Skip to content

About

DeepSeek Harness WSL kit (EN/ZH): docs + install.sh + cordis.patch for Windows browser + WSL agent plugins

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

dsh-wsl-kit

One line: DeepSeek Harness agent in WSL, chat in a Windows browser — install this kit when paths, proxy, clipboard, and “open that file” must cross the OS boundary.

This is a meta-repo (docs + install script + cordis.patch.yml). It does not ship plugin runtimes. Each plugin repo ships a homepage README.md (often Chinese-first for newer plugins) plus README.en.md / README.zh.md as needed.

中文说明 → README.zh.md


How the pieces fit

The kit is not a runtime. install.sh loads Daily / GitHub / LLM / Full plugins into the dsh web profile. Chat stays on Windows; the agent and tools stay in WSL. A second tier of Linux/local capability plugins (inference, search, media, read-only DevOps, …) is not in install.sh — use link-linux-plugins.sh or dsh plugin add as needed. IM / Obsidian / Jev are likewise off install.sh.

flowchart TB
  subgraph win [Windows]
    browser["Browser :3081/?token="]
    host["Clipboard / Explorer / default browser"]
    vault["Obsidian vault (NTFS)"]
    localLLM["Ollama / llama.cpp / vLLM"]
  end
  subgraph wslbox [WSL]
    relay["port relay"]
    dsh["dsh web :3080"]
    subgraph kitPlugins [install.sh suites]
      daily["Daily: env net fetch open clipboard path browser launch"]
      guards["repeat-stop + tool-budget"]
      more["GitHub / LLM / Full doctors"]
    end
    subgraph linuxOpt [Optional Linux local · not in install.sh]
      infer["ollama · llamacpp · vllm · vecmem"]
      media["media · search · secret · struct"]
      devops["git · tmux · compose · k8s · helm · terraform · …"]
      desk["playwright · mail · cal · pkg · rclone · db · glab"]
    end
    im["dsh-wsl-im — optional"]
    obsidian["dsh-wsl-obsidian — optional"]
    jev["dsh-wsl-jev — optional"]
  end
  api["DeepSeek API"]
  chats["Feishu / WeCom / DingTalk / QQ / Slack / Discord / Telegram"]

  browser --> relay --> dsh
  dsh --> kitPlugins
  dsh --> linuxOpt
  dsh --> api
  linuxOpt --> localLLM
  kitPlugins --> host
  chats --> im --> dsh
  obsidian --> vault
  dsh --> obsidian
  dsh --> jev
Loading
Boundary Who owns it
Windows UI Browser on :3081 with a one-shot ?token= (bare :3081 is 401; :3080 is WSL-only)
Agent dsh web inside WSL, tools via plugin ctx
Cross-OS Daily path / open / clipboard / browser / launch / net / fetch (KIT_SET=daily)
Linux local optional Inference, media, sandboxed search, secrets, read-only DevOps — see docs/OPTIONAL_PLUGINS.md; bash scripts/link-linux-plugins.sh
IM dsh-wsl-im outbound WS/Stream/Gateway → ctx.agents. One workspace per IM, one session per chat
Obsidian dsh-wsl-obsidian: WSL agent ↔ Windows NTFS vault + obsidian://
Jev dsh-wsl-jev: System One (jev_ask / check / rank) via OpenRouter or TypeSafe

Plugin versions

Sibling checkout versions on 2026-09-18. Floors enforced by scripts/check-plugin-versions.sh are the minimum, not this snapshot.

Local dsh line: 0.2.0-rc.2 (npm @next, 2026-09-29). npm latest still points at the 0.1.7 line; @next carries 0.2.0. Scripts still assume dsh ≥0.1.2.

Daily

Plugin Version Set
dsh-wsl-env 0.3.0 daily
dsh-wsl-net 0.5.2 daily
dsh-wsl-fetch 0.1.2 daily
dsh-wsl-open 0.2.0 daily
dsh-repeat-stop 0.1.2 daily
dsh-tool-budget 0.1.2 daily
dsh-wsl-clipboard 0.1.0 daily
dsh-wsl-path 0.2.0 daily
dsh-wsl-browser 0.1.0 daily
dsh-wsl-launch 0.1.0 daily

GitHub add-on and optional

Plugin Version Set
dsh-wsl-github 0.2.0 github
dsh-wsl-cred 0.2.0 github
dsh-wsl-notify 0.1.0 github
dsh-wsl-im 0.3.8 not in install.sh
dsh-wsl-obscura 0.1.0 not in Daily
dsh-wsl-obsidian 0.1.0 not in install.sh (optional)
dsh-wsl-jev 0.1.0 not in install.sh (optional)
dsh-wsl-ollama 0.1.0 not in install.sh (optional)
dsh-wsl-media 0.2.0 not in install.sh (optional)
dsh-wsl-search 0.2.0 not in install.sh (optional)
dsh-wsl-vecmem 0.1.0 not in install.sh (optional)
dsh-wsl-k8s 0.1.0 not in install.sh (optional)
dsh-wsl-secret 0.2.0 not in install.sh (optional)
dsh-wsl-llamacpp 0.1.0 not in install.sh (optional)
dsh-wsl-vllm 0.1.0 not in install.sh (optional)
dsh-wsl-struct 0.1.0 not in install.sh (optional)
dsh-wsl-git 0.1.0 not in install.sh (optional)
dsh-wsl-tmux 0.1.0 not in install.sh (optional)
dsh-wsl-compose 0.1.0 not in install.sh (optional)
dsh-wsl-systemd 0.1.0 not in install.sh (optional)
dsh-wsl-helm 0.1.0 not in install.sh (optional)
dsh-wsl-terraform 0.1.0 not in install.sh (optional)
dsh-wsl-rclone 0.1.0 not in install.sh (optional)
dsh-wsl-db 0.1.0 not in install.sh (optional)
dsh-wsl-glab 0.1.0 not in install.sh (optional)
dsh-wsl-playwright 0.1.0 not in install.sh (optional)
dsh-wsl-mail 0.1.0 not in install.sh (optional)
dsh-wsl-cal 0.1.0 not in install.sh (optional)
dsh-wsl-pkg 0.1.0 not in install.sh (optional)

Full-set extras

Plugin Version Plugin Version
gpu 0.2.2 port 0.2.2
distro 0.2.0 workspace 0.2.0
picker 0.1.0 tray 0.2.4
expose 0.2.2 hostsvc 0.4.3
clock 0.2.0 dns 0.2.0
mnt 0.2.0 editor 0.1.0
shot 0.1.0 docker 0.2.2
ssh-agent 0.2.0 encoding 0.2.0
wslconfig 0.2.0 download 0.2.0

Shared helper dsh-wsl-common 0.1.0 is a library, not a KIT_SET entry.


Compatibility (2026-09)

Piece Status
dsh This machine on 0.2.0-rc.2 (npm @next, 2026-09-29). npm latest still points at the 0.1.7 line, so @next is what carries 0.2.0. Kit scripts assume dsh ≥0.1.2 UI launch tokens (?token= on :3081). The whole plugin suite was re-verified against 0.2.0-rc.2: every lib/ entry point imports, the offline smoke set is green, and the tracked floor versions are unchanged — no plugin code change was needed.
DeepSeek V4.1 Flash Official API model id is deepseek-flash. Legacy deepseek-v4-flash / deepseek-v4-flash-vision-exp temporarily route to V4.1 Flash. Not configured by this kit — set under llm-deepseek / default model in ~/.dsh/settings.yaml.
Agent Teams Opt-in experimental package (@deepseek-ai/dsh-experimental-agent-team-profile, same line as your dsh). Not part of install.sh. Expect longer “Deep diving” turns; use a fresh non-Teams session to smoke-test models.
Plugins Snapshot: Plugin versions (sibling checkouts 2026-09-16). Floor: scripts/check-plugin-versions.sh. Daily includes dsh-wsl-fetch ≥0.1.1.

Plugin README policy

  • This Compatibility section is the suite matrix. Each plugin README has a matching Compatibility table (EN + ZH): minimum dsh ≥0.1.2, pointer here for latest verified, kit set, and notes that cloud Flash / Agent Teams are not owned by WSL plugins.
  • When dsh ships a new line (e.g. 0.1.5 GA or 0.1.6), update this kit table first, then refresh plugin “currently …” lines (or re-run the suite doc sync). Do not invent per-plugin “verified” dates without a smoke pass.
  • API-sensitive plugins (net, fetch, port, expose, tray, hostsvc) carry an extra Scope paragraph; thinner Daily tools keep the shared table only.

No kit code change is required solely for V4.1 Flash — update model ids in settings if you still default to retired names.


60-second start (recommended: Daily set)

Prereq: dsh works inside WSL (profile usually web). Prefer 0.2.0-rc.2 (@next) or newer from the same train.

curl -fsSL https://raw.githubusercontent.com/173787247/dsh-wsl-kit/master/install.sh \
  | KIT_SET=daily bash

Then:

  1. Restart via scripts/restart-dsh-web.sh (starts dsh on :3080 and the Windows relay on :3081)
  2. In Windows open the URL printed by restart-dsh-web.sh (dsh ≥0.1.2 includes ?token=; bare :3081 is 401. Not :3080). Token is also written to /tmp/dsh-ui-url (WSL).
  3. Open a new session (old sessions keep the old toolset)
  4. Optionally merge cordis.patch.yml into your profile (a later plugin config replaces the whole object — restate every key you still need)
Want Command
Daily (recommended) KIT_SET=daily bash install.sh
Daily + GitHub App / credentials KIT_SET=github bash install.sh
Local LLM + network doctor KIT_SET=llm bash install.sh
Everything KIT_SET=full bash install.sh (or omit KIT_SET — same as before)

From a local clone: KIT_SET=daily bash install.sh

What restart-dsh-web.sh loads

  • NODE_USE_ENV_PROXY=1, OLLAMA_API_KEY default ollama
  • NO_PROXY=127.0.0.1,localhost only (do not inherit Clash RFC1918 NO_PROXY globs — they make Node skip the proxy and timeout on api.deepseek.com)
  • Optional: source "$HOME/.dsh/dsh-wsl-github.env" yourself before start when using GitHub App plugins

What you get immediately

Pain Tool Plugin
Proxy / Node 24 blocks DeepSeek or npm net_doctor dsh-wsl-net
web_fetch TypeError: fetch failed (API works) Install dsh-wsl-fetch ≥0.1.1 + restart-dsh-web.sh dsh-wsl-fetch
Open a Linux path from chat on Windows (clickable paths) dsh-wsl-open
Path convert / slow /mnt/c path_convert dsh-wsl-path
Windows clipboard wsl_clipboard dsh-wsl-clipboard
Open a PR / docs URL in Windows win_open_url dsh-wsl-browser
Agent forgets it is in WSL (system prompt inject) dsh-wsl-env

Daily = table above + win_launch + dsh-repeat-stop + dsh-tool-budget + dsh-wsl-fetch.

Smoke: in a new session ask “run net_doctor” and “copy this path to the Windows clipboard”. Prefer model deepseek-flash for cloud; keep Agent Teams off for first smoke.


Install sets (short list)

Set Includes Who
Daily env, net, fetch, open, repeat-stop, tool-budget, clipboard, path, browser, launch Most WSL + Windows-browser users
GitHub day Daily + github + cred + notify Also need PR/Actions status and git push credential hints
LLM env, net, fetch, hostsvc, docker, dns, clock, gpu, port, expose, tray, open, path, browser Local Ollama / vLLM / Unsloth + connectivity
Full Everything in install.sh — Daily + GitHub extras + doctors, plus read-only Windows host observation (perf, service, eventlog, registry, defender, power) GPU/Docker/clock doctors, tray, portproxy, etc.
Desktop uia, winshot, winctl, wininput — KIT_SET=desktop Want the agent to read and drive the Windows desktop

Do not start with Full — get Daily working, then add plugins for specific pains.

Desktop is a separate set on purpose. dsh-wsl-wininput types and clicks, dsh-wsl-winctl moves and closes windows; dsh-wsl-uia and dsh-wsl-winshot are the observation half of the same pair. That is a different power level from reading counters and an event log, so full never pulls it in.

Optional: GitHub day

GitHub from WSL is credentials + API + browser open + proxy — not one mega-plugin. After KIT_SET=github:

  1. Create the App per dsh-wsl-github (read-only Metadata / PRs / Actions; webhooks off)
  2. Before start: source "$HOME/.dsh/dsh-wsl-github.env"
  3. New session → github_app_hint / github_repo_status; never paste PEM / PAT into chat

Node 24 + Windows proxy

export HTTP_PROXY=http://127.0.0.1:7890   # or Clash mixed port, e.g. 16006
export HTTPS_PROXY=http://127.0.0.1:7890
export NODE_USE_ENV_PROXY=1
# Prefer restart-dsh-web.sh so NO_PROXY stays loopback-only

Still failing → ask the agent to run net_doctor.

  • API works, web_fetch fails → dsh-wsl-fetch (Daily already installs it).
  • Third-party Workers / Cloudflare 403 (1010) via Clash → add a DIRECT rule for that host (plugin cannot override site WAF).

Local OpenAI-compatible backends on Windows: add dsh-wsl-hostsvc, run host_reach, merge examples/local-llm-providers.settings.yaml.


Troubleshooting

Connectivity, UI token 401, Ollama ctx, and fetch faults: docs/TROUBLESHOOTING.md (中文: TROUBLESHOOTING.zh.md).

Order of play: host_reach → net_doctor → dns_doctor → clock_doctor → workspace/mnt → expose (LAN only).


Maintaining this kit

Which file is generated and which is handwritten, what each of the thirty-two scripts does and when to run it, and the invariants that keep twenty-six plugin copies from drifting: docs/MAINTENANCE.zh.md.


Full catalog (reference)

Expand all plugins

Daily (KIT_SET=daily)

Plugin Role
dsh-wsl-env Inject WSL/Windows facts into the system prompt
dsh-wsl-net net_doctor
dsh-wsl-fetch Proxy-aware web_fetch (undici ProxyAgent)
dsh-wsl-open Open Linux paths from chat on Windows
dsh-repeat-stop Hard-stop identical tool loops
dsh-tool-budget Cap tool calls per session
dsh-wsl-clipboard wsl_clipboard
dsh-wsl-path path_convert
dsh-wsl-browser win_open_url
dsh-wsl-launch win_launch (allowlisted)

GitHub add-ons

Plugin Role
dsh-wsl-github github_app_hint / github_repo_status
dsh-wsl-cred cred_hint (no secrets)
dsh-wsl-notify win_notify

Doctors / UI / tier 2

Plugin Role
dsh-wsl-gpu gpu_doctor
dsh-wsl-port port_doctor
dsh-wsl-distro distro_info
dsh-wsl-workspace wsl_workspace
dsh-wsl-picker wsl_picker
dsh-wsl-tray wsl_tray
dsh-wsl-expose wsl_expose
dsh-wsl-hostsvc host_reach
dsh-wsl-clock clock_doctor
dsh-wsl-dns dns_doctor
dsh-wsl-mnt mnt_doctor
dsh-wsl-editor win_editor
dsh-wsl-shot win_shot
dsh-wsl-docker docker_doctor
dsh-wsl-ssh-agent ssh_agent_hint
dsh-wsl-encoding encoding_doctor
dsh-wsl-wslconfig wslconfig_hint
dsh-wsl-download win_download

Related: session-contract. Awesome listing snippet: awesome-wsl-kit.md.

Awesome status (2026-09-24): ~35 Daily/tool plugins on awesome main (including jev / obsidian). The 22 Linux-optional plugins are in PRs #5783–#5790 (CI green, awaiting merge). Queue: docs/AWESOME_QUEUE.zh.md. This kit meta-repo is not submitted to awesome — install via this repo / install.sh.


Beyond the kit

Do not reopen work that already shipped (fetch 0.1.2, obscura, version floors, 401 health, hostsvc apiReady, :3081 token relay). A new repo only for a new product. DingTalk does not get one.

Plan (2026-09-24): Keep Daily stable; ship new products as optional Linux/local plugins (Chinese homepage + README.en.md; read-only / double-gated by default). Full catalog + batch link → docs/OPTIONAL_PLUGINS.md · bash scripts/link-linux-plugins.sh. Awesome queue → docs/AWESOME_QUEUE.zh.md.

Track Plan Status
Feishu / WeCom / DingTalk / QQ / Slack / Discord / Telegram / Mattermost Deepen dsh-wsl-im; not in install.sh. 0.3.8; queue docs/ENHANCEMENT_QUEUE.zh.md
Obsidian / Jev obsidian · jev; not in install.sh. On awesome main; deepening
Local inference ollama · llamacpp · vllm · vecmem Repos open; see OPTIONAL_PLUGINS; deepening
Media / search / secrets / struct media · search · secret · struct Same
Read-only DevOps git · tmux · compose · systemd · k8s · helm · terraform · rclone · db · glab Deepening (not “repo-only”)
Desktop helpers playwright · mail · cal · pkg Deepening
Remote bridges remote-ssh · mac-companion · device-bridge awesome #5873
MCP / OpenClaw / Agent Teams Upstream or separate runtimes Out of kit
Thin UX editor / shot / notify / picker Deepening (ENHANCEMENT_QUEUE Wave M)

Security

  • Plugins share your Harness permissions (files, network, Windows via PowerShell/cmd).
  • win_launch is allowlisted; cred_hint / GitHub App never dump secrets into chat.
  • win_notify blocks on a MessageBox — keep text short and secret-free.
  • Keep *.env under ~/.dsh/ at chmod 600; never commit API keys.

Topics

deepseek-harness · dsh-plugin · wsl · windows · github-app

License

MIT — same as the individual plugins.

About

DeepSeek Harness WSL kit (EN/ZH): docs + install.sh + cordis.patch for Windows browser + WSL agent plugins

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages