HowTo: Save A File In Vim / Vi Without Root Permission

Posted on in Categories , , last updated May 20, 2015

This happens lot of times. I login as a normal user and start to edit httpd.conf or lighttpd.conf or named.conf in vim / vi text editor. However, I’m not able to save changes due to permission issue (all config files are owned by root). How do I save file without creating a temporary file (/tmp/httpd.conf) and then move the same (mv /tmp/httpd.conf /etc/httpd) as root using vim / vi itself?

You can use the combination of tee and sudo command (assuming that sudo is configured for your account) to save a file without creating a third file in /tmp. This is useful to write a privileged file with sudo command.

Examples

In this example, you will edit a file called /etc/apache2/conf.d/mediawiki.conf as a normal user:

$ vi /etc/apache2/conf.d/mediawiki.conf

Make some changes and try to save by pressing :w, enter:

Fig.01: Vim Cannot Open File (Permission Problem)
Fig.01: Vim Cannot Open File (Permission Problem)

To save a file, simply type the following command:

:w !sudo tee %

Fig.02: Save a file using sudo and tee
Fig.02: Save a file using sudo and tee

Where,

  • :w – Write a file.
  • !sudo – Call shell sudo command.
  • tee – The output of write (vim :w) command redirected using tee. The % is nothing but current file name i.e. /etc/apache2/conf.d/mediawiki.conf. In other words tee command is run as root and it takes standard input and write it to a file represented by %. However, this will prompt to reload file again (hit L to load changes in vim itself):
Fig.03: Save and Load File In Vim Again Without Login As Root
Fig.03: Save and Load File In Vim Again Without Login As Root

Update ~/.vimrc file

Open/Edit ~/.vimrc file and append the following code:

command W :execute ':silent w !sudo tee % > /dev/null' | :edit!

Save and close the file. Open vim/vi and try to edit a privileged file with:
$ vi /etc/hosts
Now, write a privileged file with custom command just type W:

Fig.04 VIM write a privileged file custom W command
Fig.04 VIM write a privileged file custom W command

Now, sudo requires that you authenticate yourselves with a password:
Fig.05: Sudo in action inside vim
Fig.05: Sudo in action inside vim

A note about sudo config

Make sure you add yourself to sudo file. Here is my configuration (run ‘sudo visudo‘ OR ‘su -‘ and ‘visudo‘):

# User privilege specification
root    ALL=(ALL) ALL
%admin  ALL=(ALL) ALL

Make sure you add yourself to admin group:
# usermod -a -G admin vivek
# id vivek

Sample outputs:

uid=501(veryv) gid=20(staff) groups=20(staff),80(admin),81(_appserveradm),98(_lpadmin),33(_appstore),100(_lpoperator),204(_developer)

Optional: Try vim plugins to write/edit a privileged file

Posted by: Vivek Gite

The author is the creator of nixCraft and a seasoned sysadmin and a trainer for the Linux operating system/Unix shell scripting. He has worked with global clients and in various industries, including IT, education, defense and space research, and the nonprofit sector. Follow him on Twitter, Facebook, Google+.

46 comment

  1. Wow, I can’t believe I never thought of that before.

    I added this to my .vimrc that I sync on every machine I administrate based on what you wrote:

    if has(“unix”)
    command -nargs=? Swrite :w !sudo tee %
    endif

  2. I have a :SudoW command in my vimrc that does exactly this. I got it from some one else’s blog at some point and can’t seem to find out where, at this point. Here is the snippet though.

    command! -bar -nargs=0 SudoW :silent exe “write !sudo tee % >/dev/null” | silent edit!

  3. not working for me

    :w !sudo tee%
    !sudo teea
    [No Valid Runas is Matched]
    Sorry, user xxxxx is not allowed to execute ‘teea’ as anyone on newss1.
    sudo: teea:command could not found.
    Check the path or specify path plus command.
    [Hit return to continue]
    :q
    No write since last change (:quit! overrides)
    [Hit return to continue]

    Tried with space as well after tee command

    Regards,
    Manoj

  4. @Manoj,

    Put a white space between tee and %
    :w !sudo tee %
    You must configure sudo. You use sudo for admin task, don’t you?, A typical /etc/sudoers for admin users:

    %admin ALL=(ALL) ALL

    And add your self to admin group (use usermod).

  5. This is an awesome trick, but I don’t get why the password is not asked ?

    This mean whoever get my user access can changes files on /etc/ without knowledge of the sudo password ?

  6. Nice – but – sudo on my PC is configured to ask my password for every sudo call.
    But then this tip fails, because I can see sudo requesting my password, waiting one second, then, as if I entered a wrong passwd, it fails, until three times, and I get rejected without beeing able to type my password in.
    So, will this tip only work if sudo is configured not to ask password?
    Did you test it?
    If so, do you know why sudo is getting an entry? I do not type anything, but it seems to get some input through the [:w !sudo tee %] command.
    Of course, I tried to type in my password – it failed.

  7. @Vivek,

    No, that is not related to sudo parameters.
    If found this: This tip works for [vi] or [vim],
    but I have got this problem only with [gvim] – which is odd but true.

  8. @Philippe,

    I see we are talking about GUI here. Have you tried out gui version of sudo gksudo instead of sudo? Try it on dummy file as gksudo some time provides real weird results when combined with shell utilizes (may be steams are not connected but dunno).

    HTH

  9. @Vivek,
    I just tried gksudo in place of sudo, it fails because :
    – I enter :w ! gksudo tee %
    – Then, I get a new line – no prompt – I try to enter my password, nothing happens,
    I quit by , and then file is overwritten, but emptied by the procedure!
    (also tried with gksudo -P)
    So, in a way – it works ;-) file is wiped… :-/
    That was a nice idea anyway!

  10. @Philippe,

    I’m out of ideas for gvim here and I guess it is related to GUI. Both stderr and stdout are terminal streams. And GUI version of gvim accept messages from user input devices (??), not from stdin so I guess you are getting empty file as a result. May be you need to patch gksudo to accept stderr or come with some sort of wrapper (we do this all the time with php-cgi and perl cgi fastcgi). Please update us if you find any other solution to your problem.

  11. Nice tip..but unfortunately it doesn’t work for me. I have followed discussion here and implemented the same thing …oh forget to tell that I am on Gentoo.
    1)I have used sudo before run this command..(so that’s in history)
    2)say I have open /etc/ntp.conf and once I passed the recommendation like this
    :w !sudo tee %
    it asked for password(that’s fine..if the time elapsed)

    but says “Press enter to continue..”

    @ Vivek

    any idea??

    Cheers!

    1. No idea, check /var/log/secure (RHEL / CentOS) or /var/log/auth.log (Debian and friends) logs details about sudo command and failed attempts. This may provide additional help. I’ve used this many times under Debian and RHEL based servers.

  12. How stupid can this post possibly get? If a username is already in sudo then he/she can just become root and edit a file.
    If a username is configured only to do certain things like edit config files then there should be be no problem in editing that file to begin with, just use “sudo su”.

    1. Exactly, this is a good post because if you are vim’ing a file and have spent a lot of time and effort, and then realize you don’t have rights to :w the edits, then this is a perfect quick solution.

  13. @Shane shouldn’t be calling anyone stupid when your typing sudo su. Try reading the sudo man page. The purpose of the post was to show you how to edit a file, you don’t have permissions to, without closing your editor and opening it again within sudo.

  14. @ all,

    i need to configure insult para in sudo file after given correct para it doesn’t work for me any ideas…?
    para :- Defaults instults
    :wq!

    but same message shown after configure “Sorry, try again.”

  15. :w !sudo tee %

    says:

    :w !sudo tee %
    Password:Sorry, try again.
    Password:
    Sorry, try again.
    Password:
    Sorry, try again.
    sudo: 3 incorrect password attempts

    shell returned 1
    Press ENTER or type command to continue

  16. Please help me! ANYONE !?!?!
    As you can see I’m a noob… please help me :D
    I logged in a ‘root’ etc but when I used this command ‘vi BLAHBLAH.conf’
    I can’t edit anything ;( why is this and how do I fix?

  17. I think a nicer solution that doesn’t require piping the document through tee would be to write it to a temporary file and then sudo mv tmp % – more complex to type in but if you are mapping it as a command it can be as complex as needed.

  18. If you are using this method, constantly forgetting what user account you are using, you might not want to be editing a root owned file. Maybe. If you MUST create sudo rules, specify them. Telling a new Linux user/admin to use the admin group, and then allow ALL COMMANDS to ALL HOSTS? I simply have nothing nice to say about it. Instead, I would refer you to a book called “Sudo Mastery” by Michael W. Lucas, and wish you the best of luck.

Leave a Comment