The DSH philosophy is “Everything is a plugin.” After developers obtain plugins from a community catalog (such as skillhub.cn), a controlled mechanism is needed to manage these plugins’ lifecycles and origins. This plugin provides a Host plugin market and a Web settings page, aiming to solve plugin source management, download verification, and start/stop control issues.
Features¶
This plugin mainly provides the following capabilities:
- Plugin repository management: Supports users adding HTTPS plugin repositories on the settings page. The repository state is saved in
$DSH_HOME/plugins/market/repositories.json. - Download verification: It verifies the HTTPS protocol,
manifestfields,entrypath, and SHA-256 checksum for downloads. - Static plugin attach/detach: Static plugins display their attach/detach state by default. After installation, they are disabled by default. Enable/disable operations are written to the configuration file
$DSH_HOME/plugins/market/static.patch.yml, and take effect after the next DSH startup. - Dynamic plugin control: Dynamic plugins display only run/stop state by default. Manual start/stop functionality is provided only when the
manifestdeclarescontrollable: trueand the Host explicitly injects a releasable lifecycle controller. - Security boundary: It does not automatically execute downloaded plugin code. Download content is written only to a verified installation directory, and static plugins are loaded through a Loader patch generated by the Host.
Repository Format¶
A repository is an HTTPS JSON file; the current schema version is 1. The sample content is shown below:
{
"version": 1,
"plugins": [
{
"id": "example-static",
"name": "示例静态插件",
"version": "1.0.0",
"description": "一个经过校验的静态插件。",
"type": "static",
"downloadUrl": "https://example.com/plugins/example-static/index.js",
"checksum": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
"entry": "index.js",
"permissions": ["settings.read"],
"config": {
"example": true
}
}
]
}
Field requirements are as follows:
- id:
[a-z0-9][a-z0-9._-]{0,63}. - type:
staticordynamic. - downloadUrl: Must be HTTPS.
- checksum: Lowercase SHA-256 hexadecimal digest.
- entry: Relative path; absolute paths, backslashes, and
..are prohibited. - permissions, config, and controllable are optional fields.
Installation and Enabling¶
Before installation, please read core-patches/README.md first, because the current DSH mainline has not yet merged the Host mounting logic required by this plugin. Please merge the corresponding changes into the DSH core first.
After the core patches are ready, add this repository as a dependency to DSH’s profile or web bundle, and point dsh.bundle.patch to this package’s cordis.patch.yml:
{
"dependencies": {
"@deepseek-ai/dsh-host-plugin-market": "github:V-dev-388/DSH-plugin-market"
}
}
Typical Usage¶
- Add an HTTPS plugin repository URL on DSH’s Web settings page.
- Click “Refresh catalog” to obtain the plugin list from the repository.
- Select a plugin to install or remove.
- Manage enabling or disabling installed static plugins.
- Add this repository as a dependency to DSH’s profile or web bundle.
Applicable Scenarios and Notes¶
- Suitable for developers who need to uniformly manage third-party plugin sources and ensure code security.
- Plugins run with the permissions of the current DSH process. Please review the source code and license before installation.
- The download process follows the approach of “writing to a temporary directory first, then atomically replacing the installation directory after successful verification,” ensuring the atomicity and security of the installation process.