Home / Alt manpages / newgrp(1)

  • newgrp(1)
  • User command
  • linux

Change Your Shell's Group Safely with newgrp

You will finish with a shell whose primary group is selected with newgrp, plus a quick way to prove which group that shell is using. This is a session-level change: it does not edit your account, group membership or any file ownership.

Allow about ten minutes. You need a local account and a group that already exists. The examples use the newgrp shipped by the Ubuntu login package, version 1:4.13+dfsg1-4ubuntu3.2, based on shadow-utils 4.13. You do not need sudo for the normal examples.

1. Check the installed command

Confirm the binary and package before relying on option details. These are read-only checks:

$ command -v newgrp
/usr/bin/newgrp
$ dpkg-query -W -f='${Package} ${Version}\n' login
login 1:4.13+dfsg1-4ubuntu3.2
$ newgrp --version
Usage: newgrp [-] [group]

The interface is deliberately small. You can supply an optional group name, or - to reinitialise the environment as though you had logged in again. There are no long options in this installed command's synopsis.

Checkpoint

If command -v finds a different path or the package version differs, keep the local manual page as the authority for the rest of the exercise.

2. Choose an existing group

Start with your current primary group. It is a safe smoke test because it asks for no new access and is unlikely to prompt for a group password:

$ id -gn
PRIMARY_GROUP
$ getent group PRIMARY_GROUP
PRIMARY_GROUP:x:1004:your-user

Replace PRIMARY_GROUP with the name printed by your own id -gn. Do not copy the example's numeric ID or member list. To inspect groups your account already knows about, use:

$ id -Gn
PRIMARY_GROUP OTHER_GROUP

newgrp changes the real group ID to the named group and also tries to add that group to the process's groupset. It reads group membership and group passwords from /etc/gshadow when an entry exists, otherwise from /etc/group. That makes group configuration relevant, but this command does not modify those files.

3. Start a shell with the selected group

Run newgrp with the exact group name. It starts another shell, so the command will appear to wait for input:

$ newgrp PRIMARY_GROUP

At the new prompt, verify the effective identity:

$ id -g
1004
$ id -gn
PRIMARY_GROUP
$ id -G
1004 27 987 1000 1009 1017

Your numbers and group list will differ. id -gn is the clearest check of the primary group's name. The original shell is still underneath this one. Leave the new shell with exit:

$ exit
exit

Checkpoint

After exit, you are back in the shell that launched newgrp. The primary group of that parent shell has not been changed.

4. Make the test repeatable without an interactive pause

For a script or a quick diagnostic, feed commands to the shell that newgrp starts. This keeps the test local and lets you capture the status:

$ printf '%s\n' 'id -gn' 'id -g' 'exit' | newgrp PRIMARY_GROUP
PRIMARY_GROUP
1004
$ printf 'newgrp status: %s\n' "$?"
newgrp status: 0

The output values are placeholders: use the group name and numeric ID reported on your host. A zero status here means the child shell completed successfully. It does not prove that a different group was selected unless the id output also matches your requested group.

Do not put an untrusted group name into an unquoted shell command. For a name held in a variable, quote it as a single argument:

$ TARGET_GROUP='PRIMARY_GROUP'
$ printf '%s\n' 'id -gn' 'exit' | newgrp "$TARGET_GROUP"
PRIMARY_GROUP

5. Understand the password and failure cases

If you are not root, newgrp may ask for a password when you are not listed as a member and the target group has a password. A group with an empty password does not grant access to an unlisted user. Never paste a password into a command line or a script. If the prompt is unexpected, cancel with Ctrl-C and inspect membership with getent group TARGET_GROUP and the account's configured groups.

An unknown group is a safe negative test. It should fail rather than create a group:

$ printf '%s\n' 'exit' | newgrp definitely-no-such-group-xyz
$ printf 'newgrp status: %s\n' "$?"
newgrp status: 2

The exact diagnostic text can vary, but a non-zero status is the useful result. Check spelling and group configuration before reaching for elevated privileges. newgrp cannot create a missing group, and adding membership is an administrator task outside this guide.

6. Decide whether to reinitialise the environment

Without an option, newgrp keeps the current environment and working directory. With a single hyphen, it reinitialises the environment as though you had logged in:

$ newgrp - PRIMARY_GROUP

Use this only when you specifically want login-style environment handling. It can make a diagnostic confusing because variables and startup behaviour may differ from the parent shell. Verify the result inside the new shell with id -gn, then leave it with exit as before.

There is no persistent undo command because the normal operation changes only the new shell process. Exit that shell and the parent session remains as it was. To change default group membership or account configuration, use the site's approved identity-management process rather than treating newgrp as an administrative tool.

Done means

  • You confirmed which newgrp binary and login package version are installed.
  • You selected a group that already exists instead of guessing or trying to create one.
  • id -gn and id -g verified the new shell's primary group.
  • You returned to the parent shell with exit.
  • You know that group passwords and membership can deny access, and that a failed group lookup does not change configuration.