Files
deepseek-harness/packages/session/user-id
imccyu 2c85c484d3 build(release): reference workspace members through the workspace protocol
1504 hand-written ranges pointing at workspace members become workspace:^, so
pnpm pack substitutes each member's real version at publication: sibling
peerDependencies follow the family version instead of being pinned at ^0.0.1,
and a reference to a vendored package follows that package's own line. Without
this, publishing 0.0.2 ships peer ranges naming a version that does not exist,
and 0.0.1-rc.1 does not satisfy ^0.0.1 either.

It also retires ranges that had gone stale against the workspace: ^4.0.0-rc.6
for a 4.0.0-rc.7 checkout, ^3.17.0 for schemastery 3.18.0.

workspace:* stays where an exact published version is the point, which is how
the Landlock entry pins its platform packages.

A workspace constraint now requires the protocol, so a new package cannot
reintroduce a hand-written range. The same constraint caught packages/boot/cmdline
arriving on master without the publishable trio, which this change completes.
2026-08-11 00:17:09 +08:00
..

@deepseek-ai/dsh-user-id

English | 中文

Shared anonymous identity for session telemetry and direct feedback acknowledgement. getOrCreateAnonymousUserId() returns a random UUID v4 scoped to one harness home, persisted as the bare line $DSH_HOME/.userid (~/.dsh/.userid when DSH_HOME is unset). The OpenTelemetry backend reports it as Resource user.id; /feedback includes the same value in its acknowledgement so an operator can correlate a submitted session and user with exported telemetry.

The identity is never derived from the hostname, network address, git remote, or another identifying source. Deleting .userid resets the identity on the next process launch. Separate harness homes have separate identities, and the dsh-sdk launcher telemetry intentionally keeps its own unrelated store.

Storage contract

Reads and writes are synchronous because both boot-time telemetry construction and direct command execution need one API. The result is memoized per resolved file path for the process lifetime. A first writer uses exclusive creation and a concurrent loser adopts the persisted winner; a corrupt file is replaced. Persistence is best-effort, so an unwritable home still receives a process-local UUID rather than blocking telemetry or feedback.

Composition

This package is a shared library, not a Cordis plugin. Consumers import getOrCreateAnonymousUserId() directly. Its invariant companion is intentionally empty because the package owns no event stream or public mutable relation that can be checked without creating the identity as a side effect.

Model Experience

None, as the identifier is used only in telemetry metadata and a direct human command response; it never enters a model request.

KV Cache effect

None; this package never contributes to a model request.

Known Limitations and Deferred Work

  • No recovery after deletion — loss mints a new anonymous identity by design; recovery would require stable derivation material that weakens anonymity.
  • Best-effort concurrency — a reader landing in the narrow interval between a concurrent process's exclusive create and completed write can use a different in-memory UUID for that run; later launches converge on the persisted value.
  • No cross-home identity — different $DSH_HOME values cannot be correlated, and this package does not unify the separate dsh-sdk launcher telemetry identity.