d58bf9a182cbf4dba142a7028742abf688638829 braney Sat Sep 19 18:27:02 2026 -0700 genarkLiftOverTester: pin the escaping of the GenArk accession list Before #38328 the caller pasted its accessions into one string and genarkLiftOverDbs dropped that string into a query marked NOSQLINJ, which is a promise that somebody upstream had made it safe. It now takes an slName list and builds the query itself with sqlDyStringPrintf, so the escaping happens where the values are, and a name that is not a GC accession never reaches the database. Nothing about this is visible. Correct and incorrect escaping give the same page for every input a browser sends, because the accessions come from our own chain files. The difference appears only for a value chosen to break out, which is the value that never turns up in ordinary testing. The genark table is data and it moves, so the test reads an accession out of it and asks whether the function returns that one, rather than naming an assembly that may be dropped later. Watched to fail and then pass: with the value pasted in unescaped the run dies instead of coming back with nothing, so the quoted cases turn the test red rather than quietly querying something else. Recorded as sandbox-ab in utils/testRegistry. refs #38328, refs #38391 diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile index 5a7e60dcd48..fd8208fb8b3 100644 --- src/hg/lib/tests/makefile +++ src/hg/lib/tests/makefile @@ -1,138 +1,143 @@ kentSrc = ../../.. include ../../../inc/common.mk L += ${MYSQLLIBS} -lm MYLIBDIR = ../../../lib/${MACHTYPE} MYLIBS = ${MYLIBDIR}/jkhgap.a ${MYLIBDIR}/jkweb.a BIN_DIR = bin/${MACHTYPE} all: ${BIN_DIR}/genePredTester \ ${BIN_DIR}/trashDirTester \ ${BIN_DIR}/mallocTopPadTester \ ${BIN_DIR}/pslReaderTester \ ${BIN_DIR}/quickLiftTester \ ${BIN_DIR}/sessionDataTester \ ${BIN_DIR}/trashDirTester \ # ${BIN_DIR}/annoGratorTester \ ${BIN_DIR}/binTest \ ${BIN_DIR}/customTrackTester \ ${BIN_DIR}/hgvsTester \ ${BIN_DIR}/sqlCheck ${BIN_DIR}/%: %.c ${MYLIBS} @${MKDIR} ${BIN_DIR} ${CC} ${CC_PROG_OPTS} -o $@ $*.c ${MYLIBS} $L #test: binTest spDbTest hdbTest genePredTest pslReaderTest annoGratorTest customTrackTest hgvsTest test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest \ - hVarSubstHtmlTest dataVersionPathTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest + hVarSubstHtmlTest dataVersionPathTest genarkLiftOverTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest rm -r output echo tested all mkdirs: @${MKDIR} output ${BIN_DIR} loaders: ln -sf ${CGI_BIN}/loader . spDbTest: ${BIN_DIR}/spDbTest mkdirs ${BIN_DIR}/spDbTest sp121210 Q9FFH7 > output/spDbTest ${BIN_DIR}/spDbTest sp121210 P29312 >> output/spDbTest diff expected/spDbTest output/spDbTest hdbTest: ${BIN_DIR}/hdbTest mkdirs ${BIN_DIR}/hdbTest > output/hdbTest diff expected/hdbTest output/hdbTest genePredTest: ${BIN_DIR}/genePredTester mkdirs ${MAKE} -f genePredTests.mk test pslReaderTest: ${BIN_DIR}/pslReaderTester mkdirs ${MAKE} -f pslReaderTests.mk test #annoGratorTest: ${BIN_DIR}/annoGratorTester mkdirs # ${MAKE} -f annoGratorTests.mk test customTrackTest: ${BIN_DIR}/customTrackTester loaders mkdirs ${MAKE} -f customTrackTests.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output hgvsTest: ${BIN_DIR}/hgvsTester mkdirs ${MAKE} -f hgvsTests.mk test binTest: mkdirs ${BIN_DIR}/binTest @./binTest.sh quickLiftTest: ${BIN_DIR}/quickLiftTester mkdirs ${BIN_DIR}/quickLiftTester > output/quickLiftTest diff expected/quickLiftTest output/quickLiftTest sessionDataTest: ${BIN_DIR}/sessionDataTester mkdirs ${BIN_DIR}/sessionDataTester output/sessionData > output/sessionDataTest diff expected/sessionDataTest output/sessionDataTest # Three runs, because hgConfig caches the config it read, so one process can only answer for # one spelling of sessionDataDir. The fixture is made here rather than in C: a directory, a # symlink to it, and three confs naming the same place three ways. Each conf includes the # developer's own so the database settings come along, and is mode 600 because hgConfig # refuses a group-readable file whose name begins with a dot -- these do not, but the habit is # worth keeping. trashDirTest: ${BIN_DIR}/trashDirTester mkdirs rm -rf output/sd ${MKDIR} output/sd/real/hgt ln -s real output/sd/link echo "include ${HOME}/.hg.conf" > output/sd/link.conf echo "sessionDataDir=`pwd`/output/sd/link" >> output/sd/link.conf echo "include ${HOME}/.hg.conf" > output/sd/real.conf echo "sessionDataDir=`pwd`/output/sd/real" >> output/sd/real.conf echo "include ${HOME}/.hg.conf" > output/sd/rel.conf echo "sessionDataDir=output/sd/link" >> output/sd/rel.conf HGDB_CONF=output/sd/link.conf ${BIN_DIR}/trashDirTester \ "the symlink, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \ > output/trashDirTest HGDB_CONF=output/sd/real.conf ${BIN_DIR}/trashDirTester \ "the resolved directory, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \ >> output/trashDirTest HGDB_CONF=output/sd/rel.conf ${BIN_DIR}/trashDirTester \ "the symlink, relative" `pwd`/output/sd/link `pwd`/output/sd/real \ >> output/trashDirTest diff expected/trashDirTest output/trashDirTest # Twice: once with the setting and once without, because the answer is the DIFFERENCE between # them. A single run could pass on a library whose own default happened to be large. mallocTopPadTest: ${BIN_DIR}/mallocTopPadTester mkdirs echo "include ${HOME}/.hg.conf" > output/topPadOff.conf echo "include ${HOME}/.hg.conf" > output/topPadOn.conf echo "mallocTopPad=33554432" >> output/topPadOn.conf HGDB_CONF=output/topPadOff.conf ${BIN_DIR}/mallocTopPadTester > output/mallocTopPadTest HGDB_CONF=output/topPadOn.conf ${BIN_DIR}/mallocTopPadTester >> output/mallocTopPadTest diff expected/mallocTopPadTest output/mallocTopPadTest # bedItemRgb lives in hg/cgilib, which has no tests directory, so this one test links # jkhgapcgi.a on top of the libraries the rest of this directory uses. Two runs, because the # last step of the rule reads hg.conf's alwaysItemRgb and a mirror may turn it off. bedItemRgbTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/bedItemRgbTester bedItemRgbTester.c \ ${MYLIBDIR}/jkhgapcgi.a ${MYLIBS} $L echo "include ${HOME}/.hg.conf" > output/rgbOn.conf echo "include ${HOME}/.hg.conf" > output/rgbOff.conf echo "alwaysItemRgb=off" >> output/rgbOff.conf HGDB_CONF=output/rgbOn.conf ${BIN_DIR}/bedItemRgbTester > output/bedItemRgbTest HGDB_CONF=output/rgbOff.conf ${BIN_DIR}/bedItemRgbTester >> output/bedItemRgbTest diff expected/bedItemRgbTest output/bedItemRgbTest hVarSubstHtmlTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hVarSubstHtmlTester hVarSubstHtmlTester.c ${MYLIBS} $L ${BIN_DIR}/hVarSubstHtmlTester > output/hVarSubstHtmlTest diff expected/hVarSubstHtmlTest output/hVarSubstHtmlTest dataVersionPathTest: mkdirs ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/dataVersionPathTester dataVersionPathTester.c ${MYLIBS} $L ${BIN_DIR}/dataVersionPathTester > output/dataVersionPathTest diff expected/dataVersionPathTest output/dataVersionPathTest +genarkLiftOverTest: mkdirs + ${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/genarkLiftOverTester genarkLiftOverTester.c ${MYLIBS} $L + ${BIN_DIR}/genarkLiftOverTester > output/genarkLiftOverTest + diff expected/genarkLiftOverTest output/genarkLiftOverTest + sqlCheck: ${BIN_DIR}/sqlCheck mkdirs ${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output clean: rm -rf *.o bin output *.tmp loader udcCache