Preface¶
Validating the “convergence” of control-plane changes (such as services, Task Scheduler tasks, and event logs) in a Windows environment is a complex task. dsh-windows-settlement-proof is designed to address this challenge. It provides offline, content-addressed evidence that an approved Windows control-plane change has reached consistent agreement across all required surfaces.
Core Role¶
This is a DSH plugin for the administrative security domain. Its core responsibility is to verify whether a change has been “settled” (reached agreement), not to execute the change. It compares fixed hash locks to check whether the state of key components such as the Service Control Manager, Task Scheduler, and event logs matches the expected state.
Core Features¶
The plugin operates as a verifier, not as an executor. It has the following characteristics:
- Static evidence comparison: Compares explicit redacted receipts for Service Control Manager, Task Scheduler, event logs, and policy projections against pinned hash locks.
- Zero execution risk: It does not run PowerShell,
sc.exe, registry commands, or arbitrary child processes, and does not read Windows services, task definitions, event XML, or business payloads. - Safe reporting: Reports contain only public counts, boolean values, and SHA-256 values, with no sensitive business data.
- Metadata checks: Provides inline, read-only metadata inspection.
- Convergence validation: Checks whether the change has converged, whether it persists within the required reboot epoch, and whether it matches successful event receipts.
Installation and Activation¶
Run the following command in the current working directory to install the plugin:
dsh plugin --profile proof add .
Typical Usage¶
The plugin provides verification and inspection capabilities. The following is a typical workflow:
- Install the plugin: Use the installation command above.
- Verify a specific manifest: Verify a manifest using a workspace-relative path.
node bin/dsh-windows-settlement-proof.mjs verify examples/settled.json
- Run tests: Use the project’s built-in test scripts.
npm test
npm run check
Applicable Scenarios and Notes¶
- Applicable scenarios: Suitable for scenarios that require strict auditing of Windows control-plane change consistency.
- Privileges and security: The plugin runs with the privileges of the current DSH process. Review the source code and license (MIT) before installation.
- Path safety: Manifest and artifact paths reject absolute paths, traversal, and symbolic links.
- Sensitive data: Values in key formats and fields that identify credentials are rejected.
- File writing: Artifact writes use exclusive creation and deterministic content addressing, followed by SHA-256 read-back validation after writing.
Conclusion¶
The plugin provides a mechanism for validating Windows change consistency, ensuring that changes have been properly reflected at the control-plane level. For more details, see the GitHub repository.