Files
deepseek-harness/packages/scaffold/telemetry/README.md
Tianyi Cui 3fc35c91ff refactor(packages): dissolve ui/ and rename sdk/ to scaffold/
git mv per the regrouping RFC: the five human-collaboration seams and
tui join packages/interaction/, app-boot becomes packages/boot/, and
jsonrpc joins the renamed scaffold/ (formerly sdk/) as its server half
beside client/protocol/create-sdk/helper/scripts/telemetry, whose
folders drop the legacy sdk- prefix. Three new group README triplets
replace the ui/ and sdk/ ones; tsconfig references/paths/globs,
knip keys, vitest globs, gate scripts, catalogs, docs, and the
lockfile follow. Adds the four settled FIXME rename markers
(dsh-sdk-server, dsh-sdk-telemetry, dsh-sdk-helper, dsh-sdk-scripts).

The scaffold folders diverge from their npm names until those renames
land, so tsconfig.base.json maps the three affected names explicitly
beside the group wildcard. Also repairs two pre-existing stale-path
classes the strengthened sweep surfaced: docs/web-styling.md's retired
web-ui host package and type-model spec fixture-literal joins.

app-boot's three Loader-composition specs time out at the default 5s
under full-suite parallel load on this filesystem (pre-existing;
pass isolated with --testTimeout=30000); interaction/scaffold/boot
suites otherwise green (687 passed).
2026-08-09 01:21:12 +08:00

2.7 KiB

@deepseek-ai/dsh-telemetry

English | 中文

Launcher-side telemetry primitives for the dsh-sdk toolchain. This is a plain library the launcher imports around each command; it is not a Cordis plugin, because build and first-init create never boot Cordis. Wiring the reporter into the launcher command dispatch and adding the telemetry consent feature to the dsh-helper catalog live in their owning packages, not here.

Export Role
SecretRedactor Conservative safety backstop: replaces secret-shaped values (secret-like keys, known token shapes, PEM blocks, URL credentials, high-entropy opaque tokens) with a placeholder in both parsed values (redactValue) and raw text (redactText). Never drops a field or line.
ConsentResolver Parses (never boots) a project cordis.yml and reads the telemetry entry's enabled/disabled state as consent; DO_NOT_TRACK/CI env force a hard opt-out.
buildTelemetryPayload Assembles {command, durationMs, success, cordisYmlContent, packageJsonContent}, running the redactor over the full cordis.yml and package.json text. Never reads .env; package.json ships only alongside a cordis.yml, so a command run in a non-SDK directory never uploads that directory's unrelated manifest.
getOrCreateAnonymousId Random UUID persisted in the harness home resolved by @deepseek-ai/dsh-paths ($DSH_HOME > ~/.dsh), scoped to that home rather than the machine, never derived from git.
TelemetryReporter Fire-and-forget send: report() never blocks or throws; delivery resolves on every path; flush() optionally drains in-flight sends within a cap.

Consent is carried by the telemetry entry in cordis.yml, so disabling telemetry is disabling that entry. Telemetry reports by default and is off only when a present telemetry entry is explicitly disabled: a missing cordis.yml (first create), an enabled entry, or a cordis.yml with no telemetry entry all report. DO_NOT_TRACK/CI always deny. The no-config and absent-entry defaults are configurable on ConsentResolver.

The collection endpoint is a fixed constant (DSH_TELEMETRY_ENDPOINT); its fail-safe .invalid placeholder must be replaced with the real endpoint before release.

Model Experience

None, as the reporter sends developer-cycle telemetry from the launcher and never reaches a model request.

KV Cache effect

None; this package neither assembles nor sends a provider request.

Known Limitations and Deferred Work

  • Placeholder endpointDSH_TELEMETRY_ENDPOINT points at .invalid until the real endpoint is set.
  • Redaction is heuristic — a conservative backstop, not a guarantee; secrets belong in .env, which is never read or reported.