c2e25edbf8c48361a71398664ec0c279d5fc58f5
braney
  Sat Sep 19 18:11:31 2026 -0700
hmacTest: pin the signature hgLogin puts on a pending social identity

hgLogin signs a pending social identity with hmacMd5(login.cookieSalt, fields)
and hands the signature to the browser in the account chooser, so a forgeable
signature lets an attacker choose whose account the chooser links to.  Nothing
about the page looks different either way.

Before #37984 that signature was a plain MD5 of the salt concatenated in front
of the same fields, and a hash of a secret followed by attacker-chosen text is
the wrong shape for the job.  boundaryMoves() is the case that says so: with
concatenation, hmacMd5("a", "bc") and hmacMd5("ab", "c") hash the same bytes
and sign the same, while HMAC keeps them apart.

Known answers are RFC 2202 test case 2 for MD5 and SHA1, cross-checked here
with the openssl command line.  Only the string-keyed vectors from the RFC can
be used, since this interface takes key and data as C strings.

Watched to fail and then pass: putting hmacMd5 back to the concatenation shape
turns the known answer red and makes the two boundary cases identical, both of
which the test catches.  Recorded as sandbox-ab in utils/testRegistry.

refs #37984, refs #38391

diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv
index ea3bcdb74a2..dc474afdb78 100644
--- src/utils/testRegistry/registry.tsv
+++ src/utils/testRegistry/registry.tsv
@@ -1,89 +1,89 @@
 # registry.tsv - which unit test defends which Redmine ticket.  refs #38391
 #
 # A bug ticket has no way to say whether a test now defends its fix, and a test has no way
 # to say which bug it came from.  This table answers both, and says which tickets are still
 # waiting for a test.  It is hand written: nothing generates it, so adding the row is part
 # of writing the test.
 #
 # Unit tests only.  The browser-page regression tests are the docent suite, refs #38252,
 # where the script is already named for its ticket.  A ticket whose fix only changes what a
 # page says is that suite's job and is not in here at all.
 #
 # Seven tab separated columns, sorted by ticket then by test:
 #
 #   ticket    the Redmine number, digits only
 #   release   the version the fix ships in, digits only, from the ticket's Target version.
 #             The table starts at v504.  A fix on master with no target version yet takes
 #             "-" until the ticket says.
 #   test      the file to open, as a path from kent/src, or "-" for a ticket that needs a
 #             test and does not have one.  A suite whose cases are make targets adds
 #             ::target, e.g. tests/makefile::relPath
 #   docent    the browser test that watches the same ticket, from the docent suite in
 #             hg/utils/docent/tests/regress, or "-" when there is none.  Not a second copy
 #             of that suite: it is here so "nothing is watching this ticket at all" is a
 #             question the tool can answer, which is the question worth acting on.  A
 #             docent script does not make a unit test unnecessary where the why is
 #             invisible; rm38309 cannot see a read past the end of an array, it asserts
 #             something next to it.
 #   why       why this ticket needs a unit test rather than a browser test:
 #                 invisible  the fix changes nothing on screen.  No browser test can see
 #                            it, so a unit test is the only test there can be.
 #                 perf       the fix is about speed or memory.  The test has to catch
 #                            backsliding, so it measures work done -- queries, passes,
 #                            allocations, bytes -- and never wall-clock seconds.
 #                 library    the fix is in library code that a browser reaches only
 #                            through a page, where much else can go wrong first.
 #   evidence  what has been seen, weakest first: unrecorded, assertion-only, sandbox-ab,
 #             release-ab, caught-regression.  "-" on a row with no test.  The vocabulary is
 #             proof.js's from the docent suite, minus the two levels that need a browser,
 #             so the two tables can be read on one scale.  Every row starts at unrecorded
 #             and earns its way up by measurement, not by argument.
 #   note      what the test holds down.  On a row with no test, what it would have to hold
 #             down, which is the first thing the person who writes it needs.
 #
 # One ticket can have several rows and one test can defend several tickets; both happen
 # here already.  A ticket cannot be both covered and waiting.
 #
 # `testRegistry check` reads every row and fails when one has rotted, so a test cannot be
 # renamed or deleted without coming here.
 #
 #ticket	release	test	docent	why	evidence	note
 10138	504	-	rm10138.docent.yaml	invisible	-	needs one: the session data directory hash went from 8 to 10 hex characters
 20824	504	hg/utils/netToBigNet/tests/makefile::simpleTest	-	library	unrecorded	a net converted to bigNet and back, byte compared
 27988	504	-	-	invisible	-	needs one: a server that is not the node hg.conf names has to recognise itself
 36212	504	-	rm36212.docent.yaml	library	-	needs one: an explicit itemRgb on has to beat the presence of a color setting
 37263	504	lib/tests/pathSimplifyTest.c	-	library	unrecorded	dot-dot collapsing, checked against the right answer rather than against the old one
 37969	504	-	rm37969.docent.yaml	library	-	needs one: a quickLifted container must not hide the tracks inside it
-37984	504	-	-	library	-	needs one: lib/hmac.c is new and has no test of its own
+37984	504	lib/tests/hmacTest.c	-	library	sandbox-ab	the pending social identity is signed with hmacMd5, not a plain md5 of salt plus fields
 38086	504	-	-	invisible	-	needs one: a stale cart visibility variable must not hide a new BLAT result track
 38126	504	lib/tests/htmlSanitizeTest.c	rm38126.docent.yaml	library	unrecorded	the allowlist that hub and custom track description HTML is filtered through
 38184	504	-	rm38184.docent.yaml	invisible	-	needs one: db= resolving to the assembly already loaded must keep the session position
 38185	504	hg/hgSession/tests/backupParseTest.c	rm38185.docent.yaml	invisible	unrecorded	an empty pair in a session backup must not eat the variable in front of it
 38185	504	lib/tests/cgiParseTest.c	rm38185.docent.yaml	invisible	unrecorded	an empty CGI pair must not abort the request
 38198	504	-	rm38198.docent.yaml	library	-	needs one: a second lift has to update a track already in the hub
 38225	504	-	-	perf	-	needs one: the malloc step size now comes from hg.conf; the test has to read the knob back and see it applied
 38233	504	-	-	perf	-	needs one: RefSeq status is asked once per track, not once per gene; the test has to count the queries, not the seconds
 38236	504	-	rm38236.docent.yaml	library	-	needs one: a quickLift chain with no aligned block in the window must not crash
 38248	504	-	rm38248.docent.yaml	library	-	needs one: a deprecated versioned NP_ accession has to resolve to RefSeq Historical
 38249	504	hg/lib/tests/quickLiftTester.c	rm38249.docent.yaml	library	unrecorded	the target strand of a reverse complemented protein, found in the #38349 review
 38253	504	-	-	perf	-	needs one: item coverage is built from feature runs, not one counter per base; the test has to go red if a per-base pass comes back
 38254	504	-	-	invisible	-	needs one: a composite subtrack's visibility has to settle before the parallel loaders start
 38256	504	hg/utils/hubCheck/tests/makefile::relPath	-	library	unrecorded	a local hub given by a relative path: bigDataUrl resolved once, not twice
 38260	504	hg/utils/hubCheck/tests/makefile::missingFile	-	library	unrecorded	hubCheck must say something about a bigDataUrl it cannot open
 38268	504	-	rm38268.docent.yaml	invisible	-	needs one: the tightened dataVersion path check
 38272	504	-	rm38272.docent.yaml	invisible	-	needs one: a GenArk quickLift source assembly must not be looked for in MySQL
 38273	504	-	-	perf	-	needs one: a collection's hub file is copied when it is written, not on every session load; the test has to count the copies
 38283	504	-	rm38283.docent.yaml	library	-	needs one: description page variables substituted once, and in the container
 38285	504	hg/lib/tests/input/hgvs/validTerms.txt	rm38285.docent.yaml	library	unrecorded	bare codon numbers and ranges, with expected/hgvs/validTerms.txt beside it
 38302	504	-	rm38302.docent.yaml	invisible	-	needs one: an activation token that is missing, empty or older than seven days is invalid
 38303	504	-	rm38303.docent.yaml	invisible	-	needs one: a session file path spelled through a symlinked config directory, which broke 583 saved sessions
 38309	504	-	rm38309.docent.yaml	invisible	-	needs one: exonFrames must not be read past the end on a transcript's last exon
 38313	504	-	-	library	-	needs one: a user's own __ sessions must not be hidden from My Sessions
 38317	504	-	-	invisible	-	needs one: doKnownGene must not read an uninitialised stack refLink
 38318	504	hg/lib/tests/sessionDataTester.c	-	invisible	unrecorded	the returned path must be freeable through kent's own handler stack
 38320	504	lib/tests/faSpeedReadTest.c	-	invisible	unrecorded	the buffer grower and its caller must agree on the size
 38323	504	-	-	library	-	needs one: an api key made on one geo mirror has to work on all of them
 38328	504	-	-	invisible	-	needs one: the liftOver accession list passed as an slName list
 38335	504	lib/tests/cgiParseTest.c	rm38335.docent.yaml	invisible	unrecorded	a pair with no =value must not lose the variable
 38340	504	hg/hgSession/tests/backupParseTest.c	-	invisible	unrecorded	the same pair, read back out of a session backup
 38340	504	lib/tests/cgiCookieTest.c	-	invisible	unrecorded	the same pair in a cookie header