Edit Files Safely with Vim, Read-Only Modes and AppArmor Syntax
By the end of this guide you will be able to open a file, make and verify a small change, save it deliberately, and use Vim's read-only and restricted modes when the cost of a mistake is high. You will also know how to turn on the installed AppArmor syntax rules for a profile.
The route
Jump straight to the step you need, or tick off Done means at the end.
Prerequisites: a shell, a text file you are allowed to edit, and Vim. The examples use Vim 9.1, from the installed vim-common package version 2:9.1.0016-1ubuntu7.20. Allow 10 to 15 minutes for the first pass. The commands below do not need root. Do not use sudo to edit a file unless you have already confirmed that the file really must be changed as root.
1. Check which Vim you are running
Start by checking the executable and its build. This avoids debugging a personal configuration when the real problem is a different binary.
command -v vim
vim --version | head -8
On the machine used for this guide, the version begins VIM - Vi IMproved 9.1 and reports a Huge build without GUI. Your feature list may differ. In particular, -g cannot provide a GUI when the installed build has no GUI support.
Checkpoint
If command -v vim points somewhere unexpected, stop and inspect your PATH before opening a production file.
2. Open a copy or a named file
Use an explicit path when there is any chance of editing the wrong file. The first file is read into the current buffer.
vim --clean /path/to/example.conf
--clean starts without personal configuration, plugins or viminfo. It is useful for a reproducible check. For ordinary work, vim /path/to/example.conf loads the normal startup files. To edit a filename beginning with a dash, put -- before it:
vim -- --strange-name.txt
If you open several files, Vim starts with the first one. Use :next to move to the next file. A missing file opens an empty buffer, so check the status line and path before typing content.
3. Make one small change and verify the buffer
Vim has separate Normal and Insert modes. When a file first opens, you are in Normal mode. Press i to insert before the cursor, type the change, then press Esc to return to Normal mode.
In Normal mode, :set number shows line numbers. Search with /pattern and press n for the next match. These commands change how the buffer is displayed, not the file on disk.
:set number
/PLACEHOLDER
n
Before saving, compare the buffer with the file's expected location. :file shows the current name, while :set modified? tells you whether the buffer differs from the saved file. A modified result means there are unsaved changes.
Checkpoint
Confirm the path with :file, confirm the intended text is present, and only then continue to saving.
4. Save deliberately, or leave without saving
In Normal mode, :w writes the buffer and :q quits. Use them separately when you want the save result to be visible:
:w
:q
To save and quit in one command, use :wq. To abandon changes, use :q!. The exclamation mark is a destructive boundary: it discards unsaved buffer changes, so check :set modified? first.
After saving, verify from the shell rather than trusting the editor screen:
grep -n 'EXPECTED TEXT' /path/to/example.conf
Vim normally uses a swap file. This supports recovery after a crash. The -n option disables swap files, and also makes recovery impossible, so use it only for disposable or specially controlled work. The -r option lists swap files; -r /path/to/example.conf attempts recovery for that file.
5. Use a safety mode for files you must not change
Open a file read-only when you are inspecting it:
view /path/to/example.conf
view is the same installed Vim program invoked in read-only mode. The equivalent explicit form is vim -R /path/to/example.conf. You can still edit the buffer temporarily, but Vim prevents an accidental write. A deliberate :w! can override that protection, so read-only mode is a guard against slips, not an access-control boundary.
For a stronger editing restriction, vim -M /path/to/example.conf disables modification and writing. The manpage notes that these options can be reset, so do not treat this as a security boundary either. For a command that must not launch shell commands or suspend Vim, use restricted mode:
rvim /path/to/example.conf
rvim is the restricted form of Vim and is equivalent to vim -Z. It is useful when handing an editing session to someone else, but it does not replace operating-system permissions.
Warning
Never test recovery or write overrides against the only copy of an important file. Work on a backup or a disposable copy first.
6. Inspect an AppArmor profile with syntax highlighting
The installed apparmor.vim(5) rules highlight AppArmor profiles so that suspicious permissions and structural mistakes are easier to inspect. Open a profile without changing it:
view /etc/apparmor.d/PROFILE_NAME
Inside Vim, enable the syntax rules explicitly if they were not selected automatically:
:set syntax=apparmor
Verify the setting with:
:set syntax?
The expected result includes syntax=apparmor. The colours are only a visual aid. They do not validate a profile, prove that a rule is safe, or replace AppArmor's own tooling and policy review. The local manual also warns that the rules do not properly detect dark versus light backgrounds, so do not infer meaning from an unreadable colour scheme.
If you need the setting for future sessions, configure your Vim startup files only after testing it interactively. The relevant system and personal files are /usr/share/vim/vimrc and ~/.vimrc. Editing either changes later sessions, so keep the change small and retain a copy of the original.
7. Recover from the common traps
- Vim will not quit: press
Esc, then use:q!if you intend to discard changes, or:wqif you intend to keep them. - The file looks unchanged: check
:set modified?, then check the path with:file. You may have edited a different file or not written the buffer. - A swap warning appears: do not delete the swap file automatically. First decide whether another Vim session is active. If the previous session crashed, inspect the swap list with
vim -rand use recovery mode. - A command-line option is treated as a filename: put options before the file list, or use
--before a filename that starts with a dash. - AppArmor colours are absent: run
:set syntax=apparmorand verify with:set syntax?. A syntax rule is not a policy check.
Done means
- You checked the Vim binary and version before relying on features.
- You confirmed the target path before editing.
- You know how to save with
:w, quit safely with:q!, and recover with-r. - You used
view,-R, or-Mwhen accidental writes were a risk. - You enabled and verified
apparmorsyntax without confusing highlighting with validation.