DEV Community

dpm_bush
dpm_bush

Posted on Originally published at sshflow.com

Using chown -R Safely to Change Ownership of a Linux Directory

A directory has the wrong owner, and changing just the directory itself does not fix the files inside it. On Linux, chown -R applies an ownership change recursively—but a typo in the target path can affect far more than intended.

The basic form is:

sudo chown -R user:group /path/to/directory
Enter fullscreen mode Exit fullscreen mode

Replace user, group, and the path with the account names and directory you actually want to change. Before running it, it helps to know what the command changes, what it leaves alone, and how to check the result.

Owner and group in one command

For example, to set a web application tree to the deploy user and www-data group:

sudo chown -R deploy:www-data /var/www/myapp
Enter fullscreen mode Exit fullscreen mode

The uppercase -R means recursive. chown changes the named directory and walks through its contents, including hidden files and directories such as .env and .git.

You can also change only one part of ownership:

# Change the owner; leave each item's group unchanged
sudo chown -R deploy /var/www/myapp

# Change the group; leave each item's owner unchanged
sudo chown -R :www-data /var/www/myapp
Enter fullscreen mode Exit fullscreen mode

If you only need to change the group, chgrp -R www-data /var/www/myapp is another option. For GNU Coreutils, use uppercase -R; lowercase -r is not the recursive option.

Why * can miss important files

These commands may look equivalent, but they are not:

# The shell expands * before chown runs; hidden entries are skipped
sudo chown -R deploy:www-data /var/www/myapp/*

# chown starts at the directory and includes hidden entries
sudo chown -R deploy:www-data /var/www/myapp
Enter fullscreen mode Exit fullscreen mode

The wildcard behavior comes from the shell, not from chown. If most files have the expected owner but .env or another top-level dotfile does not, check whether the command used * instead of naming the directory.

Symlinks need extra care

With GNU chown, recursive traversal does not follow directory symlinks by default. The traversal options are:

  • -P: do not traverse symlinks; this is the default when no traversal option is supplied.
  • -H: follow a symlink to a directory when that symlink is given as a command-line argument.
  • -L: follow every symlink to a directory encountered during traversal.

These options control whether the walk enters linked directories. A separate choice is whether chown changes a symlink itself or its target. GNU chown provides -h (--no-dereference) to change an encountered symlink rather than its target.

Be particularly cautious with -L: a link inside the tree could lead somewhere outside it. Avoid following links unless you understand where they point and intend to include those targets.

Check the result before moving on

List the directory, including hidden entries:

ls -la /var/www/myapp
Enter fullscreen mode Exit fullscreen mode

For a specific file, GNU/Linux stat can show its owner and group:

stat -c '%U:%G' /var/www/myapp/.env
Enter fullscreen mode Exit fullscreen mode

To find entries not owned by the expected user:

find /var/www/myapp ! -user deploy
Enter fullscreen mode Exit fullscreen mode

No output means find did not find entries with a different owner. If something appears, check whether it was created after the ownership change or is a symlink that the traversal did not follow.

Ownership is not permissions

chown changes who owns a file; chmod changes its permission bits—who can read, write, or execute it. Correct ownership does not automatically make a file accessible if its permissions still deny access. If you're deciding whether to change ownership or access modes, this guide to changing Linux file permissions explains the distinction. For recursive permission changes, see how to use chmod -R safely.

A quick safety check

Recursive ownership changes do not ask for confirmation and have no simple undo. Inspect the target path carefully before running the command, especially when copying a command into a script. A stray space can make two paths into separate targets:

# This names two paths, not one path with a space in it
sudo chown -R user:group /var/www /myapp
Enter fullscreen mode Exit fullscreen mode

Use sudo when you need elevated privileges to change ownership. Changing a file's owner to another user requires root or equivalent capabilities; a regular user may change the group of their own files only to a group they belong to. If you see Invalid user, check for a typo and confirm the account exists with id username.

For a typical directory tree, the pattern to remember is:

sudo chown -R user:group /path/to/directory
Enter fullscreen mode Exit fullscreen mode

Point it at the directory itself to include hidden entries, check symlinks before changing traversal behavior, and verify the ownership afterward.

I originally published a more detailed version of this guide on the SSHFlow blog.

I'm also building SSHFlow — an SSH client where every server gets its own workspace for terminals, SFTP, code, and databases.

Top comments (0)