Skip to content

SysD Manager Proxy

Pier edited this page Mar 10, 2026 · 16 revisions

Why

SysD Manager uses a privileged proxy daemon to perform system-level operations that require root access. Because the SysD Manager, as a GTK4 GUI can't run directly as root.

Context

The /usr/share/dbus-1/system.d/org.freedesktop.systemd1.conf file is a D-Bus policy configuration file used by systemd, the system and service manager for Linux. It defines access permissions for the org.freedesktop.systemd1 D-Bus interface, which is central to controlling and monitoring systemd-managed units, jobs, and system state.

Key Features:

Root Access: The root user is granted full access, including the ability to own the bus name and perform all operations.

Default User Access: Non-root users are denied direct access to most org.freedesktop.systemd1.Manager methods by default, but are allowed to perform read-only queries such as: GetUnit, ListUnits, ListJobs, GetUnitFileState, GetDefaultTarget, and others.

Controlled Modifications: Certain actions like StartUnit, StopUnit, EnableUnitFiles, or SetDefaultTarget are restricted and typically require polkit authorization.

How the Proxy works

The Proxy is systemd service running as root. It forwards Sysd Manager B-Bus calls to systemd.

Architecture diagram and Flow

see Architecture

Polkit policies

What operations go through the proxy

Each operation is individually configurable through Preferences. Users can choose per-operation whether to use the Proxy or fall back to default calls as configured by the local environment (D-Bus policy configuration, Polkit policies).

D-Bus Methods

  • start
  • stop
  • restart
  • clean
  • freeze
  • thaw
  • enable-unit-file
  • disable-unit-file
  • reload-daemon
  • create-drop-in

File action

  • save-file
  • revert-unit-file

Note user session calls doesn't pass trough the Proxy. i.e. If the Unit is on the System bus, the operation (user congigured) goes trough the Proxy.

Why there is no proxy with Flatpak

Because Flakpak can't run as root.

Clone this wiki locally