chown Command Explained
chown changes who owns a file. Ownership is the other half of Linux’s permission model alongside the rwx bits themselves: permissions define what actions are allowed, but ownership determines which set of permissions (owner, group, or other) actually applies to a given user trying to access the file.
Basic usage: changing the owner
sudo chown alice document.txt
ls -l document.txt
# -rw-r--r-- 1 alice colton 1024 Jul 9 document.txt
This changes only the owning user, leaving the owning group untouched. Note that changing ownership almost always requires sudo, since it is a privileged operation, explained further below.
Changing user and group together
sudo chown www-data:www-data /var/www/html
The user:group syntax sets both in a single command, which is by far the most common real-world pattern, particularly for web server directories where files need to be owned by the specific system user (and often matching group) that the web server process runs as.
# Change just the group, leaving the user untouched
sudo chown :developers project/
# Equivalent using the dedicated chgrp command instead
sudo chgrp developers project/
Starting the argument with a colon and no username changes only the group, leaving the current owner exactly as it was. chgrp exists as a separate, more narrowly focused command that does exactly this same group-only change.
Why chown requires elevated privileges
chown alice myfile.txt
# chown: changing ownership of 'myfile.txt': Operation not permitted
Unlike chmod, which a file’s owner can freely apply to their own files, changing the owner of a file is a privileged operation restricted to root. This exists for a specific security reason: without this restriction, a user could create a large file, then give ownership away to another user to dodge a per-user disk quota, or use ownership changes to obscure who actually created a given file. Requiring root privileges for chown closes that loophole.
sudo chown alice myfile.txt
# succeeds
Recursive ownership changes
sudo chown -R www-data:www-data /var/www/html
-R applies the ownership change to a directory and everything nested inside it, which is the standard step when deploying a web application: every file the web server needs to read (and, for upload directories, write) must be owned appropriately, or the service will fail with permission errors even though the files objectively exist and appear correct in a listing.
A common real-world pattern: fixing web server permissions
# Deploy files as your own user first
git clone https://example.com/myapp.git /var/www/myapp
cd /var/www/myapp
# Then hand ownership to the web server's service account
sudo chown -R www-data:www-data /var/www/myapp
# Set appropriate permissions on top of the new ownership
sudo find /var/www/myapp -type d -exec chmod 755 {} \;
sudo find /var/www/myapp -type f -exec chmod 644 {} \;
This three-step pattern, clone or deploy as yourself, hand off ownership to the service account, then set appropriate permissions, is extremely common in web deployment workflows, since Git and most deployment tools naturally create files owned by whichever user ran the command, which is rarely the same account the actual web server process runs as.
Copying ownership from another file: —reference
sudo chown --reference=template.txt newfile.txt
Instead of specifying a user and group by name, --reference copies the ownership from an existing file onto the target. This is useful when you want a new file to match an existing file’s ownership exactly without needing to look up and type the specific username and group first.
Checking ownership
ls -l file.txt
# -rw-r--r-- 1 alice developers 2048 Jul 9 10:00 file.txt
# └──┬─┘ └───┬────┘
# owner group
stat -c '%U:%G' file.txt
# alice:developers
ls -l shows both the owning user and group as the third and fourth fields respectively. stat -c '%U:%G' extracts just those two values with nothing else, which is generally more convenient inside a script that needs to check or compare ownership programmatically.
Frequently Asked Questions
What does the chown command do?
chown (change owner) changes which user and, optionally, which group owns a file or directory. Ownership determines which permission set (owner, group, or other) applies to a given user when accessing that file, so changing ownership effectively changes who counts as “the owner” for permission purposes.
What is the syntax for changing both user and group ownership at once?
Use the user:group syntax, such as chown www-data:www-data /var/www/html, which sets both the owning user and the owning group in a single command. You can also change just the user by omitting the colon and group name, chown www-data /var/www/html, or change just the group by starting with a colon, chown :www-data /var/www/html.
What is the difference between chown and chgrp?
chown can change both the owning user and the owning group, or either one independently. chgrp changes only the owning group, and is essentially a more limited, single-purpose alternative for when you specifically only want to change group ownership and never touch the user. Most people use chown for both purposes since its syntax already covers changing just the group with the :groupname form.
Why do I get “Operation not permitted” when trying to change ownership?
Changing a file’s owner is a privileged operation on Linux; a regular user cannot give away or take files they do not already own, even files they themselves created, without root privileges. This exists specifically to prevent a scenario where a user could disguise ownership of files to evade disk quotas or accountability. Running the same chown command with sudo resolves this in almost all cases.
How do I change ownership of a directory and everything inside it recursively?
Add the -R flag, such as sudo chown -R www-data:www-data /var/www/html, which applies the ownership change to the directory itself and every file and subdirectory nested inside it. This is the standard pattern used when setting up a web server directory or deploying an application that needs to run as a specific service user.
How do I check who currently owns a file before or after running chown?
Run ls -l file.txt, which shows the owning user and group as the third and fourth columns of its output, or stat -c “%U:%G” file.txt for just the owner and group names with no other information mixed in, which is more convenient to use directly inside a script.