Restart DSH
Adds a Restart DSH button to DSH Desktop → Settings → General (通用设置). It sits
directly below「繁忙时 Enter 键行为」and lets you restart the DSH Desktop application
with one click, using DSH's official graceful restart facility.
Features
- Restart DSH Desktop from Settings → General (官方 slot:
settings.general.item)
- Uses the official DSH Desktop restart API
(
ctx.desktopRuntime.requestRestart() → graceful Cordis teardown +
app.relaunch() + app.exit(0)) when a desktop shell is present
- Pure
dsh --profile web support (v0.1.7): arms a detached relauncher,
then SIGTERMs its own process so the CLI's built-in handler performs the same
graceful Cordis teardown; the relauncher waits for the old pid to die and
re-execs the original argv/cwd verbatim, then the browser panel reloads on
the new generation — still no shell, no kill/pkill/sudo
- Native confirmation dialog (native
Modal + Button primitives) before restarting
- Single-flight protection: while a restart is pending the button shows
「正在重启…」and is disabled
- Light / Dark theme via DSH design tokens (
--dsw-alias-*) — no hardcoded colors
- i18n: zh-CN + en
- No telemetry, no network access, no credential access, no filesystem access
Installation
Local install into a DSH web profile (additive, backed-up edits):
- Add to
~/.dsh/profiles/web/package.json dependencies:
"@y2zyyr/dsh-restart-control": "link:/path/to/dsh-restart-control"
- Add
@y2zyyr/dsh-restart-control to dsh.profile.bundles.
- Run
pnpm install in the profile directory.
- Restart DSH Desktop once so the new bundle's loader row activates.
Naming rule (DSH Desktop ≥ 2.0.2): the dependency key must be exactly the
plugin's package.json name (@y2zyyr/dsh-restart-control). The desktop
validates that every bundle's resolved manifest name matches its reference name
and otherwise refuses to load the whole profile with
profile package identity is invalid. Do not alias the key to a scoped name.
The plugin's own cordis.patch.yml registers the Loader entry; the host half is
loaded by Cordis and the browser half is served as
/plugins/@y2zyyr/dsh-restart-control/client.js.
Compatibility
- DSH Desktop (Electron shell) running in
compatibility or advanced mode —
provides the desktopRuntime service; the button restarts through the
official facade (mode: "desktop").
- Pure
dsh web / --profile web (no desktop shell): the button restarts the
server process itself — graceful SIGTERM teardown + detached relauncher
re-execing the captured argv/cwd (mode: "web"). Requires a real Node host
process (always true for the host half); if spawning the relauncher fails the
route returns 500 and keeps the server up.
- DSH core packages at
^0.1.0-rc.6 (compatible with the DeepSeek Harness Desktop runtime 0.1.0-rc.7; v0.1.1 widened the range so the DSH Desktop market verifier accepts the package).
Restart mechanism
The host half registers a browser-trust-fenced route (/dsh-restart-control/api,
loopback / same-origin only) and calls the official
ctx.desktopRuntime.requestRestart() when a desktop shell is present. The
official implementation disposes the whole Cordis plugin tree (flushing settings /
session state, 5 s grace), then app.relaunch() + app.exit(0). This is a
graceful restart — never a process kill. Without a desktop shell the plugin
uses its web path: it spawns a detached relauncher child FIRST, replies 202, then
sends itself SIGTERM — the dsh CLI installs
process.on("SIGTERM") -> root fiber.dispose(), so the identical graceful
teardown runs before exit. The relauncher polls until the old pid is actually
gone (bounded backstop, never double-spawns) and re-execs the captured
argv/cwd verbatim. GET /status reports { ok, restartable, mode }.
Security
- No shell execution — restart goes through the official
desktopRuntime
service; the plugin never spawns kill/pkill/osascript/sudo.
- No network — the only route is a loopback, same-origin-fenced HTTP route.
- No credential / token access — the plugin reads no .env, API keys, or
session content.
- No telemetry — the only runtime side effect is an optional boot marker under
/tmp/dsh-restart-control-test/ used purely for local verification, and it is
never shipped as telemetry.
- Minimal permissions — the host only requires
webServer (route) and
optionally desktopRuntime; the client only slots/locale.
Development
pnpm install
pnpm typecheck (tsc, no emit)
pnpm test (node --test; real Cordis integration tests)
pnpm build (scripts/build.mjs → lib/index.js + lib/client.js)