d10ef89ee5
docker run/exec argv previously carried -e KEY=VALUE pairs for every forwarded/passthrough variable. On Linux /proc/<pid>/cmdline is world-readable regardless of process owner, so every allowlisted secret was visible to all local users via plain ps for the duration of every terminal call. Emit name-only -e KEY flags and supply values via the docker client subprocess env instead: the docker CLI resolves valueless --env KEY from its own environment (documented docker/podman behavior), moving secrets from /proc/*/cmdline (0444) to /proc/*/environ (0400). Covers the docker run container-start path, the recreation/recovery path, the init-seeding exec path, and the per-command runtime exec path. Reported by @sashalab. Fixes #96268