In DeepSeek Harness (DSH), schema migrations are typically recorded in test suites. Verifying that migrations are idempotent, can be rolled back, and respect invariants is a critical part of engineering. Traditional validation approaches may make it difficult to directly verify the integrity and determinism of evidence. The dsh-schema-migration-proof plugin aims to solve this problem by generating and validating migration evidence offline.

Positioning and Features

dsh-schema-migration-proof is a DeepSeek Harness plugin maintained by dongsheng123132 and categorized as admin-security. It does not execute migrations or return data bodies; instead, it focuses on generating offline, content-addressed evidence for recorded DeepSeek Harness schema migrations. Its core purpose is to validate deterministic output for fixture envelopes, idempotent re-run capability, reversible rollback, required invariants, and explicitly declared data-loss fields.

Main features include:

  • Offline content-addressed evidence: Generates offline evidence for recorded DSH schema migrations without relying on the network or external execution.
  • Output determinism validation: Checks fixture envelopes to ensure outputs are deterministic.
  • Idempotent re-run and reversible rollback: Supports idempotent re-execution of migrations and validation of reversible rollbacks.
  • Invariant checks: Validates required invariants and uses a fail-closed strategy when they are missing or fail.
  • Explicit loss disclosure: For lossy migrations, all disclosed data-loss fields must be enumerated.

Installation and Enablement

Use the official CLI to install it. Run the following command to add the plugin to the current configuration file:

dsh plugin --profile web add github:dongsheng123132/dsh-schema-migration-proof

Typical Usage

  • CLI usage: Run the verification command in the terminal, specifying the workspace root, migration file, and artifact directory.
    dsh-schema-migration-proof verify --workspace-root examples --migration migration.json --artifact-dir artifacts
  • MCP usage: Invoke inline check and validation features through the Model Context Protocol (MCP).

Applicable Scenarios and Notes

  • Applicable scenarios: Suitable for scenarios where strict validation of schema migration evidence integrity and security is required.
  • Notes:
    • This plugin is not a migration runner, database tool, recovery system, or second-layer contract validator.
    • The plugin rejects inputs containing Body, Data, Payload, Secret, Credential, Prompt, and Message shape fields.
    • If a required invariant is missing, fails, or is not observed, validation will fail (fail closed).
    • Runtime requirements: DSH version must be >= 0.1.2-alpha.4 and Node.js version must be >= 22.

Summary

This plugin provides rigorous evidence generation and validation for DSH schema migration tests. For engineering practices that prioritize migration safety and determinism, it is a necessary auxiliary tool.