471b82ec87d4b23b03ec3f3a2a193eb1f88a035c
braney
  Sat Sep 19 18:24:53 2026 -0700
dataVersionPathTester: pin which local files a hub's dataVersion may read

A track's dataVersion setting is usually a version string, but for otto tracks
it is the path of a local file that hgTrackUi opens and prints.  On a hub track
that setting is an instruction from a stranger to read a named file on our
server and put it on the page.

#38268 narrowed it to /gbdb, which is public data mirrored on hgdownload, and
to a plain path, since a ".." component makes the name mean something outside
that tree.  The exception is needed: curated-hub assemblies are served as hubs,
so hs1's otto tracks are hub tracks, and a quickLifted track's version file
lives on the source assembly.

Nothing about the failure is visible in the usual way.  A refused path and an
accepted one both leave a page that looks reasonable, and the difference shows
only as somebody else's file appearing where a version number belongs.

The test prints a classification and never a file.  The three outcomes separate
without looking at any contents: a refused path comes back as the path itself,
an accepted path that does not exist comes back NULL, and an accepted path that
exists comes back as something else.

Watched to fail and then pass: with the /gbdb test dropped, /etc/passwd comes
back read rather than refused, and the two climbing cases come back opened.
Recorded as sandbox-ab in utils/testRegistry.

refs #38268, refs #38391

diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile
index 239a37ad450..5a7e60dcd48 100644
--- src/hg/lib/tests/makefile
+++ src/hg/lib/tests/makefile
@@ -13,31 +13,31 @@
 	${BIN_DIR}/quickLiftTester \
 	${BIN_DIR}/sessionDataTester \
 	${BIN_DIR}/trashDirTester \
 #	${BIN_DIR}/annoGratorTester \
 	${BIN_DIR}/binTest \
 	${BIN_DIR}/customTrackTester \
 	${BIN_DIR}/hgvsTester \
 	${BIN_DIR}/sqlCheck 
 
 ${BIN_DIR}/%: %.c ${MYLIBS}
 	@${MKDIR} ${BIN_DIR}
 	${CC} ${CC_PROG_OPTS} -o $@ $*.c ${MYLIBS} $L
 
 #test: binTest spDbTest hdbTest genePredTest pslReaderTest annoGratorTest customTrackTest hgvsTest
 test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest \
-	hVarSubstHtmlTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest
+	hVarSubstHtmlTest dataVersionPathTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest
 	rm -r output
 	echo tested all
 
 mkdirs:
 	@${MKDIR} output ${BIN_DIR}
 
 loaders:
 	ln -sf ${CGI_BIN}/loader .
 
 spDbTest: ${BIN_DIR}/spDbTest mkdirs
 	${BIN_DIR}/spDbTest sp121210 Q9FFH7 > output/spDbTest
 	${BIN_DIR}/spDbTest sp121210 P29312 >> output/spDbTest
 	diff expected/spDbTest output/spDbTest
 
 hdbTest: ${BIN_DIR}/hdbTest mkdirs
@@ -113,21 +113,26 @@
 bedItemRgbTest: mkdirs
 	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/bedItemRgbTester bedItemRgbTester.c \
 	    ${MYLIBDIR}/jkhgapcgi.a ${MYLIBS} $L
 	echo "include ${HOME}/.hg.conf" > output/rgbOn.conf
 	echo "include ${HOME}/.hg.conf" > output/rgbOff.conf
 	echo "alwaysItemRgb=off" >> output/rgbOff.conf
 	HGDB_CONF=output/rgbOn.conf ${BIN_DIR}/bedItemRgbTester > output/bedItemRgbTest
 	HGDB_CONF=output/rgbOff.conf ${BIN_DIR}/bedItemRgbTester >> output/bedItemRgbTest
 	diff expected/bedItemRgbTest output/bedItemRgbTest
 
 hVarSubstHtmlTest: mkdirs
 	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hVarSubstHtmlTester hVarSubstHtmlTester.c ${MYLIBS} $L
 	${BIN_DIR}/hVarSubstHtmlTester > output/hVarSubstHtmlTest
 	diff expected/hVarSubstHtmlTest output/hVarSubstHtmlTest
 
+dataVersionPathTest: mkdirs
+	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/dataVersionPathTester dataVersionPathTester.c ${MYLIBS} $L
+	${BIN_DIR}/dataVersionPathTester > output/dataVersionPathTest
+	diff expected/dataVersionPathTest output/dataVersionPathTest
+
 sqlCheck: ${BIN_DIR}/sqlCheck mkdirs
 	${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output
 
 
 clean:
 	rm -rf *.o bin output *.tmp loader udcCache