Firejail: net none in udiskie profile is causing dbus errors

Created on 28 Jun 2019  路  6Comments  路  Source: netblue30/firejail

(udiskie:34): dbind-WARNING **: 11:35:22.474: Couldn't connect to accessibility bus: Failed to connect to socket /tmp/dbus-XXX: Connection refused

udiskie complains about inability to connect do accessibily bus unless this line is commented out in its profile

https://github.com/netblue30/firejail/blob/d824eee1d0ee2dfb816ef644a1cb4b9cadd7be1c/etc/udiskie.profile#L24

question

Most helpful comment

I wouldn't worry about it, unless you use some of the accessibility features. They communicate over DBus, and "net none' is shutting down the socket.

All 6 comments

Not only udiskie, the most GTK+3 app have this.

Maybe it could be mentioned in template too then

I wouldn't worry about it, unless you use some of the accessibility features. They communicate over DBus, and "net none' is shutting down the socket.

My understanding so far was that _any_ error reported by the application and caused by too restrictive profile should be fixed. Maybe we need a definition what's an acceptable error and what is not. Though I am not sure if the one breaking accessibility features really belong to the first category.

There is already protocol unix in the udisks profile which should block network access so perhaps net none could be dropped.

I'm closing here due to inactivity, please fell free to reopen if you have more questions.

Was this page helpful?
0 / 5 - 0 ratings