cp overwrites an existing destination without asking, so the one file you meant to keep is the one it just replaced. This guide shows how to copy individual files and whole directories with GNU cp, protect an existing destination, preserve useful metadata, and verify the result. The examples match GNU coreutils 9.4, installed here as package version 9.4-3ubuntu6.3. Allow about fifteen minutes. You need a shell and read access to the source; writing into a protected destination may require elevated privileges.
Confirm which implementation your shell will run. This is a read-only check and normally needs no sudo:
$ command -v cp
/usr/bin/cp
$ cp --version
cp (GNU coreutils) 9.4
For the examples below, replace /path/to/source.txt and /path/to/backup/ with real paths. Do not use a destination containing valuable data until you have chosen an overwrite policy. cp changes the destination, not the source, but an ordinary copy replaces an existing destination file without asking.
Give the source first and the destination second:
$ cp /path/to/source.txt /path/to/copied.txt
$ test -f /path/to/copied.txt && cmp -- /path/to/source.txt /path/to/copied.txt
$ echo $?
0
A successful cp usually prints nothing. The cmp command reads both files and returns status 0 when their contents match. It is a useful checkpoint when the copy matters more than a successful-looking prompt.
If the destination is an existing directory, cp places the file inside it using the source basename:
$ cp /path/to/source.txt /path/to/backup/
$ test -f /path/to/backup/source.txt
Check the destination path carefully. A trailing directory argument and a renamed file are different operations.
Use --update=none when an existing destination must remain untouched:
$ cp --update=none /path/to/source.txt /path/to/backup/source.txt
GNU cp skips an existing destination and does not treat that skip as a failure. To ask before each overwrite instead, use --interactive:
$ cp --interactive /path/to/source.txt /path/to/backup/source.txt
cp: overwrite '/path/to/backup/source.txt'? n
Do not combine an interactive prompt with an unattended script. For a scripted job, make the policy explicit and inspect the exit status. The short option -n also means no-clobber on this GNU implementation, but --update=none states the intended policy more clearly and avoids portability warnings.
A directory needs --recursive, or its short form -R:
$ cp --recursive /path/to/project /path/to/backup/
$ test -d /path/to/backup/project
$ find /path/to/backup/project -maxdepth 2 -type f -print
This creates backup/project when backup already exists. If you want the contents merged into an existing directory, name the contents explicitly, for example cp --recursive /path/to/project/. /path/to/backup/project/. Review that destination before running it because files with matching names may be replaced.
For a directory tree that should retain modes, ownership, timestamps, symbolic links and other available attributes, use archive mode:
$ cp --archive /path/to/project /path/to/backup/
$ test -d /path/to/backup/project
--archive is equivalent to recursive copying with no dereferencing and preservation of all supported attributes. Preserving ownership may fail when you do not own the files or lack the required privilege. That is a permissions issue, not a reason to run every copy as root.
Use --update when the destination should be replaced only if it is older than its corresponding source:
$ cp --update=older /path/to/project/. /path/to/backup/project/
$ stat -c '%y %n' /path/to/project/settings.conf /path/to/backup/project/settings.conf
The --update option without a value selects older on this version. It is different from a full synchronisation: files that exist only in the destination are not removed, and files are compared using the update rule rather than a content hash. If you need an exact mirror with deletion, stop and choose a tool and recovery plan designed for that job. Do not improvise a destructive rm step.
When replacement is intended but recovery matters, ask cp to retain the old destination:
$ cp --backup=numbered /path/to/new-config /etc/example.conf
$ ls -l /etc/example.conf /etc/example.conf.~1~
Writing under /etc normally requires sudo, so use it only for that specific command after checking both paths:
$ sudo cp --backup=numbered /path/to/new-config /etc/example.conf
Numbered backups use names such as example.conf.~1~. The default backup suffix is ~, and --suffix can change it. Verify the new file and keep the backup until the service or application has been tested. To recover, copy the backup back over the destination during an appropriate maintenance window:
$ sudo cp /etc/example.conf.~1~ /etc/example.conf
That recovery itself changes live configuration. If a service reads the file only at startup, a separate service reload may be required; do not restart a production service merely because a copy completed.
If cp reports 'cannot stat', the source path does not resolve as written. Check it without changing anything:
$ ls -ld -- /path/to/source.txt
$ test -r /path/to/source.txt && echo readable
'Permission denied' at the destination usually means the directory is not writable by your account. Confirm the directory permissions first. Use elevated privileges only when the file is genuinely managed by the system, and check the source and destination again before accepting the command.
Do not use --copy-contents casually with recursive copies. It tells cp to read special files such as device files and named pipes, which can block indefinitely or consume unexpected data. The normal recursive operation copies directory entries and does not need that option for ordinary files.
Symbolic links are another boundary. Archive mode preserves links rather than following them. Options such as --dereference change that behaviour and can copy data outside the apparent source tree. Use them only after inspecting the tree and deciding that following links is intended.
cmp, or a directory copy was checked with a file listing.--recursive or --archive was used for a directory.--update=none, --interactive, or --backup was chosen when replacement needed protection.