751a1f9fff1d6d77c2da690d1369dca64ba04fee
braney
  Sat Sep 19 18:31:42 2026 -0700
sessionDirTester: pin how a saved session's data directory is named

A saved session's custom tracks and region files are moved to a durable
directory named from the user name and the session name.  #10138 widened the
session half of that name from 8 hex characters to 10: 8 characters of md5 is
4 billion values, and the birthday arithmetic over hundreds of thousands of
sessions is not comfortable, since a collision puts one user's files in another
user's session.

Widening a name that is already on disk is the risky half.  Directories written
before the change carry the old width and their files are still in use, so the
cleanup code has to be able to name both, which is why the width is a parameter
rather than a constant in the middle of the function.

The property pinned here is not the hash, it is that the short name is a PREFIX
of the long one.  That is what lets code holding the new name find a directory
written under the old one, and it holds only because both come from the same
md5 truncated to different lengths.  Also pinned: the two-character spreading
directory, the user name appearing as given, and the three calls that must
abort rather than invent a path -- a relative sessionDataDir, and a width of 0
or 33.

None of this is visible.  A session whose directory is named differently does
not report an error, it comes back without its custom track.

Watched to fail and then pass: narrowing the width back to 8 turns it red on
the width line.  Recorded as sandbox-ab in utils/testRegistry.

refs #10138, refs #38391

diff --git src/hg/lib/tests/expected/sessionDirTest src/hg/lib/tests/expected/sessionDirTest
new file mode 100644
index 00000000000..47f8b2d9fa3
--- /dev/null
+++ src/hg/lib/tests/expected/sessionDirTest
@@ -0,0 +1,19 @@
+current: /userdata/sessions/76/someUser/de19e57883
+legacy:  /userdata/sessions/76/someUser/de19e578
+  current width 10, legacy width 8
+  the legacy name is a prefix of the current one
+
+shape
+  /userdata/sessions/76/someUser/03c7c0ace3
+  spreading directory is 2 characters
+  two users, same session name, same directory? no
+
+no directory configured
+  empty sessionDataDir -> NULL
+
+refused
+  a relative sessionDataDir                aborted
+  hashLen 0                                aborted
+  hashLen 33, past the end of an md5       aborted
+
+0 failures