Preface¶
DSH adopts a plugin architecture. Installing and uninstalling plugins can leave residuals in .dsh/, the Nuke directory, the system TEMP folder, and elsewhere. Manual cleanup is prone to accidental deletion, script-based cleanup is irreversible, and incidents may be impossible to trace. This plugin applies database-level discipline to this process, providing verifiable, reversible, and auditable cleanup capabilities.
Core Capabilities¶
The plugin wraps “delete a plugin and clean up residuals” into a transaction system. Each action has a validate / preview / execute / undo closed loop. Directory deletion uses atomic rename into a recycle area, and physical deletion is allowed only after commit.
Transactions and Recovery¶
During nuke_clean execution, if it fails, Saga rollback is performed automatically. The plugin supports WAL (write-ahead logging). Together with nuke_recover, it can scan the WAL of uncommitted transactions and use reverse compensation to restore the pre-execution state.
Security Principles¶
The security mechanisms are designed based on the following principles:
* fail-closed: If the validator/health check itself fails, the operation is also rejected.
* Path Containment: All path operations are restricted to authorized directories, and a txId whitelist prevents injection.
* TOCTOU revalidation: Analysis and execution occur at different times; before execution, file fingerprints (size + SHA-256 + mtime) are revalidated.
* Honest accounting: Hard-link deduplication does not inflate bytesSaved.
* Protection list: It acts as an engine pre-hook veto; exceeding the limit causes rejection.
* Recycle area instead of physical deletion: purge is allowed only after commit.
Auditing and Verification¶
The plugin maintains a hash-chain audit log, and any tampering can be detected by nuke_verify. After installation, the tools are registered as dsh Agent tools and can be invoked directly.
Installation and Activation¶
Run the following command to install the plugin:
dsh plugin add beijingwahw/dsh-nuke-plugin --profile web
Typical Usage¶
Simulation and Execution¶
- Scan the current state: Use
nuke_scanto list third-party plugins installed under the profile and obtain statistics for reclaimable space and a five-factor score. - Oracle simulation: Use
nuke_oracleto perform an oracle simulation, predicting transaction success rate, expected recovery, and the most fragile step based on historical data. - Risk assessment: Use
nuke_blastradiusto perform a blast-radius sandbox simulation, assessing the cascading impact of deletion on other components. - Dry run: Use
nuke_clean --dry_run trueto view the plan without actually modifying files. - Execution: Use
nuke_cleanto perform cleanup; failures roll back automatically, and the audit chain is recorded throughout.
Recovery After a Crash¶
If a crash occurs during cleanup, first use nuke_status to inspect uncommitted transactions. Use nuke_recover to scan the WAL of uncommitted transactions and perform reverse-compensation recovery. Finally, use nuke_verify to verify the integrity of the audit chain.
Advanced Features: Self-Learning Intelligent Engine¶
The plugin has Bayesian self-learning capabilities and can refine predictions based on historical execution data.
Intelligent Decision-Making¶
V5.6 introduces Thompson exploration (posterior sampling decision-making) and a CVaR₁₀ downside risk model.
* Thompson exploration: It uses posterior sampling decisions to avoid the “rich get richer” effect and gives actions with little data an opportunity to be executed.
* CVaR₁₀: It calculates the average recovery under the worst 10% of scenarios, honestly answering “Can I accept the worst case?”
Self-Calibration¶
V5.5 adds a self-calibration mechanism. The plugin uses Brier skill scores and logit shifts to learn systematic bias from reconciled (prediction, outcome) pairs, dynamically correcting future predictions and making the oracle engine’s numbers more reliable.
Conclusion¶
This plugin provides industrial-grade cleanup and recovery capabilities for DSH plugin management. Before use, ensure the installation command is correct, and inspect the source code and license.