logname and id -un usually agree, until a service account or a container proves they answer different questions entirely. This guide gets you printing the login name for the current session and using the result safely in a shell check.
The examples use GNU coreutils 9.4, installed here as package version 9.4-3ubuntu6.3. Allow about five minutes. You need a shell and the logname command; neither the normal check nor its diagnostics needs elevated privileges.
Start by checking which executable the shell will run. This is a read-only command:
$ command -v logname
/usr/bin/logname
$ dpkg-query -W -f='${Package} ${Version}\n' coreutils
coreutils 9.4-3ubuntu6.3
Package versions differ between distributions. Keep the version in your local notes when a script or support report depends on exact output. The manual page describes logname as printing the user's login name: it does not take a file path, account name or configuration file.
Run the command with no operand:
$ logname
alice
Your output should be one name followed by a newline. The name above is specific to the session used for this example, so do not copy it as a fixed value. A successful exit status is also useful in a script:
$ logname > /tmp/login-name.txt
$ status=$?
$ printf 'status=%s, name=%s\n' "$status" "$(cat /tmp/login-name.txt)"
status=0, name=alice
The redirection creates or replaces /tmp/login-name.txt. That file is temporary and contains an identity value, so remove it when you no longer need it:
$ rm -- /tmp/login-name.txt
This cleanup is optional. Do not use a broad wildcard in the rm command when a specific temporary file is enough.
logname reports the login name for the session, not a name supplied as an argument. Compare it with the current effective account when troubleshooting an identity mismatch:
$ printf 'login name: %s\n' "$(logname)"
login name: alice
$ printf 'effective account: %s\n' "$(id -un)"
effective account: alice
id -un reports the account running the command.Do not use the LOGNAME environment variable as a substitute for this check. On this installation, changing that variable does not change logname's output:
$ LOGNAME=example-user logname
alice
$ LOGNAME=example-user id -un
alice
An environment variable can be inherited or edited by a process. Treat it as input, not proof of the account or login session.
If a script needs to record the login name, capture the command's status before using its output. A command substitution strips the final newline, which is convenient for a log line:
login_name=$(logname)
status=$?
if [ "$status" -ne 0 ]; then
printf '%s\n' 'Could not determine the login name.' >&2
exit "$status"
fi
printf 'session login: %s\n' "$login_name"
This code handles a command failure instead of silently writing an empty or misleading record. It does not grant permissions, select an account, or authenticate anyone. Use a separate identity and authorisation check before making a security decision.
For a simple presence check, keep the output out of the decision and test the status directly:
if logname > /dev/null 2>&1; then
printf '%s\n' 'A login name is available.'
else
printf '%s\n' 'No login name was available.' >&2
exit 1
fi
GNU coreutils 9.4 documents only --help and --version:
$ logname --help
Usage: logname [OPTION]
Print the user's login name.
--help display this help and exit
--version output version information and exit
Use --version when recording the implementation:
$ logname --version | head -n 1
logname (GNU coreutils) 9.4
There is no documented option for selecting another user, changing the login name, or formatting the output. Supplying an ordinary operand is an error:
$ logname extra
logname: extra operand 'extra'
Try 'logname --help' for more information.
$ printf 'status=%s\n' "$?"
status=1
The diagnostic formatting can vary with the locale, so scripts should use the exit status rather than matching the error text.
A non-zero result means this process could not obtain the session login name. Common causes include service managers, scheduled jobs, containers, or a shell started without the login-session records that the command expects.
First reproduce the failure in the same execution context. Do not add sudo automatically: changing privilege does not create a missing login session and can hide the real problem. Check the context with read-only commands:
$ id
$ printf 'LOGNAME=%s\n' "${LOGNAME-}"
$ tty || true
$ logname
$ printf 'status=%s\n' "$?"
If the purpose is to identify the account running a service, use the service's documented account or id -un in that service context. If the purpose is to identify an interactive login, arrange for the job to run inside the intended login session rather than inventing a value. Keep the two meanings separate in logs and access checks.
logname prints the session login name and exits with status 0 in the intended context.