From d37a3a712a9155a3dedc5842f782ca5c715742ce Mon Sep 17 00:00:00 2001 From: Chuck <33324927+ChuckBuilds@users.noreply.github.com> Date: Thu, 24 Sep 2026 17:02:15 -0400 Subject: [PATCH] style(perf): say why render_bench fell back; mark the stats path as a safe fixed name (Codacy) Codacy (Bandit B110, B108). The bench's silent except now prints why it read config.json directly. The stats file's fixed name in /dev/shm is safe: write() goes through mkstemp and os.replace, which replaces a planted symlink instead of following it; the comment says so and marks it nosec. Co-Authored-By: Claude Opus 5.5 --- scripts/render_bench.py | 5 +++-- src/common/frame_timing.py | 5 ++++- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/scripts/render_bench.py b/scripts/render_bench.py index c289546d..8994f5bc 100755 --- a/scripts/render_bench.py +++ b/scripts/render_bench.py @@ -77,8 +77,9 @@ def load_config() -> dict: config = ConfigManager().config if isinstance(config, dict) and config: return config - except Exception: - pass + except Exception as exc: # noqa: BLE001 - any failure means use the plain read + print(f"ConfigManager unavailable ({exc}); reading {CONFIG} directly", + file=sys.stderr) # ConfigManager pulls in a lot; a plain read is enough to drive the panel # and keeps the benchmark usable on a half-installed machine. try: diff --git a/src/common/frame_timing.py b/src/common/frame_timing.py index 9a39290b..c71399ff 100644 --- a/src/common/frame_timing.py +++ b/src/common/frame_timing.py @@ -145,7 +145,10 @@ STATS_FILENAME = "ledmatrix_frame_stats.json" def default_stats_path() -> str: - base = "/dev/shm" if os.path.isdir("/dev/shm") else tempfile.gettempdir() + # A fixed name in a shared directory is safe here: write() creates its + # temp file with mkstemp and os.replace()s it over this path, which swaps + # out whatever is there -- a planted symlink included -- without following it. + base = "/dev/shm" if os.path.isdir("/dev/shm") else tempfile.gettempdir() # nosec B108 return os.path.join(base, STATS_FILENAME)