style(perf): say why render_bench fell back; mark the stats path as a safe fixed name (Codacy)

Codacy (Bandit B110, B108). The bench's silent except now prints why it read
config.json directly. The stats file's fixed name in /dev/shm is safe:
write() goes through mkstemp and os.replace, which replaces a planted
symlink instead of following it; the comment says so and marks it nosec.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-24 17:02:15 -04:00
co-authored by Claude Opus 5.5
parent 52bc520335
commit d37a3a712a
2 changed files with 7 additions and 3 deletions
+4 -1
View File
@@ -145,7 +145,10 @@ STATS_FILENAME = "ledmatrix_frame_stats.json"
def default_stats_path() -> str:
base = "/dev/shm" if os.path.isdir("/dev/shm") else tempfile.gettempdir()
# A fixed name in a shared directory is safe here: write() creates its
# temp file with mkstemp and os.replace()s it over this path, which swaps
# out whatever is there -- a planted symlink included -- without following it.
base = "/dev/shm" if os.path.isdir("/dev/shm") else tempfile.gettempdir() # nosec B108
return os.path.join(base, STATS_FILENAME)