d58bf9a182cbf4dba142a7028742abf688638829
braney
  Sat Sep 19 18:27:02 2026 -0700
genarkLiftOverTester: pin the escaping of the GenArk accession list

Before #38328 the caller pasted its accessions into one string and
genarkLiftOverDbs dropped that string into a query marked NOSQLINJ, which is a
promise that somebody upstream had made it safe.  It now takes an slName list
and builds the query itself with sqlDyStringPrintf, so the escaping happens
where the values are, and a name that is not a GC accession never reaches the
database.

Nothing about this is visible.  Correct and incorrect escaping give the same
page for every input a browser sends, because the accessions come from our own
chain files.  The difference appears only for a value chosen to break out,
which is the value that never turns up in ordinary testing.

The genark table is data and it moves, so the test reads an accession out of it
and asks whether the function returns that one, rather than naming an assembly
that may be dropped later.

Watched to fail and then pass: with the value pasted in unescaped the run dies
instead of coming back with nothing, so the quoted cases turn the test red
rather than quietly querying something else.  Recorded as sandbox-ab in
utils/testRegistry.

refs #38328, refs #38391

diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv
index 86132dc17da..0127c134f02 100644
--- src/utils/testRegistry/registry.tsv
+++ src/utils/testRegistry/registry.tsv
@@ -71,19 +71,19 @@
 38256	504	hg/utils/hubCheck/tests/makefile::relPath	-	library	unrecorded	a local hub given by a relative path: bigDataUrl resolved once, not twice
 38260	504	hg/utils/hubCheck/tests/makefile::missingFile	-	library	unrecorded	hubCheck must say something about a bigDataUrl it cannot open
 38268	504	hg/lib/tests/dataVersionPathTester.c	rm38268.docent.yaml	invisible	sandbox-ab	a hub track's dataVersion may name a file only under /gbdb, and only by a plain path
 38272	504	-	rm38272.docent.yaml	invisible	-	needs one: a GenArk quickLift source assembly must not be looked for in MySQL
 38273	504	-	-	perf	-	needs one: a collection's hub file is copied when it is written, not on every session load; the test has to count the copies
 38283	504	hg/lib/tests/hVarSubstHtmlTester.c	rm38283.docent.yaml	library	sandbox-ab	a hub description page may not use $hgsid, and a native one may use only the braced form
 38285	504	hg/lib/tests/input/hgvs/validTerms.txt	rm38285.docent.yaml	library	unrecorded	bare codon numbers and ranges, with expected/hgvs/validTerms.txt beside it
 38302	504	-	rm38302.docent.yaml	invisible	-	needs one: an activation token that is missing, empty or older than seven days is invalid
 38303	504	hg/lib/tests/trashDirTester.c	rm38303.docent.yaml	invisible	sandbox-ab	a session file path spelled through a symlinked config directory, which broke 583 saved sessions
 38309	504	-	rm38309.docent.yaml	invisible	-	needs one: exonFrames must not be read past the end on a transcript's last exon
 38313	504	-	-	library	-	needs one: a user's own __ sessions must not be hidden from My Sessions
 38317	504	-	-	invisible	-	needs one: doKnownGene must not read an uninitialised stack refLink
 38318	504	hg/lib/tests/sessionDataTester.c	-	invisible	unrecorded	the returned path must be freeable through kent's own handler stack
 38320	504	lib/tests/faSpeedReadTest.c	-	invisible	unrecorded	the buffer grower and its caller must agree on the size
 38323	504	-	-	library	-	needs one: an api key made on one geo mirror has to work on all of them
-38328	504	-	-	invisible	-	needs one: the liftOver accession list passed as an slName list
+38328	504	hg/lib/tests/genarkLiftOverTester.c	-	invisible	sandbox-ab	the accession list is escaped where the values are, and a non-accession never reaches the query
 38335	504	lib/tests/cgiParseTest.c	rm38335.docent.yaml	invisible	unrecorded	a pair with no =value must not lose the variable
 38340	504	hg/hgSession/tests/backupParseTest.c	-	invisible	unrecorded	the same pair, read back out of a session backup
 38340	504	lib/tests/cgiCookieTest.c	-	invisible	unrecorded	the same pair in a cookie header