dsh-restart-control
y2zyyr/dsh-restart-control
Adds a Restart DSH button to DSH Desktop Settings → General (通用设置).
インストール
dsh plugin --profile web add github:y2zyyr/dsh-restart-controlREADME
Restart DSH
Adds a Restart DSH button to DSH Desktop → Settings → General (通用设置). It sits directly below「繁忙时 Enter 键行为」and lets you restart the DSH Desktop application with one click, using DSH's official graceful restart facility.
Features
- Restart DSH Desktop from Settings → General (官方 slot:
settings.general.item) - Uses the official DSH Desktop restart API
(
ctx.desktopRuntime.requestRestart()→ graceful Cordis teardown +app.relaunch()+app.exit(0)) when a desktop shell is present - Pure
dsh --profile websupport (v0.1.7): arms a detached relauncher, then SIGTERMs its own process so the CLI's built-in handler performs the same graceful Cordis teardown; the relauncher waits for the old pid to die and re-execs the original argv/cwd verbatim, then the browser panel reloads on the new generation — still no shell, no kill/pkill/sudo - Native confirmation dialog (native
Modal+Buttonprimitives) before restarting - Single-flight protection: while a restart is pending the button shows 「正在重启…」and is disabled
- Light / Dark theme via DSH design tokens (
--dsw-alias-*) — no hardcoded colors - i18n: zh-CN + en
- No telemetry, no network access, no credential access, no filesystem access
Installation
Local install into a DSH web profile (additive, backed-up edits):
- Add to
~/.dsh/profiles/web/package.jsondependencies:"@y2zyyr/dsh-restart-control": "link:/path/to/dsh-restart-control" - Add
@y2zyyr/dsh-restart-controltodsh.profile.bundles. - Run
pnpm installin the profile directory. - Restart DSH Desktop once so the new bundle's loader row activates.
Naming rule (DSH Desktop ≥ 2.0.2): the dependency key must be exactly the plugin's
package.jsonname(@y2zyyr/dsh-restart-control). The desktop validates that every bundle's resolved manifest name matches its reference name and otherwise refuses to load the whole profile withprofile package identity is invalid. Do not alias the key to a scoped name.
The plugin's own cordis.patch.yml registers the Loader entry; the host half is
loaded by Cordis and the browser half is served as
/plugins/@y2zyyr/dsh-restart-control/client.js.
Compatibility
- DSH Desktop (Electron shell) running in
compatibilityoradvancedmode — provides thedesktopRuntimeservice; the button restarts through the official facade (mode: "desktop"). - Pure
dsh web/--profile web(no desktop shell): the button restarts the server process itself — graceful SIGTERM teardown + detached relauncher re-execing the captured argv/cwd (mode: "web"). Requires a real Node host process (always true for the host half); if spawning the relauncher fails the route returns 500 and keeps the server up. - DSH core packages at
^0.1.0-rc.6(compatible with the DeepSeek Harness Desktop runtime 0.1.0-rc.7; v0.1.1 widened the range so the DSH Desktop market verifier accepts the package).
Restart mechanism
The host half registers a browser-trust-fenced route (/dsh-restart-control/api,
loopback / same-origin only) and calls the official
ctx.desktopRuntime.requestRestart() when a desktop shell is present. The
official implementation disposes the whole Cordis plugin tree (flushing settings /
session state, 5 s grace), then app.relaunch() + app.exit(0). This is a
graceful restart — never a process kill. Without a desktop shell the plugin
uses its web path: it spawns a detached relauncher child FIRST, replies 202, then
sends itself SIGTERM — the dsh CLI installs
process.on("SIGTERM") -> root fiber.dispose(), so the identical graceful
teardown runs before exit. The relauncher polls until the old pid is actually
gone (bounded backstop, never double-spawns) and re-execs the captured
argv/cwd verbatim. GET /status reports { ok, restartable, mode }.
Security
- No shell execution — restart goes through the official
desktopRuntimeservice; the plugin never spawns kill/pkill/osascript/sudo. - No network — the only route is a loopback, same-origin-fenced HTTP route.
- No credential / token access — the plugin reads no .env, API keys, or session content.
- No telemetry — the only runtime side effect is an optional boot marker under
/tmp/dsh-restart-control-test/used purely for local verification, and it is never shipped as telemetry. - Minimal permissions — the host only requires
webServer(route) and optionallydesktopRuntime; the client onlyslots/locale.
Development
pnpm installpnpm typecheck(tsc, no emit)pnpm test(node --test; real Cordis integration tests)pnpm build(scripts/build.mjs →lib/index.js+lib/client.js)