A development safety kit: rolling config snapshots, automatic rollback on plugin failures, boot-failure rescue, and an in-settings management panel.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:x2802490130-prog/dsh-guard
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
This plugin publishes its README in Chinese only.
DSH 开发配套守护插件:滚动快照 + 失败自动回退 + 本机管理面板。
能力
- 滚动快照:每次存档保留最近 N 份(默认 5,带时间戳+原因),同时镜像 last-good 供外部启动器/bat 互操作
- 自动存档:启动成功且度过宽限期后自动存档(reason=auto)
- 自动回退:监听到插件运行失败,三道护栏内自动回退 last-good(每启动一次、宽限期内、快照早于本次启动)
- 管理面板(仅本机):
http://127.0.0.1:<端口>/dsh-guard—— 状态 / 快照列表 / 一键存档 / 回退 / 恢复备份 / 事件日志 - 管理 API(仅本机):
/api/dsh-guard/{status,snapshots,backups,log,save,rollback,restore} - 事件日志:
snapshotRoot/guard.log
配置(profile 补丁层,均可省略)
- id: dsh-guard
config:
snapshotRoot: D:\path\to\snapshots
profileDir: C:\path\to\profiles\web
sourceDirs: [D:\path\to\plugin-src]
restartCommand: D:\path\to\restart.bat # 空 = 只回退不重启
graceMs: 120000
autoSaveDelayMs: 150000
keepSnapshots: 5
安全边界(重要)
- boot 崩坏插件救不了:进程在启动期崩溃时插件无法运行,boot 救援由外部启动器承担(见 dsh-balance-float 仓库的 windows/launch-dsh.vbs SNAP_TOOL 机制)
- 管理面板/API 仅限本机回环地址访问
- 每次启动最多自动回退一次(防死循环)
测试
node test.mjs # 21 项
License
MIT
Links
More in this category
yjh051108/dsh-routing-suite★ 7003
One repository, three parts: a runtime injector for DSH plugin packages (inject, hot-reload, unload, promote a dev staging tool to the front, route self-heal, plus a settings-page plugin manager that lists, unloads and drags folders in to internalize), a task-aware reasoning-mode router agent preset (router-standard / router-spec / router-react), and a graded two-level task protocol whose six tools (commit_star, lock_stage, revise_do, edit_plan, mark_task, redteam_verdict) pin task state to disk. The injector implementation ships in-tree, so the install carries its own behaviour rather than a dependency list.
strukto-ai/mirage#dsh★ 3666
Swaps the filesystem and bash providers for a mirage virtual workspace: file tools and shell commands run over mounted resources (RAM, S3, Redis, Slack, Gmail, Notion, Postgres) instead of the host disk, with per-mount read/write/exec modes, per-command sandbox routing (monty, pyodide, quickjs in process; docker, e2b, daytona remote), and installed CLIs (git, gh, slack, linear, ntn, gws, or one you register) as head words in the virtual terminal.
hust-open-atom-club/oh-dsh★ 325
Community distribution: TUI, desktop, and Web UI as one bundle with layered installation.
weijiafu14/pi2dsh★ 206
Pi Host ABI compatibility engine: after one install, unmodified Pi extensions from npm mount as native DSH plugins with `dsh plugin add <pi-package>`. Verified end to end on stock DSH with pi-mcp-adapter (full MCP manager: OAuth, resources, prompts, MCP Apps, elicitation, sampling), @tintinweb/pi-subagents, pi-code, pi-hermes-memory and pi-background-tasks; `pi2dsh inspect` reports a package's compatibility before installing.
lire1131/dsh-undo-savepoint★ 166
Undo/redo & rollback system for DSH: every config change is auto-snapshotted; undo/redo/restore to any version from the WebUI or the offline CLI/GUI tools (works even when DSH fails to boot).
Fishquito7/dsh-skill-mcp-panel★ 155
Manages DSH skills and MCP servers from the web settings: skill cards with hot enable/disable, workspace scopes, groups, batch migration and drag-and-drop import, plus stdio/HTTP MCP CRUD with connection tests, secret redaction and the unified dsh-panel CLI.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.