sandbase-harness
sandbaseai
Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:IoveCelestina/dsh-lifeboat
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
English | 简体中文
DSH Lifeboat is an out-of-process recovery console for DeepSeek Harness profiles. It can still start when a profile cannot: every probe runs against a temporary DSH_HOME, and the original profile manifest and patch files stay read-only until the user explicitly applies a recovery.

127.0.0.1 with live probe progress, evidence, verified recovery-plan selection, report download, and one-step undo.dsh-lifeboat/v1 JSON report without the UI.dsh --profile <name> --dump-config.cordis.patch.yml failures.GET /api/health, browser-session reconnect, restart-safe report/undo recovery, and atomically persisted reports.~/.dsh/lifeboat/last-healthy.json only after the Loader settles. The rescue server itself never runs inside the failing Harness process.Node.js ^22.19.0 || >=24.0.0 is required. There are no runtime dependencies.
node ./src/cli.js serve
Open the printed http://127.0.0.1:<port>/ address. The default port is 4317; use --port 0 for a random free port.
Terminal reports are stored under $DSH_HOME/lifeboat/reports. The service keeps the newest 500 by default; use --max-reports N, or --max-reports 0 only when an external retention policy owns cleanup. See service operation for systemd and Windows Task Scheduler guidance.
Run without the UI:
node ./src/cli.js diagnose --profile web
node ./src/cli.js diagnose --profile web --json
node ./src/cli.js diagnose --profile web --mode boot --allow-runtime-code-execution
node ./src/cli.js diagnose --profile web --mode boot --boot-confirmations 3 --allow-runtime-code-execution
node ./src/cli.js diagnose --profile web --max-exact-removals 2 --max-recovery-probes 256
When dsh is run from a Harness source checkout, use safe executable-plus-argument fields instead of a shell command string:
node ./src/cli.js diagnose \
--command pnpm \
--command-arg --dir \
--command-arg /path/to/deepseek-harness \
--command-arg dsh \
--profile web
On PowerShell, quote any argument beginning with -- when necessary.
Install the pinned v0.1.1 release directly through Harness:
dsh plugin --profile web add https://github.com/IoveCelestina/dsh-lifeboat/releases/download/v0.1.1/dsh-lifeboat-0.1.1.tgz
For a local checkout, run this from its parent directory instead:
dsh plugin --profile web add ./dsh-lifeboat
The package declares dsh.bundle through cordis.patch.yml. Installation adds the health marker to the selected profile. The rescue UI remains a standalone binary so a broken Loader cannot take it down:
pnpm --dir "$DSH_HOME/profiles/web" exec dsh-lifeboat serve
Release packages are distributed as GitHub Release assets, not through the npm registry. Validate the tarball installation command above against the current Harness CLI before relying on it for an incident.
$DSH_HOME/profiles/<name>/package.json, both user-patch layers, bounded safe Profile assets, and installed package-resolution identities into one diagnosis snapshot.dependencies become candidates.dsh-lifeboat-probe-* in the operating-system temp directory.exact; otherwise the completed 1-minimal result remains explicitly non-global. A separate small residual budget looks for equal-size alternatives.unstable-probe without offering recovery.--keep-artifacts was selected.The search never performs an unbounded 2^n powerset walk. At most half of the logical-probe budget is used to obtain the initial upper bound; the unused budget plus the reserved proof share can test C(n,1) + ... + C(n,k) candidates only below that bound. Equal-size alternative discovery has its own sub-budget within the same total (normally 4–32 probes, capped by a smaller total) and the existing result-count cap. Defaults remain exact depth 2 and 256 total recovery probes in config mode or 64 in boot mode; the advanced UI and --max-exact-removals / --max-recovery-probes expose the main limits.
These are recovery plans, not moral blame. If A and B fail only when active together, Lifeboat can offer "disable A" and "disable B" as equal one-removal alternatives. If A and B fail independently, a verified plan must remove both. Reports distinguish exact from one-minimal and record whether all equal-size alternatives were enumerated.
“Apply recovery” is deliberately unavailable until the report contains an independently verified Bundle-removal plan. When confirmed, Lifeboat:
planId from the server-owned diagnosis report and rejects arbitrary Bundle lists;.lifeboat-backups/ with its full SHA-256 in the filename;package.json, removing only the selected plan's Bundles from dsh.profile.bundles while keeping dependencies installed;Running a later dsh plugin package-manager command may reconcile an installed bundle back into the active list. Remove or update the actual faulty dependency after recovery.
127.0.0.1, rejects non-loopback Host headers, sends a restrictive CSP, and requires a random per-process token for writes.--keep-artifacts and manual inspection.taskkill /T while the owned probe process is alive.package.json unchanged are outside the immutable configuration snapshot and should be avoided during diagnosis.dependencies. Installation-owned bundles are never automatically disabled.dsh.profile.bundles format used by current pre-release Harness builds. It has not been validated against every historical release.Lifeboat was implemented independently. The closest listed community project, dsh-guard, focuses on rolling snapshots and in-process rollback; its README explicitly notes that an in-process plugin cannot rescue a startup crash without an external launcher. Lifeboat focuses on an independent diagnostic service, fresh-home reproduction, verified bounded removal plans, and evidence-gated recovery. See the non-ranking comparison.
npm test
npm run check
npm pack --dry-run --ignore-scripts
The project intentionally uses only Node.js built-ins so the rescue path does not acquire another dependency graph that can fail during an incident.
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: diagnostics。