The GID Audit
In Ubuntu Linux, just as user ownership is tracked by a numerical UID, group ownership is tracked by a numerical Group ID (GID). When a group is deleted from the system (for example, if a department like marketing is disbanded and their group is removed from /etc/group), their files are not automatically destroyed. Instead, the files are left orphaned, owned by a raw GID number that no longer maps to a textual group name. To securely clean up a shared file server, you cannot search by group name. You must explicitly query the filesystem for the raw numerical GID.
Using the find Command with -gid
The Linux find command utilizes the -gid flag to search for files based exclusively on the exact numerical identifier of the owning group.
- Open your Terminal application (Ctrl + Alt + T) or log into your server via SSH.
- To search the entire
/srv/data/directory for any files owned by GID 2045 (perhaps the old marketing department), type the following command exactly: sudo find /srv/data/ -gid 2045- Press Enter and provide your administrator password.
Targeting Orphaned Access
The -gid flag is the only reliable method to audit a system after a group deletion. If you attempt to use the standard -group marketing command after the group has been removed, the command will simply crash with an “invalid group” error. By passing the raw integer to -gid, you bypass the system’s naming abstraction entirely, allowing you to instantly locate every single abandoned document and shared folder that belonged to the deleted group, ensuring you can securely reassign permissions using chgrp.