Links of deleted attachments can be seen in emails

Bug #271460 reported by Christoph Korn
2
Affects Status Importance Assigned to Milestone
Launchpad itself
Incomplete
Undecided
Unassigned

Bug Description

If I have subscribed for a bug I also get emails from bugs which are dups.

Before those bugs are marked as duplicates and the visibility is changed to "Public"
often attachments like CoreDumps are removed.

But when I get an email about that bug it says:
** Attachment removed: "ThreadStacktrace.txt (retraced)"

   http://launchpadlibrarian.net/17696798/ThreadStacktrace.txt

And the file is still there and accessible.

Revision history for this message
Christoph Korn (c-korn) wrote :

Also the CoreDump is accessible.

*** This bug is a duplicate of bug 252174 ***
    https://bugs.launchpad.net/bugs/252174

Thank you for taking the time to report this bug and helping to make
Ubuntu better. This particular bug has already been reported and is a
duplicate of bug 252174, so it is being marked as such. Please look at
the other bug report to see if there is any missing information that you
can provide, or to see if there is a workaround for the bug.
Additionally, any further discussion regarding the bug should occur in
the other report. Feel free to continue to report any other bugs you may
find.

** Attachment removed: "CoreDump.gz"

   http://launchpadlibrarian.net/17696648/CoreDump.gz

** Attachment removed: "Dependencies.txt"

   http://launchpadlibrarian.net/17696649/Dependencies.txt

** Attachment removed: "ProcMaps.txt"

   http://launchpadlibrarian.net/17696650/ProcMaps.txt

** Attachment removed: "ProcStatus.txt"

   http://launchpadlibrarian.net/17696651/ProcStatus.txt

** Attachment removed: "Registers.txt"

   http://launchpadlibrarian.net/17696652/Registers.txt

** Attachment removed: "Stacktrace.txt"

   http://launchpadlibrarian.net/17696653/Stacktrace.txt

** Attachment removed: "ThreadStacktrace.txt"

   http://launchpadlibrarian.net/17696654/ThreadStacktrace.txt

** Attachment removed: "Stacktrace.txt (retraced)"

   http://launchpadlibrarian.net/17696788/Stacktrace.txt

** Attachment removed: "ThreadStacktrace.txt (retraced)"

   http://launchpadlibrarian.net/17696798/ThreadStacktrace.txt

** Visibility changed to: Public

** This bug has been marked a duplicate of bug 252174
   gvfsd-trash crashed with SIGSEGV in g_main_context_dispatch()

-- gvfsd-trash crashed with SIGSEGV in g_main_context_prepare() https://bugs.launchpad.net/bugs/271422

Revision history for this message
Barry Warsaw (barry) wrote :

I'm a little confused by this bug report. In the OP, you say "Before those bugs are marked as duplicates and the visibility is changed to "Public" often attachments like CoreDumps are removed." but in the quoted comment below, it looks like the bug is already being set to public, so that would seem fine to expose those links.

I'm probably misunderstanding the issue though. Could you clarify exactly what the problem is? Are you saying that private bugs have their attachments leaked when they get marked as duplicates?

Changed in launchpad:
status: New → Incomplete
Revision history for this message
Christoph Korn (c-korn) wrote :

I think this is a duplicate of bug 181365

It does not make much sense to only remove the link to the file in
the bug report that becomes public when the file is not deleted
physically and the link is sent in the email:
** Attachment removed: "CoreDump.gz"

   http://launchpadlibrarian.net/17696648/CoreDump.gz

The file still _exists_.

Curtis Hovey (sinzui)
security vulnerability: yes → no
visibility: private → public
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.