Skip to main content

Module plugin_store

Module plugin_store 

Source
Expand description

Load/save the installed-plugin registry (plugins.json), mirroring pause_store / screen_time_store: a capped read and an atomic, 0o600 write via secure_io. A missing or unparseable file yields an empty registry rather than failing startup.

Constants§

MAX_MODULE_BYTES 🔒
Cap on a module read back from disk — matches the install-time decode cap.
MAX_REGISTRY_BYTES 🔒
Defensive cap on the registry file. Generous: each record is small provenance + a list of the strings the plugin added.

Functions§

asset_file_name
Sidecar filename for one of plugin plugin_id’s image assets. Both plugin_id (reverse-DNS) and asset_id ([a-z0-9._-]) are validated at install, so the result is a single safe filename component — no separators, no traversal. Recorded in the registry so uninstall can remove exactly it.
asset_path
Absolute path for an asset sidecar named file_name, beside the modules.
delete_asset
Remove an asset sidecar. Missing is fine (idempotent uninstall).
delete_module
Remove a plugin’s module file. Missing is fine (idempotent uninstall).
load
Load the registry, defaulting to empty on a missing or malformed file.
load_module
Read a plugin’s wasm module from disk (size-capped). Errors if missing, oversized, or unreadable — callers treat that as “no detector to run”.
module_path
On-disk path for plugin id’s wasm module. id is reverse-DNS ([a-z0-9.-], validated at install) so {id}.wasm is always a single filename component — no path separators, no traversal.
modules_dir 🔒
Directory holding installed detector/export module binaries, beside plugins.json.
save
Atomically persist the registry with owner-only permissions.
save_asset
Atomically persist an image asset with owner-only permissions.
save_module
Atomically persist a plugin’s wasm module with owner-only permissions.