॥ श्री ॥

ch* Commands (chmod, chown, chattr, ACLs)

System 2026-08-28

The ch* family covers the core "change" utilities — tools that modify permissions, ownership, file attributes, and user account properties. All are pre-installed on Shani OS.


chmod — Change File Permissions

chmod sets read, write, and execute permissions for the owner, group, and others.

Symbolic mode

chmod u+x script.sh          # Add execute for owner
chmod go-w file.txt           # Remove write for group and others
chmod a+r file.txt            # Add read for everyone
chmod u=rw,go=r file.txt      # Set exact permissions per class
SymbolMeaning
uOwner (user)
gGroup
oOthers
aAll (u+g+o)
+Add permission
-Remove permission
=Set exactly (overwrites)

Octal mode

Each permission class is a 3-bit value: read=4, write=2, execute=1.

chmod 755 script.sh           # rwxr-xr-x  (owner: rwx, group: r-x, others: r-x)
chmod 644 file.txt            # rw-r--r--  (owner: rw, group: r, others: r)
chmod 600 ~/.ssh/id_ed25519   # rw-------  (private key — others must have no access)
chmod 700 ~/.ssh              # rwx------  (SSH directory)
chmod 000 locked.txt          # ---------- (no access for anyone)

Common permission patterns:

OctalSymbolicTypical use
755rwxr-xr-xExecutable scripts, directories
644rw-r--r--Regular files
600rw-------Private keys, secrets
700rwx------Private directories
664rw-rw-r--Shared group files
775rwxrwxr-xShared group directories

Recursive and special bits

chmod -R 755 /var/www/html    # Recursive (applies to all files and subdirs)

chmod u+s /usr/bin/myapp      # Setuid — runs as file owner, not caller
chmod g+s /shared/dir         # Setgid — new files inherit group; useful for shared dirs
chmod +t /tmp                 # Sticky bit — only owner can delete their own files
⚠️ Avoid chmod -R 777. It grants world-write to everything, including config files and scripts.

chown — Change Ownership

chown sets the owner and optionally the group of a file or directory.

chown alice file.txt              # Change owner to alice
chown alice:developers file.txt   # Change owner and group
chown :developers file.txt        # Change group only (note leading colon)
chown -R alice:alice /home/alice  # Recursive ownership change
chown --reference=ref.txt file.txt # Copy ownership from another file
💡 chgrp is a shorthand for changing only the group: chgrp developers file.txt is equivalent to chown :developers file.txt.

chattr — Change Extended File Attributes

chattr sets low-level filesystem attributes on ext2/ext4/Btrfs. These attributes are enforced by the kernel — even root cannot modify or delete a file with the immutable flag set without first removing the attribute.

sudo chattr +i important.conf     # Immutable — no writes, renames, or deletes
sudo chattr -i important.conf     # Remove immutable flag
sudo chattr +a logfile.log        # Append-only — can only append, not overwrite
sudo chattr +u file.txt           # Undeletable (save data on deletion for recovery)
sudo chattr +c archive.tar        # Enable transparent compression (ext4)
sudo chattr -R +i /etc/           # Recursive — use with caution

Check attributes with lsattr:

lsattr important.conf
# ----i--------e-- important.conf

lsattr -R /etc/               # Recursive listing

Common attribute flags:

FlagMeaning
iImmutable — no modifications, no deletion, even by root
aAppend-only — data can be added but not overwritten
uUndeletable — kernel keeps data recoverable after deletion
cTransparent compression
eExtents in use (set automatically, do not modify)
⚠️ The +i flag is useful for protecting config files from accidental changes, but remember to remove it before package updates that modify the file.

ACLs — Beyond Owner/Group/Other

Standard chmod/chown only give you one owner and one group per file. acl (pre-installed) adds Access Control Lists — extra permission entries for specific additional users or groups on the same file, without changing its actual owner or group.

# Grant a specific user read+write on a file, without changing its owner
sudo setfacl -m u:bob:rw file.txt

# Grant a specific group read-only access to a directory
sudo setfacl -m g:developers:rx /shared/project

# View the ACL entries on a file (also shown by ls -l as a trailing '+')
getfacl file.txt

# Apply recursively to a directory tree
sudo setfacl -R -m u:bob:rwx /shared/project

# Set a default ACL so new files created inside a directory inherit it
sudo setfacl -d -m g:developers:rwx /shared/project

# Remove one entry
sudo setfacl -x u:bob file.txt

# Remove all ACL entries (back to plain owner/group/other)
sudo setfacl -b file.txt

Filesystems must be mounted with ACL support for this to work — ext4 and XFS enable it by default; Btrfs (Shanios's own root and @home) supports ACLs natively with no mount option needed.


chage — Change Password Aging Policy

chage manages password expiry and account aging for local users. Useful for enforcing security policies without a directory service.

sudo chage -l alice               # List current aging settings
sudo chage -M 90 alice            # Password expires after 90 days
sudo chage -m 7 alice             # Minimum 7 days between password changes
sudo chage -W 14 alice            # Warn user 14 days before expiry
sudo chage -I 30 alice            # Lock account 30 days after expiry
sudo chage -E 2026-12-31 alice    # Account expires on a specific date
sudo chage -E -1 alice            # Remove account expiry
sudo chage -d 0 alice             # Force password change on next login

View aging info:

sudo chage -l alice
# Last password change                        : Apr 01, 2026
# Password expires                            : Jun 30, 2026
# Password inactive                           : Jul 30, 2026
# Account expires                             : never
# Minimum number of days between changes      : 7
# Maximum number of days between changes      : 90
# Number of days of warning before expiry     : 14

Password Strength — pwscore / pwmake

libpwquality (pre-installed) checks passwords against the same complexity policy PAM enforces at password-change time (/etc/security/pwquality.conf) — useful for testing a password before setting it, or generating a random one that already passes.

# Score a password against the configured policy (0-100, or an error if it fails)
echo "MyP@ssw0rd123" | pwscore

# Generate a random password that passes the policy (length in bits of entropy)
pwmake 128

chsh — Change Login Shell

chsh changes a user's default login shell.

chsh                              # Interactive prompt for current user
chsh -s /bin/zsh                  # Set shell to zsh for current user
chsh -s /bin/bash alice           # Set shell for another user (root only)
chsh -l                           # List valid shells (reads /etc/shells)

Shells must be listed in /etc/shells to be accepted. To add a custom shell:

which fish                        # e.g. /usr/bin/fish
echo /usr/bin/fish | sudo tee -a /etc/shells
chsh -s /usr/bin/fish

The change takes effect on the next login. Running echo $SHELL in an existing session still shows the old shell.


chfn — Change Finger (GECOS) Information

chfn updates the GECOS field in /etc/passwd — the display name and contact info shown by finger and some system tools.

chfn                              # Interactive prompts for current user
chfn -f "Alice Smith" alice       # Set full name (root only for other users)
chfn -r "Ops Team" alice          # Set room/location
chfn -w "555-1234" alice          # Set work phone
chfn -h "555-5678" alice          # Set home phone

The GECOS string is cosmetic and not security-sensitive, but it is displayed in finger, w, who, and some email clients.


chpasswd — Batch Password Changes

chpasswd reads username:password pairs from stdin and updates passwords in bulk. It is intended for provisioning scripts, not interactive use.

echo "alice:NewP@ssw0rd" | sudo chpasswd
echo "bob:AnotherSecure1" | sudo chpasswd

# Batch from a file (delete the file immediately after use)
sudo chpasswd < /tmp/passwords.txt
sudo shred -u /tmp/passwords.txt
⚠️ Avoid embedding plain-text passwords in scripts. Use chpasswd only in controlled provisioning environments, and always shred the input file after use.

Quick Reference

CommandPurpose
chmodFile/directory permissions (rwx)
chownFile owner and group
chgrpFile group only
chattrKernel-level file attributes (immutable, append-only)
lsattrList extended file attributes
setfaclGrant permissions to specific extra users/groups (ACLs)
getfaclView ACL entries on a file
pwscore / pwmakeCheck or generate a password against the pwquality policy
chagePassword aging and account expiry
chshLogin shell
chfnGECOS / display name fields
chpasswdBatch password updates

See Also