Overview

In DSH environments, agents or operational workflows often need to prove whether change settlement strictly occurred within a declared maintenance window. Platforms such as AWS and Azure define window rules (such as start time, maximum duration, cutoff time, etc.), but a tool is needed to verify whether the actual change ledger is compliant. dsh-change-window-proof focuses on this narrow problem: verifying whether the provided change ledger settles within the declared time boundaries and remains bound to change receipts, artifacts, environments, and policies.

What This Is

This is an offline, deterministic evidence-generation plugin. It provides a headless core and supports use via DSH bundles, a standalone MCP stdio server, a JavaScript API, and a CLI. Reports are sanitized and validated after writing and use content addressing.

Core Features

  • Offline and deterministic: Generates verifiable evidence without network or real-time dependencies.
  • Content-addressed reports: Generated reports are based on content hashes to ensure data integrity.
  • Maintenance window validation: Checks whether settlement start/end times fall within the declared window, validates a contiguous start → step* → finish sequence, and monotonic increasing UTC timestamps.
  • Duration and cutoff checks: Validates maximum duration and ensures no new step started after the cutoff time.
  • Binding validation: Ensures every event is bound to the same window, receipt, artifact, and environment.
  • SHA-256 chain validation: Validates hash bindings in the event chain and the declared ledger header.
  • Multiple access points: Provides MCP stdio server, JavaScript API, and CLI usage.

Installation and Enablement

Install via DSH bundle; supports local path or GitHub commit hash.

dsh plugin install /absolute/path/to/dsh-change-window-proof
dsh plugin install github:dongsheng123132/dsh-change-window-proof#<commit>

Typical Usage

The plugin provides multiple tools for inspection and validation:

  1. CLI inspection and validation
    # 检查示例文件
    node bin/dsh-change-window-proof.mjs inspect examples/compliant.json

    # 验证示例文件并生成内容寻址报告
    node bin/dsh-change-window-proof.mjs verify examples/compliant.json
  1. DSH tools
    After installation, the plugin provides the following command-line tools:

    • dsh_change_window_inspect: Accepts an inline manifestJson and returns boundary hashes and counts.
    • dsh_change_window_verify: Accepts manifestPath and artifactDir as workspace-relative paths, writes a content-addressed JSON verdict, and reads it back.
  2. MCP tools
    After starting the stdio server, you can call the MCP tools change_window_inspect and change_window_verify using newline-delimited JSON-RPC communication.

Use Cases and Notes

  • Use case: Audits change logs to ensure change operations strictly comply with maintenance-window time constraints and policy requirements.
  • Scope limitations:
    • This plugin is only used to verify evidence; it does not approve, authorize, waive, schedule, or execute changes.
    • It does not authenticate recorders or receipts.
    • It does not query live infrastructure.
    • It does not prove that unrecorded actions occurred.
  • Manifest limitations: The manifest should contain only identifiers, timestamps, counts, and SHA-256 bindings; it must not contain credentials, raw logs, prompts, request bodies, chat text, or source documents.
  • Path requirements: Input and output paths must be workspace-relative paths, and symbolic links are not supported.
  • License: MIT License.

Short Summary

dsh-change-window-proof provides the foundational capability to verify change-settlement compliance. Along with plugins such as dsh-action-parity and dsh-policy-waiver-proof, it forms part of an evidence stack for change-management validation across different dimensions.