Home / Alt manpages / rnano(1)

  • rnano(1)
  • User command
  • linux

Edit One File Without Opening the Rest of the System with rnano

You will finish with a repeatable way to edit a named file while limiting nano's file and shell features. The installed command is GNU nano 7.2 from package version 7.2-2ubuntu0.2. The restricted behaviour described here comes from the installed rnano(1) manual, so check your own version before relying on a detail in an automated workflow.

Allow about ten minutes. You need a terminal, a file you are allowed to edit, and write permission on its directory. No elevated privilege is normally needed. This guide does not use sudo, change a system configuration, or alter a service.

1. Check the command before opening a file

Ask the installed program for its version and help. These are read-only commands:

$ rnano --version
GNU nano, version 7.2
$ rnano --help
Usage: nano [OPTIONS] [[+LINE[,COLUMN]] FILE]...

Your help text will contain many nano options. The useful contract for this guide is the final argument: give rnano the file or files that are explicitly in scope. The + form can select a starting line and column, for example +25,1.

Checkpoint: confirm that the command resolves to the binary you expect:

$ command -v rnano
/usr/bin/rnano
$ dpkg-query -W -f='${Package} ${Version}\n' nano
nano 7.2-2ubuntu0.2

Package versions differ between distributions. Treat the version printed by your host as authoritative for that host.

2. Prepare a disposable test file

Test the workflow in a directory where a mistake cannot damage a useful document. The following commands create and display a temporary file; they do not need root:

$ test_dir="/tmp/rnano-demo"
$ mkdir -p -- "$test_dir"
$ printf 'first line\nsecond line\n' > "$test_dir/notes.txt"
$ ls -l -- "$test_dir/notes.txt"
-rw-r--r-- 1 user user 24 ... /tmp/rnano-demo/notes.txt

The owner, group, timestamp and exact size vary. If you use a real document instead, make a backup first. Saving in an editor is a state change, and a restricted editor does not replace your normal backup process.

To remove this disposable test later, use the exact path you created:

$ rm -- "$test_dir/notes.txt"
$ rmdir -- "$test_dir"

Those removal commands are irreversible. Do not adapt them to a directory containing anything you have not checked.

3. Open only the named file

Start rnano with the test file as its explicit target:

$ rnano "$test_dir/notes.txt"

Nano opens an interactive terminal screen. Edit the text with ordinary typing. The usual control-key help is displayed at the bottom; ^ means the Control key. Press Ctrl-O to write the current buffer, confirm the displayed filename, then press Ctrl-X to exit. If you changed nothing, exiting should not require a save.

Checkpoint: after leaving rnano, inspect the file without opening it in another editor:

$ sed -n '1,5p' -- "$test_dir/notes.txt"
first line
second line

If you added a line, it should appear here. If the save prompt shows a filename you did not intend to change, cancel it rather than confirming. A failed or cancelled save leaves the previous file in place unless you deliberately overwrote it.

4. Understand what restricted mode blocks

rnano runs nano in restricted mode. It limits the session to the file or files supplied on the command line and removes several escape routes that ordinary nano provides:

  • You cannot suspend the editor to a shell.
  • You cannot save the current buffer under a different name.
  • You cannot insert another file or open a new buffer.
  • You cannot append to or prepend to another file.
  • rnano does not make backup files and does not provide spell checking.

These limits are useful when the editing task should stay attached to a known path. They are not a complete security boundary. The editor still needs permission to read and write the named file, and a process that launches rnano may already have other access. Keep the terminal and operating-system account trustworthy.

Restricted mode also does not make a file safe to overwrite. Before editing an important file, copy it to a checked backup name in the same filesystem:

$ cp --preserve=all -- /path/to/settings.conf /path/to/settings.conf.before-rnano
$ rnano /path/to/settings.conf

After checking the result, keep the backup until you know the change is correct. To recover, restore it explicitly:

$ cp --preserve=all -- /path/to/settings.conf.before-rnano /path/to/settings.conf

Do not restore a backup over a live service configuration without checking the service's documented reload or restart procedure. That can change service behaviour immediately or at the next restart.

5. Start at a known location when needed

For a long file, pass a line number after the plus sign:

$ rnano +25 /path/to/notes.txt
$ rnano +25,1 /path/to/notes.txt

The first form starts at line 25. The second also requests column 1. These are navigation hints, not a request to edit a different file. If the file has fewer lines, nano's behaviour is version-specific enough that you should confirm the cursor position before typing.

6. Diagnose the common failure modes

If rnano cannot open a path, first check it without changing anything:

$ ls -l -- /path/to/notes.txt
$ test -r /path/to/notes.txt && echo readable
$ test -w /path/to/notes.txt && echo writable

A missing file, a read-only file, and a directory without write permission are different problems. Do not jump to sudo to hide the distinction. If the file is deliberately protected, stop and obtain the correct change process instead.

If you need a normal nano feature that rnano blocks, use ordinary nano only after confirming that the broader file access is acceptable. Switching commands changes the safety boundary; it is not a harmless workaround.

Done means

  • You checked the installed rnano and nano versions.
  • You opened only the intended path and saved it deliberately.
  • You verified the result with a separate read-only command.
  • You understand that restricted mode blocks extra file and shell operations, but does not replace permissions or backups.
  • You have a checked backup and an explicit restore command for important files.