Skip to content
rusty-snake edited this page Aug 4, 2021 · 1 revision

Firejail can restrict the D-Bus access to only allow access to whitelisted names. See the manual pages for more details. This table shows evaluations of certain names.

Legend

  • ⚠️ : You do not get what you expect
  • πŸ›‘οΈ : Access to sensitive things (e.g. passwords, keyring, ...)
  • πŸ’₯ : Can be used to escape the sandbox (in theory)
  • ❗ : Potentially unwanted things, but no sandbox escape is possible
  • βœ”οΈ : Everything is fine, there is no risk
name flags notes capabilities Policy
ca.desrt.dconf πŸ›‘οΈ πŸ’₯ Write to the dconf database. All profiles using dconf, no others.
org.freedesktop.Notifications ⚠️ πŸ’₯ ❗ This is βœ”οΈ for GNOME >= 3.36.1
org.freedesktop.ScreenSaver ❗ Can be used to unlock a locked screen. (Un-)Lock your screen. Inhibit ScreenLocking. GetSessionIdle Only Video-Player
org.freedesktop.login1 ❗
org.freedesktop.secrets πŸ›‘οΈ Opt-In, with exceptions (e.g. seahorse).
org.gnome.OnlineAccounts πŸ›‘οΈ
org.gnome.Mutter.DisplayConfig ⚠️ πŸ’₯ ❗
org.gnome.Mutter.IdleMonitor ⚠️ πŸ’₯ ❗
org.gnome.Mutter.RemoteDesktop ⚠️ πŸ’₯ ❗
org.gnome.Mutter.ScreenCast ⚠️ πŸ’₯ ❗
org.gnome.Panel ⚠️ πŸ’₯ ❗
org.gnome.ScreenSaver ⚠️ πŸ’₯ ❗
org.gnome.SessionManager ❗
org.gnome.SettingsDaemon.Color βœ”οΈ NightMode (Screen temperature) interaction.
org.gnome.SettingsDaemon.MediaKeys βœ”οΈ Handle media-keys
org.gnome.SettingsDaemon.ScreensaverProxy ❗
org.gnome.Shell πŸ’₯
org.gnome.Shell.CalendarServer βœ”οΈ
org.gnome.Shell.Extensions πŸ’₯ (un)install/update/enable/disable gnome-shell extensions
org.gnome.Shell.Notifications βœ”οΈ Show native notifications
org.gnome.Shell.Screencast ⚠️ πŸ’₯ ❗
org.gnome.Shell.Screenshot ⚠️ πŸ’₯ ❗
org.gnome.keyring πŸ›‘οΈ
org.gnome.keyring.PrivatePrompter βœ”οΈ
org.gnome.keyring.SystemPrompter ⚠️ πŸ’₯ ❗