Flatsonar
Verified creator

Cable

by Magillos

PyQt6 application to modify Pipewire and Wireplumber settings

Extensive permissions Verified creator

About

Cable is a PyQt6 application that allows you to dynamically modify Pipewire and Wireplumber settings. It features a side-by-side connections manager for easy audio routing control.

Permissions

6 permissions weaken the sandbox. Flatsonar asks before installing.

  • sandbox escape: can run commands on the host via flatpak-spawn
    --talk-name=org.freedesktop.Flatpak
  • all devices (/dev): webcams, disks, raw hardware
    --device=all
  • full access to your home folder
    --filesystem=home
  • systemd: can manage services
    --talk-name=org.freedesktop.systemd1
  • sets LD_LIBRARY_PATH: changes which libraries or plugins get loaded
    --env=LD_LIBRARY_PATH=/app/lib:/app/lib/graphviz
  • sets PATH: changes which libraries or plugins get loaded
    --env=PATH=/app/bin:/usr/bin:/bin
  • inter-process communication (needed for X11)
    --share=ipc
  • Wayland display
    --socket=wayland
  • X11 display, only when Wayland is unavailable
    --socket=fallback-x11
  • GPU acceleration
    --device=dri
  • access to xdg-run/pipewire-0
    --filesystem=xdg-run/pipewire-0
  • access to xdg-config/kdeglobals
    --filesystem=xdg-config/kdeglobals:ro
  • system tray
    --talk-name=org.kde.StatusNotifierWatcher
  • talks to org.freedesktop.StatusNotifierWatcher
    --talk-name=org.freedesktop.StatusNotifierWatcher
  • access to /tmp
    --filesystem=/tmp
  • network
    --share=network
  • audio
    --socket=pulseaudio
  • access to xdg-config/gtk-3.0
    --filesystem=xdg-config/gtk-3.0:ro
  • talks to org.kde.KWin
    --talk-name=org.kde.KWin
  • sets environment variable GRAPHVIZ_DOT
    --env=GRAPHVIZ_DOT=/app/bin/dot
  • sets environment variable GV_CONFIG_PATH
    --env=GV_CONFIG_PATH=/app/lib/graphviz/config6

Who publishes this

The creator demonstrably controls this app id: Flathub verification, the hosting account owns the namespace, or a well-known file on their domain.

  • the build has network access: it can download things the manifest does not list
    python-packages:build-options:--share=network
  • fetches from the network during the build (nothing to audit beforehand): pip3 install --prefix=/app jack-client requests pyalsaaudio dbus-python graphviz
    python-packages:build-commands
  • hosted by github.com/magillos, which owns the com.github namespace of com.github.magillos.cable
    publisher:namespace

Maintenance

Recent activity on the upstream repository, or built and reviewed by Flathub.

No staleness signals: recent activity, or built and reviewed by Flathub.