Skip to main content

base/harness/packages/bundle/base

15Stars3Forks1Issues0Watchers

The base package for the desktop version of DeepSeek Harness, providing core UI components.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
License
MIT
Branch
main
dsh-plugin

Install

cmdweb profile
$ dsh plugin --profile web add @deepseek-ai/dsh-base

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin WJZ-P/deepseek-harness-desktop/harness/packages/bundle/base for me: review the repository at https://github.com/WJZ-P/deepseek-harness-desktop first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

本文档对应 WJZ-P/deepseek-harness-desktop 仓库中 harness/packages/bundle/base 子目录,是落地页 /plugins/{owner}/{repo} 中插件百科模块的内容来源。本目录是该桌面发行版内嵌的 dsh 共享核心 profile 组合包。

一句话定位

@deepseek-ai/dsh-base 是 DSH 的共享核心 profile 组合包,在空 profile 根上一次性插入 77 行基础插件,覆盖模型适配、Agent 会话、Typert RPC、工具、本地持久化、沙箱策略、设置/凭据、遥测等所有 profile 共享的部分,作为任何 profile 加载的第一层。

核心能力

  • 在空 profile 根上注册模型适配、Agent 会话、Typert 类型注册与 RPC 网关、默认模型选择等核心服务
  • 启用模型可见的工具目录:文件读写、字符串替换编辑、子代理、计划模式、Todo、目标、Web 搜索、bash/pwsh 等
  • 挂载本地化数据平面:JSONL 会话持久化、SQLite 会话索引(默认内存、按需开启)、本地附件、凭据与设置文件
  • 安装默认沙箱与权限策略:文件效果策略、bash/pwsh shell 栈(按平台自动二选一)、审批与权限预设
  • 注册宿主级子代理与工作流能力:进程内 spawn/fork 子代理、worker-thread 工作流执行、目标多轮驱动
  • 配置基础遥测与会话检查点:默认关闭的 OTLP 日志上送、按模型请求的检查点持久化、上下文溢出保护

技术实现

  • 语言: TypeScript(ESM,src/index.ts 仅 export {},包内代码只用于注册 invariant 配套)
  • 关键依赖: @deepseek-ai/cordis(peer,宿主运行时)、@deepseek-ai/dsh-llm(模型能力面)、@deepseek-ai/dsh-session(会话核心)、@deepseek-ai/dsh-sandbox-local(沙箱);dependencies 中还包含约 78 个工作区包,覆盖工具、设置、凭据、子代理、工作流等所有下层组件
  • 架构模式: 组合包(profile bundle)—— cordis.patch.yml 通过 manifest 字段 dsh.bundle.patch 暴露给 profile 组合器,由组合器按顺序读出 77 行 insert 并应用到空 profile 根;包自身不注册 Service,而是提供一份"行清单"
  • 入口文件: src/index.ts(无运行时导出)+ src/invariant.ts(空实现,仅注册包名以满足 invariant 配套规则)+ 实质载荷 cordis.patch.yml

适用场景

任何要在自己机器上跑 DSH agent 的用户,都会在第一步遇到这个 bundle:它是 --profile web、--profile headless 等所有 profile 的公共地基。当用户希望直接获得 DeepSeek 模型调用、本地会话存档、按平台自动选择 bash/pwsh、默认文件沙箱保护等基础能力,而不需要再为每个 profile 重复拼装这些组件时,把它装进 profile 即可。

前置依赖与兼容性

依赖最低版本说明
DSH0.1.0-rc.5该包自身版本即为 0.1.0-rc.5;peerDependencies 声明 @deepseek-ai/dsh-invariants 与 @deepseek-ai/cordis 需在宿主中可用,与上游 0.1.0-rc.5 同周期发布
Node^22.19.0 || >=24.0.0来自上层 monorepo harness/package.json 的 engines.node;本包 tsconfig.json 通过 tsconfig.base.json 间接继承
平台macOS / Windows / Linux同一份 patch 文件跨平台工作;shell 栈按 process.platform 自动启用 bash(POSIX)或 pwsh(Windows),不依赖平台分支 patch
原生模块无该包本身未声明原生依赖;下层 @deepseek-ai/dsh-sandbox-local 在 Windows 上挂载 @deepseek-ai/dsh-sandbox-windows-acl 实现受限令牌 runner,是组合行为而非本包声明

安装方式

dsh plugin --profile web add github:WJZ-P/deepseek-harness-desktop/harness/packages/bundle/base

配置项

本 bundle 本身没有面向用户暴露的独立 config。它在 cordis.patch.yml 中给下游约 77 个插件行写入了默认 config,这是 profile 组合器读取的静态声明,不通过 dsh 命令行或 settings 文件直接覆盖。若要改这些行的值,请在更上层的 profile cordis.patch.yml 或 bundle 层按 id 整体替换该行。下面列出 patch 中设置的关键默认值(仅供查阅,不是用户配置入口):

默认值所属行默认值含义(人话)
agent-default-model.providerdeepseek-official默认模型提供方
agent-default-model.modeldeepseek-v4-flash默认模型 ID
session-title.fallbackMaxWords5会话标题回退词数上限
session-title-llm.timeoutMs60000LLM 生成标题超时(毫秒)
session-persistence-jsonl.rootdshHomePath('sessions')JSONL 会话日志根目录
session-query-sqlite.openAtnever全文本搜索默认关闭;SQLite 不打开,精确读与会话谱系查询仍可用
session-telemetry-otel.modeprocess.env.DSH_TELEMETRY_MODE || 'DISABLED'遥测模式(FULL / FEEDBACK_ONLY / DISABLED)
sandbox-policy.modeprocess.env.DSH_PERMISSION_MODE ?? 'workspace-write'默认文件沙箱模式(仅写工作区)
bash-sandbox.disabledprocess.platform === 'win32'bash 沙箱在 Windows 上关闭
pwsh-sandbox.disabledprocess.platform !== 'win32'pwsh 沙箱在非 Windows 上关闭
approval.policy跟随 DSH_PERMISSION_MODE,danger-full-access 时设为 never,否则 ask用户审批默认行为
permission.presetsread-only / workspace-write / danger-full-access权限预设集合
tool-web.fetchfalse关闭模型驱动的 Web 抓取(保留搜索)
tool-web.searchTimeoutMs60000DeepSeek 搜索超时(毫秒)
skill-badge.disabledtrue技能徽章默认关闭
system-prompt.persona''不绑定特定 persona,由后续 bundle 注入

常见问题

Q: 装上这个 bundle 之后是否会自动获得 DeepSeek 联网搜索能力?

A: 是。patch 注册了 DeepSeek 官方搜索路由,复用 Models 页管理的同一个 API Key,超时 60 秒;但不提供 Web 抓取(tool-web.fetch 默认关闭)。

Q: Windows 上跑这个 bundle 需要额外装什么吗?

A: 不需要。bash 与 pwsh 两套 shell 栈在同一份 patch 内按平台互斥挂载,Windows 自动启用 pwsh 沙箱与 pwsh 工具。如果你更希望直接执行不受沙盒约束的本地 PowerShell,需在自己的 cordis.patch.yml 中完整覆盖:禁用 pwsh 行并重新启用 bash 行(两者注册同一个 bash 服务,配方不全会在加载时报错)。

Q: 默认是否会上送遥测数据?

A: 不上送。session-telemetry-otel 默认 mode: 'DISABLED'。要开启需设置环境变量 DSH_TELEMETRY_MODE=FULL 或 FEEDBACK_ONLY,端点用 DSH_TELEMETRY_OTLP_URL 覆盖;非空的 DSH_TELEMETRY_DISABLED 也会反向强制关闭。

Q: 我想换默认模型,应该改这个 bundle 的 patch 还是改 settings?

A: 改 settings。llm-deepseek: 或 llm-pi-ai: 段写在 $DSH_HOME/settings.yaml 中即可热更新,不需要重新打 bundle;Web 的 Models 页面写的就是这个文档。

Q: 装上后会不会把 Codex / Claude Code provider 也装上?

A: 不会。该 bundle 的 package.json 与 patch 都明确不依赖、不挂载 @deepseek-ai/dsh-subagent-codex 与 @deepseek-ai/dsh-subagent-claude-code;要使用需另装对应的 Profile 包。

Q: 默认的"工作区内可写"沙箱到底管什么?

A: 写入被限制在当前工作目录与该会话的临时子目录;只读模式不授予任何写入权限。Windows 上文件效果通过 ACL 受限令牌 runner 强制,权限切换器和审批服务按相同语义工作。

Q: 我的 profile 写了 cordis.patch.yml,会不会和这个 bundle 冲突?

A: 不会冲突,但会按 id 整体替换该行的 config。bundle 与你的 patch 没有深度合并;如果你的覆盖里没重述某个字段,新值由 bundle 默认决定;升级 bundle 版本时,自定义覆盖仍按 id 命中整行。

上手难度

入门 — 这是 profile 必备的地基层,无需阅读源码即可使用;如需定制只需在更上层写一行 cordis.patch.yml 按 id 替换默认值。

已知问题与限制

  • 整行 config 替换:patch 用同一行 id 命中即整行覆盖,没有深度合并层;profile 覆盖必须重述该行希望保留的全部字段,否则会被 bundle 默认值覆盖
  • Windows 临时目录授权是按会话的私有子目录:workspace-write 把可写范围限制在工作区 + 该会话自己的 temp 子目录(形如 <temp>\dsh-<hash>,受限子进程的 TMP/TEMP 被改写);read-only 不授予任何临时目录写入权限

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/WJZ-P/deepseek-harness-desktop/harness/packages/bundle/base)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory