Send a Safe Terminal Announcement with wall

wall broadcasts a message to every logged-in terminal by default, which makes it just as easy to send a private note to the whole machine by mistake.

This guide sends a short message to logged-in terminal users, or to members of one group, while keeping the broadcast scope visible before you press Enter. Allow about ten minutes. This guide uses the packaged /usr/bin/wall on this machine, reporting util-linux 2.39.3 and supplied by the installed bsdutils package, version 1:2.39.3-9ubuntu6.6.

A different wall earlier in PATH may have different packaging, so check the binary before relying on examples.

1. Confirm which wall you will run

Check the path and the local interface without sending anything:

$ command -v wall
/usr/bin/wall
$ /usr/bin/wall --version
wall from util-linux 2.39.3
$ /usr/bin/wall --help

The help output shows the available controls: --group, --nobanner, --timeout, --help and --version. Use the absolute path in a script when you need the packaged behaviour, or resolve PATH deliberately and record what it selected.

Checkpoint: you know the exact executable and have not contacted any terminal yet.

2. Understand the broadcast boundary

wall writes to the terminals of all currently logged-in users by default. It can take the message as an argument, read it from a file, or read it from standard input. That makes it useful for a maintenance warning, but also easy to send a private note to the whole machine by mistake.

Warning: the next command changes other users' terminal sessions. Do not run it on a shared or production host until the text and audience are checked.

3. Send a short message to everyone

For a deliberate all-user announcement, pass the message as one quoted argument:

$ /usr/bin/wall 'Maintenance starts at 22:00. Save work and log out before then.'

Each recipient sees the message with a banner unless you suppress it. The command does not create a file or change a service, so there is no rollback for the delivery itself. If the wording is wrong, send a correction rather than pretending the first message can be withdrawn.

For a message containing several lines, use standard input. A quoted here-document keeps the content together and avoids accidental shell expansion:

$ /usr/bin/wall <<'MESSAGE'
Planned maintenance starts at 22:00.
Save work and log out before then.
MESSAGE

Do not put a variable or command substitution inside an unquoted here-document unless you have consciously reviewed the expansion. The command wraps long lines at 79 characters, pads shorter lines, and adds a carriage return and newline to each line.

4. Limit the message to a group

If the announcement belongs to one Unix group, use its name or numeric group ID:

$ getent group operators
operators:x:1002:alice,bob
$ /usr/bin/wall --group operators 'The operators maintenance window begins at 22:00.'

Here, operators is a placeholder. Replace it only after checking the group database on this host. The option limits printing to members of that group among the users currently logged in; it does not log people in, change group membership or deliver to an offline mailbox. Use the numeric form when that is the stable identifier in your runbook:

$ /usr/bin/wall --group 1002 'The operators maintenance window begins at 22:00.'

Checkpoint: a group message is correctly scoped only if the group name or ID was verified first. An invalid group is rejected before delivery.

5. Choose the banner and timeout

--nobanner suppresses the banner. The local help says this works only for root, so treat it as a privileged presentation choice, not a normal-user option:

# /usr/bin/wall --nobanner 'The maintenance window is now open.'

Use a positive integer with --timeout when a slow or unavailable terminal must not hold the operation indefinitely:

$ /usr/bin/wall --timeout 30 'Maintenance begins in 30 minutes.'

The default timeout is 300 seconds. The timeout is measured in seconds and zero is not accepted. A timeout limits the write attempt; it does not guarantee every recipient saw the complete message.

Only the superuser can write to terminals whose owners have disabled messages, or to terminals used by a program that automatically denies them. Do not reach for sudo by habit. If ordinary delivery is sufficient, keep the command unprivileged. Use elevated access only under your host's change policy, after checking the target and the content.

6. Diagnose without broadcasting again

First check syntax with a harmless query:

$ /usr/bin/wall --help
$ /usr/bin/wall --timeout 0 'test'
wall: invalid timeout argument: 0

The second command should fail before sending because the timeout must be positive. An unknown group is similarly rejected:

$ /usr/bin/wall --group definitely-no-such-group 'test'
wall: invalid group argument: 'definitely-no-such-group'

If a valid command reports a write failure, check which users are actually logged in and which terminals they own. Some sessions are deliberately skipped when their utmp record begins with a colon, to avoid write errors. A user who has disabled messages may also not receive an ordinary broadcast.

Tip: reading a file is another boundary to remember. The local manual says a non-superuser cannot read a file through wall when the program is set-user-ID or set-group-ID. For a sensitive announcement, prefer reviewed standard input or an argument rather than pointing at an arbitrary file.

Done means