DeepSeek Harness (DSH) uses a plugin-based architecture. This makes it very convenient to extend functionality through plugins, but it also introduces the risk that configuration changes or upgrades may break the existing environment. dsh-safe-launch is a plugin focused on managing safe launch. It safeguards DSH instance stability by recording the last successful configuration, performing update trial runs in isolated environments, and strictly checking plugin compatibility.

Plugin Role

dsh-safe-launch is a DSH safe-launch management plugin maintained by dHR-P. Its core value is providing a “safety net” for DSH: before performing any operation that may affect the runtime environment, such as a core upgrade or installing a new plugin, it first validates the operation in an isolated environment. Only after validation passes is the operation applied to the current instance.

Core Features

The plugin provides the following five main capabilities:

  1. Successful launch configuration: It records the last successful configuration in ~/.dsh/safe-launch/last-good.json. Before a configuration change, the plugin automatically backs it up.
  2. Core update trial run: When installing a new DSH core, it first loads the core into an isolated runtime/<version> directory and starts a test using an isolated HOME and a random port. It writes the new configuration only if the test passes; if the test fails, it automatically discards the candidate version.
  3. Compatibility-checked plugin installation: Before installing a new plugin, it copies the profile to a temporary directory, installs the plugin in an isolated environment, and starts a test using the current successful configuration on a new port. If the test passes, it adds the plugin to the real profile using the official command dsh plugin add; if the test fails, it only reports the failure and does not affect the current instance.
  4. Plugin update regression: When updating plugins in bulk, it first backs up the manifest, then performs regression testing after the update. If the regression tests pass, it commits the update; if they fail, it rolls back.
  5. Safe restart: It uses a decoupled helper process to take over the “stop old instance - start new instance - verify liveness” flow, so the parent process does not need to terminate itself.

Installation and Enablement

Installing the plugin is straightforward; simply use DSH’s plugin management command:

dsh plugin --profile web add github:dHR-P/dsh-safe-launch

After installation, you must restart DSH to complete initialization. The plugin automatically bootstraps a “successful launch configuration” from the currently running instance, with no extra steps required. After restarting, the plugin enters a pending bootstrap state, during which it provides automatic inspection, upgrade prompts, and compatibility-checked installation.

Typical Usage

1. Web Configuration Panel

The plugin provides a self-contained web management panel at:

http://127.0.0.1:3080/dsh-safe-launch/panel

In this panel, you can manage the safe-launch status, view plugin versions and compatibility, check for manifest drift, and perform restart or rollback operations.

2. Authorized takeover of the desktop launcher

By default, the plugin runs only as an enhancement component. If you want it to take over the desktop shortcut so that DSH can be safely launched from the desktop icon, explicit user consent is required. You can do this by calling the API:

curl -s http://127.0.0.1:3080/dsh-safe-launch/setup/desktop-launcher -d '{}'

If you decline the takeover, keep the pure plugin mode and call the following command:

curl -s http://127.0.0.1:3080/dsh-safe-launch/setup/dismiss-onboarding -d '{}'

3. Plugin compatibility installation

Before installing a new plugin, it is recommended to run the check through the plugin’s API. For example, to install a plugin from GitHub:

curl -s http://127.0.0.1:3080/dsh-safe-launch/install-plugin \
     -d '{"source":"github:someone/some-dsh-plugin"}'

This endpoint returns a task ID. You can then poll the /job endpoint for task status and logs to confirm whether the installation succeeded.

4. Startup parameter adaptation

The plugin automatically adapts to different DSH CLI argument shapes (for example, the difference between --profile web and placing the web argument in a different position). It captures the current startup arguments via process.argv, templates them into the configuration, and ensures that restarts and trial runs use the correct argument format.

Applicable Scenarios and Dependencies

  • Applicable scenarios: Developers who frequently install new plugins or upgrade the DSH core; environments where DSH instances need to be protected from crashes caused by misoperations.
  • Runtime environment: Requires the Windows operating system, pnpm on the system PATH, and Node.js version ≥ 20.
  • Compatibility: Supports any DSH version. The plugin uses a default-open compatibility policy, so it can be installed on any DSH version without affecting host startup.
  • Build requirements: This package has no build scripts (no prepare/postinstall) and will not be blocked by pnpm allowBuilds.

Summary

dsh-safe-launch addresses stability risks in DSH plugin management by moving high-risk operations, such as updates and installations, into an isolated environment for prior validation. It is not only a configuration backup tool but also a safety gatekeeper for operational workflows. Through its API and web panel, developers can confidently explore and extend DSH functionality.