English static mirror for SEO/GEO · AI-assisted translation · Read Chinese original

DeepSeek Harness Deep Dive: Everything Is a Plugin, Even the Agent Loop

Forum topic · QianXun · 2026-08-14

Summary

A code-level research report on DeepSeek Harness (dsh), an open-source (MIT) agent runtime base released by DeepSeek on 2026-08-13 (v0.1.0-rc.5). Built on the Cordis plugin microframework (TypeScript/Node.js ≥22.19), dsh treats models, tools, UI, sandboxing, and even the agent loop as replaceable plugins assembled via cordis.yml configuration. The report verifies via file:line citations that dsh uses a no-privileged-core microkernel, mechanically enforced observability (model-visible messages must match the append-only session event log), OS-level sandboxing (Windows restricted tokens, Linux Landlock/bwrap, macOS Seatbelt), four agent presets (Standard/Code-PTC/Minimal/Creator), and a unified subagent interface that can delegate to Claude Code, Codex, ACP, or a full dsh SDK runtime. Key corrections to external coverage: Creator mode plugins are in-memory only and cannot hot-swap the running assembly; pure host-half dynamic packages activate without approval; long-term memory and adaptive context compression are roadmap items, not implemented. Multi-agent orchestration is hierarchical supervisor-worker with no swarm primitives. The article assesses risks (interface stability, no external PRs, breaking changes ahead, concurrent V4-Pro API price hike of ~4.6x) and frames dsh as DeepSeek commoditizing the harness complement to benefit its models.

DeepSeek Harness Deep Dive: Everything Is a Plugin, Even the Agent Loop

> Research subject: github.com/deepseek-ai/deepseek-harness (v0.1.0-rc.5, MIT license, local shallow clone deepseek-harness-research) > Method: four parallel specialist agents performed code-level verification (Cordis/tool pipeline, four modes, multi-agent, event stream) plus external cross-checks (InfoQ, technical teardowns, web search). Every key claim is backed by file:line references; discrepancies with external coverage are listed as "fact corrections."

Key points

  • Positioning: dsh is an open-source agent runtime base (plugin-centric, "concrete-harness"), not a fixed-feature coding agent. Formula: Model + Harness = Agent — the model is the horse; the harness is the全套 engineering that lets it work in the real world.
  • Analogy: Claude Code is like an iPhone (closed, vertically integrated); Codex is a polished open-but-finished product; dsh is like Android — it open-sources the full blueprint so anyone can assemble their own agent.
  • 1. Basic profile

    | Item | Value | | --- | --- | | First release | 2026-08-13 (developer preview) | | Version | v0.1.0-rc.5 (README warns of compatibility-breaking changes) | | Stack | TypeScript / Node.js (≥22.19), built on the Cordis plugin meta-framework | | Scale | 49-package monorepo, 1981 TS files (~198k LOC est.) | | License | MIT (closed-source commercial use allowed); no external PRs accepted yet | | Launch | npx @deepseek-ai/dsh web → http://127.0.0.1:3080 | | Models | Model-agnostic: default DeepSeek; adapters for Anthropic/OpenAI/Bedrock/Vertex/Azure and any OpenAI-compatible endpoint |

    Cordis originates from the Koishi ecosystem's plugin kernel (cordiverse), grounded in the paper *A Programming Paradigm for Spatiotemporal Composability*, battle-tested in Koishi for four years.

    2. Architecture: microkernel + plugin galaxy

  • A running dsh instance is a Cordis Context: all capabilities register services, events, and effects as plugins; a cordis.yml assembles the runnable agent (cordis-host-runner/src/index.ts:7-8).
  • Four-layer config synthesis (bundle → profile patch → home patch → --patch, last-write-wins); dsh --dump-config prints the pure synthesis without booting — config is the runtime state.
  • Waterfall interception: tool execution flows through tools/pre-execute → execute → post-execute → result; hooks, approval, permissions, sandboxing, and timeouts all attach to the same waterfall. All call paths (model, workflow, subagent, ACP, remote) pass one ToolRuntime.execute gate, so programmatic tool calls (PTC) cannot bypass approval/sandbox.
  • OS-level sandboxing: Windows CreateRestrictedToken (fails closed), Linux Landlock/bwrap, macOS Seatbelt. Note: the host-half node:vm sandbox explicitly self-describes as "not containment."
  • 3. Four modes (four preset combinations, not four systems)

    | Mode | Notes | | --- | --- | | Standard | Full toolset | | Code (publicly: "PTC") | Wire tools collapse to [run_code]; the model writes TypeScript to batch multi-step calls into one round trip | | Minimal | Persistent bash + editor only | | Creator (cordis) | Adds 7 cordis_* tools for runtime introspection and plugin authoring |

    Creator mode — real boundaries: dynamic packages are immutable and in-memory only (lost on restart); activation is additive versioning, not hot-swapping the live assembly. Pure host-half packages activate without approval — correcting external claims that approval is always required. Persistent authoring writes new presets to disk, effective only after remount.

    4. Multi-agent: supervisor-worker, not swarm

  • Spawn: fresh-context child; Fork: inherits a snapshot of the parent's completed turns.
  • Ralph: a hard-coded fixed loop spawning structured-output subagents; Workflow: model-written JS in a sandboxed worker thread with no fs/net.
  • Six subagent providers behind one interface: spawn/fork (default on), plus opt-in claude-code, codex, acp, dsh-sdk — dsh can genuinely delegate to Claude Code or Codex via the same subagent tool.
  • Orchestration is strictly hierarchical supervisor–worker (maxDepth:3); grep for swarm/self-organizing/blackboard primitives returns zero hits — architecturally novel abstraction, no paradigm breakthrough.
  • 5. Unified event stream: model-visible means logged

  • Turns/Steps are append-only SessionEvents; deriveMessages() is a pure-function projection — model history is never stored separately. An invariant compares the outgoing request against the log-derived reconstruction with JSON.stringify before every dispatch (agent-loop/src/invariant.ts:39-52); mismatch = fail.
  • Fork, resume, transcripts, telemetry, and persistence all derive from this stream. Crash repair synthesizes TOOL_OUTCOME_UNKNOWN events. Auto-continuation deliberately requires human-authorized resume — dsh assumes "a human sits in front."
  • Compaction: a replaceable CompactionEngine seam + basic provider exist; long-term memory / adaptive context compression / causal-graph retrieval are roadmap, absent from code (correcting InfoQ).
  • 6. Fact corrections vs. external coverage

    | Claim | Verdict | | --- | --- | | "Creator mode lets the agent rewrite its own harness" | Half-true: temporary in-memory extension + new preset authoring; no live hot-swap | | "No privileged core" | Holds at implementation level (whitelisted facades, denyContext), but the node:vm sandbox is not containment, and a de-facto contract kernel exists (ctx.* services, agent/* events, SessionEvent) | | "Memory compression/conflict cleanup/path reuse/plan validation are next focus" | Only compaction is implemented; the rest are roadmap, not code |

    7. Assessment and risks

  • InfoQ's claims largely hold at code level; "everything is a plugin" genuinely preserves replaceability, including the agent loop itself.
  • But replaceability ≠ usability: interface stability, 49-package dependency management, waterfall overhead, distributed debugging, and ecosystem governance (no external PRs, breaking changes imminent) are all open problems.
  • Strategy: commoditize your complement — an MIT, model-agnostic harness funnels demand toward the best model. A closed-source managed/cloud bundle is architecturally reserved via open-core. Notably, DeepSeek's V4-Pro API price rises ~4.6× on 8-16, days after launch.

8. Conclusion

dsh is the most radical "everything is a plugin" agent runtime to date: code-verified no-privileged microkernel, mechanically enforced observability, OS-level sandboxing, and a subagent abstraction that absorbs competitor agents. Its success hinges on freezing the contract kernel, shipping trustworthy defaults and evaluations, and whether third parties build on it. v0.1 remains a blueprint — the question is whether "everything is a plugin" becomes a shared industry harness or stays the embryo of DeepSeek's own coding product.

---

*Original four-track research reports: report-甲.md (Cordis & tool pipeline), report-乙.md (four modes & Creator), report-丙.md (multi-agent & comparison), report-丁.md (event stream & observability).*

Tags

#deepseek#agent-runtime#plugins#cordis#open-source#llm-agents#architecture#multi-agent

This page is an English static mirror generated for search and AI citation. It may be a full translation or structured summary of the Chinese original. Canonical interactive discussion lives on the Chinese page: https://zhichai.net/topic/178633474