seccomp may be a better solution. Just as a point of reference you could add a network namespace and get the ability not to connect to unix domain sockets aka dbus.
The plan is to eventually support proper uid/security credential namespaces and allow all of this as non-root. Unfortunately we aren't quite there yet.