Introduction

GPT-series models make extensive use of OpenAI Codex’s apply_patch tool during training. When these models are used in DSH, they instinctively attempt to call the tool, but DSH does not provide it by default, causing errors. This plugin fills this gap using DSH’s powerful plugin system, and fully relies on DSH’s built-in sandbox system, never bypassing the sandbox to modify files directly.

Core Features

The plugin injects the apply_patch tool into DSH models, with the following characteristics:

  • Tool Definition: Patch format fully consistent with OpenAI Codex (*** Begin Patch / *** Update File: / *** Add File: / *** Delete File: / *** End of File / *** End Patch), and supports lenient parsing of gpt-4.1 style heredoc (<<'EOF' ... EOF).
  • Sandbox Writes: All file writes are executed via ctx.fs (DSH sandboxed filesystem), and deletions are executed via sandbox bash. If the sandbox denies an operation, it returns a [sandbox: ...] error; it never bypasses the sandbox.
  • Model-Conditional Injection: The settings card has only one dropdown option: Off, GPT models only (default), or all models.
  • Settings Card: Settings → Plugins → Plugin Configuration → Apply Patch, effective in real time.

Installation

Install it to the target profile (default web) using the dsh plugin command:

dsh plugin --profile web add @fonlan/dsh-apply-patch

You can also install it from GitHub (supports default branch or specified tag):

# 默认分支
dsh plugin --profile web add github:fonlan/dsh-apply-patch

# 指定 release tag
dsh plugin --profile web add github:fonlan/dsh-apply-patch#v0.1.0

Install from local source (for development):

pnpm build
dsh plugin --profile web add .

Note: After installation, the dsh web process must be restarted for changes to take effect.

Typical Usage

Models (especially GPT-series models) call apply_patch directly, just like in Codex. The tool returns a Codex-style summary:

*** Begin Patch
*** Update File: hello.py
@@
-print("hello")
+print("hello, world")
*** Add File: new.py
+x = 1
*** Delete File: old.py
*** End Patch

After execution, it returns:

Success. Updated the following files:
M /path/to/hello.py
A /path/to/new.py
D /path/to/old.py

Sandbox Notes

All changes are executed through DSH’s built-in sandbox, with the following policies:

Operation Sandbox Path Description
Add / Update / Move writes ctx.fs.writeText Follows the session sandbox mode and workspace root
Delete / Move original file deletion ctx.shell Follows the same policy
  • In read-only mode, any write is denied by the sandbox and returns [sandbox: file access denied under read-only mode].
  • In workspace-write mode, only writes to the workspace root (and /tmp if allowed by the sandbox policy) are permitted.
  • The observation policy requires reading before writing, and the tool automatically completes the stat/read/observe/write flow internally.

Configuration

In the DSH UI, go to Settings → Plugins → Plugin Configuration → Apply Patch to configure the injection policy:
* Off: Do not inject apply_patch at all.
* GPT models only (default): Inject only for models whose model ID starts with gpt-.
* All models: Inject for all models.

Configuration changes take effect in real time through the settings card, without restarting the process.

Summary

The dsh-apply-patch plugin resolves errors caused by the missing tool for GPT-series models in the DSH environment. It not only provides a patch format consistent with Codex, but also ensures operational safety through DSH’s native sandbox mechanism. It is suitable for agent developers who need to use GPT models in DSH for file operations.

Plugin source code and documentation: https://github.com/fonlan/dsh-apply-patch