Summary: 60 instances, 58 unique

Text	Count
// SAFETY: `read_fd` is a valid owned fd in the parent.	1
// SAFETY: `getpid` has no preconditions and is safe to call here.	1
// SAFETY: SHGetKnownFolderPath initializes path_ptr with a CoTaskMem-allocated,	1
// SAFETY: proc_pidinfo accepts a null buffer when its size is zero.	1
// SAFETY: Both process handles remain valid and duplicated receives an owned file handle.	1
// SAFETY: saved_stderr remains owned for the duration of this call.	1
// SAFETY: saved_stderr is a fresh descriptor returned by dup above.	1
// SAFETY: `self.handle` is owned by this struct and closed exactly once	1
// SAFETY: querying the system page size does not access caller-owned memory.	1
// SAFETY: `self.handle` is the handle owned by this `PowerRequest`, and	1
// SAFETY: F_SETFD takes integer flags, not a pointer; `control` owns the	1
// SAFETY: the outer helper left this descriptor open across exec, which	1
// SAFETY: `handle` was returned by `PowerCreateRequest` and has not	1
// SAFETY: `assertion_type_ref` and `assertion_name_ref` are valid `CFStringRef`s and	1
// SAFETY: The successful OpenProcess result is owned by this scope.	1
// SAFETY: `self.id` was returned by `IOPMAssertionCreateWithName` and this `Drop`	1
// SAFETY: `value` points to `self.job_list`, which remains alive while	2
// SAFETY: dup returns a newly owned file descriptor on success.	1
// SAFETY: both descriptors are valid for the duration of this call.	1
// SAFETY: Descriptor cleanup only uses fork-safe system calls.	1
// SAFETY: `context` points to a valid `REASON_CONTEXT` for the duration	1
// SAFETY: OpenProcess returns an owned handle or null on failure.	1
// SAFETY: saved_stderr is a fresh descriptor returned by dup above.	1
// SAFETY: both output pointers reference valid storage for libc to initialize.	1
// SAFETY: both fstat calls above returned successfully.	1
// SAFETY: `fd` is an owned descriptor kept alive by `files`.	1
// SAFETY: fcntl and close only operate on a descriptor owned by this process.	1
// SAFETY: the pseudo-handle is valid and the kernel initializes this	1
// SAFETY: `program` and every entry in `argv_ptrs` are valid C strings for	1
// SAFETY: `hpc` is the Windows-defined value and size for this attribute.	1
// SAFETY: `pre_exec` must be registered before spawn. The closure only	1
// SAFETY: proc_pidinfo writes descriptor records into the stack buffer.	1
// SAFETY: `value` points to `self.handle_list`, which remains alive	1
// SAFETY: path_ptr is a valid null-terminated UTF-16 string allocated by	1
// SAFETY: `file` owns this handle for the duration of the call.	1
// SAFETY: DuplicateHandle transferred ownership of the new file handle.	1
// SAFETY: EventType identifies the active INPUT_RECORD union member.	1
// SAFETY: `con` is the Windows-defined value and size for this attribute.	1
// SAFETY: the kernel initializes this correctly sized buffer on success.	1
// SAFETY: `fd` is valid for the duration of the test.	2
// SAFETY: app-server calls this synchronously at process startup, before spawning threads.	1
// SAFETY: `handle` is a live power request handle and `request_type` is a	1
// SAFETY: saved_stderr was duplicated from stderr and remains owned here.	1
// SAFETY: `fd` is valid and we are only clearing FD_CLOEXEC.	1
// SAFETY: the sandbox helper is single-threaded here, before it forks bridge workers or	1
// SAFETY: We provide a null-terminated argv vector whose pointers remain	1
// SAFETY: getrlimit writes into the stack-owned resource-limit structure.	1
// SAFETY: `program_cstring` and every entry in `argv_ptrs` are valid C	1
// SAFETY: ReadConsoleInputW populates the UnicodeChar member of KEY_EVENT_RECORD.	1
// SAFETY: F_GETFD takes only a descriptor, with no pointer arguments;	1
// SAFETY: this helper process is single-threaded at this point, and	1
// SAFETY: capability ABI version 3 uses a [version, pid] header and	1
// SAFETY: F_DUPFD_CLOEXEC takes an integer lower bound, not a pointer;	1
// SAFETY: F_DUPFD_CLOEXEC returned a new descriptor; the original owner drops here.	1
// SAFETY: `byte` is a valid mutable reference into `bytes`.	1
// SAFETY: both descriptors are valid for the duration of this call.	1
// SAFETY: dup returns a newly owned file descriptor on success.	1
// SAFETY: the launcher transferred this live descriptor to this stage,	1
