471b82ec87d4b23b03ec3f3a2a193eb1f88a035c
braney
  Sat Sep 19 18:24:53 2026 -0700
dataVersionPathTester: pin which local files a hub's dataVersion may read

A track's dataVersion setting is usually a version string, but for otto tracks
it is the path of a local file that hgTrackUi opens and prints.  On a hub track
that setting is an instruction from a stranger to read a named file on our
server and put it on the page.

#38268 narrowed it to /gbdb, which is public data mirrored on hgdownload, and
to a plain path, since a ".." component makes the name mean something outside
that tree.  The exception is needed: curated-hub assemblies are served as hubs,
so hs1's otto tracks are hub tracks, and a quickLifted track's version file
lives on the source assembly.

Nothing about the failure is visible in the usual way.  A refused path and an
accepted one both leave a page that looks reasonable, and the difference shows
only as somebody else's file appearing where a version number belongs.

The test prints a classification and never a file.  The three outcomes separate
without looking at any contents: a refused path comes back as the path itself,
an accepted path that does not exist comes back NULL, and an accepted path that
exists comes back as something else.

Watched to fail and then pass: with the /gbdb test dropped, /etc/passwd comes
back read rather than refused, and the two climbing cases come back opened.
Recorded as sandbox-ab in utils/testRegistry.

refs #38268, refs #38391

diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv
index 276b94a7e53..86132dc17da 100644
--- src/utils/testRegistry/registry.tsv
+++ src/utils/testRegistry/registry.tsv
@@ -58,31 +58,31 @@
 38086	504	-	-	invisible	-	needs one: a stale cart visibility variable must not hide a new BLAT result track
 38126	504	lib/tests/htmlSanitizeTest.c	rm38126.docent.yaml	library	unrecorded	the allowlist that hub and custom track description HTML is filtered through
 38184	504	-	rm38184.docent.yaml	invisible	-	needs one: db= resolving to the assembly already loaded must keep the session position
 38185	504	hg/hgSession/tests/backupParseTest.c	rm38185.docent.yaml	invisible	unrecorded	an empty pair in a session backup must not eat the variable in front of it
 38185	504	lib/tests/cgiParseTest.c	rm38185.docent.yaml	invisible	unrecorded	an empty CGI pair must not abort the request
 38198	504	-	rm38198.docent.yaml	library	-	needs one: a second lift has to update a track already in the hub
 38225	504	hg/lib/tests/mallocTopPadTester.c	-	perf	sandbox-ab	the hg.conf step size reaches the C library: the heap grows in one 16 MB jump, not the default one
 38233	504	-	-	perf	-	needs one: RefSeq status is asked once per track, not once per gene; the test has to count the queries, not the seconds
 38236	504	-	rm38236.docent.yaml	library	-	needs one: a quickLift chain with no aligned block in the window must not crash
 38248	504	-	rm38248.docent.yaml	library	-	needs one: a deprecated versioned NP_ accession has to resolve to RefSeq Historical
 38249	504	hg/lib/tests/quickLiftTester.c	rm38249.docent.yaml	library	unrecorded	the target strand of a reverse complemented protein, found in the #38349 review
 38253	504	-	-	perf	-	needs one: item coverage is built from feature runs, not one counter per base; the test has to go red if a per-base pass comes back
 38254	504	-	-	invisible	-	needs one: a composite subtrack's visibility has to settle before the parallel loaders start
 38256	504	hg/utils/hubCheck/tests/makefile::relPath	-	library	unrecorded	a local hub given by a relative path: bigDataUrl resolved once, not twice
 38260	504	hg/utils/hubCheck/tests/makefile::missingFile	-	library	unrecorded	hubCheck must say something about a bigDataUrl it cannot open
-38268	504	-	rm38268.docent.yaml	invisible	-	needs one: the tightened dataVersion path check
+38268	504	hg/lib/tests/dataVersionPathTester.c	rm38268.docent.yaml	invisible	sandbox-ab	a hub track's dataVersion may name a file only under /gbdb, and only by a plain path
 38272	504	-	rm38272.docent.yaml	invisible	-	needs one: a GenArk quickLift source assembly must not be looked for in MySQL
 38273	504	-	-	perf	-	needs one: a collection's hub file is copied when it is written, not on every session load; the test has to count the copies
 38283	504	hg/lib/tests/hVarSubstHtmlTester.c	rm38283.docent.yaml	library	sandbox-ab	a hub description page may not use $hgsid, and a native one may use only the braced form
 38285	504	hg/lib/tests/input/hgvs/validTerms.txt	rm38285.docent.yaml	library	unrecorded	bare codon numbers and ranges, with expected/hgvs/validTerms.txt beside it
 38302	504	-	rm38302.docent.yaml	invisible	-	needs one: an activation token that is missing, empty or older than seven days is invalid
 38303	504	hg/lib/tests/trashDirTester.c	rm38303.docent.yaml	invisible	sandbox-ab	a session file path spelled through a symlinked config directory, which broke 583 saved sessions
 38309	504	-	rm38309.docent.yaml	invisible	-	needs one: exonFrames must not be read past the end on a transcript's last exon
 38313	504	-	-	library	-	needs one: a user's own __ sessions must not be hidden from My Sessions
 38317	504	-	-	invisible	-	needs one: doKnownGene must not read an uninitialised stack refLink
 38318	504	hg/lib/tests/sessionDataTester.c	-	invisible	unrecorded	the returned path must be freeable through kent's own handler stack
 38320	504	lib/tests/faSpeedReadTest.c	-	invisible	unrecorded	the buffer grower and its caller must agree on the size
 38323	504	-	-	library	-	needs one: an api key made on one geo mirror has to work on all of them
 38328	504	-	-	invisible	-	needs one: the liftOver accession list passed as an slName list
 38335	504	lib/tests/cgiParseTest.c	rm38335.docent.yaml	invisible	unrecorded	a pair with no =value must not lose the variable
 38340	504	hg/hgSession/tests/backupParseTest.c	-	invisible	unrecorded	the same pair, read back out of a session backup