6256dc2c93839878b3faef3ee64214d0abcd6d4e
markd
  Tue Sep 22 11:32:49 2026 -0700
used sameOk instead of sameString to protect agaisnt NULL dereference

diff --git src/hg/hgTrackUi/hgTrackUi.c src/hg/hgTrackUi/hgTrackUi.c
index bbb9878110f..0ac1d4afcb0 100644
--- src/hg/hgTrackUi/hgTrackUi.c
+++ src/hg/hgTrackUi/hgTrackUi.c
@@ -4452,31 +4452,31 @@
 /* Check if a hub track comes from the curated hub that dbDb names for this assembly.
  * A curated hub such as hs1 keeps its data outside the hub.txt directory, so
  * fileUrlMatchesHub rejects it, but its trackDb is admin-configured and as
  * trustworthy as a native track's.  A user hub attached to the same assembly is
  * not, hence the match against the one hub dbDb names. */
 {
 char *curatedUrl = NULL;
 if (!hubConnectGetCuratedUrl(trackHubSkipHubName(db), &curatedUrl) || isEmpty(curatedUrl))
     return FALSE;
 curatedUrl = hReplaceGbdb(curatedUrl);
 unsigned hubId = hubIdFromTrackName(track);
 struct hubConnectStatus *hubStatus;
 for (hubStatus = hubStatusList; hubStatus != NULL; hubStatus = hubStatus->next)
     {
     if (hubStatus->id == hubId)
-        return sameString(hubStatus->hubUrl, curatedUrl);
+        return sameOk(hubStatus->hubUrl, curatedUrl);
     }
 return FALSE;
 }
 
 void handleFileFetch(struct cart *cart)
 /* Checks if a requested file is a legal request based on an attached cart or
  * native track.  If so, retrieves the file content via UDC and retransmits
  * it as the page content. */
 {
 char *genome = NULL;
 getDbAndGenome(cart, &database, &genome, NULL);
 initGenbankTableNames(database);
 
 char *fileUrl = cartOptionalString(cart, "fileUrl");
 char *urlClone = cloneString(fileUrl);