471b82ec87d4b23b03ec3f3a2a193eb1f88a035c braney Sat Sep 19 18:24:53 2026 -0700 dataVersionPathTester: pin which local files a hub's dataVersion may read A track's dataVersion setting is usually a version string, but for otto tracks it is the path of a local file that hgTrackUi opens and prints. On a hub track that setting is an instruction from a stranger to read a named file on our server and put it on the page. #38268 narrowed it to /gbdb, which is public data mirrored on hgdownload, and to a plain path, since a ".." component makes the name mean something outside that tree. The exception is needed: curated-hub assemblies are served as hubs, so hs1's otto tracks are hub tracks, and a quickLifted track's version file lives on the source assembly. Nothing about the failure is visible in the usual way. A refused path and an accepted one both leave a page that looks reasonable, and the difference shows only as somebody else's file appearing where a version number belongs. The test prints a classification and never a file. The three outcomes separate without looking at any contents: a refused path comes back as the path itself, an accepted path that does not exist comes back NULL, and an accepted path that exists comes back as something else. Watched to fail and then pass: with the /gbdb test dropped, /etc/passwd comes back read rather than refused, and the two climbing cases come back opened. Recorded as sandbox-ab in utils/testRegistry. refs #38268, refs #38391 diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv index 276b94a7e53..86132dc17da 100644 --- src/utils/testRegistry/registry.tsv +++ src/utils/testRegistry/registry.tsv @@ -58,31 +58,31 @@ 38086 504 - - invisible - needs one: a stale cart visibility variable must not hide a new BLAT result track 38126 504 lib/tests/htmlSanitizeTest.c rm38126.docent.yaml library unrecorded the allowlist that hub and custom track description HTML is filtered through 38184 504 - rm38184.docent.yaml invisible - needs one: db= resolving to the assembly already loaded must keep the session position 38185 504 hg/hgSession/tests/backupParseTest.c rm38185.docent.yaml invisible unrecorded an empty pair in a session backup must not eat the variable in front of it 38185 504 lib/tests/cgiParseTest.c rm38185.docent.yaml invisible unrecorded an empty CGI pair must not abort the request 38198 504 - rm38198.docent.yaml library - needs one: a second lift has to update a track already in the hub 38225 504 hg/lib/tests/mallocTopPadTester.c - perf sandbox-ab the hg.conf step size reaches the C library: the heap grows in one 16 MB jump, not the default one 38233 504 - - perf - needs one: RefSeq status is asked once per track, not once per gene; the test has to count the queries, not the seconds 38236 504 - rm38236.docent.yaml library - needs one: a quickLift chain with no aligned block in the window must not crash 38248 504 - rm38248.docent.yaml library - needs one: a deprecated versioned NP_ accession has to resolve to RefSeq Historical 38249 504 hg/lib/tests/quickLiftTester.c rm38249.docent.yaml library unrecorded the target strand of a reverse complemented protein, found in the #38349 review 38253 504 - - perf - needs one: item coverage is built from feature runs, not one counter per base; the test has to go red if a per-base pass comes back 38254 504 - - invisible - needs one: a composite subtrack's visibility has to settle before the parallel loaders start 38256 504 hg/utils/hubCheck/tests/makefile::relPath - library unrecorded a local hub given by a relative path: bigDataUrl resolved once, not twice 38260 504 hg/utils/hubCheck/tests/makefile::missingFile - library unrecorded hubCheck must say something about a bigDataUrl it cannot open -38268 504 - rm38268.docent.yaml invisible - needs one: the tightened dataVersion path check +38268 504 hg/lib/tests/dataVersionPathTester.c rm38268.docent.yaml invisible sandbox-ab a hub track's dataVersion may name a file only under /gbdb, and only by a plain path 38272 504 - rm38272.docent.yaml invisible - needs one: a GenArk quickLift source assembly must not be looked for in MySQL 38273 504 - - perf - needs one: a collection's hub file is copied when it is written, not on every session load; the test has to count the copies 38283 504 hg/lib/tests/hVarSubstHtmlTester.c rm38283.docent.yaml library sandbox-ab a hub description page may not use $hgsid, and a native one may use only the braced form 38285 504 hg/lib/tests/input/hgvs/validTerms.txt rm38285.docent.yaml library unrecorded bare codon numbers and ranges, with expected/hgvs/validTerms.txt beside it 38302 504 - rm38302.docent.yaml invisible - needs one: an activation token that is missing, empty or older than seven days is invalid 38303 504 hg/lib/tests/trashDirTester.c rm38303.docent.yaml invisible sandbox-ab a session file path spelled through a symlinked config directory, which broke 583 saved sessions 38309 504 - rm38309.docent.yaml invisible - needs one: exonFrames must not be read past the end on a transcript's last exon 38313 504 - - library - needs one: a user's own __ sessions must not be hidden from My Sessions 38317 504 - - invisible - needs one: doKnownGene must not read an uninitialised stack refLink 38318 504 hg/lib/tests/sessionDataTester.c - invisible unrecorded the returned path must be freeable through kent's own handler stack 38320 504 lib/tests/faSpeedReadTest.c - invisible unrecorded the buffer grower and its caller must agree on the size 38323 504 - - library - needs one: an api key made on one geo mirror has to work on all of them 38328 504 - - invisible - needs one: the liftOver accession list passed as an slName list 38335 504 lib/tests/cgiParseTest.c rm38335.docent.yaml invisible unrecorded a pair with no =value must not lose the variable 38340 504 hg/hgSession/tests/backupParseTest.c - invisible unrecorded the same pair, read back out of a session backup