d58bf9a182cbf4dba142a7028742abf688638829
braney
  Sat Sep 19 18:27:02 2026 -0700
genarkLiftOverTester: pin the escaping of the GenArk accession list

Before #38328 the caller pasted its accessions into one string and
genarkLiftOverDbs dropped that string into a query marked NOSQLINJ, which is a
promise that somebody upstream had made it safe.  It now takes an slName list
and builds the query itself with sqlDyStringPrintf, so the escaping happens
where the values are, and a name that is not a GC accession never reaches the
database.

Nothing about this is visible.  Correct and incorrect escaping give the same
page for every input a browser sends, because the accessions come from our own
chain files.  The difference appears only for a value chosen to break out,
which is the value that never turns up in ordinary testing.

The genark table is data and it moves, so the test reads an accession out of it
and asks whether the function returns that one, rather than naming an assembly
that may be dropped later.

Watched to fail and then pass: with the value pasted in unescaped the run dies
instead of coming back with nothing, so the quoted cases turn the test red
rather than quietly querying something else.  Recorded as sandbox-ab in
utils/testRegistry.

refs #38328, refs #38391

diff --git src/hg/lib/tests/makefile src/hg/lib/tests/makefile
index 5a7e60dcd48..fd8208fb8b3 100644
--- src/hg/lib/tests/makefile
+++ src/hg/lib/tests/makefile
@@ -1,138 +1,143 @@
 kentSrc = ../../..
 include ../../../inc/common.mk
 
 L += ${MYSQLLIBS} -lm
 MYLIBDIR = ../../../lib/${MACHTYPE}
 MYLIBS =  ${MYLIBDIR}/jkhgap.a ${MYLIBDIR}/jkweb.a
 BIN_DIR = bin/${MACHTYPE}
 
 all: 	${BIN_DIR}/genePredTester \
 	${BIN_DIR}/trashDirTester \
 	${BIN_DIR}/mallocTopPadTester \
 	${BIN_DIR}/pslReaderTester \
 	${BIN_DIR}/quickLiftTester \
 	${BIN_DIR}/sessionDataTester \
 	${BIN_DIR}/trashDirTester \
 #	${BIN_DIR}/annoGratorTester \
 	${BIN_DIR}/binTest \
 	${BIN_DIR}/customTrackTester \
 	${BIN_DIR}/hgvsTester \
 	${BIN_DIR}/sqlCheck 
 
 ${BIN_DIR}/%: %.c ${MYLIBS}
 	@${MKDIR} ${BIN_DIR}
 	${CC} ${CC_PROG_OPTS} -o $@ $*.c ${MYLIBS} $L
 
 #test: binTest spDbTest hdbTest genePredTest pslReaderTest annoGratorTest customTrackTest hgvsTest
 test: binTest quickLiftTest sessionDataTest trashDirTest mallocTopPadTest bedItemRgbTest \
-	hVarSubstHtmlTest dataVersionPathTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest
+	hVarSubstHtmlTest dataVersionPathTest genarkLiftOverTest spDbTest hdbTest genePredTest pslReaderTest customTrackTest hgvsTest
 	rm -r output
 	echo tested all
 
 mkdirs:
 	@${MKDIR} output ${BIN_DIR}
 
 loaders:
 	ln -sf ${CGI_BIN}/loader .
 
 spDbTest: ${BIN_DIR}/spDbTest mkdirs
 	${BIN_DIR}/spDbTest sp121210 Q9FFH7 > output/spDbTest
 	${BIN_DIR}/spDbTest sp121210 P29312 >> output/spDbTest
 	diff expected/spDbTest output/spDbTest
 
 hdbTest: ${BIN_DIR}/hdbTest mkdirs
 	${BIN_DIR}/hdbTest > output/hdbTest
 	diff expected/hdbTest output/hdbTest
 
 genePredTest: ${BIN_DIR}/genePredTester mkdirs
 	${MAKE} -f genePredTests.mk test
 
 pslReaderTest: ${BIN_DIR}/pslReaderTester mkdirs
 	${MAKE} -f pslReaderTests.mk test
 
 #annoGratorTest: ${BIN_DIR}/annoGratorTester mkdirs
 #	${MAKE} -f annoGratorTests.mk test
 
 customTrackTest: ${BIN_DIR}/customTrackTester loaders mkdirs
 	${MAKE} -f customTrackTests.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output
 
 hgvsTest: ${BIN_DIR}/hgvsTester mkdirs
 	${MAKE} -f hgvsTests.mk test
 
 binTest: mkdirs ${BIN_DIR}/binTest
 	@./binTest.sh
 
 quickLiftTest: ${BIN_DIR}/quickLiftTester mkdirs
 	${BIN_DIR}/quickLiftTester > output/quickLiftTest
 	diff expected/quickLiftTest output/quickLiftTest
 
 sessionDataTest: ${BIN_DIR}/sessionDataTester mkdirs
 	${BIN_DIR}/sessionDataTester output/sessionData > output/sessionDataTest
 	diff expected/sessionDataTest output/sessionDataTest
 
 # Three runs, because hgConfig caches the config it read, so one process can only answer for
 # one spelling of sessionDataDir.  The fixture is made here rather than in C: a directory, a
 # symlink to it, and three confs naming the same place three ways.  Each conf includes the
 # developer's own so the database settings come along, and is mode 600 because hgConfig
 # refuses a group-readable file whose name begins with a dot -- these do not, but the habit is
 # worth keeping.
 trashDirTest: ${BIN_DIR}/trashDirTester mkdirs
 	rm -rf output/sd
 	${MKDIR} output/sd/real/hgt
 	ln -s real output/sd/link
 	echo "include ${HOME}/.hg.conf" > output/sd/link.conf
 	echo "sessionDataDir=`pwd`/output/sd/link" >> output/sd/link.conf
 	echo "include ${HOME}/.hg.conf" > output/sd/real.conf
 	echo "sessionDataDir=`pwd`/output/sd/real" >> output/sd/real.conf
 	echo "include ${HOME}/.hg.conf" > output/sd/rel.conf
 	echo "sessionDataDir=output/sd/link" >> output/sd/rel.conf
 	HGDB_CONF=output/sd/link.conf ${BIN_DIR}/trashDirTester \
 	    "the symlink, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \
 	    > output/trashDirTest
 	HGDB_CONF=output/sd/real.conf ${BIN_DIR}/trashDirTester \
 	    "the resolved directory, absolute" `pwd`/output/sd/link `pwd`/output/sd/real \
 	    >> output/trashDirTest
 	HGDB_CONF=output/sd/rel.conf ${BIN_DIR}/trashDirTester \
 	    "the symlink, relative" `pwd`/output/sd/link `pwd`/output/sd/real \
 	    >> output/trashDirTest
 	diff expected/trashDirTest output/trashDirTest
 
 # Twice: once with the setting and once without, because the answer is the DIFFERENCE between
 # them.  A single run could pass on a library whose own default happened to be large.
 mallocTopPadTest: ${BIN_DIR}/mallocTopPadTester mkdirs
 	echo "include ${HOME}/.hg.conf" > output/topPadOff.conf
 	echo "include ${HOME}/.hg.conf" > output/topPadOn.conf
 	echo "mallocTopPad=33554432" >> output/topPadOn.conf
 	HGDB_CONF=output/topPadOff.conf ${BIN_DIR}/mallocTopPadTester > output/mallocTopPadTest
 	HGDB_CONF=output/topPadOn.conf ${BIN_DIR}/mallocTopPadTester >> output/mallocTopPadTest
 	diff expected/mallocTopPadTest output/mallocTopPadTest
 
 # bedItemRgb lives in hg/cgilib, which has no tests directory, so this one test links
 # jkhgapcgi.a on top of the libraries the rest of this directory uses.  Two runs, because the
 # last step of the rule reads hg.conf's alwaysItemRgb and a mirror may turn it off.
 bedItemRgbTest: mkdirs
 	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/bedItemRgbTester bedItemRgbTester.c \
 	    ${MYLIBDIR}/jkhgapcgi.a ${MYLIBS} $L
 	echo "include ${HOME}/.hg.conf" > output/rgbOn.conf
 	echo "include ${HOME}/.hg.conf" > output/rgbOff.conf
 	echo "alwaysItemRgb=off" >> output/rgbOff.conf
 	HGDB_CONF=output/rgbOn.conf ${BIN_DIR}/bedItemRgbTester > output/bedItemRgbTest
 	HGDB_CONF=output/rgbOff.conf ${BIN_DIR}/bedItemRgbTester >> output/bedItemRgbTest
 	diff expected/bedItemRgbTest output/bedItemRgbTest
 
 hVarSubstHtmlTest: mkdirs
 	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/hVarSubstHtmlTester hVarSubstHtmlTester.c ${MYLIBS} $L
 	${BIN_DIR}/hVarSubstHtmlTester > output/hVarSubstHtmlTest
 	diff expected/hVarSubstHtmlTest output/hVarSubstHtmlTest
 
 dataVersionPathTest: mkdirs
 	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/dataVersionPathTester dataVersionPathTester.c ${MYLIBS} $L
 	${BIN_DIR}/dataVersionPathTester > output/dataVersionPathTest
 	diff expected/dataVersionPathTest output/dataVersionPathTest
 
+genarkLiftOverTest: mkdirs
+	${CC} ${CC_PROG_OPTS} -o ${BIN_DIR}/genarkLiftOverTester genarkLiftOverTester.c ${MYLIBS} $L
+	${BIN_DIR}/genarkLiftOverTester > output/genarkLiftOverTest
+	diff expected/genarkLiftOverTest output/genarkLiftOverTest
+
 sqlCheck: ${BIN_DIR}/sqlCheck mkdirs
 	${MAKE} -f sqlCheck.mk test BIN_DIR=${BIN_DIR} OUT_DIR=output
 
 
 clean:
 	rm -rf *.o bin output *.tmp loader udcCache