49e53454d32ce13f5af4ece42112423534102fdd
braney
  Tue Sep 29 14:30:20 2026 -0700
docent regression scripts for #38428 and #38430, and the #38387 registry note, refs #38428, #38430, #38387, #38252

rm38428 checks that a hub track's svg color legend survives the description
filter and the script inside it does not.  rm38430 checks that hgGateway filters
a hub assembly's description page.  Both need hubHtmlSanitize=on, and both fail
on a v504_branch build with the gate on and pass on genome-test.  Fixtures in
docentFixtures/rm38428 and rm38430.

The #38387 registry note records the docker QA instances: kent-tip, built after
the fix, runs ft_min_word_len=3 and finds hs1; kent-beta, built before it, runs 4
and does not.

diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv
index 9a88f62ebee..11e8dae6640 100644
--- src/utils/testRegistry/registry.tsv
+++ src/utils/testRegistry/registry.tsv
@@ -127,21 +127,21 @@
 38313	504	hg/lib/tests/snapshotTypeTester.c	-	library	sandbox-ab	the fast snapshotType reader agrees with raFromString, including on a longer tag that starts the same
 38317	504	-	rm38317.docent.yaml	invisible	-	needs one: doKnownGene must not read an uninitialised stack refLink. Docent covers it as of 2026-09-20, refs #38252. BLOCKED for a unit test: doKnownGene is static in hgc.c, 27000 lines and not linkable on its own
 38318	504	hg/lib/tests/sessionDataTester.c	-	invisible	unrecorded	the returned path must be freeable through kent's own handler stack
 38320	504	lib/tests/faSpeedReadTest.c	-	invisible	unrecorded	the buffer grower and its caller must agree on the size
 38323	504	-	-	library	-	needs one: an api key made on one geo mirror has to work on all of them. BLOCKED: needs hubSpaceKeys rows in hgcentral, which means a test that writes
 38328	504	hg/lib/tests/genarkLiftOverTester.c	-	invisible	sandbox-ab	the accession list is escaped where the values are, and a non-accession never reaches the query
 38335	504	lib/tests/cgiParseTest.c	rm38335.docent.yaml	invisible	unrecorded	a pair with no =value must not lose the variable
 38339	504	-	-	page	-	the wording when CILogon returns an unverified email. The fix is in hg/hgLogin, so what changed is what a page says or does
 38340	504	hg/hgSession/tests/backupParseTest.c	-	invisible	unrecorded	the same pair, read back out of a session backup
 38340	504	lib/tests/cgiCookieTest.c	-	invisible	unrecorded	the same pair in a cookie header
 38356	504	-	-	page	-	the hgTablesTest robot finishing a run instead of aborting. The fix is in hg/hgTablesTest, so what changed is what a page says or does
 38359	-	lib/tests/netSlurpMaxTest.c	-	invisible	sandbox-ab	a response past the ceiling is refused and the buffer freed, instead of the run dying inside carefulAlloc with nothing in the log. Nothing reaches a page: the only caller is the hgTablesTest robot. Release is "-" because the fix is held for after the v504 branch cut and the ticket has no target version yet
 38364	504	-	rm38364.docent.yaml	page	-	a density mode that keeps items clickable. The fix is in hg/hgTracks, so what changed is what a page says or does
 38372	504	-	-	page	-	changing genome on hgCustom re-submitting the form. The fix is in hg/hgCustom, so what changed is what a page says or does
 38384	504	-	-	page	-	a 400 fetching faceted composite metadata on a curated hub. The fix is in hg/hgTrackUi, so what changed is what a page says or does
-38387	505	-	-	page	-	three-letter assembly names (hs1, rn7, dm6) found by the search box in a release image. The fix is in src/product/installer/browserSetup.sh (ft_min_word_len=3), so only a released docker image or a fresh mirror can show it; hgwdev has always run 3
+38387	505	-	-	page	-	three-letter assembly names (hs1, rn7, dm6) found by the search box in a release image. The fix is in src/product/installer/browserSetup.sh (ft_min_word_len=3), so only a released docker image or a fresh mirror can show it; hgwdev has always run 3. Seen 2026-09-29 on the docker QA instances: kent-tip (built after the fix) runs 3 and hubApi/findGenome?q=hs1 finds hs1; kent-beta (built 2026-09-21) runs 4 and does not
 38398	505	-	rm38398.docent.yaml	page	-	the Hub Upload file card keeping the genome and hub name a hub.txt names. The fix is in hg/js, so what changed is what a page says or does
 38414	505	hg/lib/tests/trackHubSkipHubNameTester.c	-	invisible	sandbox-ab	a hub_ name with no second underscore comes back whole, not as a pointer one past NULL
-38428	505	lib/tests/htmlSanitizeTest.c	-	library	sandbox-ab	simple svg drawings (svg, g and the shapes, with their size, position, fill and stroke) survive the sanitizer, and the non-drawing parts (defs, script, event attributes) do not. Backed out by hand on 2026-09-29: every svg case comes out empty. Behind the hubHtmlSanitize gate, off on every server on 2026-09-29
-38430	505	-	-	page	-	hgGateway passing a hub assembly's description page through the sanitizer like the other hub pages. The fix is in hg/hgGateway, so what changed is what a page says or does. Behind the hubHtmlSanitize gate, off on every server on 2026-09-29
+38428	505	lib/tests/htmlSanitizeTest.c	rm38428.docent.yaml	library	sandbox-ab	simple svg drawings (svg, g and the shapes, with their size, position, fill and stroke) survive the sanitizer, and the non-drawing parts (defs, script, event attributes) do not. Backed out by hand on 2026-09-29: every svg case comes out empty. Behind the hubHtmlSanitize gate, off on every server on 2026-09-29
+38430	505	-	rm38430.docent.yaml	page	-	hgGateway passing a hub assembly's description page through the sanitizer like the other hub pages. The fix is in hg/hgGateway, so what changed is what a page says or does. Behind the hubHtmlSanitize gate, off on every server on 2026-09-29
 38442	505	hg/lib/tests/cartPcrVarTester.c	rm38442.docent.yaml	library	sandbox-ab	hgPcrResult_imgOrd, the PCR track's place after a drag, survives a cart load while a result that is not two trash files is still dropped