zhiheng-zhang-Mera/dsh-restart ↗★ 0

dsh-restart

Safe restart execution for DeepSeek Harness: request validation, checkpoint gating, restart locking, graceful shutdown, crash-loop breaking and an external supervisor. It never decides when to restart. 用于执行安全的进程重启。适合需要防崩溃循环、确保重启过程安全稳定的生产环境。

패키지
dsh-restart
호환성
미검증
Harness peer 범위
^0.1.1-rc.1
Cordis peer 범위
^4.0.1
버전
0.1.0
라이선스
MIT
최근 업데이트
2026. 9. 15.

같은 패키지 이름의 다른 저장소

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:zhiheng-zhang-Mera/dsh-restart

Configuration

Every key is optional; the values below are the shipped defaults, and each is documented with the risk of changing it in cordis.patch.yml. Types and effects in full: docs/operations.md.

KeyTypeDefaultEffect
enabledbooleantruemaster switch; false refuses every request with DISABLED
applicationRestart.enabledbooleantruewhether application restarts may happen
applicationRestart.minIntervalMsnumber1200000enforced cooldown between application restarts (20 min)
systemRestart.enabledbooleanfalsewhether the system mode may be used
systemRestart.minIntervalMsnumber3600000enforced cooldown between system restarts (60 min)
allowedSourcesstring[]dsh-health-scheduler, dsh-cli, operatorwho may submit; an empty list is a ConfigError
allowedPrioritiesstring[]low, normal, high, emergencyaccepted priority vocabulary
allowSystemRebootbooleanfalsesecond gate for mode: system; a request must also acknowledge
safety.checkpointRequiredbooleantruewhether a requested checkpoint must succeed
safety.duplicateSuppressionbooleantruewhether a replayed requestId returns the previous answer
safety.crashLoopLimitnumber3unclean starts inside the window that trip the breaker
safety.crashLoopWindowMsnumber600000rolling breaker window (10 min)
safety.safeModeOnLoopbooleantruewhether tripping the breaker also enters safe mode
safety.shutdownTimeoutMsnumber90000shutdown budget, also used as the checkpoint budget
safety.allowForceTerminatebooleanfalsedeclared, validated, never consulted by this release
safety.allowRestartWithoutSupervisorbooleanfalsewhether to exit with nobody to relaunch
supervisor.heartbeatIntervalMsnumber5000supervisor heartbeat period
supervisor.heartbeatTimeoutMsnumber30000age after which the supervisor counts as absent
supervisor.relaunchTimeoutMsnumber90000time a relaunched pid has to be alive
supervisor.launchCommandstring[] | nullnullrelaunch command; null means "reuse the supervisor's argv"
supervisor.launchArgsstring[][]extra arguments appended to the relaunch
supervisor.launchCwdstring | nullnullworking directory for the relaunch
supervisor.pollIntervalMsnumber1000pid poll interval
supervisor.ticketTtlMsnumber600000how long a pending ticket stays valid
supervisor.detachbooleantruewhether the supervisor runs detached — declared and validated, read only by spawnSupervisor(), which this package never calls: see the divergence note below. Only the uncalled spawnSupervisor() consults it
storage.directorystring | nullnullaudit-log directory; null = the state directory
storage.maxLogBytesnumber4194304audit log rotation threshold
storage.maxRecentAttemptsnumber25attempts kept in memory for status
knownReasonCodesstring[]nine codescodes accepted without complaint; unknown ones are logged, not refused

Invalid documents are refused at load with a dotted path, and the plugin continues on the defaults rather than failing the host's boot. For example:

dsh-restart config: supervisor.heartbeatTimeoutMs must exceed supervisor.heartbeatIntervalMs (60000), received 30000
dsh-restart config: allowedSources must list at least one source; an empty list would refuse every request, including an operator request