Skip to content

Releases: yyh-001/DSH-X

DSH-X v0.1.14

Choose a tag to compare

@yyh-001 yyh-001 released this 24 Sep 06:55

中文 | English

新功能

  • 支持 macOS:原生 .app 与 dmg 安装包(Apple Silicon / Intel 各一份),mac 上同样能自更新、开机自启、用系统对话框选目录。 @Arrosam
  • 夜间模式:可跟随系统,也可手动选浅色 / 深色;另可调悬浮窗透明度、隐藏背景或看板娘。
  • 插件页可检查并更新插件(单个 / 全部),带进度条;profile 切换移到插件页。
  • 设置页重做:顶栏标签并入设置页(右上角齿轮进入),分「常规 / 插件 / 外观 / 日志 / 高级设置」,切换带过渡动效。
  • 可选下载源(镜像源 / 官方源),插件更新走同一个源。 @YD-233
  • 安装时可选择界面语言,README 与落地页提供中英文。
  • 更新弹窗新增「手动下载」:自动更新不管用时,直接去发布页取对应平台的安装包。

问题修复

  • 适配 dsh 0.1.7-rc.1:设置改存进 profile(每个 profile 一套设置);可选插件启动失败不再一律被自动禁用,改按官方诊断处理。 (#24)
  • 修复远程插件的「局域网访问」开关不起作用:启动器不再用 --host 127.0.0.1 钉死绑定,并新增「Web 绑定」设置。 @Carson0323
  • 修复启动失败自愈里的漏洞:清理悬空链接时漏了带 scope 的目录(@local/xxx 这类),导致重建 profile 依赖时直接崩掉;现在也补上了「这台机器读不了目录链接就改用真实目录」的退路。
  • 启动时不再自动弹出更新提示,dsh 升级改为先确认。
  • 切换版本目录前先确认目标目录可写。

其他变更

  • 发布资产增加 SBOM 与签名的发布清单,任何人都能核对下载到的包是否被替换过。
  • GitHub Actions 自动打包:打 tag 或手动触发,Windows 与 macOS 各自出包。
  • npm test 扩到 100 余条,覆盖插件更新、发布清单、兼容钩子等。

Features

  • macOS support: a native .app and dmg installers (one for Apple Silicon, one for Intel), with self-update, launch at login and a native folder picker. @Arrosam
  • Dark mode: follow the system, or pick light / dark yourself, plus floating-panel transparency and switches to hide the background or the mascot.
  • The plugins page can check for and install updates (one or all), with a progress bar; the profile switcher moved there.
  • The settings page was rebuilt: the top-bar tabs are folded into it (open it from the gear icon), grouped as General / Plugins / Appearance / Log / Advanced, with animated transitions.
  • A selectable download source (mirror / official), used for plugin updates as well. @YD-233
  • Pick the UI language during install; the README and landing page come in Chinese and English.
  • The update dialog has a new "Download manually" link: when the automatic update does not work, take the right installer straight from the releases page.

Fixes

  • Adapted to dsh 0.1.7-rc.1: settings now live in the profile (one set per profile); optional plugins that fail at startup are no longer disabled automatically, the official diagnostics are used instead. (#24)
  • Fixed the remote plugin's LAN switch doing nothing: the launcher no longer pins the binding with --host 127.0.0.1, and a "Web binding" setting was added. @Carson0323
  • Fixed a hole in the failed-start self-repair: dangling links under a scope directory (@local/xxx) were missed, so rebuilding the profile dependencies crashed; it also now falls back to real directories when the machine cannot follow directory links.
  • No automatic update prompt at startup any more; dsh upgrades ask first.
  • The version directory is checked for write access before switching to it.

Other changes

  • Releases now carry an SBOM and a signed release manifest, so anyone can check that a download was not replaced.
  • GitHub Actions builds both packages on tag push or on demand.
  • npm test grew past 100 cases, covering plugin updates, the release manifest and the compatibility hooks.

DSH-X v0.1.13

Choose a tag to compare

@yyh-001 yyh-001 released this 22 Sep 05:40

中文 | English

安全修复

  • 修复 /api/open 命令注入:构造 http://127.0.0.1:1/?&命令 可在本机执行任意命令;打开链接不再经过 cmd。 @Carson0323
  • 管理页接口校验 Origin 与 Host,挡下跨站请求与 DNS rebinding。 @Carson0323
  • 以上影响 v0.1.12 及更早版本,建议升级。

问题修复

  • 修复装到带空格路径(如 D:\Program Files\DSH-X)时 dsh 启动失败。 (#18)
  • 修复装旧版本会连带删掉最新版本的问题。 @Carson0323
  • 修复老 profile 插件安装/更新报 ERR_PNPM_UNEXPECTED_STORE:系统已有 pnpm 时优先用系统的。 (#12)
  • 修复插件开关显示已启用但实际未生效(补丁行的 disabled 位置不固定)。 @Carson0323
  • 修复预发布版本号排序(alpha.10 排在 alpha.2 之前)。 @Carson0323
  • 修复版本目录填相对路径被静默接受的问题。 @Carson0323

新功能

  • 冷启动提速:端口探测改为并行 + 350ms 总预算,此前最坏会卡几十秒。
  • 管理页端口可自定义,被占用时自动顺延。 (#3)
  • 启动 profile 可切换。 (#10)
  • 版本目录可改,带「浏览…」目录选择框。 (#15)
  • 支持额外启动参数。 (#17)
  • 默认带上 --use-system-ca,挂代理 / TUN 时不再 transport failed。 (#1)

其他变更

  • 仓库加入 npm test(零依赖),覆盖版本号比较、清理策略、插件补丁解析、运行时 PATH、设置页结构、启动参数分词。
  • exe 与安装包补全版本信息;README 增加杀软误报的处理指引。

Security fixes

  • Fix a command injection in /api/open: a URL like http://127.0.0.1:1/?&command could run arbitrary commands on the machine; links no longer go through cmd. @Carson0323
  • The manager API now validates Origin and Host, blocking cross-site requests and DNS rebinding. @Carson0323
  • Both affect v0.1.12 and earlier — please upgrade.

Fixes

  • Starting dsh no longer fails when the launcher is installed to a path with spaces (e.g. D:\Program Files\DSH-X). (#18)
  • Installing an older version no longer deletes the newest one. @Carson0323
  • Plugin installs/updates on older profiles no longer fail with ERR_PNPM_UNEXPECTED_STORE: a system pnpm now wins over the bundled one. (#12)
  • Plugin toggles that showed "enabled" without taking effect (the disabled key can sit anywhere in a patch row). @Carson0323
  • Prerelease ordering (alpha.10 sorted below alpha.2). @Carson0323
  • A relative version directory is no longer accepted silently. @Carson0323

Features

  • Faster cold start: port probing is parallel with a 350 ms budget, previously up to tens of seconds.
  • Configurable manager port, with automatic fallback when it is taken. (#3)
  • Switchable start profile. (#10)
  • Changeable version directory, with a browse dialog. (#15)
  • Extra startup arguments. (#17)
  • --use-system-ca by default, so proxies / TUN no longer end in transport failed. (#1)

Other changes

  • npm test (zero dependencies) covering version comparison, pruning, plugin patch parsing, runtime PATH, the settings page and argument splitting.
  • Version metadata filled in for the exe and the installer; a README section on antivirus false positives.

DSH-X v0.1.12

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 15:14
  • 更新改成静默安装:点更新后不再出现「以下应用程序正在使用将由安装程序更新的文件」那一页,全程没有任何要点的选项。
  • 修掉一个让更新彻底没反应的坑:拉起安装程序时用了 detached 启动,而 Node 在 Windows 上会给 detached 的子进程设 DETACHED_PROCESS,PowerShell 作为控制台程序这样起不来,且不报错、不留日志。之前「点了更新没反应」就是它。
  • 静默安装装完后,由安装程序自己拉起新版并删掉安装包;手动双击安装包走的仍是向导,完成页那两个勾选框照旧。
  • 每次更新都带 /log,安装日志留在 %TEMP%\DSH-X-install.log,出问题有据可查。
  • 修好插件市场的预装判断:原来只检查「清单里有 + 目录里有」,但 dsh 实际加载的是 dsh.profile.bundles。结果是包装上了却没启用时市场一直不出现,而且再也不会重试;现在三条都检查,包在、只是没启用就补一行启用,不再重复跑注定失败的安装。

DSH-X v0.1.11

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 14:02
  • 更新流程重做:下载时有进度条(百分比和已下载大小),下完由你点「打开安装程序」,用安装程序自己的界面完成安装。
  • 不再静默安装。以前点确认后屏幕上什么都没有,装没装成也不知道;现在看得见、点得到,中途想取消也可以。
  • 安装程序在需要替换正在运行的文件时会自己提示关闭 DSH-X,不再由启动器抢在它前面退出。
  • 安装完成页新增「删除安装包」勾选框,默认勾选;不想删的取消勾选即可。
  • 启动器启动时会清掉临时目录里上次下载留下的安装包(只认自己下载时的文件名)。

DSH-X v0.1.10

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 13:39
  • 修复:某些机器上插件装不上。现象是 pnpm 报告装完了、紧接着报 unknown error, open ... ode_modules<包>package.json,退出码 -4094(libuv 的 UV_UNKNOWN)。真因是那台机器读不了目录链接(junction)——连用两个普通真实目录新建的 junction 都读不了。现在遇到这类失败会自动让 pnpm 改用真实目录(node-linker=hoisted + package-import-method=copy)重试一次,pnpm 就不再需要任何链接
  • 不再反复重试。以前安装失败会等 3 秒原样重试,而启动失败时的自动修复会重跑启动流程、每次又重试一遍,失败信息会刷满终端。现在最多重试一次,且只在重试确实换了东西时才重试(换参数或换布局);认不出原因就直接报出来,不硬试
  • 预装 dshmarket 失败后,同一次运行里不再重试,留到下次启动再试,日志里也会说明;想装可以在插件页手动装
  • 安装插件前会清掉 node_modules 里悬空的链接(断链),这类链接会让安装报出上面那个 unknown error

DSH-X v0.1.9

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 13:27
  • 更新变成全自动:点「更新启动器」后自动下载、静默安装、自己重启。不再跳浏览器、不再过安装向导、不需要管理员权限(安装包是装在用户目录的低权限模式)
  • 顶栏的更新按钮改成弹更新窗口:先看清这个版本改了什么再决定,而不是点一下就开始下载安装包
  • 弹窗的「暂不更新,直接启动」改成「暂不更新」:点了只关弹窗。启动器早已不在开机时自动拉起 dsh,那个按钮顺手启动它是个残留
  • 插件安装失败按类型重试:peer 求交的问题才换参数重试;其余情况(典型是杀毒软件正扫着刚写进去的文件)等 3 秒原样重试一次,不再对所有失败都乱换参数
  • 预装 dshmarket 前会确认包真的在:以前只看 profile 清单,清单里有、目录却是半装的坏链时,以后每次启动都会跳过预装、永远修不回来

DSH-X v0.1.8

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 12:55
  • 修复:链接点了没反应。Star、运行地址、更新日志这些在 app 窗口里点下去毫无动静——wry 在没有新窗口处理器时会把 target="_blank" 直接取消。现在这类链接一律交给系统浏览器打开
  • 修复:窗口可能被导航走。页面里 /api/open 失败时会退化成 location.href,那会把窗口从管理页导走,自定义标题栏和最小化/最大化/关闭按钮跟着消失。现在只放行管理页自己
  • 桌面快捷方式图标会随版本刷新(图标文件名带版本号,绕开 Windows 按路径缓存的老问题)

DSH-X v0.1.7

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 06:31
  • 界面装进自己的窗口:不再是浏览器标签页,无边框加自定义标题栏(Star、页签、最小化/最大化/关闭都画在页面里),首次出现在主屏正中,双击标题栏切换最大化
  • 原生托盘:托盘随应用本体,不再额外跑一个 3.6 MB 的 Go 进程。左键打开界面,右键弹菜单
  • 托盘退出会停掉 dsh 并关掉窗口;关窗口只隐藏,托盘仍在,随时叫回来
  • 双击桌面快捷方式不再闪一下:已有实例时直接唤醒它的窗口,不再白建一个窗口和 WebView2
  • 打开启动器不再自动启动 dsh:要跑哪个版本由你在界面上点
  • 兼容模式更聪明:dsh 报「插件不兼容新版本」时(例如 dsh-cost-meter 在 0.1.6-alpha.2 上),能认出真正该禁用的插件并自动禁用后重试
  • 安装向导简体中文,默认勾选创建桌面快捷方式,安装包版本号不再固定显示 0.1.0
  • 安装进度不再刷屏终端(进度条本来就在显示)
  • 版本下拉只列最近 5 个,其余进「更多版本」
  • 启动失败改用页面内提示,不再弹系统弹窗

DSH-X v0.1.6

Choose a tag to compare

@yyh-001 yyh-001 released this 19 Sep 04:17
  • 更新前先问你:检测到 dsh 或启动器有新版本时,不再直接自动启动 dsh,先在管理页弹窗询问;弹窗里直接列出该版本的更新内容(中英双语取中文段)
  • 可以「暂不更新」:选暂不更新会记住这个版本,同一个版本不再重复提示;以后出了更新的版本仍会提示
  • 最新版判定统一:主界面和更新提示以前各算一套口径(前者忽略 alpha、后者计入),现在统一由服务端算一次,alpha 预发布同样计为最新版
  • 托盘退出会关掉管理页:浏览器不允许脚本关标签页时,改为显示一张告别页,不再留一个连不上后端的死页面
  • 界面:新的角色背景,带漂浮动画与水波效果;右上角新增 Star 入口
  • 修复:安装向导一直是英文。脚本缺 [Languages] 段,默认走英文 Default.isl,现接入简体中文语言包
  • 修复:安装包版本号永远停在 0.1.0。pack.mjs 传的 /DMyAppVersion 被 iss 里写死的 #define 静默覆盖,已加 #ifndef 保护

DSH启动器 v0.1.5

Choose a tag to compare

@yyh-001 yyh-001 released this 11 Sep 06:14
  • 修复:profile 依赖缺失时能自愈。启动报 cannot resolve profile bundle "x"(pnpm 被中断、依赖断链)时,自动重建 profile 依赖并重试,不再直接启动失败
  • 装插件更稳:遇到 peer 解析失败(官方包在 npm 上只有 prerelease)自动关掉 auto-install-peers 重试
  • 沿用 0.1.4:自带 pnpm,新机器也能装插件