Files
deepseek-harness/packages/scaffold/telemetry/README.md
Chinesezjc ec236b273e fix(telemetry): freeze launcher consent before running a command
dsh-sdk resolved launcher telemetry consent in the finally block, after
startSDK had already loaded the project .env into process.env, so a
project file or project code could grant reporting of its own cordis.yml
and package.json. Freeze the decision from the launching environment
before dispatch and pass it to the reporter; an unsupported mode denies
instead of throwing because telemetry may never change a command result.
Configuration source ownership denies the whole DSH_* namespace to
discovered files, so the launcher must not read a mutated environment.
2026-08-11 14:48:02 +08:00

2.6 KiB

@deepseek-ai/dsh-telemetry

English | 中文

Launcher-side telemetry primitives for the dsh-sdk toolchain. This is a plain library the launcher imports around each command; it is not a Cordis plugin because build and first-init create never boot Cordis. Wiring the reporter into launcher command dispatch lives in its owning package.

Export Role
SecretRedactor Conservative safety backstop: replaces secret-shaped values (secret-like keys, known token shapes, PEM blocks, URL credentials, high-entropy opaque tokens) with a placeholder in both parsed values (redactValue) and raw text (redactText). Never drops a field or line.
resolveTelemetryConsent Reads the shared DSH_TELEMETRY_MODE; only FULL permits launcher reporting, while FEEDBACK_ONLY, DISABLED, unset, and empty values deny it.
buildTelemetryPayload Assembles {command, durationMs, success, cordisYmlContent, packageJsonContent}, running the redactor over the full cordis.yml and package.json text. Never reads .env; package.json ships only alongside a cordis.yml, so a command run in a non-SDK directory never uploads that directory's unrelated manifest.
getOrCreateAnonymousId Random UUID persisted in the harness home resolved by @deepseek-ai/dsh-paths ($DSH_HOME > ~/.dsh), scoped to that home rather than the machine, never derived from git.
TelemetryReporter Fire-and-forget send: report() never blocks or throws; delivery resolves on every path; flush() optionally drains in-flight sends within a cap.

DSH_TELEMETRY_MODE is the single positive consent setting for session and launcher telemetry. FULL enables this launcher feed; FEEDBACK_ONLY keeps command telemetry off and permits only feedback-triggered Session Log sharing; every other supported state keeps this feed off. Callers must resolve consent from the launching environment before running a command, because a command may load a project .env or mutate process.env; the launcher wiring in @deepseek-ai/dsh-scripts freezes the decision up front.

The collection endpoint is a fixed constant (DSH_TELEMETRY_ENDPOINT).

Model Experience

None, as the reporter sends developer-cycle telemetry from the launcher and never reaches a model request.

KV Cache effect

None; this package neither assembles nor sends a provider request.

Known Limitations and Deferred Work

  • Placeholder endpoint — DSH_TELEMETRY_ENDPOINT points at .invalid until the real endpoint is set.
  • Redaction is heuristic — a conservative backstop, not a guarantee; secrets belong in .env, which is never read or reported.