Computing and the Command Line

Root and sudo

Root can do anything, which is why you don't work as root. Ubuntu locks the root account and grants power one command at a time through sudo, with your own password and a short grace period; since Ubuntu 25.10 that sudo is sudo-rs. su versus sudo, sudo -i and sudo -l, editing system files with sudoedit, the redirection trap and the tee fix, and adding users and giving them sudo.

  • 7 min
  • 8 steps
  • 3 questions
  • Lesson 9 of 80

In this lesson

  1. The superuser
  2. How sudo works
  3. su, the older way
  4. The redirection trap
  5. Editing system files
  6. Users and the sudo group
  7. Your turn
  8. So

The superuser

One account, root (user ID 0), skips every permission check: it can read, change, or delete any file and change any setting 1. That’s what system administration needs, and it’s exactly why you shouldn’t work as root day to day. A typo or a malicious program running as root can damage the whole system; running as an ordinary user, the damage stops at your own files 1.

Unix has always separated users from administrators and handed out root’s power only when it’s needed. Windows’ habit of letting everyone run as administrator gives malware free rein; running Linux as root all the time throws away the main thing that protects it 1.

How sudo works

Ubuntu locks the root account: it has a password hash that matches nothing, so nobody can log in as root 2. Instead you put sudo (“superuser do”) in front of one command at a time 2 1:

me@linuxbox:~$ apt update
E: Could not open lock file /var/lib/apt/lists/lock - open (13: Permission denied)
me@linuxbox:~$ sudo apt update
[sudo: authenticate] Password:
  • sudo asks for your own password, not root’s 2 1.
  • It checks the rules in /etc/sudoers to see whether you’re allowed to run that command 1. On Ubuntu, members of the sudo group may run anything 2.
  • After you authenticate it trusts you for a few minutes (5 in the classic sudo’s default settings), so a string of sudo commands asks only once 3 1.
  • Every use is logged, so there’s a record of who did what as root 2.

From Ubuntu 25.10 on, the sudo command is sudo-rs, a rewrite in the Rust language; it works the same way for ordinary use 2.

Useful forms 1:

me@linuxbox:~$ sudo -l              # what am I allowed to run?
me@linuxbox:~$ sudo -i              # a full root shell (prompt ends in #); exit to leave
me@linuxbox:~$ sudo -u sam ls ~sam   # run as some other user

Use sudo -i sparingly, for a burst of admin work, and exit as soon as you’re done.

Quick check

When sudo asks for a password on Ubuntu, whose password is it?

su, the older way

su (“substitute user”) starts a shell as another user, by default root, and asks for that user’s password 1. su - gives you root’s full login environment. Since Ubuntu’s root has no password, plain su doesn’t work there, and modern distributions have moved to sudo 1 2. You’ll still see su - in older guides and on Fedora or Debian systems where a root password was set.

Two terminals. The first, which fails: sudo echo 3 > /sys/class/backlight/x/brightness prints bash: Permission denied. Steps: 1, your shell, running as you, opens the file for the > redirection; 2, it isn't allowed, so everything stops; 3, sudo would only have made echo run as root. The second, which works: echo 3 | sudo tee /sys/class/backlight/x/brightness prints 3. Steps: 1, you run echo and the shell makes a pipe; 2, sudo runs tee as root; 3, tee, as root, opens and writes the file. Also works: sudo sh -c 'echo 3 > file', and sudoedit /etc/some.conf.
Redirection is done by your shell, before sudo runs. Credit: StudyCorner diagram · CC BY 4.0 · Source

The redirection trap

This looks right and fails 4:

me@linuxbox:~$ sudo echo "Welcome to linuxbox" > /etc/motd
bash: /etc/motd: Permission denied

The > isn’t part of echo’s command. Redirection is done by your shell, which reads the whole line first, opens /etc/motd for writing, and only then starts sudo echo .... Your shell is running as you, so opening the file fails before sudo ever runs 4. The same goes for | and <: the shell does them, not the program.

The fix is to give root’s power to the program that opens the file 4:

me@linuxbox:~$ echo "Welcome to linuxbox" | sudo tee /etc/motd
me@linuxbox:~$ echo "one more line" | sudo tee -a /etc/motd     # -a appends

tee copies its input to a file (and to the screen); run with sudo, it’s the one opening the file, as root. Add > /dev/null if you don’t want the echo on screen.

Quick check

Why does sudo echo hello > /etc/motd fail with Permission denied?

Editing system files

To change a file in /etc, don’t run your editor as root. Use sudoedit (same as sudo -e) 5:

me@linuxbox:~$ sudoedit /etc/hosts

sudoedit copies the file somewhere you can write, opens your editor as you, and copies the result back as root when you save. Your editor, its plugins, and its settings never run as root 5. The editor it uses comes from the EDITOR variable (module 5); nano is the friendly default.

The sudo rules themselves, /etc/sudoers, are edited only with sudo visudo, which locks the file and refuses to save it with a syntax error 6. A broken sudoers file can lock you out of sudo entirely.

Users and the sudo group

Ubuntu’s own tools for accounts 2:

me@linuxbox:~$ sudo adduser sam               # new user, asks for a password and details
me@linuxbox:~$ sudo usermod -aG sudo sam      # give sam full sudo rights
me@linuxbox:~$ sudo passwd -l sam             # lock sam's password
me@linuxbox:~$ sudo deluser sam               # remove the account (the home folder stays)
me@linuxbox:~$ passwd                          # change your own password

The first account created when Ubuntu is installed (or the one you made when setting up WSL) is already in the sudo group 2.

Quick check

Which command gives an existing user named sam full sudo rights on Ubuntu?

Your turn

Exercises

  1. Run sudo -l. What does it say you may run?
  2. Run sudo whoami, then whoami. Run sudo -i, then whoami and pwd, then exit.
  3. Try sudo echo test > /etc/test-file. Read the error, then do it correctly with tee. Check with cat, then remove it with sudo rm /etc/test-file.
  4. Run ls -l /etc/sudoers. Can you read it? Can you with sudo?
  5. Create a test user practice, add it to a new group crew, check with id practice, then delete both (sudo deluser practice, sudo delgroup crew).
Answers
  1. On your first account: (ALL : ALL) ALL, meaning any command as any user.
  2. sudo whoami prints root; plain whoami prints your name. In the sudo -i shell, whoami is root and pwd is /root, and the prompt ends in #.
  3. The first fails with Permission denied (your shell can’t open the file). echo test | sudo tee /etc/test-file works.
  4. It’s -r--r----- root root: no access for you. sudo cat /etc/sudoers works, but edit it only with sudo visudo.
  5. sudo adduser practice (answer the prompts), sudo addgroup crew, sudo adduser practice crew, then id practice lists crew. sudo deluser practice and sudo delgroup crew clean up; sudo rm -r /home/practice removes the leftover home folder.

So

Work as an ordinary user and borrow root’s power one command at a time with sudo, which asks for your own password and trusts you for a few minutes. Remember that redirection happens in your shell, so write root-owned files with sudo tee or sudoedit, and manage users with adduser, usermod -aG, and passwd.

Lesson complete

Nice work.

1day streak
0/1today's goal
–correct

Up next · 6 min

Standard Input, Output, and Error

Next lesson
Sources for this lesson
  1. 1
    William Shotts. The Linux Command Line, Seventh Internet Edition (25.12A). LinuxCommand.org (print edition by No Starch Press). 2026. verifiedFree CC BY-NC-ND 3.0 book, release 25.12A of July 18, 2026. Part 1, Learning the Shell: the shell and terminal emulators, prompts ($ vs. # for the superuser), command history (most distributions keep the last 1,000 commands), Shift-Ctrl-C/V for copy and paste; navigation and the directory tree; exploring the system (ls options and the long listing, file, less, the guided tour of /, symbolic links); manipulating files (wildcards and character classes, mkdir, cp, mv, rm, ln; no undelete, test wildcards with ls first); working with commands (four kinds of commands, type, which, help, --help, man and its sections, apropos, whatis, info, alias); redirection; expansion and quoting; Readline keyboard tricks, completion, history search; permissions; processes. Later parts cover the environment, vi, packages, storage, networking, find, archiving, regular expressions, text processing, and shell scripting.
  2. 2
    User management (Ubuntu Server documentation). Canonical. verifiedUbuntu disables the root account by giving it a password hash that matches nothing; sudo lets an authorized user elevate privileges with their own password, providing accountability. From Ubuntu 25.10 sudo is provided by sudo-rs (Rust), with the original sudo kept as sudo.ws through 26.04 LTS; most use is unchanged. sudo passwd enables root, sudo passwd -l root disables it. The installer's first user is in group sudo, which /etc/sudoers authorizes; add others to that group for full sudo. Local users in /etc/passwd and groups in /etc/group; UID 0-99 preinstalled system users, 100-999 dynamic system users, 1000 and up regular users. adduser, deluser (home folder kept), passwd -l/-u, addgroup, adduser user group.
  3. 3
    Todd C. Miller. Sudoers Manual. sudo.ws. verifiedThe sudoers policy and file format. After authenticating, a user may use sudo without a password for a short time, 5 minutes unless changed with the timestamp_timeout option; env_reset and related options control which environment variables pass through.
  4. 4
    Anish Athalye, Jon Gjengset, Jose Javier Gonzalez Ortiz. Course Overview + The Shell (The Missing Semester of Your CS Education, 2020). MIT CSAIL. 2020. verifiedCC BY-NC-SA. Explains ls -l permission bits (directory x is 'search' permission), streams and redirection (<, >, >>, |), root and sudo, and why sudo echo 3 > brightness fails: operations like |, >, and < are done by the shell, not the program, and the shell runs as you, so the shell's attempt to open the file is denied; echo 3 | sudo tee brightness works because tee, running as root, opens the file. Exercises: write a script with a shebang, chmod it executable, and run it.
  5. 5
    Todd C. Miller. Sudo Manual (sudo, sudoedit). sudo.ws. verifiedsudo executes a command as another user, by default root, under the security policy; -l lists allowed commands, -i runs a login shell, -u picks the user. sudoedit (sudo -e) makes temporary copies of the files owned by the invoking user, runs the editor named by SUDO_EDITOR, VISUAL, or EDITOR as that user, then copies changed files back to their original locations.
  6. 6
    Todd C. Miller. Visudo Manual. sudo.ws. verifiedvisudo edits the sudoers file safely: it locks the file against simultaneous edits, performs validity checks, and will not save changes with a syntax error, offering to re-edit with the cursor on the bad line.