99eb74885ff5bce42cadafee93274df7039dcab5
braney
  Sat Sep 26 17:34:11 2026 -0700
unit tests for four v503 tickets, refs #38391, #37262, #38120, #38107, #38125, #38154

cgiDecodeTest prints what malformed and cut-short %hh escapes decode to, and
checks that cgiDecode never reads past the length it is given.  udcDotsTest
prints the cache directory udc makes for remote URLs with "." and ".." in
them, including the ones that must abort.  pngWriteTest writes a memGfx image
as a PNG, reads it back with libpng, compares every pixel, and checks the row
filter of every row.  pgSnpManyAllelesTester builds per-allele counts from a
VCF record with 150 ALT alleles.

Each test fails with its fix backed out, except that zlib-ng was not swapped
out for #38125.  The test registry gets a row for each ticket.

diff --git src/lib/tests/makefile src/lib/tests/makefile
index 6a1719a0fb8..53e81c530d6 100644
--- src/lib/tests/makefile
+++ src/lib/tests/makefile
@@ -1,29 +1,29 @@
 kentSrc = ../..
 include ../../inc/common.mk
 
 MYLIBDIR = ../../lib/${MACHTYPE}
 MYLIBS = ${MYLIBDIR}/jkweb.a
 BIN_DIR = bin/${MACHTYPE}
 
 pipelineTester = ${BIN_DIR}/pipelineTester
 
 test: errCatchTest htmlPageTest htmlExpandUrlTest htmlSanitizeTest pipelineTests dyStringTest \
     mimeTests base64Tests quotedPTests safeTest hashTest fetchUrlTest gff3Test \
     tabixTest vcfTest hacTreeTest mmHashTest testSumDoubles jsonQueryTest \
     dnaCodonTest pathSimplifyTest faSpeedReadTest cgiParseTest cgiCookieTest \
-    hmacTest netSlurpMaxTest htmlEncodeTest
+    hmacTest netSlurpMaxTest htmlEncodeTest cgiDecodeTest udcDotsTest pngWriteTest
 	rm -r output fetchUrlTest testSumDoubles
 	@echo tested all
 
 
 mkdirs:
 	${MKDIR} output ${BIN_DIR}
 
 testSumDoubles: testSumDoubles.o ${MYLIBS}
 	@${MKDIR} $(dir $@)
 	${CC} ${COPT} -o ./testSumDoubles testSumDoubles.o ${MYLIBS} ${L}
 
 hmacTest: hmacTest.o ${MYLIBS} mkdirs
 	@${MKDIR} $(dir $@)
 	${CC} ${COPT} -o ${BIN_DIR}/hmacTest hmacTest.o ${MYLIBS} ${L}
 	${STRIP} ${BIN_DIR}/hmacTest${EXE}
@@ -60,30 +60,50 @@
 
 dnaCodonTest: dnaCodonTest.o ${MYLIBS} mkdirs
 	@${MKDIR} $(dir $@)
 	${CC} ${COPT} -o ${BIN_DIR}/dnaCodonTest dnaCodonTest.o ${MYLIBS} ${L}
 	${STRIP} ${BIN_DIR}/dnaCodonTest${EXE}
 	${BIN_DIR}/dnaCodonTest > output/dnaCodonTest
 	diff expected/dnaCodonTest output/dnaCodonTest
 
 cgiCookieTest: cgiCookieTest.o ${MYLIBS} mkdirs
 	@${MKDIR} $(dir $@)
 	${CC} ${COPT} -o ${BIN_DIR}/cgiCookieTest cgiCookieTest.o ${MYLIBS} ${L}
 	${STRIP} ${BIN_DIR}/cgiCookieTest${EXE}
 	${BIN_DIR}/cgiCookieTest > output/cgiCookieTest
 	diff expected/cgiCookieTest output/cgiCookieTest
 
+# cgiDecode on malformed %hh escapes, and a check that it never reads past its input.
+# refs #37262
+cgiDecodeTest: cgiDecodeTest.o ${MYLIBS} mkdirs
+	${CC} ${COPT} -o ${BIN_DIR}/cgiDecodeTest cgiDecodeTest.o ${MYLIBS} ${L}
+	${BIN_DIR}/cgiDecodeTest > output/cgiDecodeTest
+	diff expected/cgiDecodeTest output/cgiDecodeTest
+
+# the cache path udc makes for a remote URL with "." or ".." in it.  refs #38120
+udcDotsTest: udcDotsTest.o ${MYLIBS} mkdirs
+	${CC} ${COPT} -o ${BIN_DIR}/udcDotsTest udcDotsTest.o ${MYLIBS} ${L}
+	${BIN_DIR}/udcDotsTest > output/udcDotsTest
+	diff expected/udcDotsTest output/udcDotsTest
+
+# a PNG written from a memGfx decodes to the same pixels, with the UP row filter.
+# refs #38107, #38125
+pngWriteTest: pngWriteTest.o ${MYLIBS} mkdirs
+	${CC} ${COPT} -o ${BIN_DIR}/pngWriteTest pngWriteTest.o ${MYLIBS} ${L}
+	${BIN_DIR}/pngWriteTest output/pngWriteTest.png > output/pngWriteTest
+	diff expected/pngWriteTest output/pngWriteTest
+
 cgiParseTest: cgiParseTest.o ${MYLIBS} mkdirs
 	@${MKDIR} $(dir $@)
 	${CC} ${COPT} -o ${BIN_DIR}/cgiParseTest cgiParseTest.o ${MYLIBS} ${L}
 	${STRIP} ${BIN_DIR}/cgiParseTest${EXE}
 	${BIN_DIR}/cgiParseTest > output/cgiParseTest
 	diff expected/cgiParseTest output/cgiParseTest
 
 htmlSanitizeTest: htmlSanitizeTest.o ${MYLIBS} mkdirs
 	@${MKDIR} $(dir $@)
 	${CC} ${COPT} -o ${BIN_DIR}/htmlSanitizeTest htmlSanitizeTest.o ${MYLIBS} ${L}
 	${STRIP} ${BIN_DIR}/htmlSanitizeTest${EXE}
 	${BIN_DIR}/htmlSanitizeTest > output/htmlSanitizeTest
 	diff expected/htmlSanitizeTest output/htmlSanitizeTest
 
 errCatchTest: errCatchTest.o ${MYLIBS} mkdirs