Configure systemd-logind Safely with a Drop-In

One bad HandleLidSwitch setting in logind.conf can suspend a production server the moment someone shuts a laptop lid. This guide gets you creating a small local override for systemd-logind, reloading the service, and keeping an easy undo path.

The examples use systemd 255.4-1ubuntu8.17, reported by the installed systemd --version. Allow about fifteen minutes, including a logout or lid-switch test. You need a shell and sudo access for the changes.

Warning: This guide changes login-manager behaviour. A setting such as HandleLidSwitch=hibernate can suspend or power off a machine when a physical lid or key event occurs. Read the complete example before applying it, and keep an existing remote session open while testing on a server.

1. Choose one behaviour to change

logind.conf contains many unrelated controls, so start with one concrete requirement. For a laptop, this example makes closing the lid lock sessions rather than suspend the machine:

[Login]
HandleLidSwitch=lock

Do not assume a setting will win against a desktop environment. A graphical session can take a low-level inhibitor lock for lid, power or sleep handling. When it does, logind does not act on that event and the Handle* values are irrelevant.

2. Inspect the installed baseline

Use ordinary, read-only commands to see which configuration files exist and to record the service state:

$ systemd --version
$ systemctl status systemd-logind.service --no-pager
$ find /usr/lib/systemd/logind.conf.d /usr/local/lib/systemd/logind.conf.d /etc/systemd/logind.conf.d -maxdepth 1 -type f -name '*.conf' -print 2>/dev/null

The main file may be under /usr/lib/systemd/ or /etc/systemd/. Do not edit a vendor file in /usr/lib. A local drop-in under /etc/systemd/logind.conf.d/ has higher precedence and survives package upgrades.

Checkpoint: if the final command prints no paths, that is fine. It means there are no matching drop-ins in those directories, not that logind has no defaults. Defaults are compiled into systemd and are commonly shown as comments in the main file.

3. Create the local drop-in

This is the first privileged step. The directory and file are local administrator state, so use a descriptive numeric prefix and write only the option you intend to change:

$ sudo install -d -m 0755 /etc/systemd/logind.conf.d
$ sudo tee /etc/systemd/logind.conf.d/90-local-lid.conf >/dev/null <<'EOF'
[Login]
HandleLidSwitch=lock
EOF

Shell redirection is deliberately sent to /dev/null; sudo applies to tee, which opens the root-owned file. Check the exact contents before reloading:

$ sudo sed -n '1,20p' /etc/systemd/logind.conf.d/90-local-lid.conf
[Login]
HandleLidSwitch=lock

Drop-ins are sorted lexicographically across the configuration directories. For a single-value option, the last assignment wins, so a later file such as 99-vendor-test.conf or another local file could override this one. Avoid duplicate assignments unless the ordering is intentional.

4. Reload logind and check for errors

Reload the service so it reads the changed configuration:

$ sudo systemctl reload systemd-logind.service
$ systemctl show systemd-logind.service -p ActiveState -p CanReload --no-pager
ActiveState=active
CanReload=yes

The exact output can include additional properties, but an active service and CanReload=yes are the useful checks on this system. Then inspect recent service messages:

$ systemctl status systemd-logind.service --no-pager
$ journalctl -u systemd-logind.service -b --no-pager -n 30

For a syntax or value error, stop before testing a lid or power key. Read the journal, correct the drop-in, and run the reload again. A reload is preferable to a full restart while sessions are active, but it still changes behaviour for future events.

5. Test the event without guessing

Test the exact event on the target machine. For a lid setting, save work first and keep a second access method available. HandleLidSwitch=lock asks logind to lock all running sessions when logind handles the switch; it does not guarantee a desktop environment will use its own lock screen in exactly the same way.

For a non-hardware setting, use a direct observation instead. After changing RuntimeDirectorySize=20%, log out fully and log in again, then inspect the per-user runtime mount:

$ findmnt -T "$XDG_RUNTIME_DIR" -o TARGET,FSTYPE,OPTIONS
$ df -h "$XDG_RUNTIME_DIR"

The mount is a tmpfs and its displayed size should reflect the configured safety limit. Memory is consumed as files are created, so a large displayed limit does not mean memory has already been reserved.

6. Undo the change

Removing the drop-in is reversible, but it is still a privileged change. Preserve it first if you may need to compare the result later:

$ sudo cp --preserve=all /etc/systemd/logind.conf.d/90-local-lid.conf /etc/systemd/logind.conf.d/90-local-lid.conf.save
$ sudo rm /etc/systemd/logind.conf.d/90-local-lid.conf
$ sudo systemctl reload systemd-logind.service

Recovery: after the reload, the compiled or vendor default applies again. On this installation, the documented default for HandleLidSwitch is suspend, while HandleLidSwitchExternalPower is ignored until explicitly set and HandleLidSwitchDocked defaults to ignore. Keep the backup outside the drop-in directory if you want it not to be read accidentally. Once satisfied, remove the backup explicitly; that deletion is irreversible.

Common traps

Done means