Skip to content

Releases: oh-summy/dsh-remote-control

v0.3.1 · 修复 launchd 下看门狗通知静默丢弃

Choose a tag to compare

@oh-summy oh-summy released this 25 Sep 13:35
2380434

watchdog/selfheal 发出的 changed/down/recovered 通知在 launchd 环境因 PATH 缺少 lark-cli/node 而静默落入 skip(no-channel)(仅 remote.started 曾可达)。PATH 补齐逻辑收进 bin/common.sh(rc_add_npm_global_path),三个脚本共用,并补 /usr/local/bin 与 /opt/homebrew/bin 以覆盖 lark-cli 的 env node shebang。launchd 同款最小环境实测 dm-card-ok。升级:git pull 或重跑一键安装后 dsh-web restart。

v0.3.0 · 常驻自愈守护

Choose a tag to compare

@oh-summy oh-summy released this 25 Sep 13:24
0411b07

新增

  • 常驻看门狗自愈:caddy/auth 退出原地重拉(URL 不变);cloudflared 退出交棒 selfheal.sh 自动重建(30s→600s 退避,6 次),全部失败进入冷却并推送人工介入告警,dsh-web start 成功后自动解除
  • 启动握手协议:run/starting 启动锁防止启动窗口误判与双 up.sh 互杀;run/stopped 人工停止优先于一切自愈;pid 全部 noclobber 原子认领 + 命令行身份校验(防 pid 复用)
  • launchd 守护看门狗:dsh-web autostart 的 KeepAlive 守护看门狗本身;dsh-web install 自动迁移旧版自启配置;autostart off 确定性停止看门狗
  • 隧道协议可配置:RC_TUNNEL_PROTOCOL(默认 http2,规避代理 TUN 下 QUIC 抖动导致的间歇性 502/530)

修复

  • Named Tunnel 启动与换密码通知中 $var 紧跟全角字符导致 macOS bash 3.2 崩溃(up.sh/notify-feishu.sh,由新增 CI 门禁的毒化测试发现)
  • 停止链路时 selfheal 的孤儿 up.sh 可能撤销人工停止;停止报文更如实

门禁与工程

  • 新增 scripts/check-bash32-pitfall.sh(CI 在 GNU/BSD grep 双平台运行),专抓 bash 3.2 运行时陷阱
  • 新增 bin/common.sh:组件身份特征单一事实源(此前四份重复)
  • shellcheck -S style 全绿;打包断言覆盖新增脚本

升级说明

已装 ≤ v0.2.x 且开启自启的机器:拉取新版后执行一次 dsh-web install(或 dsh-web autostart)切换到常驻守护模式,然后 dsh-web restart 让看门狗加载新代码。新机器照旧一键安装:curl -fsSL https://raw.githubusercontent.com/oh-summy/dsh-remote-control/main/scripts/install-remote.sh | bash

v0.2.5

Choose a tag to compare

@oh-summy oh-summy released this 16 Sep 16:40
316123a

修复

  • 登录后仍被 DSH 401 拦截(#25):auth-server 从 logs/dsh.log 读取 DSH launch token,而链路实际写 logs/dsh-web.log,文件名不一致导致 Linux 全新部署上 dsh-auth cookie 从不签发。修复后密码门登录一步直达 DSH(自动签发双 cookie),无需再手动拼接 token URL。
  • 健壮性加固:token 提取到 run/dsh-token 状态文件(不受日志轮转影响,watchdog 在 DSH 恢复后自动刷新);日志扫描只读尾部 256KB;token 正则收紧;找不到 token 时 auth.log 输出告警。

文档

  • README / README.zh-CN:补充双鉴权说明(登录自动签发 DSH cookie)、刷新示例版本号
  • roadmap:M3(Linux/VPS)推进为 In progress(一键安装 + VPS 验收已实测)

安装

curl -fsSL https://raw.githubusercontent.com/oh-summy/dsh-remote-control/main/scripts/install-remote.sh | bash

Full Changelog: v0.2.4...v0.2.5

v0.2.4

Choose a tag to compare

@oh-summy oh-summy released this 16 Sep 15:51
20ae485

修复

  • 一键安装死链修复(#23):install-remote.sh 不再从 mktemp 临时目录运行 install.sh(EXIT trap 清理后 dsh-web 软链即失效),改为解压到持久目录 ~/.remote-control/app。此 bug 使「curl | bash 一键安装」路径此前实际不可用,已在 Ubuntu 24.04 VPS 端到端实测验证。
  • curl 000 双写修复(#24):curl -w %{http_code} 失败时自会输出 000,句尾 || echo 000 导致变量变成 000000、判断永不命中。修复 DSH 未运行时 dsh-web start 的自动拉起静默失效、看门狗上游宕机/恢复告警永不触发、status 显示 HTTP 000000 三个问题。

安装

curl -fsSL https://raw.githubusercontent.com/oh-summy/dsh-remote-control/main/scripts/install-remote.sh | bash

Full Changelog: v0.2.3...v0.2.4

v0.2.3

Choose a tag to compare

@oh-summy oh-summy released this 16 Sep 15:21
17ae1d4

通知功能改进(#22)

  • 新增 RC_NOTIFY_NOTE:rc.env 可选配置,自定义文本显示在通知卡片顶部(「访问地址」之前),每次通知实时读取、改后无需重启。多机部署时可标明来源,如「公司 VPS,入口 7 天有效」
  • RC_NOTIFY_PASSWORD=mask 现在真正生效:推送「密码后 4 位」提示;其他值则不发送密码消息(默认 full 行为不变)
  • 卡片排版修复:「访问地址」与 URL 之间从多行空行改为恰好一行
  • 文档同步:README / README.zh-CN 配置表、rc.env.tmpl

兼容性修复(#17,随 v0.2.2 已发)

  • Caddyfile 改为 admin off:修复与宿主机已有 Caddy 实例(如 VPS systemd caddy)的 2019 端口冲突,同时关闭无鉴权 admin API

安装

curl -fsSL https://raw.githubusercontent.com/oh-summy/dsh-remote-control/main/scripts/install-remote.sh | bash

Full Changelog: v0.2.1...v0.2.3

v0.2.2

Choose a tag to compare

@oh-summy oh-summy released this 16 Sep 14:33
62b99da

修复

  • Caddyfile 关闭 admin API(#17):修复在已运行系统级 Caddy 的机器(如 VPS systemd caddy 占用 2019 端口)上 remote-control 的 caddy 实例启动失败的问题。脚本本就通过 PID 文件管理进程,不依赖 admin API。

安装

curl -fsSL https://raw.githubusercontent.com/oh-summy/dsh-remote-control/main/scripts/install-remote.sh | bash

Full Changelog: v0.2.1...v0.2.2

v0.2.1 — one-click installer via GitHub Releases

Choose a tag to compare

@oh-summy oh-summy released this 09 Sep 13:34
93c08b2

one-click installer + packaging fixes

新增

修复

  • P0: 打包不再误删 etc/Caddyfile(全新安装失败的根因)
  • 一键安装: SHA256 完整性校验 → 解压 → 调用 install.sh
  • shellcheck SC2115: rm -rf 加 :? 保护

资产

  • dsh-remote-control-0.2.1.tar.gz + .sha256(源码包,安装时自动下载 cloudflared/caddy)

v0.2.0 — M2 stability improvements

Choose a tag to compare

@oh-summy oh-summy released this 09 Sep 09:06
55a3754

English

Release v0.2.0 — M2 stability improvements. Verified end-to-end on macOS (x86_64):

New features

  • Named Tunnel support for fixed domain (RC_TUNNEL_NAME + RC_TUNNEL_HOSTNAME)
  • rotate-password command: dsh-web rotate-password
  • Automatic log rotation (1MB threshold, 5 backups, copytruncate keeps daemon FDs)
  • launchd autostart for macOS: dsh-web autostart [off]
  • install.sh idempotency: safe to re-run, --force to reinstall binaries

Command reference

Command Purpose
dsh-web start Start the chain, print URL + password
dsh-web stop Stop everything
dsh-web restart Restart
dsh-web status Component status + gate/upstream health
dsh-web logs Tail logs
dsh-web password Print access password
dsh-web url Print entry URL
dsh-web install Install/repair
dsh-web tunnel-setup Named Tunnel guide
dsh-web rotate-password Rotate access password
dsh-web autostart [off] launchd autostart (macOS)

Issue fixes

  • #3: up.sh password display fallback
  • #4: down.sh pgrep precise matching
  • #6: dsh-web logs caddy missing-file message

Code review fixes

  • P1: Named Tunnel residual cleanup in down.sh
  • P1: Log rotation copytruncate (keeps daemon FDs) in watchdog.sh
  • P2: rotate-password.sh hardening (atomic write, flock, error handling)
  • P2: Named Tunnel validation in up.sh
  • P2: dsh-web help output and autostart robustness
  • P3: README.zh-CN.md sync, CI enhancements

CI

  • shellcheck, bash syntax, py_compile, secret scan, script permissions, required files, docs sync (EN+ZH), plist validation, macOS test job.

中文

v0.2.0 发布 —— M2 稳定性改进。macOS (x86_64) 端到端验证通过:

新功能

  • Named Tunnel 固定域名支持(RC_TUNNEL_NAME + RC_TUNNEL_HOSTNAME)
  • rotate-password 密码轮换命令:dsh-web rotate-password
  • 自动日志轮转(1MB 阈值、保留 5 份备份、copytruncate 保持 daemon 文件描述符)
  • launchd 开机自启(macOS):dsh-web autostart [off]
  • install.sh 幂等性:可安全重复运行,--force 重新安装二进制

命令参考

命令 用途
dsh-web start 启动全链路,打印 URL + 密码
dsh-web stop 停止全链路
dsh-web restart 重启
dsh-web status 组件状态 + 网关/上游健康度
dsh-web logs 查看日志
dsh-web password 打印访问密码
dsh-web url 打印入口 URL
dsh-web install 安装/修复
dsh-web tunnel-setup Named Tunnel 设置指南
dsh-web rotate-password 轮换访问密码
dsh-web autostart [off] launchd 开机自启(macOS)

Issue 修复

  • #3: up.sh 密码显示回退
  • #4: down.sh pgrep 精确匹配
  • #6: dsh-web logs caddy 日志缺失提示

代码审查修复

  • P1: down.sh Named Tunnel 残留清理
  • P1: watchdog.sh 日志轮转 copytruncate(保持 daemon 文件描述符)
  • P2: rotate-password.sh 加固(原子写入、flock、错误处理)
  • P2: up.sh Named Tunnel 验证
  • P2: dsh-web help 输出和 autostart 健壮性
  • P3: README.zh-CN.md 同步、CI 增强

CI

  • shellcheck、bash 语法、python 编译、密钥扫描、脚本权限、必需文件、文档同步(中英文)、plist 验证、macOS 测试任务。

v0.1.0 — first public release 首个公开版本

Choose a tag to compare

@oh-summy oh-summy released this 30 Aug 16:32

English

First public release. Verified end-to-end on macOS (x86_64):

  • dsh-web CLI: start / stop / restart / status / logs / password / url / install
  • Cloudflare Quick Tunnel → password gate (login page, 7-day cookie session, per-IP lockout) → DSH (loopback, untouched)
  • Host/Origin rewritten at the proxy so DSH's browser-trust fence passes even as the tunnel host rotates
  • Feishu notifications: interactive card + separate bare-password text message (bot DM primary, group webhook fallback)
  • Installer downloads official cloudflared/caddy static binaries (no brew/apt needed); bash 3.2/POSIX compatible
  • CI: shellcheck + bash -n + py_compile + secret scan

Platform support: macOS ✅ · Linux installer ready (systemd units planned for M3) · Windows: PRs welcome with real test evidence.

中文

首个公开版本。macOS(x86_64)端到端验证通过:

  • dsh-web 一站式命令:启动/停止/重启/状态/日志/密码/URL/安装
  • Cloudflare Quick Tunnel → 密码门(登录页、7 天会话 Cookie、失败 5 次锁 IP)→ DSH(只绑 loopback,零改动)
  • 代理层重写 Host/Origin,隧道域名每次变化 DSH 的 browser-trust 防线依旧放行
  • 飞书通知:交互卡片 + 单独可复制的密码纯文本消息(bot 私发为主、群 Webhook 兜底)
  • 安装器下载官方 cloudflared/caddy 静态二进制(无需 brew/apt);脚本保持 bash 3.2/POSIX 兼容
  • CI:shellcheck + bash 语法 + python 编译 + 密钥扫描

平台支持:macOS ✅ · Linux 安装器就绪(systemd 单元见 M3)· Windows:欢迎附实测证据提 PR。