8 ms·
One of those left out features is `sudoedit` or `sudo -e`. I use this a lot when editing files in /etc or any file that my user does not have permissions. The f
by hpb42 3y ago
One of those left out features is `sudoedit` or `sudo -e`. I use this a lot when editing files in /etc or any file that my user does not have permissions. The flag first copies the file to a temporary location with permissions for my user to edit, then opens my text editor (defined via $SUDO_EDITOR env var) as _my user_, without any sudo permissions. After I close the editor, the file is copied back with the original permissions only if there were any changes.
The cool thing is running the editor via my user, which loads my user's configuration/plugins, instead of the root user's.
- tambourine_man 3y agoIn Vim: :w !sudo tee % Which I map to :w!! Of course, if you’re not using Vim, you’re doing it wrong :)
- phanimahesh 3y agoIt is a little less useful if the file is not readable by your user, and once you authenticate anything within your vim can also silently run other sudo commands since on most distros sudo remembers the autnentication for a while. Now that I think of it, not sure how sudoedit behaves wrt this cached auth.
- KMnO4 3y agoI think you can use the sudo -k flag to clear the cached auth
- deleted 3y ago[deleted]
- Zardoz84 3y agoI usully use "sudo -E EDITOR_OF_MY_CHOICE"
- liftm 3y agoMany editors can execute shell commands, so this isn't the same at all.
- Denvercoder9 3y agoThat makes your editor run as root, which is a bad idea for many reasons (aside from security, any mistake now has the potential mess with the whole system).
- josephg 3y agoThis would be a great use case for a capability security model. Essentially what you really want is the sudo command to acquire a temporary capability token to edit that specific file. Then run your editor and pass it the capability. (And revoke the capability when the editor process closes). It’s a pity this isn’t more straight forward to implement on Linux.
- quotemstr 3y ago> Essentially what you really want is the sudo command to acquire a temporary capability token to edit that specific file. This should be doable with an XDG portal model, right?
- yakubin 3y agoIt's doable by opening the file in a privileged process (sudo) and passing the file descriptor to a non-privileged process. Maybe one could make a sudoedit that opens a file in sudo process and then spawns a non-privileged editor process which inherits the file descriptor and is given the /dev/fd/ path on the command line, so it stays none the wiser about the whole process.
- vlovich123 3y agoSounds like a bit of recipe for accidentally handing access to an unintended privileged fd through inheritance (ignoring the /dev/fd one) such that a compromised unprivileged SUDO_EDITOR value gives you sudo access. Maybe not likely, but I’d really be hesitant about any feature that relies on implicit fd inheritance…
- yakubin 3y agoClose all other fds between fork and exec then (you can look at the code of base::LaunchProcess in Chromium for an example). It’s a minuscule amount of code to audit compared to XDG portals. And it’s backwards-compatible with decades of unix programs. For a more complicated solution: spawn a zygote process early with a unix socket which you’ll use to send the fd later. Zygote at start drops provileges. When it receives the fd, it closes the socket and execs the editor.
- lucideer 3y ago> One of those left out features They indicate that many omittted features are by design, but this particular one is implied to be planned: > Some functionality is not yet supported; in particular sudoedit
- aumerle 3y agoSo now any program that's running as your user, even your browser, can edit any file you edit with sudo. It just has to watch for your editor to quit and win a race with sudo to modify the file before sudo reads it.
- bombcar 3y agoIt sounds like 90% of "sudoedit" can be done without elevated permissions, assuming your user can read the file.