471b82ec87d4b23b03ec3f3a2a193eb1f88a035c braney Sat Sep 19 18:24:53 2026 -0700 dataVersionPathTester: pin which local files a hub's dataVersion may read A track's dataVersion setting is usually a version string, but for otto tracks it is the path of a local file that hgTrackUi opens and prints. On a hub track that setting is an instruction from a stranger to read a named file on our server and put it on the page. #38268 narrowed it to /gbdb, which is public data mirrored on hgdownload, and to a plain path, since a ".." component makes the name mean something outside that tree. The exception is needed: curated-hub assemblies are served as hubs, so hs1's otto tracks are hub tracks, and a quickLifted track's version file lives on the source assembly. Nothing about the failure is visible in the usual way. A refused path and an accepted one both leave a page that looks reasonable, and the difference shows only as somebody else's file appearing where a version number belongs. The test prints a classification and never a file. The three outcomes separate without looking at any contents: a refused path comes back as the path itself, an accepted path that does not exist comes back NULL, and an accepted path that exists comes back as something else. Watched to fail and then pass: with the /gbdb test dropped, /etc/passwd comes back read rather than refused, and the two climbing cases come back opened. Recorded as sandbox-ab in utils/testRegistry. refs #38268, refs #38391 diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile index 239a37ad450..5a7e60dcd48 100644 --- src/hg/lib/tests/makefile +++ src/hg/lib/tests/makefile @@ -1,133 +1,138 @@ kentSrc = ../../.. include ../../../inc/common.mk L += ${MYSQLLIBS} -lm MYLIBDIR = ../../../lib/${MACHTYPE} MYLIBS = ${MYLIBDIR}/jkhgap.a ${MYLIBDIR}/jkweb.a BIN_DIR = bin/${MACHTYPE} all: ${BIN_DIR}/genePredTester \ ${BIN_DIR}/trashDirTester \ ${BIN_DIR}/mallocTopPadTester \ ${BIN_DIR}/pslReaderTester \ ${BIN_DIR}/quickLiftTester \ ${BIN_DIR}/sessionDataTester \ ${BIN_DIR}/trashDirTester \ # ${BIN_DIR}/annoGratorTester \ ${BIN_DIR}/binTest \ ${BIN_DIR}/customTrackTester \ ${BIN_DIR}/hgvsTester \ ${BIN_DIR}/sqlCheck ${BIN_DIR}/%: %.c ${MYLIBS} @${MKDIR} ${BIN_DIR} ${CC} ${CC_PROG_OPTS} -o $@ $*.c ${MYLIBS} $L #test: binTest spDbTest hdbTest genePredTest pslReaderTest annoGratorTest customTrackTest hgvsTest test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest \ - hVarSubstHtmlTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest + hVarSubstHtmlTest dataVersionPathTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest rm -r output echo tested all mkdirs: @${MKDIR} output ${BIN_DIR} loaders: ln -sf ${CGI_BIN}/loader . spDbTest: ${BIN_DIR}/spDbTest mkdirs ${BIN_DIR}/spDbTest sp121210 Q9FFH7 > output/spDbTest ${BIN_DIR}/spDbTest sp121210 P29312 >> output/spDbTest diff expected/spDbTest output/spDbTest hdbTest: ${BIN_DIR}/hdbTest mkdirs ${BIN_DIR}/hdbTest > output/hdbTest diff expected/hdbTest output/hdbTest genePredTest: ${BIN_DIR}/genePredTester mkdirs ${MAKE} -f genePredTests.mk test pslReaderTest: ${BIN_DIR}/pslReaderTester mkdirs ${MAKE} -f pslReaderTests.mk test #annoGratorTest: ${BIN_DIR}/annoGratorTester mkdirs # ${MAKE} -f annoGratorTests.mk test customTrackTest: ${BIN_DIR}/customTrackTester loaders mkdirs ${MAKE} -f customTrackTests.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output hgvsTest: ${BIN_DIR}/hgvsTester mkdirs ${MAKE} -f hgvsTests.mk test binTest: mkdirs ${BIN_DIR}/binTest @./binTest.sh quickLiftTest: ${BIN_DIR}/quickLiftTester mkdirs ${BIN_DIR}/quickLiftTester > output/quickLiftTest diff expected/quickLiftTest output/quickLiftTest sessionDataTest: ${BIN_DIR}/sessionDataTester mkdirs ${BIN_DIR}/sessionDataTester output/sessionData > output/sessionDataTest diff expected/sessionDataTest output/sessionDataTest # Three runs, because hgConfig caches the config it read, so one process can only answer for # one spelling of sessionDataDir. The fixture is made here rather than in C: a directory, a # symlink to it, and three confs naming the same place three ways. Each conf includes the # developer's own so the database settings come along, and is mode 600 because hgConfig # refuses a group-readable file whose name begins with a dot -- these do not, but the habit is # worth keeping. trashDirTest: ${BIN_DIR}/trashDirTester mkdirs rm -rf output/sd ${MKDIR} output/sd/real/hgt ln -s real output/sd/link echo "include ${HOME}/.hg.conf" > output/sd/link.conf echo "sessionDataDir=`pwd`/output/sd/link" >> output/sd/link.conf echo "include ${HOME}/.hg.conf" > output/sd/real.conf echo "sessionDataDir=`pwd`/output/sd/real" >> output/sd/real.conf echo "include ${HOME}/.hg.conf" > output/sd/rel.conf echo "sessionDataDir=output/sd/link" >> output/sd/rel.conf HGDB_CONF=output/sd/link.conf ${BIN_DIR}/trashDirTester \ "the symlink, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \ > output/trashDirTest HGDB_CONF=output/sd/real.conf ${BIN_DIR}/trashDirTester \ "the resolved directory, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \ >> output/trashDirTest HGDB_CONF=output/sd/rel.conf ${BIN_DIR}/trashDirTester \ "the symlink, relative" `pwd`/output/sd/link `pwd`/output/sd/real \ >> output/trashDirTest diff expected/trashDirTest output/trashDirTest # Twice: once with the setting and once without, because the answer is the DIFFERENCE between # them. A single run could pass on a library whose own default happened to be large. mallocTopPadTest: ${BIN_DIR}/mallocTopPadTester mkdirs echo "include ${HOME}/.hg.conf" > output/topPadOff.conf echo "include ${HOME}/.hg.conf" > output/topPadOn.conf echo "mallocTopPad=33554432" >> output/topPadOn.conf HGDB_CONF=output/topPadOff.conf ${BIN_DIR}/mallocTopPadTester > output/mallocTopPadTest HGDB_CONF=output/topPadOn.conf ${BIN_DIR}/mallocTopPadTester >> output/mallocTopPadTest diff expected/mallocTopPadTest output/mallocTopPadTest # bedItemRgb lives in hg/cgilib, which has no tests directory, so this one test links # jkhgapcgi.a on top of the libraries the rest of this directory uses. Two runs, because the # last step of the rule reads hg.conf's alwaysItemRgb and a mirror may turn it off. bedItemRgbTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/bedItemRgbTester bedItemRgbTester.c \ ${MYLIBDIR}/jkhgapcgi.a ${MYLIBS} $L echo "include ${HOME}/.hg.conf" > output/rgbOn.conf echo "include ${HOME}/.hg.conf" > output/rgbOff.conf echo "alwaysItemRgb=off" >> output/rgbOff.conf HGDB_CONF=output/rgbOn.conf ${BIN_DIR}/bedItemRgbTester > output/bedItemRgbTest HGDB_CONF=output/rgbOff.conf ${BIN_DIR}/bedItemRgbTester >> output/bedItemRgbTest diff expected/bedItemRgbTest output/bedItemRgbTest hVarSubstHtmlTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hVarSubstHtmlTester hVarSubstHtmlTester.c ${MYLIBS} $L ${BIN_DIR}/hVarSubstHtmlTester > output/hVarSubstHtmlTest diff expected/hVarSubstHtmlTest output/hVarSubstHtmlTest +dataVersionPathTest: mkdirs + ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/dataVersionPathTester dataVersionPathTester.c ${MYLIBS} $L + ${BIN_DIR}/dataVersionPathTester > output/dataVersionPathTest + diff expected/dataVersionPathTest output/dataVersionPathTest + sqlCheck: ${BIN_DIR}/sqlCheck mkdirs ${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output clean: rm -rf *.o bin output *.tmp loader udcCache