macOS终端管理服务需分清用户级代理与系统级守护进程,正确使用launchctl命令并配置权限。用户级服务位于~/Library/LaunchAgents/,可用launchctl unload/rm操作;系统级服务位于/Library/LaunchDaemons/,须sudo操作且文件权限须为root:wheel、644;排查时用plutil校验语法、控制台查日志。
终端管理 macos 系统服务的核心在于分清层级、选对命令、配好权限。用户级代理(launch agents)影响单个账户,操作安全;系统级守护进程(launch daemons)开机即运行,修改需谨慎。
看清当前所有服务在跑什么
先确认现状,再动手干预:
- 查用户级自启项(登录后启动的图形/后台程序):
launchctl list | grep -v '^-' | grep -v '0x' - 查系统级守护进程(需管理员权限):
sudo launchctl list | grep -v '^-' - 快速定位某软件相关配置:
ls ~/Library/LaunchAgents/ /Library/LaunchDaemons/ 2>/dev/null - 查看某个服务详细状态:
launchctl print gui/$(id -u)/com.feishu.desktop(用户级)或launchctl print system/com.apple.mDNSResponder(系统级)
禁用用户级自启代理(最常用且安全)
多数第三方应用(飞书、钉钉、网易云音乐等)把自启配置放在~/Library/LaunchAgents/,直接操作即可:
- 停用并停止运行:
launchctl unload ~/Library/LaunchAgents/com.feishu.desktop.plist - 永久移除(卸载后删文件):
rm ~/Library/LaunchAgents/com.feishu.desktop.plist - 只临时停用不卸载(保留配置):
launchctl bootout gui/$(id -u) /path/to/file.plist - 批量清理建议:先
ls ~/Library/LaunchAgents,对含auto、update、agent等关键词的 plist 文件逐个处理
管理系统级守护进程(必须用 sudo,慎操作)
这类服务由安装包或驱动添加,影响所有用户,文件存于/Library/LaunchDaemons/:
- 加载启用:
sudo launchctl load /Library/LaunchDaemons/com.example.service.plist - 卸载禁用:
sudo launchctl unload /Library/LaunchDaemons/com.example.service.plist - 立即停止正在运行的服务:
sudo launchctl stop com.example.service - 关键前提:plist 文件必须属主
root:wheel,权限为644,否则报 “Operation not permitted” - 注意:
/System/Library/LaunchDaemons/下的系统服务受 SIP 保护,不可 load/unload
排查与验证服务是否生效
命令执行成功但没反应?大概率是配置或权限问题:
- 校验 plist 语法是否合法:
plutil -lint /path/to/file.plist - 检查归属和权限:
ls -l /Library/LaunchDaemons/com.example.plist,应显示root:wheel和-rw-r--r-- - 看日志找线索:在“控制台”App 中搜索进程名,或执行
log show --predicate 'process == "com.example.service"' --last 1h - 若脚本依赖环境变量(如 PATH),需在 plist 中显式声明,否则可能静默失败


















