Expand description
Load/save the installed-plugin registry (plugins.json), mirroring
pause_store / screen_time_store: a capped read and an atomic,
0o600 write via secure_io. A missing or unparseable file yields an
empty registry rather than failing startup.
Constants§
- MAX_
MODULE_ 🔒BYTES - Cap on a module read back from disk — matches the install-time decode cap.
- MAX_
REGISTRY_ 🔒BYTES - Defensive cap on the registry file. Generous: each record is small provenance + a list of the strings the plugin added.
Functions§
- asset_
file_ name - Sidecar filename for one of plugin
plugin_id’s image assets. Bothplugin_id(reverse-DNS) andasset_id([a-z0-9._-]) are validated at install, so the result is a single safe filename component — no separators, no traversal. Recorded in the registry so uninstall can remove exactly it. - asset_
path - Absolute path for an asset sidecar named
file_name, beside the modules. - delete_
asset - Remove an asset sidecar. Missing is fine (idempotent uninstall).
- delete_
module - Remove a plugin’s module file. Missing is fine (idempotent uninstall).
- load
- Load the registry, defaulting to empty on a missing or malformed file.
- load_
module - Read a plugin’s wasm module from disk (size-capped). Errors if missing, oversized, or unreadable — callers treat that as “no detector to run”.
- module_
path - On-disk path for plugin
id’s wasm module.idis reverse-DNS ([a-z0-9.-], validated at install) so{id}.wasmis always a single filename component — no path separators, no traversal. - modules_
dir 🔒 - Directory holding installed detector/export module binaries, beside
plugins.json. - save
- Atomically persist the registry with owner-only permissions.
- save_
asset - Atomically persist an image asset with owner-only permissions.
- save_
module - Atomically persist a plugin’s wasm module with owner-only permissions.