Subject
bon 3.9.1 is the runtime half of a builder-pattern code-generation library. It re-exports five proc-macro entry points (builder, bon, Builder, map, set) from the sibling crate bon-macros, which does all the heavy lifting. The runtime crate contributes: the IsSet/IsUnset sealed marker traits that back the typestate API (src/builder_state.rs); four declarative macros for collection construction with Into coercion (src/collections.rs); and a private module (src/__/) that holds IDE-completion stubs, error-message helpers, and a compile-time cfg-predicate evaluator. The public API is no-std-compatible via the alloc and std feature flags; the std feature is the default. Two experimental features (experimental-overwritable, experimental-generics-setters) and one stabilised legacy alias (experimental-getter) are present; all delegate to feature flags on bon-macros.
Methodology
Audit performed using openvet 0.6.0. All 570 lines across six source files (src/lib.rs, src/builder_state.rs, src/collections.rs, src/__/mod.rs, src/__/better_errors.rs, src/__/cfg_eval.rs, src/__/ide.rs) were read in full. Source surveys used ripgrep patterns from the audit runbook to check for unsafe blocks, FFI, network, filesystem, process execution, environment variable access, cryptographic operations, RNG, and concurrency primitives; all returned no matches. The published tarball was diffed against the VCS checkout (vcs/, SHA1 1f427d01048ae86c6d929ed1e7c18ec994b43227, repository path bon within https://github.com/elastio/bon). No build script is present.
Results
The diff between contents/ and vcs/ shows only the normalised Cargo.toml differing; all source files are byte-for-byte identical. No binary assets are present. The VCS directory does not contain a .git directory in the pre-loaded workspace, so git-level provenance was verified via the embedded .cargo_vcs_info.json commit SHA rather than by running git log.
The crate contains no unsafe blocks, no FFI declarations, no network or filesystem access, and no process execution at runtime or build time. Accordingly uses-unsafe=false, uses-network=false, uses-filesystem=false, uses-exec=false, uses-crypto=false, uses-environment=false, uses-concurrency=false, uses-jit=false, and uses-interpreter=false all hold. There is no binary crate, no build script, and no install script, so has-binaries=false, has-build-exec=false, and has-install-exec=false.
On the implementation side, the crate delegates parsing to bon-macros and does not itself implement a parser, algorithm, data structure, protocol, concurrency primitive, or cryptographic operation: impl-parser=false, impl-algorithm=false, impl-datastructure=false, impl-protocol=false, impl-concurrency=false, impl-crypto=false, impl-jit=false, and impl-interpreter=false.
Unit tests in src/collections.rs cover arr!, vec!, map!, and set! with both empty and non-empty cases (has-unit-tests=true). The tests/integration/ directory contains 202 annotated test functions across 32 files covering builder attributes, generics, cfg handling, and UI compile-failure expectations (has-integration-tests=true). No fuzz or property tests are present (has-fuzz-tests=false, has-property-tests=false).
No obfuscated code, base64-encoded payloads, telemetry, timing-dependent behaviour, or suspicious network endpoints were observed. is-benign=true.
No findings were raised. The code is straightforward and well-commented; the cfg_eval.rs module in particular documents its non-obvious declarative macro technique with an inline explanation.
Conclusion
bon 3.9.1 is a thin runtime companion to bon-macros. Its own code carries no safety hazards: no unsafe blocks, no I/O, and no build-time execution. The typestate machinery in builder_state.rs is sound safe Rust. The only substantive logic is the cfg-predicate evaluator, which is purely declarative and thoroughly documented.