Skip to main content

Protected storage and locks

A managed child uses the paths and identity assigned to its installation. storage provides owner-only directories, bounded reads, atomic writes, and exclusive host locks.

Startup and identity​

read_startup(descriptor) reads the bounded host-provided startup record. identity(path) creates or reads the retained identity at its protected location. A restart should read the same identity, rather than replace the node’s identity or settings store.

Files​

Use secure_directory() for protected directories and read_private() for bounded reads. atomic_private() replaces a file through the SDK’s protected atomic-write path; its explicit executable option is for artifacts that require execution. Validate application content before persisting it.

load_manifest() reads and validates a manifest. executable_digest() computes the artifact identity used by the managed contract. Hashing a file establishes its content identity; publisher trust and installation authorization remain host responsibilities.

Ownership​

HostLock fences operations that require exclusive ownership. Keep the lock for the full operation it protects and close it in a guaranteed cleanup path. A lock conflict is an admission problem; it is not a reason to steal another process’s lock.

Never put credentials into descriptors, ordinary configuration, diagnostic responses, or rendered pages. Use the host’s declared credential and protected-reference flow.

Storage API reference