2770f93064
A WS 'profile' param like '../../foo' normalized to a path component that escaped the profiles root, letting a connected client bind an arbitrary existing directory as a profile home (state.db opened there, and session delete chains into per-id file cleanup under <dir>/sessions/). get_profile_dir now validates the canonical name against the profile id regex before joining it under profiles/. The regex only, not the reserved list, so pre-reserved-list dirs like profiles/hermes keep resolving. Callers that probe existence (profile_exists, _profile_home, the 4064 resolvers) treat ValueError as 'not found'.