kovey/dsh-engineering-suite--packages-dsh-evidence-gate ↗★ 0
dsh-evidence-gate
Evidence and delivery gate for DeepSeek Harness: bind commands, test reports, artifacts and Git fingerprints to a mission, fail closed on missing or stale evidence, and issue an immutable receipt only after a deterministic quality-gate PASS. 适合在交付前需要严格校验测试报告、Git指纹等证据的项目。
설치
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:kovey/dsh-engineering-suite#4a618ac4376c4a075c99c92b69895163bb21b0ce&path:packages/dsh-evidence-gate配置
| 键 | 默认值 | 说明 |
|---|---|---|
enabled | true | 关闭后不注册任何工具与提示词。 |
logFile | ~/.dsh/evidence-gate.log | 只写文件,绝不写 stdout(DSH_ENG_DEBUG=1 时镜像 stderr)。 |
layout.rootDir / missionsDir / specsDir | .dsh / .dsh/missions / .dsh/specs | 也可用扁平键 rootDir / missionsDir / specsDir 覆盖。 |
requireGate | true | 是否要求存在确定性门禁记录。置 false 时不再校验门禁的 scope/results/台账一致性(宿主逃生舱),但仍会展示最新记录。 |
gateSource | dsh-quality-gate | 其裁决被认可为交付依据的插件 id。 |
requiredEvidenceKinds | ['command','test'] | 必填证据类型;显式传 [] 表示不要求类型,全是未知名字则回退默认(fail closed)。 |
maxOutputTail | 2000 | 每条证据保留的输出字符数(tail(),含丢弃字符数提示)。 |
requireCleanTree | true | 交付时工作区指纹必须与门禁观测时一致(比对双方都排除 .dsh/ 台账目录)。 |
maxGateAgeMinutes | 0 | 0 = 不限年龄;否则早于 N 分钟的门禁阻断。 |
prompt.enabled / prompt.order | true / 650 | 系统提示词章节 eng:evidence-gate;章节文本按本次装配的调用会话解析(见上"工作区")。 |
项目级配置(同一个 dsh 进程服务多个仓库)
一个 profile 同时服务多个仓库,所以全局的"必填证据类型"不可能对每个仓库都合适:
每个仓库可以用自己的 .dsh/evidence-gate.json 细化自己的交付检查表,profile 永远是上限。
{
"requiredEvidenceKinds": ["artifact"],
"requireCleanTree": false,
"maxGateAgeMinutes": 30
}
| 可覆盖键 | 类型 | 映射到 |
|---|---|---|
requiredEvidenceKinds | ('command'|'test'|'artifact'|'diff'|'manual')[] | requiredEvidenceKinds(未知名字丢弃并记问题;'gate' 永不接受——gate 行由质量门禁自己写入,模型无法登记;全数组都不可用时回退 profile,绝不 fail open;显式 [] 表示"本仓库不要求类型") |
requireCleanTree | boolean | requireCleanTree |
requireGate | boolean | requireGate |
gateSource | 非空字符串 | gateSource |
maxGateAgeMinutes | ≥ 0 的数字 | maxGateAgeMinutes |
maxOutputTail | 正整数 | maxOutputTail |
| 不可覆盖键(写了会被忽略并记问题) | 为什么 |
|---|---|
enabled | 是否加载插件是部署决策:项目文件不能把交付门禁关掉。 |
logFile | 日志落盘位置是部署决策。 |
rootDir / missionsDir / specsDir / layout | 工件(证据台账 / 门禁记录 / 回执)落在哪由宿主布局决定,项目文件不能迁移它们。 |
allowForceOverride | 它决定模型传入的 force: true 能否放松检查表,只能由宿主显式开启(默认 false);项目文件是模型可能经 shell 改写的路径,不得打开这个逃生舱。 |
prompt | 系统提示词章节属于宿主装配决策。 |
- 文件本身在信任根里:
dsh-spec-gate的 guard 关闭了.dsh/**(只有派生的specs/*.md可写), 所以模型不能用write/edit把自己的交付检查表改松——这也是允许项目级细化的前提。 - 绝不 fail open:文件损坏(非法 JSON / 顶层不是对象)、或某个可覆盖键类型不对(例如
requireCleanTree: "yes"),该键一律回退 profile 值并记问题;requiredEvidenceKinds里的 未知名字与'gate'逐个丢弃并记问题,若因此一个可用类型都不剩,同样回退 profile 的类型。 - 来源可见:
evidence_status会打印配置来源:项目级/配置来源:profile,以及生效的requireGate/requiredEvidenceKinds/requireCleanTree/maxGateAgeMinutes。 只有当项目文件确实改了某个可覆盖键时才写"项目级"——把所有键都拒绝掉(或全是坏类型)的文件 不构成检查表的来源,会显示为profile并附上配置问题条数。 - 读取结果按 mtime+size 缓存(门禁在热路径上求值),改完文件即刻生效。