5 ms·
sudo $EDITOR launches the editor itself as root, sudo -e launches the editor as a regular user on a temporary copy of the original file, and copies the contents
by hvdijk 5y ago
sudo $EDITOR launches the editor itself as root, sudo -e launches the editor as a regular user on a temporary copy of the original file, and copies the contents back over to the original file when you are done. The less done as root, the less opportunity to mess things up.
- stardenburden 5y agoCouldn't a malicious actor edit the temporary file without the user who invoked sudo -e noticing?
- lysium 5y agoYes, I think she can. I think this is better than running the whole editor as root.
- deleted 5y ago[deleted]
- daptaq 5y agoPerhaps, but you will still overwrite it when you exit the editor and let sudo copy the contents back (that being said, there might be a race condition between closing the editor and sudo noticing that the process has terminated). Not sure if this would work, but a possible workaround could be to use /dev/shm (https://www.kernel.org/doc/gorman/html/understand/understand015.html https://www.kernel.org/doc/gorman/html/understand/understand...).
- hvdijk 5y agoThe temporary file should be created in such a way that other users cannot modify it. If that does not happen, if other users can modify it, I would regard that as a bug. Malicious processes running as the same user could potentially modify the file, but if you have malicious processes running as a user with sudo privileges you have probably already lost.