zhangzhangco/dsh-llm-codex ↗★ 0
dsh-llm-codex
Codex route for DeepSeek Harness: local Codex CLI first, OpenAI-compatible API fallback 适合需要结合本地Codex命令行与云端API进行模型调用的用户。
Other repositories with this package name
Install
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:zhangzhangco/dsh-llm-codexREADME
Read the full README ↗Configuration
Mounted from ~/.dsh/profiles/web/cordis.patch.yml:
- insert:
- id: llm-codex
name: dsh-llm-codex
config:
provider: codex-local
# Codex's own sandbox (not the harness permission mode). See
# "Sandbox and file writes" below before choosing a value.
sandbox: read-only
ephemeral: true
transport: auto
reasoningEffort: ''
fallback:
baseURL: ''
apiKeyEnv: CODEX_FALLBACK_API_KEY
| Field | Default | Meaning |
|---|---|---|
provider | codex-local | Route name shown to the model picker |
command | discovered | Codex CLI to run; empty discovers it ($CODEX_COMMAND, PATH, known installs) |
args | [] | Extra argv passed to codex exec before the prompt |
model | empty | Pin one model; empty uses the catalog, then $CODEX_HOME/config.toml |
reasoningEffort | empty | Default effort; a session selection wins |
sandbox | read-only | read-only, workspace-write, or danger-full-access |
cwd | empty | Codex working root; empty uses the session workspace |
ephemeral | true | Run without persisting Codex threads under $CODEX_HOME |
timeoutMs | 600000 | Wall-clock budget for one codex exec |
codexHome | empty | $CODEX_HOME for the child; empty inherits the environment |
modelsCachePath | $CODEX_HOME/models_cache.json | Catalog cache |
models | [] | Extra ids to advertise when the cache is missing |
defaultContextWindow | 272000 | Capacity fallback for unknown ids |
transport | auto | auto (CLI, then fallback), cli only, or api only |
fallback.baseURL | empty | OpenAI-compatible base URL; empty disables the fallback |
fallback.apiKeyEnv | CODEX_FALLBACK_API_KEY | Variable holding the fallback key |
fallback.model | empty | Model id for the fallback; empty reuses the request id |
fallback.headers | {} | Extra request headers |
fallback.timeoutMs | 300000 | Fallback request budget |
Sandbox and file writes
sandbox selects Codex's own sandbox for the CLI route. It is a different
boundary from this harness's permission mode, which keeps gating DSH's own tools
independently; changing one does not change the other.
| Value | Effect on Codex's tools |
|---|---|
read-only | Reads and answers; every file write is refused |
workspace-write | Writes inside the session workspace; other targets stay refused |
danger-full-access | No Codex sandbox at all |
The two sandboxed modes need macOS Seatbelt, applied through sandbox-exec. A
host that already runs inside a sandbox cannot apply a nested profile — the call
fails with sandbox_apply: Operation not permitted — and then every
sandboxed mode refuses writes, no matter which roots are allowed: