# How does mender client store provides on the device?

**URL:** <https://hub.mender.io/t/how-does-mender-client-store-provides-on-the-device/4258>\
**Category:** General Discussions\
**Tags:** mender-client, provides\
**Created:** [October 30, 2021, 7:48pm UTC](https://hub.mender.io/t/how-does-mender-client-store-provides-on-the-device/4258 "2021-10-30T19:48:34Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mho](https://avatars.discourse-cdn.com/v4/letter/m/a183cd/32.png) [@mho](https://hub.mender.io/u/mho)\
**Post date:** [October 30, 2021, 7:48pm UTC](https://hub.mender.io/t/how-does-mender-client-store-provides-on-the-device/4258/1 "2021-10-30T19:48:34Z")

</div>

I’m trying to understand how mender-client stores provides on device.

- Where are they stored, and when do they get written to the device?
- Are they available pre-commit of the artifact?
- How is the data protected - could an attacker change the value of provides, or is it guarded against modification in any way?
- Is there a command or file where they’re stored, if I want to programmatically read provides on-device?

I found this doc, but it doesn’t go into much detail.  
[https://docs.mender.io/overview/artifact#provides-and-depends](https://docs.mender.io/overview/artifact#provides-and-depends)

I have a few different use cases for provides pre-commit, but I don’t have enough information to understand how to use it on-device.

---

<div class="post-metadata">

**Author:** ![kacf](https://yyz2.discourse-cdn.com/flex036/user_avatar/hub.mender.io/kacf/32/146_2.png) [@kacf](https://hub.mender.io/u/kacf)\
**Post date:** [November 1, 2021, 8:15am UTC](https://hub.mender.io/t/how-does-mender-client-store-provides-on-the-device/4258/2 "2021-11-01T08:15:17Z")

</div>

> [@mho](#):
>
> Where are they stored, and when do they get written to the device?

They are stored in `/var/lib/mender/mender-store`, an LMDB database. They get written immediately after the `ArtifactCommit` state has finished successfully, together with the new artifact name.

> [@mho](#):
>
> Are they available pre-commit of the artifact?

Yes, but only in Update Modules, not in state scripts. They are available as artifact headers in `header/header-info` inside the directory which is passed to the Update Module when it is called. See [the File API](https://github.com/mendersoftware/mender/blob/3.1.0/Documentation/update-modules-v3-file-api.md#file-api) in the Update Module specification for more information.

> [@mho](#):
>
> How is the data protected - could an attacker change the value of provides, or is it guarded against modification in any way?

They are protected by normal Unix file permissions, writable by root only.

> [@mho](#):
>
> Is there a command or file where they’re stored, if I want to programmatically read provides on-device?

Yes, use `mender show-provides`. Note that these only display the currently active provides, which during an installation, are still the old provides. Use the header approach I described above if you need the provides of the new artifact during installation.
