On this page

Qt D-Bus Security Considerations

This page covers security considerations for applications using Qt D-Bus.

Exporting QObjects directly

QDBusConnection::registerObject() can export a QObject's own slots directly, by passing ExportNonScriptableSlots or ExportAllSlots. Doing so makes all of that object's invocables accessible remotely, including those inherited from any superclass, not only the ones declared on the object's own class. Only QObject's own built-in slots (such as deleteLater()) are excluded.

If you need precise, explicit control over which methods are bus-callable, use the adaptor pattern instead. See Using Qt D-Bus Adaptors for details.

Message validation relies on libdbus-1

Qt D-Bus does not itself validate incoming message size, nesting depth, or type validity. This is delegated to libdbus-1, which rejects malformed messages before Qt D-Bus reads them. Qt D-Bus links against whichever libdbus-1 is installed on the system, not a version it ships or controls, so this validation depends on that system library's version and behavior.

© 2026 The Qt Company Ltd. Documentation contributions included herein are the copyrights of their respective owners. The documentation provided herein is licensed under the terms of the GNU Free Documentation License version 1.3 as published by the Free Software Foundation. Qt and respective logos are trademarks of The Qt Company Ltd. in Finland and/or other countries worldwide. All other trademarks are property of their respective owners.