In the DeepSeek Harness (DSH) ecosystem, verifying the consistency of build processes is a common requirement. How can independent builders confirm that their outputs are identical? Existing tools usually check signatures or download status, but do not verify byte-level matching between independent builders. The dsh-reproducible-build-proof plugin is designed to address this problem.

What Is It

This is a DeepSeek Harness plugin that provides offline content-addressed proof to verify whether independent builds produce byte-for-byte identical outputs. It is maintained by dongsheng123132.

It focuses on validating the convergence of independent builds: confirming whether multiple independent operators, using the same source revision, recipe, build type, parameters, dependency set, and associated environment contracts, ultimately produce the same designated artifact byte-for-byte.

Core Features

  • Offline content-addressed proof: Validates outputs without network requests.
  • Independent build convergence validation: Checks the consistency of input declarations.
  • Input checks: Verifies source revision, recipe, build type, parameters, dependency set, and environment contracts.
  • Explicit hash receipts: Only validates explicit hashes; does not execute builds or packages.
  • Deterministic output: Generates deterministic content-addressed outputs.
  • No runtime dependencies: The validator itself has no external dependencies.

Installation and Enablement

Run the following command in the terminal to install the plugin:

dsh plugin add github:dongsheng123132/dsh-reproducible-build-proof#COMMIT

Typical Usage

The plugin provides multiple invocation methods.

  1. CLI commands: You can directly use the dsh_reproducible_build_inspect and dsh_reproducible_build_verify commands.
  2. MCP stdio server: Exposes the reproducible_build_inspect and reproducible_build_verify interfaces through an MCP stdio server.
  3. CLI JSON path: The CLI supports argument forms that use inspect or verify together with an explicit JSON path.

At runtime, the plugin reads workspace-relative non-symlink manifests and writes results into an explicit workspace-relative artifactDir. It rejects materials shaped like secrets, raw logs, and body/content fields.

Use Cases and Notes

  • Functional boundaries: This plugin does not execute builds, packages, authenticate origins, issue SLSA Verified Property, or claim to protect against threats to source code, dependencies, or distribution. It only verifies the matching of explicit hash receipts. If origin attestation is required, use a provenance/signature verifier.
  • Environment requirements: Requires Node.js 22 or newer.
  • Network and dependencies: The validator has no runtime dependencies and does not initiate network requests.
  • Manifest format: The DSH verify tool only reads workspace-relative non-symlink manifests.

Summary

This tool provides an offline, deterministic evidence layer for the DeepSeek Harness supply chain to validate the consistency of independent builds. To learn more details or view examples, you can access the plugin directory or the GitHub repository.