Files
deepseek-harness/packages/session/user-id
imccyu ec601ca13d build(vendor): rescope the vendored Cordis packages into @deepseek-ai
Machine-produced by `pnpm run rescope-vendor --apply` plus the regeneration it
prints: `pnpm install` for the lockfile, `pnpm run gen-third-party-notices`,
`verify-translation-pairing --write` for the touched bilingual pairs,
`gen-doc-graphs`, and one typert snapshot whose ids embed character offsets.
`pnpm run rescope-vendor --check` verifies the result.

Renames nine vendored packages (cordis, cosmokit, schemastery and the six
@cordisjs plugins) and every reference that resolves them: manifest names and
dependency keys, module specifiers including declare-module merges, cordis.yml
plugin names, tsconfig paths, every Markdown fence, and `docs/` prose.
Directory names, upstream versions, and dependency ranges are unchanged, so
vendor/README.md still reads as an upstream snapshot; its manifest table gains
an upstream-name column so THIRD_PARTY_NOTICES keeps MIT attribution pointed
at each fork's origin.

The tutorial tier follows the rename end to end: its yaml fences named plugins
the Loader can no longer resolve, its `ts ignore-check` fences disagreed with
the compiled fences beside them, and its prose quoted both. The contracts that
told readers to keep upstream names — the root convention and the vendoring
cookbook's tree comment and manifest invariant — now say to rescope instead.

Two rules read `@deepseek-ai/` as "another workspace plugin": the client bundle
purity gate now names the vendored libraries a browser bundle inlines, and the
files where a bare `cordis` is an agent-preset id keep that product data.
2026-08-10 22:04:13 +08:00
..

@deepseek-ai/dsh-user-id

English | 中文

Shared anonymous identity for session telemetry and direct feedback acknowledgement. getOrCreateAnonymousUserId() returns a random UUID v4 scoped to one harness home, persisted as the bare line $DSH_HOME/.userid (~/.dsh/.userid when DSH_HOME is unset). The OpenTelemetry backend reports it as Resource user.id; /feedback includes the same value in its acknowledgement so an operator can correlate a submitted session and user with exported telemetry.

The identity is never derived from the hostname, network address, git remote, or another identifying source. Deleting .userid resets the identity on the next process launch. Separate harness homes have separate identities, and the dsh-sdk launcher telemetry intentionally keeps its own unrelated store.

Storage contract

Reads and writes are synchronous because both boot-time telemetry construction and direct command execution need one API. The result is memoized per resolved file path for the process lifetime. A first writer uses exclusive creation and a concurrent loser adopts the persisted winner; a corrupt file is replaced. Persistence is best-effort, so an unwritable home still receives a process-local UUID rather than blocking telemetry or feedback.

Composition

This package is a shared library, not a Cordis plugin. Consumers import getOrCreateAnonymousUserId() directly. Its invariant companion is intentionally empty because the package owns no event stream or public mutable relation that can be checked without creating the identity as a side effect.

Model Experience

None, as the identifier is used only in telemetry metadata and a direct human command response; it never enters a model request.

KV Cache effect

None; this package never contributes to a model request.

Known Limitations and Deferred Work

  • No recovery after deletion — loss mints a new anonymous identity by design; recovery would require stable derivation material that weakens anonymity.
  • Best-effort concurrency — a reader landing in the narrow interval between a concurrent process's exclusive create and completed write can use a different in-memory UUID for that run; later launches converge on the persisted value.
  • No cross-home identity — different $DSH_HOME values cannot be correlated, and this package does not unify the separate dsh-sdk launcher telemetry identity.