6256dc2c93839878b3faef3ee64214d0abcd6d4e markd Tue Sep 22 11:32:49 2026 -0700 used sameOk instead of sameString to protect agaisnt NULL dereference diff --git src/hg/hgTrackUi/hgTrackUi.c src/hg/hgTrackUi/hgTrackUi.c index bbb9878110f..0ac1d4afcb0 100644 --- src/hg/hgTrackUi/hgTrackUi.c +++ src/hg/hgTrackUi/hgTrackUi.c @@ -4452,31 +4452,31 @@ /* Check if a hub track comes from the curated hub that dbDb names for this assembly. * A curated hub such as hs1 keeps its data outside the hub.txt directory, so * fileUrlMatchesHub rejects it, but its trackDb is admin-configured and as * trustworthy as a native track's. A user hub attached to the same assembly is * not, hence the match against the one hub dbDb names. */ { char *curatedUrl = NULL; if (!hubConnectGetCuratedUrl(trackHubSkipHubName(db), &curatedUrl) || isEmpty(curatedUrl)) return FALSE; curatedUrl = hReplaceGbdb(curatedUrl); unsigned hubId = hubIdFromTrackName(track); struct hubConnectStatus *hubStatus; for (hubStatus = hubStatusList; hubStatus != NULL; hubStatus = hubStatus->next) { if (hubStatus->id == hubId) - return sameString(hubStatus->hubUrl, curatedUrl); + return sameOk(hubStatus->hubUrl, curatedUrl); } return FALSE; } void handleFileFetch(struct cart *cart) /* Checks if a requested file is a legal request based on an attached cart or * native track. If so, retrieves the file content via UDC and retransmits * it as the page content. */ { char *genome = NULL; getDbAndGenome(cart, &database, &genome, NULL); initGenbankTableNames(database); char *fileUrl = cartOptionalString(cart, "fileUrl"); char *urlClone = cloneString(fileUrl);