Linux Tutorial / Understand Users, Groups, and File Ownership
Linux assigns a user ID (UID) to an account and a group ID (GID) to a group. A file records an owning user and group, while an account can have a primary group and supplementary groups. Use id, groups, getent, and ls -l to inspect these relationships. This lesson focuses on reading ownership information without changing any accounts or files' owners.
What user and group IDs mean
A human-readable account name such as learner corresponds to a numeric UID. A group has a name and numeric GID. A user's primary group is the main group recorded in the account data; supplementary groups are additional memberships. Access decisions combine file owner, group, permission bits, and other system rules. Membership alone does not grant the ability to read or modify every file owned by that group.
The administrator account root normally has UID 0. Do not assume ordinary user IDs or group IDs always start at 1000; values depend on system and account policy.
Inspect the current session's user and groups
These commands work for an ordinary user and do not change the account. id shows user and group names alongside numeric IDs. id -un prints the user name, id -gn the primary group name, and id -nG the names of the groups in the current context.
id id -un id -gn id -nG groups
An illustrative id result is uid=1000(learner) gid=1000(learner) groups=1000(learner),10(wheel). Actual names, numbers, and groups vary. The gid=... portion gives the primary group; groups=... lists groups effective in the current session.
groups offers a shorter group-name listing. If an administrator just changed your memberships, an already-open login session may not immediately gain the new group list. Distinguish the account database's configuration from the groups applied to the current process.
Query account data with getent
getent queries account and group databases through the system's Name Service Switch (NSS). Depending on the configuration, results can come from local files or an external directory service. This can reflect actual name resolution better than reading /etc/passwd alone. Query your current account and primary group with:
getent passwd "$(id -un)" getent group "$(id -gn)"
A getent passwd row usually contains colon-separated name, password placeholder, UID, primary GID, description, home directory, and login shell. This does not mean that a plaintext password is shown. A getent group row includes the group name and GID. The member list in a group row need not list everyone whose primary group is that group, so use id when checking a particular user's actual groups.
A minimal installation may not include getent. In that case, consult the lookup tools provided with the installed libc or distribution. Do not casually edit /etc/passwd or /etc/group to change account data.
Read a file's owner and group
Create a practice file to inspect. If ~/linux-course-16-practice exists, choose another name. Stop if mkdir fails; touch can change timestamps when given an existing file.
mkdir ~/linux-course-16-practice cd ~/linux-course-16-practice pwd touch own.txt ls -l own.txt
In an ls -l row, the two names after permissions and link count normally identify the owning user and group. A new file is usually owned by the current user, but its group can depend on the parent directory's settings and file-system behavior; do not assume it always equals your primary group. Size and timestamps also vary.
GNU stat can print names and numeric IDs on one line. %U and %G are owner and group names; %u and %g are their numeric IDs.
stat -c '%U | %G | %u | %g | %n' own.txt
The output could resemble learner | learner | 1000 | 1000 | own.txt, but check your own values. Ownership records who owns the file; permissions are separate information about what actions are allowed. chown changes ownership and can affect real data, so it is deliberately omitted from this read-only exercise.
Keep three distinctions clear
- User name versus UID: The name is for display and lookup; the system also uses the numeric ID.
- Primary versus supplementary groups: Distinguish the account's one primary group from the groups present in a session.
- Account data versus a current session: Database changes may not update group memberships in a session that is already open.
When investigating a permission problem, first run id for the session's user and groups, then ls -l or stat for the target file's owner and group. Compare those results before examining permission settings.
Official documentation
The GNU Coreutils manual documents id, groups, ls, and stat. The getent(1) manual and nsswitch.conf(5) manual explain account-data lookup.









