secureKeyChildEnvironment function
The child environment for a helper spawn (gh-1059 H1): explicit
overrides RIDE the full inherited environment. A non-null map passed to
Process.start REPLACES the whole child environment — a helper spawned
without PATH/HOME/SystemRoot cannot run, which reads as a silent
keyless boot. Null stays null = full inheritance.
Implementation
@visibleForTesting
Map<String, String>? secureKeyChildEnvironment(
Map<String, String>? overrides,
) => overrides == null ? null : {...Platform.environment, ...overrides};