Change File Ownership Safely with chown
You will change the owner, group, or both for a file, then verify exactly what changed. This guide uses GNU chown from coreutils 9.4, the version installed on this machine. Allow about ten minutes for a single file, or longer if you are reviewing a directory tree before using --recursive.
The route
Jump straight to the step you need, or tick off Done means at the end.
- 1. Inspect the target before changing it
- 2. Change only the owner
- 3. Change the group, or set both values
- 4. Use a condition when the current state must match
- 5. Copy ownership from a known-good reference
- 6. Treat recursive changes as a maintenance operation
- 7. Handle symbolic links deliberately
- 8. Recover from a mistaken change
You need a shell, a target path, and an owner or group that exists on the host. Changing ownership is usually an administrator operation. Use sudo only when the command reports that your account lacks permission. The examples use placeholders rather than assuming that a particular user or group exists.
1. Inspect the target before changing it
Start by checking the path, its current numeric owner and group, and the names your system resolves for them:
$ TARGET='/path/to/file'
$ ls -ld -- "$TARGET"
$ stat -c 'owner=%U (%u) group=%G (%g) mode=%A path=%n' -- "$TARGET"
$ id
ls -ld is important for a directory: it describes the directory itself instead of listing its contents. The stat line gives you a record that can help with recovery. Save the old owner and group somewhere trustworthy before a large change. Do not infer an account from a display name alone; names and numeric IDs are both accepted, but the ID is tied to this host's account database.
Checkpoint
Confirm that TARGET is the exact file or directory you intend to change. A typo in a privileged path can be more serious than a failed command.
2. Change only the owner
Pass an owner followed by one or more file paths. This leaves the group unchanged:
$ sudo chown OWNER '/path/to/file'
$ stat -c 'owner=%U (%u) group=%G (%g)' -- '/path/to/file'
owner=OWNER (1234) group=OLD_GROUP (5678)
Replace OWNER with an existing login name or numeric user ID. The sample output is illustrative: use the values printed by your own host. If the command succeeds it normally prints nothing. The second command is the verification, and should be run as a separate command so that you inspect the new state rather than a status from an unrelated command.
Use --verbose when processing several paths or when you need a diagnostic for every path:
$ sudo chown --verbose OWNER '/path/to/file'
changed ownership of '/path/to/file' from OLD_OWNER to OWNER
The wording and old values depend on the host. --changes is quieter: it reports only paths whose ownership changed. Neither option changes what the ownership request means.
3. Change the group, or set both values
Put a colon between the owner and group, with no spaces:
$ sudo chown OWNER:GROUP '/path/to/file'
$ stat -c 'owner=%U (%u) group=%G (%g)' -- '/path/to/file'
owner=OWNER (1234) group=GROUP (5678)
To change only the group, omit the owner but keep the colon:
$ sudo chown :GROUP '/path/to/file'
There is a subtle shorthand to avoid using accidentally. OWNER: changes the owner and changes the group to that user's login group. It does not mean "owner only". For owner only, leave out the colon entirely. An empty operand, such as a lone colon, does not change either value and is not a useful way to test a command.
Numeric values are useful when you are matching an account database across systems, but check them with getent passwd and getent group first. A numeric ID can belong to a different named account on another machine.
4. Use a condition when the current state must match
--from adds a guard: the change is made only when the current owner and group match the values you specify. This is useful in deployment or repair scripts where an unexpected current owner should stop the change from applying blindly:
$ sudo chown --from=OLD_OWNER:OLD_GROUP OWNER:GROUP '/path/to/file'
$ stat -c 'owner=%U group=%G' -- '/path/to/file'
owner=OWNER group=GROUP
Either side of the --from value may be omitted when that attribute is not part of the condition. Keep the value quoted if it is assembled by a script, and check the exit status in that script. A condition that does not match is a signal to inspect the file, not permission to retry with a broader command.
5. Copy ownership from a known-good reference
When the desired owner and group are already present on another file, use --reference:
$ REFERENCE='/path/to/known-good-file'
$ TARGET='/path/to/file'
$ stat -c 'reference: %U:%G, target: %U:%G' -- "$REFERENCE" "$TARGET"
$ sudo chown --reference="$REFERENCE" -- "$TARGET"
$ stat -c 'target: %U:%G' -- "$TARGET"
target: OWNER:GROUP
This copies both ownership fields from the reference. The reference is always dereferenced, so if it is a symbolic link, chown reads the ownership of its target. Check both paths before running the command. This operation does not copy permissions, timestamps, ACLs or extended attributes.
6. Treat recursive changes as a maintenance operation
-R or --recursive applies the request to a directory and the entries below it. It can affect application data, sockets, nested mounts and files that should deliberately retain a different owner:
$ sudo chown --verbose --recursive OWNER:GROUP '/path/to/specific-directory'
$ find '/path/to/specific-directory' -printf '%u:%g %p\n' | head
Review the directory with find first, take a backup of the ownership list, and schedule the operation when services using the tree can be checked. Do not replace the quoted directory with / or a broad wildcard. The default recursive traversal is -P: symbolic links are not followed. -H follows a command-line symbolic link to a directory, while -L follows every symbolic link to a directory encountered. Only the last of these traversal options takes effect.
--preserve-root makes recursive use fail on /. It is a useful additional guard for scripts, but it does not validate every other path. The default is --no-preserve-root, so do not rely on an implicit safety barrier.
7. Handle symbolic links deliberately
Without an option, GNU chown dereferences a symbolic link and changes its referent. That can modify a file outside the directory you were inspecting:
$ ls -l '/path/to/link'
$ sudo chown --no-dereference OWNER:GROUP '/path/to/link'
$ ls -l '/path/to/link'
--no-dereference, also written -h, requests a change to the link itself on systems that support changing symlink ownership. Use it when the link's metadata, rather than its target, is the object under review. Confirm the result with ls -l and do not assume that a symlink option has the same effect on every filesystem.
8. Recover from a mistaken change
There is no general undo command. Ownership is restored by running chown again with the original owner and group, if you recorded them and the accounts still exist:
$ sudo chown OLD_OWNER:OLD_GROUP '/path/to/file'
$ stat -c 'owner=%U (%u) group=%G (%g)' -- '/path/to/file'
For a recursive change, use the saved per-path ownership list to restore only the affected paths. Do not guess that one owner and group applied to the whole tree unless you verified that before the change. If a service stopped working, stop making ownership changes, preserve logs, and compare the current state with the service's documented account and the backup record. Correcting ownership does not restore deleted files, altered permissions or application data.
Done means
- You checked the exact target and recorded its original owner and group.
- You used an owner, group or reference that exists on this host.
- You remembered that
OWNER:implies the owner's login group. - You verified the result with
stat, and inspected symlinks before changing them. - You treated
--recursiveas a reviewed maintenance operation. - You have enough recorded information to restore the previous ownership if needed.