49e53454d32ce13f5af4ece42112423534102fdd
braney
  Tue Sep 29 14:30:20 2026 -0700
docent regression scripts for #38428 and #38430, and the #38387 registry note, refs #38428, #38430, #38387, #38252

rm38428 checks that a hub track's svg color legend survives the description
filter and the script inside it does not.  rm38430 checks that hgGateway filters
a hub assembly's description page.  Both need hubHtmlSanitize=on, and both fail
on a v504_branch build with the gate on and pass on genome-test.  Fixtures in
docentFixtures/rm38428 and rm38430.

The #38387 registry note records the docker QA instances: kent-tip, built after
the fix, runs ft_min_word_len=3 and finds hs1; kent-beta, built before it, runs 4
and does not.

diff --git src/hg/utils/docent/tests/regress/rm38430.docent.yaml src/hg/utils/docent/tests/regress/rm38430.docent.yaml
new file mode 100644
index 00000000000..3c19af6b721
--- /dev/null
+++ src/hg/utils/docent/tests/regress/rm38430.docent.yaml
@@ -0,0 +1,31 @@
+# #38430 -- hgGateway showed a hub assembly's description page without the #38126 filter.
+#
+# The fix is 7b3bd7a453e, eight lines in src/hg/hgGateway/hgGateway.c:
+# maybeGetDescriptionText() now passes a hub assembly's page through htmlSanitize(), the way
+# every other page that shows hub HTML already did.  Sub-ticket of #38126.
+#
+# HG.CONF GATE.  The filter runs only with hubHtmlSanitize=on (hg/lib/trackHub.c,
+# hubHtmlSanitizeOn(), default off).  With the gate off the gateway shows the page raw on
+# every build, fixed or not, so a red run here first asks:
+#     grep hubHtmlSanitize /usr/local/apache/cgi-bin/hg.conf
+# It was turned on for genome-test on 2026-09-29.
+#
+# The fixture, ~/public_html/docentFixtures/rm38430/, is an assembly hub: one sequence (a
+# copy of hg38 chrM) and an htmlPath page with a paragraph, a script and a form.  The
+# paragraph must reach the gateway's description panel; the script and the form must not.
+proof:
+  - "assertion-only 2026-09-29 -- written from #38430 and 7b3bd7a453e"
+  - "release-ab 2026-09-29 -- fails on v504 and passes on genome-test, both with hubHtmlSanitize=on. v504_branch d46687cc563 built from ~/kentV504 into ts park 38423 (CGIs, js, htdocs), gate set in its hg.conf: the gateway description panel carries the form, its input and the script"
+
+target: genome-test
+db: hg38
+reset: true
+fast: true
+steps:
+  - goto: "/cgi-bin/hgTracks?hubUrl=https://hgwdev.gi.ucsc.edu/~braney/docentFixtures/rm38430/hub.txt&genome=rm38430asm&pix=1000"
+  - goto: "/cgi-bin/hgGateway"
+  # The filter keeps an id but prefixes it (descPage-), so ids are matched by their ending.
+  - wait: '#descriptionText [id$="rm38430Text"]'
+  - expect:
+      text: "This paragraph must survive the filter on the gateway page."
+      noHas: ['#descriptionText form', '#descriptionText script', 'input[name="rm38430Input"]', '[id$="rm38430Script"]']