d58bf9a182cbf4dba142a7028742abf688638829 braney Sat Sep 19 18:27:02 2026 -0700 genarkLiftOverTester: pin the escaping of the GenArk accession list Before #38328 the caller pasted its accessions into one string and genarkLiftOverDbs dropped that string into a query marked NOSQLINJ, which is a promise that somebody upstream had made it safe. It now takes an slName list and builds the query itself with sqlDyStringPrintf, so the escaping happens where the values are, and a name that is not a GC accession never reaches the database. Nothing about this is visible. Correct and incorrect escaping give the same page for every input a browser sends, because the accessions come from our own chain files. The difference appears only for a value chosen to break out, which is the value that never turns up in ordinary testing. The genark table is data and it moves, so the test reads an accession out of it and asks whether the function returns that one, rather than naming an assembly that may be dropped later. Watched to fail and then pass: with the value pasted in unescaped the run dies instead of coming back with nothing, so the quoted cases turn the test red rather than quietly querying something else. Recorded as sandbox-ab in utils/testRegistry. refs #38328, refs #38391 diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv index 86132dc17da..0127c134f02 100644 --- src/utils/testRegistry/registry.tsv +++ src/utils/testRegistry/registry.tsv @@ -71,19 +71,19 @@ 38256 504 hg/utils/hubCheck/tests/makefile::relPath - library unrecorded a local hub given by a relative path: bigDataUrl resolved once, not twice 38260 504 hg/utils/hubCheck/tests/makefile::missingFile - library unrecorded hubCheck must say something about a bigDataUrl it cannot open 38268 504 hg/lib/tests/dataVersionPathTester.c rm38268.docent.yaml invisible sandbox-ab a hub track's dataVersion may name a file only under /gbdb, and only by a plain path 38272 504 - rm38272.docent.yaml invisible - needs one: a GenArk quickLift source assembly must not be looked for in MySQL 38273 504 - - perf - needs one: a collection's hub file is copied when it is written, not on every session load; the test has to count the copies 38283 504 hg/lib/tests/hVarSubstHtmlTester.c rm38283.docent.yaml library sandbox-ab a hub description page may not use $hgsid, and a native one may use only the braced form 38285 504 hg/lib/tests/input/hgvs/validTerms.txt rm38285.docent.yaml library unrecorded bare codon numbers and ranges, with expected/hgvs/validTerms.txt beside it 38302 504 - rm38302.docent.yaml invisible - needs one: an activation token that is missing, empty or older than seven days is invalid 38303 504 hg/lib/tests/trashDirTester.c rm38303.docent.yaml invisible sandbox-ab a session file path spelled through a symlinked config directory, which broke 583 saved sessions 38309 504 - rm38309.docent.yaml invisible - needs one: exonFrames must not be read past the end on a transcript's last exon 38313 504 - - library - needs one: a user's own __ sessions must not be hidden from My Sessions 38317 504 - - invisible - needs one: doKnownGene must not read an uninitialised stack refLink 38318 504 hg/lib/tests/sessionDataTester.c - invisible unrecorded the returned path must be freeable through kent's own handler stack 38320 504 lib/tests/faSpeedReadTest.c - invisible unrecorded the buffer grower and its caller must agree on the size 38323 504 - - library - needs one: an api key made on one geo mirror has to work on all of them -38328 504 - - invisible - needs one: the liftOver accession list passed as an slName list +38328 504 hg/lib/tests/genarkLiftOverTester.c - invisible sandbox-ab the accession list is escaped where the values are, and a non-accession never reaches the query 38335 504 lib/tests/cgiParseTest.c rm38335.docent.yaml invisible unrecorded a pair with no =value must not lose the variable 38340 504 hg/hgSession/tests/backupParseTest.c - invisible unrecorded the same pair, read back out of a session backup 38340 504 lib/tests/cgiCookieTest.c - invisible unrecorded the same pair in a cookie header