隔离插件卸载后验证 Cordis 管理的运行时资源是否回到基线,并生成确定性清理回执。
安装
# GitHub 源码(首次需按提示配置 allowBuilds 构建授权后重试)
dsh plugin --profile web add github:chouyong/dsh-effect-doctor
装任何插件都等于在你的机器上跑第三方代码,权限和你本人一样大——能读你的文件、用你的凭据、访问网络,工具审批管不到它。GitHub 来源的插件还会在安装时执行构建脚本——pnpm 默认拦截,所以安装可能停在 ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED 或 ERR_PNPM_IGNORED_BUILDS;dsh 会打印出需要添加的确切键名,把它加进该 profile 的 pnpm-workspace.yaml 的 allowBuilds 下,重跑一次即可装上。放行构建本身就是一次信任判断:请只安装可信来源,并尽量锁定 commit(github:owner/repo#sha)。
README
该插件的 README 只有英文版本。
dsh-effect-doctor verifies one narrow lifecycle property: after a fixture is mounted, exercised, unmounted, and allowed to settle, the Cordis-managed resources visible through the supported adapter return to their baseline.
The project is a technical preview. Its verified release classification is PASS_AFTER_CHANGES, not FIRST_PASS.
What it proves
The current adapter is pinned to DeepSeek Harness's vendored @deepseek-ai/cordis@4.0.1. It observes:
- plugin fibers and lifecycle state;
- registry runtimes;
- Cordis-managed effects and disposables;
- Cordis event registrations;
- Cordis services/providers visible through the adapter;
- timer effects registered through Cordis when the timer plugin is present.
The adapter checks every private observation surface before use. An unsupported version or changed runtime structure produces UNVERIFIABLE_VERSION or UNVERIFIABLE_SURFACE; it never silently becomes PASS.
What it does not prove
This is not a general memory-leak detector. It does not claim coverage for bare JavaScript timers, DOM or global listeners, native handles, external processes, arbitrary heap growth, or resources that bypass Cordis. It is not a security audit or production approval.
The audit runner does not inspect prompts, session bodies, tool arguments/results, credentials, cookies, or plugin business data. Receipts contain only runtime identity, lifecycle configuration, stable resource metadata, bounded error names/codes, the comparison, and stated limitations.
CLI
Install dependencies and build without running dependency scripts:
npm ci --ignore-scripts
npm run build
Run a fixture against the DSH vendored Cordis module:
node dist/src/cli.js `
--fixture clean `
--cordis-module D:\knowledgeBase\deepseek-harness\vendor\cordis\lib\index.js `
--out-dir artifacts\latest
The output directory receives deterministic receipt.json, receipt.md, and self-contained receipt.html files. The CLI uses a single-run lock and bounded mount, exercise, unmount, and settle phases.
Supported fixtures are clean, leaky, throwing-disposer, hanging-disposer, startup-failure, and unknown-version. Run node dist/src/cli.js --help for timing and lock options.
Outcomes
| Outcome | Exit | Meaning |
|---|---|---|
PASS |
0 | Declared Cordis-managed resources returned to baseline. |
FAIL_LEAK |
20 | A declared resource remained after settle. |
FAIL_DISPOSE |
21 | Cordis logged a disposer failure. |
FAIL_TIMEOUT |
22 | A bounded lifecycle or settle phase timed out. |
FAIL_MOUNT |
23 | Fixture startup failed. |
FAIL_EXERCISE |
24 | The explicit exercise callback failed. |
FAIL_LOCKED |
25 | Another audit owns the single-run lock. |
UNVERIFIABLE_VERSION |
30 | The Cordis package/version is unsupported. |
UNVERIFIABLE_SURFACE |
31 | A required observation surface failed validation. |
Every non-PASS result exits non-zero. Red lines use explicit checks, not assert.
DSH receipt tool
The package also contains a host-only DSH bundle. It registers one generic tool, effect_doctor_receipt, which reads an already-completed receipt from the configured absolute path and returns a strict, sanitized summary.
The tool does not start an audit, unload a live plugin, accept a caller-controlled path, or read session content. It enforces a configurable byte limit, rejects unknown JSON fields, omits the receipt's host module path, and uses DSH's effect-owned tool registration so unloading the bundle removes the tool.
The bundle defaults to:
$DSH_HOME/effect-doctor/latest/receipt.json
Generate that file by setting the CLI output directory to $DSH_HOME/effect-doctor/latest. The bundle configuration can override receiptPath, maxBytes, and timeoutMs in a later DSH patch layer.
This package has no client bundle or browser surface. Browser screenshots, GIFs, client assets, style nodes, and page-console checks are therefore inapplicable and must not be substituted or fabricated.
Local bundle install
Build a precompiled tarball, then install it into an isolated profile from the DeepSeek Harness checkout:
npm pack --pack-destination artifacts\stage-3
$env:DSH_HOME = 'D:\dsh-effect-doctor-gate'
Set-Location D:\knowledgeBase\deepseek-harness
pnpm dsh plugin --profile effect-doctor-stage3 add D:\knowledgeBase\dsh-effect-doctor\artifacts\stage-3\dsh-effect-doctor-0.1.0.tgz
pnpm dsh --profile effect-doctor-stage3 --dump-config
The tarball is prebuilt; installation does not need a package build-script allowance. Use a fresh D-drive DSH_HOME for audit evidence and never install or unload fixtures in an active production profile.
After installation, run the keyless real Loader gate against the installed module:
node dist/scripts/dsh-real-gate.js `
--dsh-source D:\knowledgeBase\deepseek-harness `
--dsh-home D:\dsh-effect-doctor-gate `
--profile effect-doctor-stage3 `
--receipt D:\dsh-effect-doctor-gate\effect-doctor\latest\receipt.json `
--tarball D:\path\to\dsh-effect-doctor-0.1.0.tgz `
--out-dir D:\path\to\stage-3-evidence
This gate rechecks the installed profile and dumped composition, boots a minimal real DSH Loader tree, executes the registered tool, validates its output against the completed receipt, disposes only the doctor Loader entry, and proves the tool registration disappears.
Verification
npm run verify
The command runs strict typechecking, a production build, unit contracts, the CLI contract, tests against the real DSH vendored Cordis runtime, and the isolated child-process gate. Stage evidence and artifact identities are recorded in docs/.
Publication remains fail-closed. No PR may be created until the GitHub repository is at least 24 hours old, the product has at least 10 genuine functional commits, Stage 0–3 evidence is complete, any applicable real screenshots exist, and Claude's independent read-only review ends with FINAL_DECISION: GO.
链接
同类插件
yjh051108/dsh-routing-suite★ 6990
一个仓库三件套:DSH 插件包的运行时注入器(注入、热重载、卸载、开发侧挂区一键转正、路由自愈,外带设置页插件管理:列出、卸载、拖入文件夹内化)、任务感知的思维模式路由 agent 预设(router-standard / router-spec / router-react)、以及分级两级任务协议(commit_star / lock_stage / revise_do / edit_plan / mark_task / redteam_verdict 六个工具,任务状态落盘)。注入器实现直接在库内,安装的是它自己的行为而不是一份依赖清单。
strukto-ai/mirage#dsh★ 3670
把文件系统与 bash 提供者换成 mirage 虚拟工作区:文件工具与 shell 命令作用于挂载的资源(RAM、S3、Redis、Slack、Gmail、Notion、Postgres)而非宿主磁盘,支持按挂载点设置读/写/执行模式、按命令选择沙箱(进程内 monty、pyodide、quickjs;远程 docker、e2b、daytona),并可在虚拟终端中安装 CLI(git、gh、slack、linear、ntn、gws,或自行注册的程序树)作为命令头词。
hust-open-atom-club/oh-dsh★ 325
社区发行版:TUI、桌面端与 Web UI 统一体验,分层安装、一步到位。
weijiafu14/pi2dsh★ 210
Pi Host ABI 兼容引擎:装一次之后,npm 上的 Pi 扩展原包经 `dsh plugin add <pi-package>` 直接作为 DSH 原生插件挂载。已在官方 DSH 上端到端验证 pi-mcp-adapter(完整 MCP 管理面:OAuth、resources、prompts、MCP Apps、elicitation、sampling)、@tintinweb/pi-subagents、pi-code、pi-hermes-memory、pi-background-tasks;`pi2dsh inspect` 在安装前报告一个包的兼容情况。
lire1131/dsh-undo-savepoint★ 168
DSH 撤销/回退系统:配置变更自动存档,一键撤销/恢复/回退到任意版本,支持 WebUI 与离线 CLI/GUI 工具(DSH 启动失败也能救)。
Fishquito7/dsh-skill-mcp-panel★ 161
在 DSH Web 设置中管理技能与 MCP 服务器:技能卡片热启停、工作区作用域、分组、批量迁移与拖拽导入,以及 stdio/HTTP MCP 增删改查、连接测试、密钥脱敏,并附带统一 dsh-panel 命令行。
社区评论
评论公开保存在 GitHub Discussions。加载评论会连接 GitHub 和 Giscus;发表内容需要 GitHub 账号。