restricted \write18 enabled: Not an Error—What to Check Next

You ran a build, it failed, and while scrolling the log you found this near the top:

restricted \write18 enabled.

It is an informational LaTeX message, not an error. It means restricted shell escape is active: TeX can run certain permitted external commands.

If your build failed, look further down the log for the first error message—often a line beginning with !. Start with that error and its surrounding lines, rather than changing shell-escape settings just because you saw this status message.

What the line actually means

\write18 is TeX’s mechanism for running shell commands during compilation — historically, stream 18 was the one wired to the operating system. A package can use it to call external programs mid-build: syntax highlighters, plotting tools, image converters.

Running arbitrary shell commands from a document you may have downloaded from the internet is, obviously, a security hazard. So modern TeX distributions ship with a compromise: restricted mode. A short, vetted whitelist of safe programs (like bibtex, kpsewhich, epstopdf) is allowed to run; everything else is blocked. The log line is simply the engine announcing this default state:

  • restricted \write18 enabled — the normal, safe default. Whitelisted helpers can run, nothing else.
  • \write18 enabled (no “restricted”) — full shell access is on, because you passed -shell-escape.
  • \write18 disabled — shell access is fully off, usually via -no-shell-escape.

It’s an informational status line, printed before your document is even read. It cannot be the reason your build failed.

So where is the real error?

Further down. In a TeX log, actual errors start with ! at the beginning of a line — for example:

! Undefined control sequence.
l.42 \includegraphcis
                      {fig/tree.pdf}

Search the log for a line starting with ! (in a text editor, search for a newline followed by !), and read the l.<number> line below it — that’s the file line where TeX gave up. If there’s no ! at all, check for Emergency stop or a missing-file message like LaTeX Error: File '...' not found.

When you actually need \write18

Some packages genuinely need to run external programs, and restricted mode is not enough for them. The usual suspects:

  • minted — calls Pygments for syntax-highlighted code listings
  • gnuplottex / pgfplots with external data pipelines — call gnuplot
  • svg — calls Inkscape to convert SVG figures
  • tikz externalization — compiles each TikZ picture as a separate job to speed up rebuilds

These packages fail with messages like Package minted Error: You must invoke LaTeX with the -shell-escape flag — which is your cue, and the only situation where changing the default makes sense. Add the flag to your compile command:

xelatex -shell-escape -synctex=1 main.tex

One honest caution: -shell-escape means the document can run any command your user can. That’s fine for your own manuscript; it’s worth a moment’s thought before compiling a .tex file a stranger sent you. Turn it on for projects that need it, not globally.

Setting it per project in texspark

In texspark, the build command is an editable shell command, remembered per project — so -shell-escape lives only where it belongs. Edit the command in the Terminal panel’s header (or Preferences → Compile) for the project that needs it:

xelatex -interaction=nonstopmode -synctex=1 -shell-escape {file}

Your other projects keep the safe default. And when a build does fail, the Issues panel has already parsed the log for you — every ! error listed with its file and line, one click from the offending spot. No scrolling past status lines that were never the problem.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *