> Canonical guide: https://developers.foxlight.ai/build/sdk/reference/storage/
> Contract snapshots: Skulk 2.0.0 (b0af39c79b6b7102b2478062904f1d7cc8619975); SDK 0.4.0 (31bb090b8f64689f87514e48385e22b6ad94a6c2). Check the installed runtime when versions differ.

# storage API

SDK 0.4.0. This reference describes the supported authoring interface.

## `secure_directory`

Create or validate a private directory without accepting a symlink.

```python
def secure_directory(path: Path) -> None:
    ...
```

## `read_private`

Read a bounded owner-only regular file, rejecting symlink substitution.

```python
def read_private(path: Path, limit: int=...) -> bytes:
    ...
```

## `read_startup`

Read and close the startup record the owner handed this child.

Bounded by `MAX_STARTUP_BYTES` (the manifest's own bound plus one frame
for the installation's identity and settings) and validated strictly: a
child starts from exactly the record its owner wrote, or not at all.

```python
def read_startup(descriptor: int) -> Startup:
    ...
```

## `identity`

Persist a UUID once; callers must hold the host lock before creation.

```python
def identity(path: Path) -> str:
    ...
```

## `HostLock`

Fence concurrent supervisors sharing one private installation directory.

### `HostLock.__init__`



```python
def __init__(self, root: Path) -> None:
    ...
```

### `HostLock.close`

Release installation ownership after every child has been reaped.

```python
def close(self) -> None:
    ...
```

## `executable_digest`

Hash an installed executable without loading its complete bytes in memory.

```python
def executable_digest(path: Path) -> str:
    ...
```

## `load_manifest`

Validate an explicit private manifest and absolute pinned executable.

```python
def load_manifest(path: Path) -> Manifest:
    ...
```

## `atomic_private`

Fsync a new owner-only file before atomic replacement and directory flush.

```python
def atomic_private(path: Path, value: bytes, *, executable: bool=False) -> None:
    ...
```
