Sandbox & Runtimedsh-plugin

dsh-single-instance-guard

A zero-dependency DeepSeek Harness plugin that acquires an exclusive lock on the DSH_HOME data directory at startup, aborting loudly if another live dsh server is already using it, to prevent session-log corruption from concurrent writers.

Stars
0
Forks
0
Open issues
0
Last push
Aug 16, 2026
Latest release
—
24h Growth
+0
7d Growth
+0

Installation

dsh plugin --profile <profile> add dsh-single-instance-guard

Overview

A zero-dependency DeepSeek Harness plugin that acquires an exclusive lock on the DSH_HOME data directory at startup, aborting loudly if another live dsh server is already using it, to prevent session-log corruption from concurrent writers.

  • Acquires an exclusive lock on DSH_HOME data directory at startup using atomic O_EXCL lock file creation.
  • Aborts startup loudly with a clear bilingual error if another live dsh server is already using the same data directory.
  • Prevents JSONL session persistence corruption caused by concurrent writers with stale sequence cursors.
  • Probes holder process liveness on conflict; removes stale locks and retries acquisition.
  • Removes the lock file on process exit only if still owned by this process.
  • Resolves DSH_HOME exactly like dsh itself: $DSH_HOME or ~/.dsh, so different data roots never conflict.
  • Zero runtime dependencies, easy to install via dsh plugin CLI or manual cordis.patch.yml insertion.
  • Includes a known-limits note about a tiny race in stale-lock retry, still guaranteeing exactly one winner via atomic O_EXCL.

Related plugins

dsh-approve-for-me

Unofficial DeepSeek Harness plugin for rule-gated automatic approval of Shell and PowerShell sandbox escalations. It applies fixed high-risk checks and literal command-prefix rules, optionally uses a tool-free LLM reviewer, grants only one allowed-once per decision, and returns uncertain requests to native human approval.

Sandbox & Runtimedsh-plugin
151TypeScriptSep 12, 2026
dsh-server-deployment

Server-side deployment for DeepSeek Harness: a zero-dependency Node gateway adds a multi-user login portal, per-user independent DSH instances with OS-level isolation, per-user API keys, and a delivery file drawer. File access runs through sudo helper scripts using runuser to drop privileges to dsh-<name> (fixes issue #1 TOCTOU). Not a local/desktop tool.

Sandbox & Runtimedsh-plugin
81JavaScriptAug 18, 2026
QAQ

QAQ is a launch resilience guard for DeepSeek Harness (DSH) by WTStarMark. It supervises the `dsh web` process, reads the browser's real DOM through headless Chrome + CDP, detects host crashes, Web UI red screens and plugin degradation, then restores the configuration snapshot from the last successful boot and restarts, preserving the broken config for manual recovery. It is described as non-invasive, shipped as a one-command script with structured logs, and includes a plugin hot-update guard (c

Sandbox & Runtimedsh-plugin
41TypeScriptAug 17, 2026
DSHBox

DSHBox is an Android application that lets users run the complete DeepSeek Harness locally on Android 10+ ARM64 devices by bundling Debian, Node.js, DSH, PRoot, and an embedded WebView into one APK without root or Termux.

Sandbox & Runtimedsh-plugin
30KotlinSep 9, 2026