Introduction

The core philosophy of DSH (DeepSeek Harness) is “everything is a plugin.” As the number of plugins grows, manually managing dependencies, configuring hot reloading, and handling version synchronization can become cumbersome. dsh-package-manager is a package management middleware for DSH. It wraps the existing add mode and supports presets and plugins. By using the official watchUserPatches mechanism, it enables declarative plugin installation and hot mount/unmount without restarting the process.

How It Works

This plugin retains a single installation pipeline: install a dsh-bundle plugin as a profile dependency and write the plugin’s declared dsh.bundle.patch into the profile’s own cordis.patch.yml.

Hot mounting, hot unmounting, and disabling/enabling no longer manipulate the Loader API directly. Instead, they are fully delegated to the watchUserPatches set up by the host at startup. At startup, DSH merges the patch layer into a Loader tree. This plugin writes marked managed blocks into cordis.patch.yml and uses line-level diffs to realize updates:

  • Writing a block = hot mounting
  • Deleting a block = hot unmounting
  • Rewriting to “original patch line + { disabled: true }” = hot disable/enable

This approach avoids repeatedly assembling the same set of lines and allows plugins to take efect without a restart.

Core Features

  1. Single-pipeline hot mount/unmount for dsh-bundle: Uses the official hot-reload path and requires no restart.
  2. Toggling as a patch-line disable: Disable operations preserve dependency records and only add or remove patch lines at the tail of the managed block.
  3. Update checking: Runs git ls-remote for plugins from git sources, automatically syncs the mirror when updates are available, and performs a hot update.
  4. Custom adapter support: Plugins without a bundle can still perform arbitrary install/uninstall steps using a declarative YAML adapter.
  5. Requirements restore and sync: Manages install / keep / update / uninstall / disable / enable with a minimal diff via deps.yaml.
  6. Local plugin discovery: Watches Cordis internal/plugin and iterates existing fibers to automatically display local plugins.
  7. CLI + Web + API: Provides a unified dpm CLI, Web settings-page interface, and programmatic API.
  8. Pre-install validation: Rejects packages with workspace: dependencies, non-ESM code, missing dsh.bundle.patch, or unbuilt entry points.
  9. doctor: Cleans up stale ledger records, lingering managed blocks, and the profile pnpm tree.

Installation and Enabling

Prerequisite: An existing DSH profile (for example, <home>/profiles/web) is available, and this package has not been installed yet.

  1. Install dependencies in the profile directory:
    cd <home>/profiles/web
    pnpm add github:space-spacee-clamation/dsh-package-manager
    pnpm install
  1. Edit <home>/profiles/web/package.json and add the dependency (do not add it to dsh.profile.bundles):
    {
      "dependencies": {
        "@dsh-ext/dsh-package-manager": "github:space-spacee-clamation/dsh-package-manager"
      }
    }
  1. Move the package manager itself into the profile’s cordis.patch.yml managed block:
    dpm self-managed --repo /path/to/dsh-package-manager --profile web

After restarting DSH, the package manager is mounted by the user-level managed block. Subsequent updates can be applied via watchUserPatches as hot updates.

If it has not been deployed to a profile, you can also run node bin/dpm.mjs ... to use the CLI directly.

Typical Usage

# 查看状态
dpm state

# 安装插件(dry-run)
dpm install --profile web --source github:owner/repo --adapter auto --dry-run

# 安装并允许构建
dpm install --profile web --source github:owner/repo --allow-build

# 卸载
dpm uninstall --profile web --id repo

# 检查更新
dpm check-update --profile web --id repo

# 禁用/启用
dpm disable --profile web --id repo
dpm enable --profile web --id repo

# 还原 requirements
dpm restore --file ./requirements/deps.yaml

# 同步 profile
dpm sync --repo . --modes web,headless

# 运行诊断
dpm doctor

Use Cases and Notes

This plugin is suitable for DSH users who need to manage DSH plugin dependencies and hot reloading in bulk. Because plugins run with the permissions of the current DSH process, carefully review the source code and license before installation.

The current content is still being iterated on.

Conclusion

dsh-package-manager simplifies the installation and hot-update workflow for DSH plugins through a unified pipeline and managed block mechanism. By combining CLI, Web, and API capabilities, it provides a complete tool chain for plugin management from the command line to visual interfaces.