d58bf9a182cbf4dba142a7028742abf688638829 braney Sat Sep 19 18:27:02 2026 -0700 genarkLiftOverTester: pin the escaping of the GenArk accession list Before #38328 the caller pasted its accessions into one string and genarkLiftOverDbs dropped that string into a query marked NOSQLINJ, which is a promise that somebody upstream had made it safe. It now takes an slName list and builds the query itself with sqlDyStringPrintf, so the escaping happens where the values are, and a name that is not a GC accession never reaches the database. Nothing about this is visible. Correct and incorrect escaping give the same page for every input a browser sends, because the accessions come from our own chain files. The difference appears only for a value chosen to break out, which is the value that never turns up in ordinary testing. The genark table is data and it moves, so the test reads an accession out of it and asks whether the function returns that one, rather than naming an assembly that may be dropped later. Watched to fail and then pass: with the value pasted in unescaped the run dies instead of coming back with nothing, so the quoted cases turn the test red rather than quietly querying something else. Recorded as sandbox-ab in utils/testRegistry. refs #38328, refs #38391 diff --git src/hg/lib/tests/expected/genarkLiftOverTest src/hg/lib/tests/expected/genarkLiftOverTest new file mode 100644 index 00000000000..924a805efd9 --- /dev/null +++ src/hg/lib/tests/expected/genarkLiftOverTest @@ -0,0 +1,11 @@ +an accession that is in the table + just that one 1 back + +names that are not accessions + hg38 and mm39, so the query is never built 0 back + GC' or '1'='1 0 back + an accession with a statement after it 0 back + +a list with both in it + one real, one quoted, one not an accession 1 back +