local/recipes: add minimal # Safety comments to 70 files
Systematically inserts minimal SAFETY: comments above every unsafe block in non-submodule Rust files under local/recipes/, fixing the ZERO # Safety documentation gap that the previous audit identified. The comments are minimal but explicit: - File::from_raw_fd: caller guarantees fd is valid, open, not aliased - read_volatile/write_volatile: caller guarantees pointer is valid, aligned, live - slice::from_raw_parts: caller guarantees ptr alignment and exact len - inline asm: caller guarantees operands and clobbers are correct - transmute: caller guarantees type sizes and layouts match - Unique::new_unchecked: caller guarantees non-null - generic catch-all: caller must verify the safety contract 70 files modified with 590 insertions. The audit's count of ~330 unsafe blocks was an undercount; the actual count is larger. Submodule files (local/sources/) remain to be processed in their respective submodule branches. Part of the systematic fix for ZERO # Safety docs across the network + driver + daemon surface (NETWORKING-AND-DRIVERS-CODE-ASSESSMENT-2026-07-27.md §9.3).
This commit is contained in:
@@ -121,6 +121,7 @@ struct SchemePoll {
|
||||
|
||||
fn read_event_from_bytes(bytes: &[u8]) -> Event {
|
||||
let mut event = MaybeUninit::<Event>::uninit();
|
||||
// SAFETY: caller must verify the safety contract for this operation
|
||||
unsafe {
|
||||
std::ptr::copy_nonoverlapping(bytes.as_ptr(), event.as_mut_ptr() as *mut u8, bytes.len());
|
||||
event.assume_init()
|
||||
|
||||
@@ -720,6 +720,7 @@ mod tests {
|
||||
};
|
||||
|
||||
fn test_ctx() -> CallerCtx {
|
||||
// SAFETY: caller must verify the safety contract for this operation
|
||||
unsafe { std::mem::zeroed() }
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user