You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

非root用户通过DBus执行关机操作遇权限拒绝问题求助

解决Yocto中通过systemd-logind D-Bus执行PowerOff的权限问题

一、调整DBus策略文件的正确方式

  • 不要直接修改/etc/dbus-1/system.conf,优先使用/etc/dbus-1/system.d/logind.conf——该目录下的配置会覆盖默认策略,且更符合DBus的配置规范。
  • 配置需精准匹配调用场景,针对user1的最小权限示例如下(替换你之前的冗余配置):
<busconfig>
  <policy user="user1">
    <!-- 允许调用logind的PowerOff方法 -->
    <allow send_destination="org.freedesktop.login1"
           send_interface="org.freedesktop.login1.Manager"
           send_member="PowerOff"/>
    <!-- 允许获取服务属性(部分场景依赖) -->
    <allow send_destination="org.freedesktop.login1"
           send_interface="org.freedesktop.DBus.Properties"/>
  </policy>
</busconfig>
  • 配置后重启DBus服务生效:systemctl restart dbus,注意检查XML语法(引号、标签闭合),语法错误会导致DBus启动失败。

二、绕过logind内部权限验证(无Polkit场景)

即使DBus策略允许,logind默认仅允许root或活跃会话用户执行关机操作,需修改logind配置关闭授权检查:

  1. 编辑/etc/systemd/logind.conf,添加或修改:
[Login]
AllowPowerOffWithoutAuthorization=yes
  1. 重启logind服务:systemctl restart systemd-logind

三、调试排查方法

  • 查看DBus日志定位拒绝原因:journalctl -u dbus,日志会明确显示是哪条策略阻止了请求。
  • 用dbus-send模拟应用调用(切换到user1执行):
dbus-send --system --print-reply --dest=org.freedesktop.login1 /org/freedesktop/login1 org.freedesktop.login1.Manager.PowerOff boolean:true

根据输出的错误信息直接定位权限卡点。

  • 验证DBus策略是否生效:使用busctl查看当前连接的权限规则,或检查策略加载情况:
busctl introspect org.freedesktop.DBus /org/freedesktop/DBus org.freedesktop.DBus.Policy

四、额外检查项

  • 确认user1加入了power用户组(部分系统中该组默认拥有关机权限):usermod -aG power user1
  • 检查应用是否确实以user1身份运行:ps aux | grep <你的应用名>

内容的提问来源于stack exchange,提问作者Rowan Klein Gunnewiek

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 06:24:57