T-Auto/dsh-dpx

Isolated Multi-Environment Manager for DSH / DSH 多隔离环境管理器

Project Overview项目介绍

dsh-dpx is a multi-environment package manager built specifically for DeepSeek Harness (DSH); it creates, installs, discovers, and launches named, mutually isolated DSH environments on a single machine. The project explicitly states it is not a DSH plugin and does not modify DSH core or the plugin protocol; instead it ships as an npm package installed globally via npm install -g dsh-dpx (or invoked through npx dsh-dpx --help) and can also be built locally with git clone https://github.com/T-Auto/dsh-dpx.git followed by npm link. Each registered environment owns an independent npm global prefix, download cache, DSH_HOME, DSH_AGENTS_HOME, working directory, and a self-describing dsh-distribution.json descriptor that implements the DistributionDescriptor, ManagedLayout, and EnvironmentDiscovery faces of the dsh-distribution meta-protocol.

The typical workflow starts with dpx npm install -g @deepseek-ai/dsh @deepseek-harness-tui/dsh-tui --test --"D:\DevEnvs\Projects", which scaffolds a brand-new environment named test (ASCII letters, digits, hyphens; must begin with a letter) inside the parent directory supplied via the second --"path" argument. After creation, operators inspect state with dpx env list, dpx env show --test, dpx env doctor --test, dpx which --test, and dpx descriptor --test; registry corruption, duplicate names, instance-identity conflicts, or missing roots trigger fail-closed behaviour rather than automatic rescans or rebuilds. On Windows the first creation also drops a double-clickable DSH DeepSeek Harness Desktop.exe showing a minimal black-and-white splash (DSH / DeepSeek Harness Desktop / 隔离环境:<名称> / 正在启动本地 DSH 服务…) before loading that environment's DSH Web UI inside a bundled WebView2 control; --no-desktop opts out, and macos/linux hosts always remain pure CLI. Launching the in-environment TUI is currently done with dpx run --test dsh-tui, since a global dsh-tui --test adapter must still be merged into the separate dsh-tui project.

Dependencies are deliberately narrow: Node.js >=22.19.0 is the only runtime requirement, and the project is labelled experimental with Windows as the priority target. Isolation is a per-directory npm/DSH partitioning rather than an operating-system sandbox, so npm package lifecycle scripts still execute with the current user's privileges and untrusted packages must not be treated as a safe execution environment. The repository ships with npm test, npm run check, and npm run pack:check, all of which use temporary directories and a fake npm binary without downloading upstream packages or touching real DSH profiles. The descriptor can be validated offline using the dsh-distribution conformance CLI (node ..\dsh-distribution\packages\conformance\lib\cli.js "$PWD\dsh-distribution.json"), and the Windows discovery pointer HKCU\Software\DSH\DPX is purely a non-executable location hint for compatible managers. Cleanup uses dpx env remove --test to unregister while preserving the root, and dpx env remove --test --purge to delete a registry-validated environment root; neither command removes global Node/npm, default DSH directories, or other environments. The license field is not declared in the repository metadata, which should be checked before redistribution.

dsh-dpx 是面向 DeepSeek Harness(DSH)的多环境包管理器,负责命名隔离环境的创建、安装、发现与启动。它本身不是 DSH 插件,也不修改 DSH 核心或插件协议,而是经 npm 全局安装 dsh-dpx 或 npx dsh-dpx --help 直接调用,也可从源码 git clone + npm link 本地构建运行,每个环境拥有独立的 npm prefix、缓存、DSH_HOME、AGENTS_HOME 与 dsh-distribution 描述符。

典型工作流是用一条命令创建带名环境,如 dpx npm install -g @deepseek-ai/dsh @deepseek-harness-tui/dsh-tui --test --"D:\DevEnvs\Projects",随后通过 dpx env list、dpx env doctor --test、dpx which --test、dpx descriptor --test 查看与诊断,Windows 上首次创建还会自动复制一个可双击的桌面端 EXE。它适合需要同时维护 test、stable、alpha 多套 DSH 版本以复现和比较问题的开发者,以及想按 dsh-distribution 协议发布整合包、让其他兼容管理器无需扫盘即可发现实例的整合包作者。当前状态:0.1.3 已实现命名隔离安装、桌面 EXE、dpx run --test dsh-tui 与 DPX registry/profile 入口;全局 dsh-tui --test 需要由 dsh-tui 项目接入 DPX 适配器后才能生效。

依赖方面要求 Node.js >=22.19.0,目前标记为实验性、Windows 优先,macOS/Linux 保持纯 CLI、不创建 desktop EXE;首次创建环境时 --no-desktop 与父目录参数才会生效,后续 dpx npm install 不会触碰桌面端。隔离是目录级别的 npm/DSH 隔离而非 OS 沙箱,npm 包生命周期脚本仍以当前用户权限运行;许可证未在仓库元数据中声明。首次使用需注意 dpx env remove --test --purge 只会清理 registry 登记的环境根,不会删除全局 Node/npm、默认 DSH 目录或其他环境,且 dsh-distribution.json 的完整性需用 dsh-distribution 仓库的 conformance CLI 离线校验,HKCU\Software\DSH\DPX 仅作 DPX 自身的发现指针,不授予任何可执行权限或信任。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 3 warnings3 项注意
  • No license declared - all rights reserved by default; ask the author before commercial use or redistribution未声明开源许可证 —— 默认「保留所有权利」,商用或再分发前先问作者
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
  • No DSH plugin manifest detected - it may only carry the dsh-plugin topic, so the install method must be confirmed on the spot未检测到 DSH 插件清单:可能只是打了 dsh-plugin 话题,安装方式要现场确认
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add github:T-Auto/dsh-dpx

把 T-Auto/dsh-dpx 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-dpx

dsh-dpx 是给 DeepSeek Harness(DSH)创建、安装、发现和启动多个彼此隔离环境的包管理器。它不是 DSH 插件,也不修改 DSH 的核心或插件协议。

在 Windows 上,首次创建环境会默认同时放入一个可双击的桌面端 EXE;它以极简黑白启动页显示 DSH / DeepSeek Harness Desktop / 隔离环境:<名称> / 正在启动本地 DSH 服务…,随后在内置 WebView 中载入该环境的 DSH Web UI。

它服务于两个目标:

  1. 开发与调试:一台电脑可以保留多个命名 DSH 环境,例如 test、stable、alpha;它们可安装不同版本的 DSH、TUI 或第三方包,互不污染,便于复现和比较问题。
  2. 未来的第三方整合包:整合包可按 dsh-distribution 的环境身份与发现规则注册实例,让其他兼容包管理器不扫描磁盘也能找到它。

当前状态:实验性、Windows 优先。需要 Node.js >=22.19.0。0.1.0 已实现命名隔离安装、DPX 发现 profile、环境内 DSH/TUI 启动;dsh-tui --环境名 的全局启动器兼容层需要由 dsh-tui 项目接入,详见“dsh-tui --test”。

与 dsh-distribution 的关系(消费覆盖)

dsh-distribution 定义"一个 DSH 环境如何被外部世界识别、发现、管理与迁移"的环境元协议;本仓库是它的一个实现范例,不是它的标准来源,也不是唯一的环境管理器。协议正文与条款 ID 以该仓库的 docs/proposals/ 为准;本仓库只负责:实现它、并如实说明自己实现了哪些面。

仓库根的 dsh-distribution.json 是本仓库作为发行物的自我声明。它当前声明 7 个协议面里的 2 个:

dsh-distribution 协议面 本仓库是否声明/实现 证据
身份与声明(DistributionDescriptor) ✅ 声明 dsh-distribution.json 本体
受管存储归属(ManagedLayout) ✅ 声明 同上:environment-root、registry 两个独占资源(exclusive + conditional)
发现与环境实例(EnvironmentDiscovery + EnvironmentInstance) ✅ 声明 描述符中的 references;运行期写入的实例记录与注册表(src/index.js 的 EnvironmentInstance 记录与 instanceId 唯一性校验)
环境组成声明(EnvironmentComposition) ❌ 未声明 无
环境生命周期观察(EnvironmentLifecycle) ❌ 未声明 无
可迁移性计划与恢复日志(EnvironmentPortability) ❌ 未声明 无
可枚举共识入口(Lodgement) ❌ 未声明 无

未声明的面不表示"不适用",只表示本仓库没有为此提供实现或证据。因此:

  • 不要据本仓库推断 dsh-distribution 已被完整实现——它目前只在"身份 + 归属 + 发现"三面有实现证据;
  • 也不要据本仓库推断某个环境管理器是唯一选择;协议明确允许私有坐标与非中央的多来源模型;
  • 描述符可以离线校验。用一个实现了该协议的校验器读它(例如 dsh-distribution 仓库的 packages/conformance CLI),应当得到 valid: true, complete: true: 这两项只说明结构完整,不说明来源可信、隔离成立或有权执行管理操作。

与普通 DSH 插件安装的区别

例如,TUI 这类 DSH 插件可用普通 npm 全局安装:

npm install -g @deepseek-ai/dsh @deepseek-harness-tui/dsh-tui

此命令会在全局 DeepSeek Harness 上安装 DSH 与 TUI 启动器;TUI 首次运行时会通过 DSH 的插件机制写入默认的全局 DSH profile。它适合只有一个日常 DSH 环境的用户。

dsh-dpx 的定位不同:它是管理多个隔离 DSH 发行环境的包管理器/环境管理器。它可以经由 npm/npx 直接拉取,也可以从本仓库本地构建、链接和运行。每个环境独立拥有 npm 全局前缀、下载缓存、DSH 状态、agents/skills、工作目录和环境描述符;安装到 test 不会改变全局 DSH,也不会改变 stable。环境里的 npm 保持原生行为(原生默认落在环境自己隔离出来的 profile 里,不是 dpx 管理的 npm-prefix),要写进环境必须显式给出 --prefix / --cache(或直接用 dpx npm install),并且每个环境都会自动得到一份说明自己在哪、怎么设计的 dsh-home\AGENTS.md。

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev DeepSeek-cli 下一个 Next dsh-restart-button →