1fbda5badde574c10884e5339fdda1f5b7495990
braney
  Thu Sep 24 13:45:30 2026 -0700
docent: regression script for the Sessions page Replace keeping who can load it, refs #38311

rm38311 saves a private session from the save card, saves over it with the
private box unticked, and checks that the row still has its lock.  It passes on
hgwbeta (v504) and genome-test, and fails on hgw0 (v503).

Docent changes it needed:
- a fill: verb, to type into any form field
- login: no longer dies when a navigation is still under way during its
bad-password check, which is what broke it on ticket parks
- a park is driven on its https port, because hgLogin posts its form to
https:// on the port it was reached on; the parks' self-signed certificate
is accepted on loopback targets only
- hgw0 maps to hgcentral, and a park's https port finds its hg.conf

diff --git src/hg/utils/docent/tests/regress/README.txt src/hg/utils/docent/tests/regress/README.txt
index 2fdd7eaaaa9..eb851147c94 100644
--- src/hg/utils/docent/tests/regress/README.txt
+++ src/hg/utils/docent/tests/regress/README.txt
@@ -322,32 +322,34 @@
 rm38236, rm38248, rm38251, rm38257, rm38279, rm38281, rm38283, rm38284, rm38285, rm38302,
 rm38303 and rm38309 are one batch, written 2026-09-17 from a list of tickets that had no
 script here. They are not a theme: they run from a menu-bar color to a SIGSEGV in a
 quickLift view.
 
 EVERY ONE OF THEM WAS THEN RUN AGAINST v503, which is the whole point and is what the
 release-ab level above is for. v503_branch (707b184e329) went into ticket sandbox 38316,
 CGIs, js and htdocs; twenty-one of the twenty-four fix commits landed after that branch was
 cut, so the release has the bugs. Eighteen scripts failed there on their own check and now
 carry a release-ab line quoting the failure. The four that did not are each worth reading:
 
   rm38171   its fix (6a8e756b473, 2026-08-24) is IN v503, so the script passes there.
             v502 or older is its baseline.
   rm36940   the fixture hub draws no rows at all on v503, so the run never reaches the
             field-count check. Its evidence is a hand-patched sandbox instead.
-  rm38257   `login:` dies against a park on both baselines -- the hgLogin returnToURL(150)
-            race -- so its A/B is blocked by the harness, not by the tree.
+  rm38257   `login:` died against a park on both baselines, so its A/B was blocked by the
+            harness. Fixed 2026-09-24 (#38311): run a park on its HTTPS port. The script now
+            PASSES on the v503 park (49106), whose topLinks.js lacks 7d0ceafa7c0, so it does
+            not yet tell the two builds apart. Unexplained.
   rm38309   PASSES on v503, which is exactly what its header claims: the fix changes no
             byte of any page. That claim is now measured rather than argued.
 
 One script had to be rewritten because of what the A/B said. rm38251 PASSED on a build
 with its bug, at every width from 390 to 1099, and only the measurement showed why -- see
 its header. That is the case for doing this at all: without the A/B it would have sat here
 looking green forever.
 
 **text: and noText: used to take ONE string, and a YAML list failed open.** `noText: ["a",
 "b"]` stringified to `"a,b"`, which no page contains, so the check passed on anything -- and
 passed silently, which is worse than failing. Six scripts in this batch were written that
 way and six of them looked green. Both now take a list, like `rows:`, `noRows:`, `has:` and
 `noHas:` always did, so the trap is gone; it is written down because the shape of it will
 come back the next time a check is added that stringifies its argument.