style(perf): say why render_bench fell back; mark the stats path as a safe fixed name (Codacy)

Codacy (Bandit B110, B108). The bench's silent except now prints why it read
config.json directly. The stats file's fixed name in /dev/shm is safe:
write() goes through mkstemp and os.replace, which replaces a planted
symlink instead of following it; the comment says so and marks it nosec.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Chuck
2026-09-24 17:02:15 -04:00
co-authored by Claude Opus 5.5
parent 52bc520335
commit d37a3a712a
2 changed files with 7 additions and 3 deletions
+3 -2
View File
@@ -77,8 +77,9 @@ def load_config() -> dict:
config = ConfigManager().config
if isinstance(config, dict) and config:
return config
except Exception:
pass
except Exception as exc: # noqa: BLE001 - any failure means use the plain read
print(f"ConfigManager unavailable ({exc}); reading {CONFIG} directly",
file=sys.stderr)
# ConfigManager pulls in a lot; a plain read is enough to drive the panel
# and keeps the benchmark usable on a half-installed machine.
try:
+4 -1
View File
@@ -145,7 +145,10 @@ STATS_FILENAME = "ledmatrix_frame_stats.json"
def default_stats_path() -> str:
base = "/dev/shm" if os.path.isdir("/dev/shm") else tempfile.gettempdir()
# A fixed name in a shared directory is safe here: write() creates its
# temp file with mkstemp and os.replace()s it over this path, which swaps
# out whatever is there -- a planted symlink included -- without following it.
base = "/dev/shm" if os.path.isdir("/dev/shm") else tempfile.gettempdir() # nosec B108
return os.path.join(base, STATS_FILENAME)