On Mon, 1 Apr 2024 17:57:55 +0700 Max Nikulin <maniku...@gmail.com> wrote: > On Sun, 31 Mar 2024 12:51:52 +0300 Antti-Pekka Johannes Känsälä wrote: > > > > https://lists.debian.org/debian-user/2024/03/msg00721.html > > Notice that this thread is broken into many part. (Perhaps because gmail > does not support In-Reply-To in mailto: links) > > > I am worried Gmail in a Firefox tab is able to break out of Firefox > > somehow, gaining unauthorized access to 128 files on a mounted USB stick. > > Output of the command to confirm the statement was not provided. > > From my point of view, something close to valid behavior was described. > > - If a file from an external drive is chosen for <input type="file"> > then it is reasonable to expect that it can be used later when a form is > submitted or an e-mail with the attachment is sent. Users are free to > select another file, so eagerly reading the file to memory is not always > reasonable. As a result it may be impossible to unmount the drive > immediately. > - File icons should appear in the file chooser and it may assume > determining media types of these files. > > So precise description of steps and observed effects is necessary to > make this bug report convincing.
Ok, so I send Gmail to myself, with the single attached file "file4.gpg" on a mounted USB stick (icon menu,mount only, not opening an Xfce file browser). Even after I've received my own Gmail, the stick is unable to unmount (icon menu again), I get a graphical dialog (Xfce) saying the Gmail Inbox tab blocks it, that "there's still data that needs to be written to the device". Closing the Gmail tab will not help. I still get this: appe@renaissance:~$ lsof | grep -i KINGSTON x-www-bro 83803 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83807 glean.dis appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83809 IPC\x20I/ appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83810 Timer appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83811 Netlink appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83812 Socket appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83813 IPDL\x20B appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83815 HTML5\x20 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83817 JS\x20Wat appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83821 Cache2 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83822 Cookie appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83824 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83825 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83826 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83827 TaskCon~l appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83834 Worker appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83835 gmain appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83836 gdbus appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83845 x-www-b:d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83846 GLXVsyncT appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83847 x-www-b:d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83848 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83849 CanvasRen appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83850 Renderer appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83851 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83852 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83853 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83854 WRWorker# appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83855 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83856 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83857 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83858 WRWorkerL appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83859 Composito appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83860 x-www-b:d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83861 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83862 ImageIO appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83863 Permissio appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83864 Breakpad appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83865 SandboxRe appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83866 IPC\x20La appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83870 QuotaMana appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83875 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83879 TRR\x20Ba appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83881 dconf\x20 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83887 StyleThre appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83888 StyleThre appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83889 StyleThre appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83891 GMPThread appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83893 ImageBrid appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83894 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83895 ProcessHa appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83904 AudioIP~v appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83905 AudioIP~a appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83906 AudioIP~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83920 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83921 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83922 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83923 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83942 URL\x20Cl appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83943 DOM\x20Wo appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83966 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83980 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83989 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83990 RemoteLzy appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 83991 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84004 MemoryPol appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84008 glean.mps appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84015 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84048 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84098 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84129 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84133 mozStorag appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84135 LS\x20Thr appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84358 SwComposi appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84359 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84360 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84361 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84431 SwComposi appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84432 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84433 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84434 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84495 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84496 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84517 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84801 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84915 SwComposi appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84916 WRScene~i appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84917 WRScene~d appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 84918 WRRende~c appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85044 x-www-br: appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85527 threaded- appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85979 BgIOThr~P appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85984 DNS\x20Re appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 85985 DNS\x20Re appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86067 Backgro~o appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86068 DNS\x20Re appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86221 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86261 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86292 FSBroker8 appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86854 StreamTra appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg x-www-bro 83803 86905 StreamTra appe 128r REG 8,33 3433 6939 /media/appe/KINGSTON/noname/file4.gpg Only after closing Firefox the stick was able to unmount. HTH.