dongsheng123132/dsh-surface-contract-proof
Content-addressed conformance proof across recorded DSH ToolRuntime, MCP JSON-RPC and CLI JSON surfaces
Content-addressed conformance proof across recorded DSH ToolRuntime, MCP JSON-RPC and CLI JSON interfaces. Baseline and observed fixtures bind target revisions, contract/schema versions, transport versions and SHA-256 bytes, and the checker compares them so that missing, stale, malformed, secret-shaped, schema/version-drifted or semantically different fixtures fail closed. It answers a different upgrade question than action-parity plugins: whether a change altered the exact bytes and versions the interfaces agreed on. The package declares dsh.bundle.patch so it becomes an active profile layer.
Install
dsh plugin --profile surface-contract add github:dongsheng123132/dsh-surface-contract-proofREADME-documented install (the README pins an optional #<commit>). The README uses a dedicated profile named surface-contract — substitute your own profile if you prefer. npm ci / npm test / npm run check and the smoke:plugin and smoke:mcp scripts are documented for local verification.
Compatibility
DSH profile install. Version 0.2.0 removes the bundled DSH tool runtime and the default export that the stock Cordis Loader misclassified; it exposes host-neutral tool definitions through its namespace export instead.
Details
- Repo: dongsheng123132/dsh-surface-contract-proof
- Category: Files & Data
- Stars: 2
- Version: GitHub main (no npm package; README notes version 0.2.0)
- Last push: 2026-09-07
- First seen: 2026-08-14
FAQ
- How do I install dsh-surface-contract-proof?
- Run: dsh plugin --profile surface-contract add github:dongsheng123132/dsh-surface-contract-proof (the README's example profile is named surface-contract — substitute your own), optionally pinned to a #<commit>.
- What does it prove?
- That recorded ToolRuntime, MCP JSON-RPC and CLI JSON interfaces still match their baselines — target revision, contract/schema versions, transport versions and SHA-256 bytes — failing closed on drift.
- What changed in 0.2.0?
- It removes the bundled DSH tool runtime and the default export the stock Cordis Loader misclassified, exposing host-neutral tool definitions through its namespace export instead.
Alternatives
imsai-sh/zhuzhiliao · bruc3van/awesome-dsh-plugin · ZSeven-W/dsh-openpencil