99eb74885ff5bce42cadafee93274df7039dcab5 braney Sat Sep 26 17:34:11 2026 -0700 unit tests for four v503 tickets, refs #38391, #37262, #38120, #38107, #38125, #38154 cgiDecodeTest prints what malformed and cut-short %hh escapes decode to, and checks that cgiDecode never reads past the length it is given. udcDotsTest prints the cache directory udc makes for remote URLs with "." and ".." in them, including the ones that must abort. pngWriteTest writes a memGfx image as a PNG, reads it back with libpng, compares every pixel, and checks the row filter of every row. pgSnpManyAllelesTester builds per-allele counts from a VCF record with 150 ALT alleles. Each test fails with its fix backed out, except that zlib-ng was not swapped out for #38125. The test registry gets a row for each ticket. diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv index 0f8a5820dda..2837d58fc69 100644 --- src/utils/testRegistry/registry.tsv +++ src/utils/testRegistry/registry.tsv @@ -1,31 +1,32 @@ # registry.tsv - which unit test defends which Redmine ticket. refs #38391 # # A bug ticket has no way to say whether a test now defends its fix, and a test has no way # to say which bug it came from. This table answers both, and says which tickets are still # waiting for a test. It is hand written: nothing generates it, so adding the row is part # of writing the test. # # Unit tests only. The browser-page regression tests are the docent suite, refs #38252, # where the script is already named for its ticket. A ticket whose fix only changes what a # page says is that suite's job and is not in here at all. # # Seven tab separated columns, sorted by ticket then by test: # # ticket the Redmine number, digits only # release the version the fix ships in, digits only, from the ticket's Target version. -# The table starts at v504. A fix on master with no target version yet takes +# The table starts at v504, plus the v503 +# tickets that were given a test afterwards. A fix on master with no target version yet takes # "-" until the ticket says. # test the file to open, as a path from kent/src, or "-" for a ticket that needs a # test and does not have one. A suite whose cases are make targets adds # ::target, e.g. tests/makefile::relPath # docent the browser test that watches the same ticket, from the docent suite in # hg/utils/docent/tests/regress, or "-" when there is none. BOTH values are # checked: a named script must exist and must belong to this ticket, and a "-" # must still be true, so a script written later for a ticket whose row says "-" # fails rather than passing unnoticed. Not a second copy # of that suite: it is here so "nothing is watching this ticket at all" is a # question the tool can answer, which is the question worth acting on. A # docent script does not make a unit test unnecessary where the why is # invisible; rm38309 cannot see a read past the end of an array, it asserts # something next to it. # why why this ticket needs a unit test rather than a browser test, or that it does @@ -55,42 +56,47 @@ # # One ticket can have several rows and one test can defend several tickets; both happen # here already. A ticket cannot be both covered and waiting. # # `testRegistry check` reads every row and fails when one has rotted, so a test cannot be # renamed or deleted without coming here. # #ticket release test docent why evidence note 10138 504 hg/lib/tests/sessionDirTester.c rm10138.docent.yaml invisible sandbox-ab the session directory hash is 10 characters and the legacy 8 is a prefix of it 20824 504 hg/utils/netToBigNet/tests/makefile::simpleTest - library unrecorded a net converted to bigNet and back, byte compared 27988 504 hg/lib/tests/geoMirrorSelfTester.c - invisible sandbox-ab the host the visitor typed decides which gbNode row the server calls itself 36212 504 hg/cgilib/tests/bedItemRgbTester.c rm36212.docent.yaml library sandbox-ab an explicit itemRgb on beats the presence of a color setting, in the stanza and from a parent 36292 504 - - page - the Keep-only-last-search checkbox on the BLAT form. The fix is in hg/hgBlat, hg/js, so what changed is what a page says or does 36621 504 - - page - header dependencies written by the compiler; the test is that the tree builds. The fix is in the makefiles, so what changed is what a page says or does 36940 504 - rm36940.docent.yaml page - the bigBedOnePath fallback removed, leaving one load path. The fix is in hg/hgTracks, hg/hgc, so what changed is what a page says or does +37262 503 lib/tests/cgiDecodeTest.c - perf sandbox-ab malformed and cut-short %hh escapes decode to '?', and decoding never reads past the length it is given, the read-ahead that made it quadratic 37263 504 lib/tests/pathSimplifyTest.c - library unrecorded dot-dot collapsing, checked against the right answer rather than against the old one 37595 504 - - page - where the iframe sits on an item details page. The fix is in hg/hgc, so what changed is what a page says or does 37617 505 hg/lib/tests/vcfInfoFilterTester.c - library sandbox-ab filter.*, filterText.* and filterValues.* on VCF INFO fields and vep sub-fields, and the warning for each filter the VCF header cannot support 37617 505 lib/tests/htmlEncodeTest.c - library sandbox-ab the tag strippers return a terminated string for a label with no tags in it 37618 505 hg/lib/tests/vcfInfoFilterTester.c - library sandbox-ab colorByInfo on an INFO field and on a vep sub-field, where the value declared first wins across a record's annotations 37621 504 - - page - a quickLift bigWig block placed by the window, not the chain. The fix is in hg/hgTracks, so what changed is what a page says or does 37929 504 - - page - the login page's wording and the social sign-in buttons. The fix is in hg/hgLogin, hg/lib, so what changed is what a page says or does 37969 504 - rm37969.docent.yaml library - needs one: a quickLifted container must not hide the tracks inside it. BLOCKED: dumpTdbAndChildren is static in trackHub.c and its public caller needs a cart 37984 504 lib/tests/hmacTest.c - library sandbox-ab the pending social identity is signed with hmacMd5, not a plain md5 of salt plus fields 37996 504 - rm37996.docent.yaml page - the new BLAT results page and its banner. The fix is in hg/hgBlat, hg/js, so what changed is what a page says or does 38086 504 - rm38086.docent.yaml invisible - needs one: a stale cart visibility variable must not hide a new BLAT result track. Docent covers it as of 2026-09-20, refs #38252. BLOCKED for a unit test: checkGroup is static in customFactory.c and the path needs a cart +38107 503 lib/tests/pngWriteTest.c - perf sandbox-ab every row of a written PNG carries the UP filter, and the decoded pixels are exactly the ones drawn +38120 503 lib/tests/udcDotsTest.c - library sandbox-ab . and .. in a remote URL resolve in the cache path the way the server resolves them, a path without them is unchanged, and climbing above the host aborts +38125 503 lib/tests/pngWriteTest.c - library unrecorded a PNG written through zlib-ng decodes to exactly the pixels drawn 38126 504 lib/tests/htmlSanitizeTest.c rm38126.docent.yaml library unrecorded the allowlist that hub and custom track description HTML is filtered through +38154 503 hg/lib/tests/pgSnpManyAllelesTester.c - library sandbox-ab per-allele counts from AN and AC on a record with 150 ALT alleles, more than the old fixed array of 80 38184 504 - rm38184.docent.yaml invisible - needs one: db= resolving to the assembly already loaded must keep the session position. BLOCKED: needs a live cart, so hgcentral rows to read and write 38185 504 hg/hgSession/tests/backupParseTest.c rm38185.docent.yaml invisible unrecorded an empty pair in a session backup must not eat the variable in front of it 38185 504 lib/tests/cgiParseTest.c rm38185.docent.yaml invisible unrecorded an empty CGI pair must not abort the request 38192 504 - - page - Login and Sign out returning to a page reached by POST. The fix is in hg/lib, hg/hgTrackUi, so what changed is what a page says or does 38197 504 - - page - setting and validating a recovery email address. The fix is in hg/hgLogin, hg/lib, so what changed is what a page says or does 38198 504 - rm38198.docent.yaml library - needs one: a second lift has to update a track already in the hub. BLOCKED: readStanzas is static in trackHub.c and the public entry takes a cart and a trash file 38200 504 - rm38200.docent.yaml page - a table name ending in an accession, and escaped examples. The fix is in hg/hgTables, so what changed is what a page says or does 38205 504 - rm38205.docent.yaml page - the session description taken back out of the cart. The fix is in hg/hgSession, so what changed is what a page says or does 38206 504 - rm38206.docent.yaml page - one blue for the menu bar on every page. The fix is in hg/htdocs/style, so what changed is what a page says or does 38208 504 - - page - an obsolete hg.conf flag and its code removed. The fix is in hg/hgTracks, so what changed is what a page says or does 38223 504 - rm38223.docent.yaml page - a stray formMethod value in the form. The fix is in hg/hgLiftOver, so what changed is what a page says or does 38225 504 hg/lib/tests/mallocTopPadTester.c - perf sandbox-ab the hg.conf step size reaches the C library: the heap grows in one 16 MB jump, not the default one 38226 505 lib/tests/htmlEncodeTest.c rm38226.docent.yaml library sandbox-ab htmlEncode and attributeEncode return an empty string for NULL, which an item with no name hands them 38233 504 - - perf - needs one: RefSeq status is asked once per track, not once per gene; the test has to count the queries. Brian's call 2026-09-20 was that docent covers these, but THIS ONE HAS NO DOCENT SCRIPT, so nothing watches it; it needs one on #38252. BLOCKED for a unit test: the change is in a static function in hgTracks/simpleTracks.c 38236 504 - rm38236.docent.yaml library - needs one: a quickLift chain with no aligned block in the window must not crash. Brian's call 2026-09-20: docent covers it, and it has a script. Left here so the reason stays recorded. BLOCKED for a unit test: the change is in hgTracks/bigWigTrack.c