DeepSeek Harness (DSH) uses a plugin-based architecture, allowing users to extend functionality through configuration files. In some scenarios, developers need GPU access to run model inference, but writes to the file system must be strictly restricted. The dsh-full-with-approval plugin fills this gap by introducing a hybrid mode of “full compute access + write approval.”

Plugin Overview

A DSH configuration file plugin maintained by zjuhbh. It does not modify the DSH core package; instead, it introduces a fourth permission preset, full-with-approval, through the mounting layer. Its core value is: while preserving the danger-full-access sandbox mode (supporting GPU, network, and devices), it adds a one-time approval mechanism for writes outside the workspace or writes to protected files.

Core Features

  1. Full Compute Access: After activating this preset, the session sandbox mode is danger-full-access; process execution is unrestricted, and CUDA, GPU, device, and network access are unblocked.
  2. Write Operation Approval: When executing write or edit operations, if the target is a file outside the workspace or a protected file inside the workspace (by default .git/**, .env*), the system requests one-time approval via an interactive prompt. If approval is not granted or is canceled, the operation fails.
  3. Shell Modification Approval: Through bashGuard heuristic rules, it detects whether shell commands contain evidence of external file modifications (e.g., redirection >, chmod, rm, python -o, etc.). Commands containing only read operations (e.g., cat, ls) can execute without prompting.
  4. Non-Invasive Design: The plugin is mounted via cordis.patch.yml and does not affect DSH core code.

Installation and Activation

In the DSH profile directory, run the following command to install:

dsh plugin --profile web add ./dsh-full-with-approval

After installation, restart or refresh the Web UI to load the plugin. It can also be installed using an absolute path or an npm package name.

Usage

  1. Activate Preset: At the command line, enter /permission full-with-approval, or select “Full With Approval” in the Web UI permission selector.
  2. Execute Operation: When attempting to write to protected files or external files, the system will display an approval dialog.
  3. Switch Preset: You can switch back to workspace-write, danger-full-access, or read-only presets at any time, and the approval mechanism applies accordingly.

Configuration

By overriding the configuration in cordis.patch.yml, you can adjust protected paths and approval rules:

- id: full-with-approval
  config:
    # POSIX 相对路径的通配符匹配,或绝对路径
    protectedPaths:
      - ".git/**"
      - ".env*"
    # 除了平台临时目录外,绝对路径的额外可写根目录(不会触发审批)
    extraWritableRoots: []
    # 是否启用 Shell 守卫层(默认 true)
    bashGuard: true
    # 强制触发审批的额外子字符串
    extraBashTokens: []

Known Limitations and Notes

  • Missing Icon: The Web UI icon comes from the core client value-key table; newly added presets in the plugin cannot provide custom icons.
  • Code Execution Not Checked: run_code / code-mode execution is not checked for file side effects; only native write/edit and shell commands are checked.
  • Path Boundary Determination: Normalized paths are used for comparison; symbolic link aliases such as Windows 8.3 may make boundary determination advisory; kernel-level sandbox restrictions remain authoritative.
  • Shell Limitation Mechanism: Shell writes are subject to heuristic restrictions rather than kernel restrictions, and commands can evade checks through dynamic path construction, relative writes after cd, and other methods.

This plugin is suitable for management scenarios where GPU capability is required in a DSH environment while file write permissions must be strictly controlled. Before use, be sure to check the source code and license.