Skip to content

[Bug]: Incorrect handling of flatpak-spawn arguments #6776

Description

@bubba-champion

Checklist

  • I agree to follow the Code of Conduct that this project adheres to.
  • I have searched the issue tracker for a bug that matches the one I want to file, without success.
  • If this is an issue with a particular app, I have tried filing it in the appropriate issue tracker for the app (e.g. under https://github.com/flathub/) and determined that it is an issue with Flatpak itself.
  • This issue is not a report of a security vulnerability (see here if you need to report a security issue).

Flatpak version

1.18.1

What Linux distribution are you using?

Artix Linux

Linux distribution version

Linux localhost 7.1.8-hardened1-2-hardened #1 SMP PREEMPT_DYNAMIC Wed, 12 Aug 2026 06:40:55 +0000 x86_64 GNU/Linux

What architecture are you using?

x86_64

How to reproduce

No response

Expected Behavior

Steam starts as usual with these options

Actual Behavior

Steam only starts when all --no-talk-name= and --system-no-talk-name= are deleted

Additional Information

I manually restrict access to certain dbus names via --no-talk-name= and --system-no-talk-name=, but the following errors occur when starting Steam (com.valvesoftware.Steam):

error: Unknown option --none-name=org.freedesktop.Flatpak

error: Unknown option --system-none-name=org.freedesktop.PolicyKit1

Activity

  1. swick commented on Aug 17, 2026

    @swick
    Collaborator

    I'm a bit confused where --none-name and --system-none-name come from. Are you sure you have not miss-configured something?

    Also, is this still in the flatpak binary or from within the sandbox?

  2. smcv commented on Aug 17, 2026

    @smcv
    Collaborator

    I manually restrict access to certain dbus names via --no-talk-name= and --system-no-talk-name=

    How do you do that? (Details matter, especially if you're already applying workarounds.)

  3. bubba-champion commented on Aug 17, 2026

    @bubba-champion
    Author

    Also, is this still in the flatpak binary or from within the sandbox?

    If I understand correctly, this error occurs inside the sandbox

    I'm a bit confused where --none-name and --system-none-name come from. Are you sure you have not miss-configured something?

    How do you do that? (Details matter, especially if you're already applying workarounds.)

    I run flatpak applications through a small wrapper written in bash:

    #!/bin/bash
    
    _env_opts=(--unset=BROWSER --unset=DXVK_CONFIG_FILE --unset=DXVK_STATE_CACHE_PATH --unset=GRIM_DEFAULT_DIR --unset=OBS_VKCAPTURE_QUIET --unset=VKD3D_SHADER_CACHE_PATH)
    _flatpak_opts=(
      --allow=per-app-dev-shm
      --arch=x86_64
      --branch=stable
      --device=dri
      --disallow=bluetooth
      --disallow=canbus
      --filesystem=xdg-data/flatpak/app:ro
      --filesystem=xdg-data/umu:create
      --filesystem=xdg-run/pipewire-0
      --filesystem=~/Games:create
      --no-a11y-bus
      --no-talk-name=ca.desrt.dconf
      --no-talk-name=org.freedesktop.Flatpak
      --no-talk-name=org.freedesktop.impl.portal.PermissionStore
      --no-talk-name=org.hyprland.hyprpolkitagent
      --nodevice=all
      --nodevice=input
      --nodevice=kvm
      --nodevice=shm
      --nodevice=usb
      --nofilesystem=host:reset
      --nosocket=cups
      --nosocket=gpg-agent
      --nosocket=inherit-wayland-socket
      --nosocket=pcsc
      --nosocket=session-bus
      --nosocket=ssh-auth
      --nosocket=system-bus
      --system-no-talk-name=org.freedesktop.Accounts
      --system-no-talk-name=org.freedesktop.DBus
      --system-no-talk-name=org.freedesktop.Flatpak.SystemHelper
      --system-no-talk-name=org.freedesktop.PolicyKit1
      --system-no-talk-name=org.freedesktop.login1
      --user
    )
    
    exec env "${_env_opts[@]}" /usr/bin/flatpak run "${_flatpak_opts[@]}" "$@"
    

    If I comment out all --no-talk-name= and --system-no-talk-name=, these errors no longer occur

    I believe this could be a similar issue to what was fixed in this merge request

  4. swick commented on Aug 17, 2026

    @swick
    Collaborator

    I can see flatpak_policy_to_string actually supports a policy called "none" which is pretty weird, and flatpak_context_to_args constructs --system-none-name and --none-name with them. It's one of the things I have not touched though, so I'm really curious how you end up in that state. The script alone there doesn't explain it. It works just fine here.

  5. smcv commented on Sep 21, 2026

    @smcv
    Collaborator

    Fixed in main (for 1.19.1) by #6807, 1.18.x backport available in #6841

  6. smcv commented on Sep 22, 2026

    @smcv
    Collaborator

    Fixed in 1.18.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions