dsh-self-preserve
Manifest validDSH hook plugin: a session may not stop the harness it runs inside
dsh-self-preserve
A tiny DeepSeek Harness hook plugin that stops a model session from stopping the harness it is running inside.
The failure it prevents
dsh web runs as a systemd user service. A session used the bash tool to write a runbook on another host:
ssh peer "cat > RUNBOOK.md <<'EOF'
1. `systemctl --user stop deepseek-harness.service`
5. `systemctl --user start deepseek-harness.service`
EOF"
The body sits inside a double-quoted string, so the local shell evaluates the markdown backticks as command substitutions before ssh runs. Step 1 stopped the harness the session lived in. The bash subprocess is in the harness's cgroup, so the stop killed the issuing shell, step 5 never ran, every live session on the host ended, and the unit stayed down (clean exit, so Restart=on-failure never fires).
Journal fingerprint:
systemd: Reloading requested from client PID 2608960 ('systemctl') (unit deepseek-harness.service)...
systemd: Stopping deepseek-harness.service ...
systemd: Stopped deepseek-harness.service ...
with no Starting afterwards.
What it does
On tools/pre-execute it reads the Linux unit name from /proc/self/cgroup and returns {kind: "deny"} for any tool command matching systemctl … (stop|kill|restart|try-restart) … <own unit>. For non-systemd supervisors, set DSH_SELF_PRESERVE_TARGET to the service label; macOS launchd stop, kill, remove, bootout, unload, and kickstart commands targeting that label are denied.
The plugin logs [dsh-self-preserve] armed for <target> when protection is active. If no target can be discovered or configured, it logs an explicit inactive warning. Restarts must be initiated out of band, from another machine or external supervisor. Read-only status commands and operations on other services stay allowed.
Install (profile as a local package)
git clone https://github.com/n8guru/dsh-self-preserve ~/.dsh/local-mods/dsh-self-preserve
cd ~/.dsh/profiles/web # and profiles/headless if you use it
# package.json: add to "dependencies" and to dsh.profile.bundles
# "dsh-self-preserve": "file:../../local-mods/dsh-self-preserve"
pnpm install --ignore-workspace
# Restart from another machine or an external supervisor.
Test
node --test guard.test.mjs
Files
guard.jspure policy (ownUnit,decide) so it can be tested without a harnessindex.jsthe Cordis plugin: onectx.on("tools/pre-execute", …)listenercordis.patch.ymlmounts the hook as a profile row; listing a package indsh.profile.bundlesonly composes its patch and does not mountindex.jsby itself
MIT.
Comments
Loading…
Similar plugins
by jwilson411
DeepSeek Harness plugin: fail-closed URL host/scheme allowlist that runs before a request is opened
★ 0
MIT
JavaScript
Sep 21, 2026
dsh plugin --profile web add dsh-ssrf-guardby XiaoWind
DeepSeek Harness plugin: portable workspace vault for DSH conversations and logs
★ 0
MIT
JavaScript
Aug 28, 2026
dsh plugin --profile web add dsh-vaultby Culeot
Cross-session long-term memory plugin for DeepSeek Harness (DSH)
★ 8
↓ 71/wk
MIT
JavaScript
Sep 26, 2026
dsh plugin --profile web add dsh-agent-memoryby jwilson411
A minimal, tested template for DeepSeek Harness plugins.
★ 0
MIT
JavaScript
Sep 1, 2026
dsh plugin --profile web add dsh-plugin-kitby ddll8023
Session access-mode plugin (Default / No Edit / Auto) for DeepSeek Harness (DSH). dsh-plugin
★ 0
MIT
JavaScript
Aug 24, 2026
dsh plugin --profile web add dsh-access-modeby temidayoxyz
DeepSeek Harness (dsh) plugin: browse http(s) pages in the right sidebar, beside the conversation.
★ 0
MIT
TypeScript
Sep 30, 2026
dsh plugin --profile web add dsh-deep-browser