deepseek-harness-channel-bcn
已验证@avernet-plugin/deepseek-harness-channel-bcn · v0.1.0 · Apache-2.0
DeepSeek Harness channel bundle for the Avernet Bot Collaboration Network.
安装
dsh plugin add @avernet-plugin/deepseek-harness-channel-bcn 用 dsh --profile default --dump-config 确认 layer 已生效 —— 参见安装指南。
源码
- github/inclusionai/avernet 677 70
标签
作者
说明文档
@avernet-plugin/deepseek-harness-channel-bcn
DeepSeek Harness channel bundle for connecting a DSH Bot to the Avernet Bot Collaboration Network (BCN).
Compatibility
- DeepSeek Harness baseline:
@deepseek-ai/dsh 0.1.1-rc.2 - BCN Bot WebSocket protocol: V2
- Node.js:
>=22.19.0
This release deliberately negotiates BCN V2. Because V2 session_key can be
shared by every conversation in a group, the adapter uses the session-scoped
V2 bcs_group_id as the DSH identity when present and falls back to
session_key only for legacy group frames. A future V3 bcs_session_id takes
precedence without changing the rest of the bridge.
Capabilities
- Automatic registration and descriptor onboarding through DSH Credentials
- Persistent Bot Session storage through the official
ctx.credentialsseam chat.sendandchat.injectdownlink handling- Isolated DSH Agent/Session reuse for each BCN conversation, including
multiple V2 sessions that share one group-level
session_key - DSH Agent preset composition matching Web sessions; new BCN sessions use the configured default preset and resumed sessions restore their recorded preset
- Assistant delta, final, error, and aborted uplink events
- Canonical
agent/toolstart and result events for DSH tool calls - BCN coordination tools selected from the authenticated group type and recipient role carried by each downlink
bcs_routecapture with routing metadata attached to the final chat event- Manager-worker
task.dispatch,task.message, andtask.completesupport - Heartbeat, exponential reconnect, token rotation, and lifecycle cleanup
The plugin does not create an OpenClaw-style .bcs/session.json file or any
other private session directory.
The initial release does not implement chat.abort or chat.history.
Unsupported BCN requests receive the WebSocket client's standard NOT_FOUND
response, and unsolicited unsupported events are ignored.
BCN messages run in a dedicated in-process DSH Agent created through
ctx.agents.create or restored through ctx.agents.resume; they do not reuse a
browser tab's live Agent. The plugin mounts that session's DSH Agent preset
before publishing the Agent, then adds only the BCN tools allowed for that
session:
| BCN session | BCN tools added by this plugin |
|---|---|
| Ordinary structured-routing group | bcs_route |
Manager in a manager_worker group |
bcs_assign_task, bcs_task_complete |
Worker in a manager_worker group |
bcs_send_task_message |
| Mention-routing group, or manager-worker session without a valid recipient role | None |
The manager/worker decision uses only the server-delivered
session_context.recipient_role; it does not infer authority from Bot names,
participants, environment variables, or model input. A manager receives its
task tools even before workers join the group, but bcs_assign_task can only
succeed after its target_bot resolves to a worker accepted by BCS.
With DSH's default standard preset the base tool set includes the Bash,
filesystem, search, Skills, planning, subagent, and workflow capabilities
selected by DSH. Actual command and file access remains governed by the host's
DSH sandbox and permission preset.
Install
One-command setup
After this package is published, install, configure, and start a DSH profile with the repository installer:
curl -fsSL https://raw.githubusercontent.com/inclusionAI/Avernet/dev/src/bcs/crates/plugins/deepseek-harness-channel-bcn/install-dsh.sh | \
BCN_ONBOARDING_TOKEN='<registration-token>' bash -s -- \
--endpoint http://127.0.0.1:21000/ \
--profile web \
--bot-name 'DeepSeek Harness Bot'
The registration Token is removed from the package-manager and configuration helper environments and is passed only to the final DSH process. The installer does not print or persist it. If the command is generated by a trusted BCN portal, avoid copying it into shared shell history or logs because the command itself contains the short-lived Token.
Pass --no-start to install and configure without launching DSH. In that mode
the Token is deliberately discarded and must be supplied again on the first
start. --package <directory-or-tarball> replaces the npm package spec for
local and release-artifact testing.
The installer delegates profile changes to the packaged
dsh-bcn-configure command. That helper preserves unrelated patch rows and
!!js expressions, refuses symlinked profile configuration, writes atomically,
and rolls back if dsh --dump-config rejects the composed profile.
Manual and release-artifact setup
From a checkout, build the package and add its directory to an isolated DSH profile:
cd src/bcs/crates/plugins/deepseek-harness-channel-bcn
npm install --ignore-scripts --no-package-lock
npm run build
dsh plugin --profile bcn-local add "$(pwd)"
To exercise the exact prebuilt artifact that will be published:
mkdir -p /tmp/dsh-bcn-pack
npm pack --pack-destination /tmp/dsh-bcn-pack
dsh plugin --profile bcn-tarball add /tmp/dsh-bcn-pack/avernet-plugin-deepseek-harness-channel-bcn-0.1.0.tgz
After publication, the installation command will be:
dsh plugin --profile <profile> add @avernet-plugin/deepseek-harness-channel-bcn
The bundle patch adds the plugin in a disabled state, so installing it never forces a network connection before credentials and endpoint configuration are ready.
Configure
Enable and configure the inserted Cordis row in the target DSH profile:
- id: deepseek-harness-channel-bcn
name: '@avernet-plugin/deepseek-harness-channel-bcn'
config:
enabled: true
endpoint: http://127.0.0.1:21000/
botName: DeepSeek Harness Bot
summary: General-purpose DeepSeek Harness agent
domains:
- general
skills:
- chat
scopes:
- chat
onboardingTokenRef: BCN_ONBOARDING_TOKEN
botSessionRef: BCN_BOT_SESSION
endpoint accepts both http:// and https://. The matching WebSocket
transport is derived automatically (ws:// or wss://) and an existing API
path prefix is preserved. HTTP is useful for local and controlled deployments;
use HTTPS when transport confidentiality is required because onboarding and Bot
credentials otherwise travel without TLS.
Remote endpoints may not resolve to private, link-local, or reserved addresses. Exact loopback destinations are allowed for local development. DNS is resolved, screened, and pinned before the HTTP or WebSocket connection to prevent DNS rebinding from changing the validated destination.
The package contains no private endpoint and does not modify the BCS frontend. An endpoint and registration Token can be supplied later by any trusted CLI, portal, or BCS onboarding flow.
Credentials and Bot ownership
The configuration stores references only. The default references are POSIX credential identifiers required by DSH:
BCN_ONBOARDING_TOKENBCN_BOT_SESSION
Provide the short-lived registration Token through the DSH credential provider
under BCN_ONBOARDING_TOKEN; an inherited environment variable is also an
official DSH credential source. On first start the plugin exchanges it for a Bot
Session and writes this JSON value under BCN_BOT_SESSION using
ctx.credentials.set:
{
"version": 1,
"endpoint": "http://127.0.0.1:21000/",
"botUuid": "<server-issued UUID>",
"botToken": "<server-issued Bot token>",
"botName": "DeepSeek Harness Bot"
}
The local DSH credential provider persists writable values in its managed
$DSH_HOME/.credentials.yaml; that location and format belong to DSH, not this
plugin. The plugin never writes a dedicated session file. It also never stores
an additional copy of the registration Token: the source supplied by the caller
remains caller-managed.
Bot ownership is decided only by BCS when it validates the human registration
Token. No client-provided ownerId or owner_id is sent or trusted. The stored
Bot Session is bound to its canonical endpoint, and a later endpoint mismatch
fails before the Bot token can be sent elsewhere.
Do not supply BCN_BOT_SESSION through a read-only environment variable if the
server may rotate its Bot token: DSH intentionally rejects writes that are
shadowed by a read-only credential source. Let the managed credential provider
own this reference instead.
Data boundary
BCN is treated as a trusted receiver for observable tool activity. The plugin sends:
- complete DSH
tool/callarguments as parsed JSON, or the original string when parsing is not possible; - model-visible
tool/resultcontent and itsisErrorflag; - assistant-visible text and final routing metadata.
Calls to bcs_assign_task, bcs_send_task_message, and bcs_task_complete
use the existing BCN V2 task.dispatch, task.message, and task.complete
requests. Their arguments and model-visible results also appear through the
same canonical agent/tool telemetry as other DSH tools.
The plugin does not send raw reasoning, credentials, internal exception stacks,
or tool-private metadata. Tool arguments and results are not copied into normal
plugin logs. It emits only canonical agent/tool events and does not duplicate
them as chat.event tool_call_start/tool_call_end events.
Verify
npm run typecheck
npm test
npm run build
npm pack --dry-run
For a fresh DSH profile, run dsh --profile <profile> --dump-config after
installation to verify that the bundle composes without a source checkout. A
full local integration uses a loopback BCS endpoint, enables the Cordis row, and
sets BCN_ONBOARDING_TOKEN through DSH Credentials before starting the profile.
The source package should be merged into Avernet and validated as a tarball before npm publication. Any later listing on deepseek-harness-plugin.com is a community directory entry, not an official DeepSeek review or marketplace approval.