fix: address blocking sentinel findings (unsafe SAFETY comment, unwrap panics)
Some checks failed
Public Repo Readiness / Check Public Repo Readiness (push) Failing after 4s

This commit is contained in:
Joseph O'Brien
2026-04-01 08:59:28 -04:00
parent bd06746b31
commit 403bcc4436
2 changed files with 6 additions and 3 deletions

View File

@@ -108,7 +108,10 @@ pub fn run(opts: BootstrapOptions) -> Result<Report> {
let k = k.trim();
let v = v.trim().trim_matches('"');
if !k.is_empty() && !k.starts_with('#') {
// Safety: single-threaded bootstrap, no concurrent env readers
// SAFETY: `notstrap` is a single-threaded bootstrap binary. No other threads
// are spawned before this point, and `env_injector` is called before any
// `Command::spawn` calls in this `run()` invocation. Callers that use
// `env_injector: None` (e.g. tests) never reach this block.
unsafe { std::env::set_var(k, v); }
}
}