wqx11235/dsh-upgrade-guard

DSH 升级守卫:升级前兼容盘点 / 升级后契约扫描 / 启动冒烟(DeepSeek Harness 插件)

Project Overview项目介绍

dsh-upgrade-guard is a native upgrade-guard bundle for DeepSeek Harness (DSH) that turns every past post-mortem into a reusable rule, codified in lib/guard.mjs as KNOWN_RULES. It exposes three actions through the host route POST /api/dsh-upgrade-guard and through node lib/guard.mjs: an offline "scan" that flags removed services such as settingsScope and conversationEvents, the deprecated session message source: { kind: 'plugin' } V3 form, references to primitives exports no longer present in @deepseek-ai/dsh-client-ui-primitives, and exact-pinned plugin versions that drift behind the host; a network "preflight" (10–40 s) that walks each installed plugin, reads its declared compatibility range from npm, and produces a "can I upgrade + which to upgrade together + disable list" matrix; and a "smoke" pass (30–90 s) that boots the candidate host on port 3099, captures SKIPPED / PENDING / DEGRADED / BADBUNDLE entries, probes every client bundle for reachability, and only returns PASS when the bundle tree is clean — the test process is killed by default unless DSH_SMOKE_KEEP=1.

The bundle targets DSH operators who keep non-trivial profile bundles and have been bitten by cascading failures such as "31 plugins pending" after a 0.1.2→0.1.5 host bump or a React #130 crash after the 0.1.7-alpha.1 primitives rename. Console output is intentionally ASCII to survive Windows cmd code page 936; Chinese reports are written to the --report file. Every new breakage is meant to be added to KNOWN_RULES, so the tool gets sharper with use.

Install with pnpm add github:wqx11235/dsh-upgrade-guard inside %USERPROFILE%\.dsh\profiles\web, append the bundle name to dsh.profile.bundles, restart the host via the desktop shortcut or restart-dsh-web.cmd, then Ctrl+F5 and open Settings → General → 升级守卫. Limits: smoke covers only startup, not render-time React errors; scan only sees rules already in KNOWN_RULES; preflight cannot resolve github:... git/url sources to a latest version; host-skipped bundles are reported as SKIPPED and require dsh plugin allow-version to re-enable. License: MIT.

dsh-upgrade-guard 是面向 DeepSeek Harness(DSH)的原生升级守卫插件,把每次排障得到的破坏性契约沉淀为可复用的检查规则。它在升级前做联网盘点(拉取插件 npm 元数据判断兼容范围)、平时做离线契约扫描、切换端口前在测试端口(默认 3099)跑启动冒烟,三步闭环降低宿主版本升级后"页面 Failed to load plugins"或"31 个插件连锁 pending"这类连环崩溃的概率。

典型用法:进入 DSH "设置 → 通用 → 升级守卫"点击三个按钮,或在命令行执行 node lib/guard.mjs scan|preflight|smoke,支持 --json --report file.md 输出中文报告。它适合长期维护多插件 profile 的 DSH 用户、需要在团队内统一升级节奏的维护者,以及每次 DSH 发版前都想先冒烟再切的谨慎型玩家;冒烟通过后才建议切换主端口,结束时默认必杀进程。

依赖方面仅需 Node.js 与 pnpm,按 pnpm add github:wqx11235/dsh-upgrade-guard 装入 %USERPROFILE%\.dsh\profiles\web 后写入 dsh.profile.bundles,重启宿主并 Ctrl+F5 即可启用。局限:冒烟只覆盖启动期不覆盖渲染期 React #130 类错误;契约扫描仅识别 KNOWN_RULES 中已收录的破坏模式;git/url 源插件查不到最新版需人工核对;license 为 MIT。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:wqx11235/dsh-upgrade-guard

把 wqx11235/dsh-upgrade-guard 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-upgrade-guard · DSH 升级守卫

让「更新 DeepSeek Harness 本体」不再变成「更新一次崩一次」。 升级前盘点插件兼容性 → 升级后扫描已知破坏性契约 → 切换端口前先启动冒烟,不通过就别切。

DeepSeek Harness(dsh) 的插件生态很活跃,但宿主每次升级都可能改契约,跟在后面的插件就容易崩。真实案例(同一个坑反复出现):

事故 根因 症状
0.1.1 → 0.1.2 client-modules 模块表变严 页面 Failed to load plugins
0.1.2 → 0.1.5 服务访问契约变严(inject 缺失即崩) 31 个插件连锁 pending
0.1.6 → 0.1.7 服务 settingsScope 被移除/改名 26 个插件 pending(Console 只有 4 条真节点)
0.1.7-alpha.1 primitives 图标改名(IconXxx14 → IconXxxRegular,无别名) 插件面板 Minified React error #130(元素类型 undefined)
0.1.7 会话消息 V4 source 契约 某轮对话跑完后失败:format v4 message requires a producer-owned source kind

这些都是运行库版本升级 → 底层契约变更 → 插件没跟上。本插件把每次排障得到的判据固化成可复用检查。

三个动作

动作 什么时候用 做什么
契约扫描(离线,秒级) 平时 / 升级后 按「已知破坏性契约」目录扫已装插件:被移除的服务名、会话消息旧 source 写法、引用了宿主导出表里不存在的 primitives 成员
联网盘点(10–40 秒) 升级前 逐个插件看:声明了什么兼容范围、npm 上有没有新版、新版是否声明支持目标版本 → 产出「能不能升 + 哪些要一起升 + 停用清单」
启动冒烟(30–90 秒) 切换端口前 在测试端口(默认 3099)起一次被检查的宿主 → 抓「被 peer 门跳过的插件 / 功能降级 / pending / 插件树真凶」+ 逐个探 client bundle 可达性 → PASS 才建议切换;结束必杀测试宿主

安装

三种方式,任选:

# ① 直接从一个 GitHub 仓库装(pnpm 会拉取并安装到 profile)
cd $env:USERPROFILE\.dsh\profiles\web
pnpm add github:wqx11235/dsh-upgrade-guard
# 然后把它加进 profile 的 dsh.profile.bundles:编辑 package.json 的 dsh.profile.bundles 数组,加入 "dsh-upgrade-guard"

# ② 手动放置(无网络依赖)
#   把本仓库整个目录复制到 %USERPROFILE%\.dsh\profiles\web\node_modules\dsh-upgrade-guard
#   同样把它加入 dsh.profile.bundles

# ③ 通过 dsh 插件市场安装(若已上架)

装完重启宿主(桌面快捷方式 / restart-dsh-web.cmd),浏览器 Ctrl+F5,然后进 设置 → 通用 → 升级守卫。

使用

在界面里

设置 → 通用 → 升级守卫,三个按钮:

  • 契约扫描 → ⚠ 契约扫描:critical N / warn N(扫了 M 个插件) + 明细
  • 联网盘点 → 📋 联网盘点(目标 x.y.z):N 个插件,K 个有新版 + 新版本清单
  • 启动冒烟 → ✅ 启动冒烟:PASS / ❌ FAIL + 关键输出行(ROOT? / PENDING / SKIPPED / DEGRADED / BADBUNDLE)

命令行(同一份引擎)

node lib/guard.mjs scan       --json --report report-scan.md
node lib/guard.mjs preflight  --json --report report-preflight.md --target 0.1.8-rc.1
node lib/guard.mjs smoke

smoke 用环境变量配置:

变量 说明 默认
DSH_SMOKE_BIN 要冒烟的 dsh 入口(.../dsh/lib/bin.js) 当前安装
DSH_SMOKE_PORT 测试端口 3099
DSH_SMOKE_CWD 启动工作目录 当前目录
DSH_SMOKE_TIMEOUT 等待就绪秒数 120
DSH_SMOKE_KEEP=1 跑完不杀测试宿主(排障用) 关

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-live-inspector 下一个 Next dsh-sidebar-plus →