Back to home@dongsheng123132

dsh-build-hermeticity-proof

Offline hash-only proof that recorded build accesses stayed within a declared closure

Stars
0
Language
JavaScript
Created
Aug 26, 2026
Updated
Aug 26, 2026
GitHub repo

Introduction

DSH Build Hermeticity Proof

An offline, deterministic evidence layer for DeepSeek Harness supply chains. It verifies whether an explicit, hash-only build access receipt stayed inside its declared file, environment, network, clock, randomness and output closure.

It does not execute a build, does not enforce a sandbox, authenticate the receipt, or prove that unrecorded accesses could not occur. It also does not prove reproducibility. A hermetic verdict means only that the supplied receipt is internally complete and policy-conformant.

Complementary boundary

  • dsh-reproducible-build-proof compares independently operated rebuild receipts for byte-identical specified outputs.
  • dsh-attestation-proof verifies DSSE/in-toto signatures, subjects and signer thresholds.
  • This plugin checks one recorded build's declared external-influence closure: file reads/writes, environment reads, network, clock and randomness.

Observed undeclared access fails. A denied undeclared attempt is retained as containment evidence but does not breach the closure. Observed network access always fails under the v1 deny-only network policy. Declared inputs and outputs must all appear in the receipt; the source revision, invocation, clock value, random seed and allowed environment values are hash-bound.

Install

dsh plugin add github:dongsheng123132/dsh-build-hermeticity-proof#COMMIT

The bundle exposes dsh_build_hermeticity_inspect and dsh_build_hermeticity_verify from one headless core. The independent MCP stdio server exposes build_hermeticity_inspect and build_hermeticity_verify. The CLI accepts inspect or verify plus an explicit JSON path.

See examples/hermetic.json. Reports contain only hashes, counts, booleans, classifications and verdicts. Secret-shaped material, raw logs and body/content fields are rejected. The DSH verify tool reads a workspace-relative non-symlink manifest, writes only to an explicit workspace-relative artifactDir, creates deterministic content-addressed output exclusively, and verifies it by read-back.

npm test
npm run check
npm run smoke:plugin
npm run smoke:mcp
python C:/Users/YOU/.codex/skills/.system/plugin-creator/scripts/validate_plugin.py .

Node.js 22 or newer is required. The verifier has no runtime dependency, spawns no process and makes no network request.