a9054011188cb975a65a7d9767096a0ffdceb366
braney
  Mon Sep 21 17:34:46 2026 -0700
netSlurpMaxTest: cover the response size ceiling, refs #38359

The fix this defends changes nothing on any page.  Its only caller is the
hgTablesTest robot, and the failure it prevents is the process exiting from
inside carefulAlloc with nothing written to the log, so a unit test is the only
test there can be.

Four parts.  netSlurpFileMax on a plain file, both sides of the boundary,
including a ceiling exactly at the file size, which has to read it.  The same
calls under pushCarefulMemHandler, where carefulTotalAllocated() says whether
the abandoned buffer was really freed: a buffer left behind would stay counted
against the ceiling and the cap would buy one oversized page and no more.  A
matched pair of forked children on a file past the allocator ceiling, one read
capped and one not, since exit(1) from inside the allocator cannot be seen any
other way.  And htmlPageSetMaxSize reaching htmlSlurpWithCookies against a
server on the loopback interface, because the ceiling travels through a
module-wide static and that wiring can rot with no caller changing.

Backed the fix out three ways and watched each go red for its own reason.
Removing the size check fails 9 of the 18 assertions.  Keeping the check and
dropping only the dyStringFree fails 3, and only the three that count
allocation.  Reverting htmlSlurpWithCookies to a plain netSlurpFile fails 2,
and only the two that reach through htmlPage.  Recorded as sandbox-ab.

The registry row carries "-" for the release: the ticket has no target version.

diff --git src/utils/testRegistry/registry.tsv src/utils/testRegistry/registry.tsv
index 5cbf7cb0c45..edd2bc2b226 100644
--- src/utils/testRegistry/registry.tsv
+++ src/utils/testRegistry/registry.tsv
@@ -113,18 +113,19 @@
 38303	504	hg/lib/tests/trashDirTester.c	rm38303.docent.yaml	invisible	sandbox-ab	a session file path spelled through a symlinked config directory, which broke 583 saved sessions
 38309	504	-	rm38309.docent.yaml	invisible	-	needs one: exonFrames must not be read past the end on a transcript's last exon. Brian's call 2026-09-20: docent covers it, and it has a script.  Left here so the reason stays recorded. BLOCKED for a unit test: the change is inside drawing code in hgTracks/simpleTracks.c
 38310	504	-	rm38310.docent.yaml	page	-	a hub track declaring more bigBed fields than the file has. The fix is in hg/hgTracks, hg/hgc, so what changed is what a page says or does
 38311	504	-	-	page	-	the New Sessions page's watermark and tooltip. The fix is in hg/js, hg/htdocs/style, so what changed is what a page says or does
 38313	504	hg/lib/tests/snapshotTypeTester.c	-	library	sandbox-ab	the fast snapshotType reader agrees with raFromString, including on a longer tag that starts the same
 38317	504	-	rm38317.docent.yaml	invisible	-	needs one: doKnownGene must not read an uninitialised stack refLink. Docent covers it as of 2026-09-20, refs #38252. BLOCKED for a unit test: doKnownGene is static in hgc.c, 27000 lines and not linkable on its own
 38318	504	hg/lib/tests/sessionDataTester.c	-	invisible	unrecorded	the returned path must be freeable through kent's own handler stack
 38320	504	lib/tests/faSpeedReadTest.c	-	invisible	unrecorded	the buffer grower and its caller must agree on the size
 38323	504	-	-	library	-	needs one: an api key made on one geo mirror has to work on all of them. BLOCKED: needs hubSpaceKeys rows in hgcentral, which means a test that writes
 38328	504	hg/lib/tests/genarkLiftOverTester.c	-	invisible	sandbox-ab	the accession list is escaped where the values are, and a non-accession never reaches the query
 38335	504	lib/tests/cgiParseTest.c	rm38335.docent.yaml	invisible	unrecorded	a pair with no =value must not lose the variable
 38339	504	-	-	page	-	the wording when CILogon returns an unverified email. The fix is in hg/hgLogin, so what changed is what a page says or does
 38340	504	hg/hgSession/tests/backupParseTest.c	-	invisible	unrecorded	the same pair, read back out of a session backup
 38340	504	lib/tests/cgiCookieTest.c	-	invisible	unrecorded	the same pair in a cookie header
 38356	504	-	-	page	-	the hgTablesTest robot finishing a run instead of aborting. The fix is in hg/hgTablesTest, so what changed is what a page says or does
+38359	-	lib/tests/netSlurpMaxTest.c	-	invisible	sandbox-ab	a response past the ceiling is refused and the buffer freed, instead of the run dying inside carefulAlloc with nothing in the log. Nothing reaches a page: the only caller is the hgTablesTest robot. Release is "-" because the fix is held for after the v504 branch cut and the ticket has no target version yet
 38364	504	-	rm38364.docent.yaml	page	-	a density mode that keeps items clickable. The fix is in hg/hgTracks, so what changed is what a page says or does
 38372	504	-	-	page	-	changing genome on hgCustom re-submitting the form. The fix is in hg/hgCustom, so what changed is what a page says or does
 38384	504	-	-	page	-	a 400 fetching faceted composite metadata on a curated hub. The fix is in hg/hgTrackUi, so what changed is what a page says or does