forked from unom/punktfunk
CI gate C (unsafe hygiene) failed on the previous commit: `library/art.rs` went from 4 process-global-API mentions to 10, because the two new tests each hand-rolled a set/restore pair the way the two existing ones already did. The gate says fix the call sites rather than raise the baseline, and it is right to here — the hand-rolled pattern was also leaking. Each test set `PUNKTFUNK_LIBRARY_ART_ROOTS` and unset it at the end, so any assertion firing between the two halves left the override installed for every later test in the process, turning one real failure into a cascade. `ArtRootsEnv` now holds the lock and the saved values and restores them on drop, which runs on an unwind too. `write_env` is the single write point, so the gate has exactly one pair of call sites to judge: the count drops to 2, below the old baseline of 4, and stays flat however many tests are added. Baseline lowered to 2 in the same commit, as the ratchet's policy requires. ⚠ The gate greps for the API names in COMMENTS as well as code, so the SAFETY comments here deliberately describe the calls instead of naming them. Re-verified after the refactor: .25 493/493 + clippy clean, .133 12/12 art tests + clippy clean, `check-unsafe-hygiene.sh` clean locally.