuntu3.2.
The route
Jump straight to the step you need, or tick off Done means at the end.
These are account metadata changes, not password changes. They can still affect address books, login displays and scripts that read the GECOS field. Record the old value before changing it so that you can restore it if another program depends on the previous spelling.
1. Check the installed command and account
Start with read-only checks. This confirms which binary will run and identifies the account without changing anything:
$ command -v chfn
/usr/bin/chfn
$ id -un
YOUR_LOGIN
$ getent passwd "$USER"
YOUR_LOGIN:x:1000:1000:Your Full Name,Room,Work Phone,Home Phone:/home/YOUR_LOGIN:/bin/bash
The last line is account-specific. The fifth colon-separated field is the GECOS field, commonly displayed as comma-separated full name, room, work phone and home phone values. Do not paste the illustrative line into a file. Save the current values somewhere private if you need an undo path.
Checkpoint: make sure id -un names the account you intend to change. A normal user can change only their own account, subject to the host's restrictions. A superuser can target another account, so check the login argument twice before using elevated privileges.
2. Read the host's restriction
Regular users are controlled by CHFN_RESTRICT in /etc/login.defs. The letters mean full name (f), room (r), work phone (w) and home phone (h). This machine has:
$ grep -E '^[[:space:]]*CHFN_RESTRICT[[:space:]]+' /etc/login.defs
CHFN_RESTRICT rwh
With rwh, an ordinary user may change room, work phone and home phone, but not the full name. The installed manual documents yes as the older spelling for rwh, and no as the spelling for all four fields. If the setting is absent, the manual says that only the superuser can make changes. The most restrictive arrangement is not installing chfn set-user-ID at all.
Do not work around a rejected full-name change by changing /etc/login.defs casually. That is a system-wide policy decision. Ask the system administrator, and check how the account database is managed before changing local policy.
3. Choose one field and make a reversible change
Use a long option with one value and an explicit login. Replace YOUR_LOGIN and the example value with your own authorised values:
$ chfn --room "Room 4" YOUR_LOGIN
$ chfn --work-phone "+44 20 0000 0000" YOUR_LOGIN
$ chfn --home-phone "+44 20 0000 0001" YOUR_LOGIN
Run one command at a time and verify it before changing another field. These commands normally run as the account owner. Use sudo only when you are authorised to administer the target account:
$ sudo chfn --room "Room 4" OTHER_LOGIN
Before pressing Enter, check the destination and value. The field must not contain a colon. Except for the other field, the manual advises avoiding commas and equal signs too. Phone numbers have additional non-US-ASCII enforcement. Keep values short, plain and compatible with the applications that consume them.
Checkpoint: the command should return to the prompt with status zero and no error text. Verify the changed field through the account database:
$ getent passwd "YOUR_LOGIN" | cut -d: -f5
Your Full Name,Room 4,+44 20 0000 0000,+44 20 0000 0001
Do not assume that getent always reads only local /etc/passwd. Name-service configuration can return account data from another source. If the result does not match the database you intended to edit, stop and check /etc/nsswitch.conf and your account-management system.
4. Use interactive mode when several values need review
With no field option, chfn prompts for the current account's values. Each current value appears between square brackets. Type a replacement, or leave the line blank to keep that value:
$ chfn
Changing the user information for YOUR_LOGIN
Enter the new value, or press ENTER for the default
Full Name [Your Full Name]:
Room Number [Room 4]: Room 5
Work Phone [+44 20 0000 0000]:
Home Phone [+44 20 0000 0001]:
The exact prompt wording can vary with the installed build and locale. The important rule is that a blank answer keeps the displayed value. Interactive mode is easy to misread when you are returning to it after an interruption, so pause at each prompt and confirm which field is active.
If you need to undo a change, run the same option again with the old value you recorded. For an interactive change, restore each old value at its matching prompt. There is no separate undo command, and chfn does not maintain a version history.
5. Handle the privileged other field carefully
The --other option changes the undefined or accounting portion of GECOS data. Only the superuser may use it. Treat its contents as an interface for local applications, not as a free-form note:
$ sudo chfn --other "ACCOUNTING_VALUE" OTHER_LOGIN
$ getent passwd "OTHER_LOGIN" | cut -d: -f5
Do not use this option merely because a full-name change was refused. First determine whether CHFN_RESTRICT or another account-management policy caused the refusal. Before changing an existing value, identify the application that owns it and preserve the old value. A mistaken replacement can break lookups even though the command exits successfully.
6. Understand chroot mode and common failures
--root applies the change inside a chroot directory and reads configuration files from that directory. The path must be absolute:
$ sudo chfn --root /srv/example-root --room "Room 4" CHROOT_LOGIN
Use this only when /srv/example-root/etc/passwd and its related configuration are the intended database. An absolute path does not make an arbitrary directory a complete or safe account environment. Check the target files first, and do not point this option at a live system root as a way to avoid naming the account explicitly.
A "Permission denied" or restriction error usually means the account, field or local policy is outside your authority. A malformed-value error usually means a forbidden colon or another invalid character. Check the command's error, re-read the restriction and inspect the current GECOS value. Do not edit /etc/passwd with a text editor to force a result.
Done means
- You confirmed the installed
chfnand the exact target account. - You read
CHFN_RESTRICTbefore choosing a field. - You used one explicit field option or reviewed interactive prompts carefully.
- You verified the resulting GECOS field with
getent passwd. - You recorded the old value and can restore it with the same option.
- You used elevated privileges only for an authorised administrative change.