It seems that lxsession-logout checks with /usr/share/PolicyKit/policy/org.freedesktop.hal.power-management.policy to make sure it is allowed to shutdown or reboot the computer.

I created a second account on a Knoppix 6.2 CD system, put it in the same groups as the knoppix account, gave it the same line as koppix in /etc/sudoers, and then changed USER="knoppix" and GROUP="knoppix" in /etc/init.d/knoppix-startx. Then I logged out of the knoppix account and was automagically logged back in to the new account. I did a recursive diff of the two home directories and didn't see any differences which seemed relevant.

However, unlike the knoppix account, the new account can't shut down the system via a call to lxsession-logout; all that happens is that the new account is logged out and then automatically logged back in again.

polkit-auth shows that the knoppix account has (among many other things) org.freedesktop.hal.power-management.reboot and org.freedesktop.hal.power-management.reboot-multiple-sessions, whereas my new account does not have the -multiple-sessions capability. Further, strace'ing lxsession-logout shows that the -multiple-sessions capability is the one desired.

Q1: given there is only one session, why does lxsession-logout look for org.freedesktop.hal.power-management.reboot-multiple-sessions

Q2: why does the knoppix user get this capability, but not my new account?

If anyone can shed some light on this, I'd appreciate it.

(I can work around this by modifying usr/share/PolicyKit/policy/org.freedesktop.hal.power-management.policy, but I prefer to not mess with things like that if I don't really need to.)

Thanks.

Jim