Skip to content

feat(telemetry): qualify installation usage and runtime clocks - #5477

Merged
huangruiteng merged 4 commits into
mainfrom
codex/telemetry-local-clocks-20261002
Oct 2, 2026
Merged

huangruiteng merged 4 commits into
mainfrom
codex/telemetry-local-clocks-20261002

Conversation

@huangruiteng

@huangruiteng huangruiteng commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Outcome and boundary

Installation-level feature use was unavailable from ID-free summaries, and numeric Codex provider timestamps could omit completed runtime or include delayed token recording. Extend the existing TypeScript usage-statistics owner with truthful, bounded daily installation profiles and a voluntary device setting; Python, Workspace and collector remain adapters.

  • Union observed intervals across Goals separately for quota_cycle, codex_turn and host_call, split UTC days and floor after union. Missing or unfinished work stays unobserved; these clocks cannot be added or interpreted as uptime, completion or billing.
  • Persist voluntary context through CLI and packaged Workspace. Environment override wins; labeling never enables statistics, changes installation identity or relabels daily history. One pure shared vocabulary and typed input rejection keep the browser/CLI/HTTP contract aligned.
  • Use completed/aborted numeric or ISO provider envelopes, removing delayed token-prefix extrapolation.
  • Renew disclosure to notice 6 and retain CI/DNT/disable/consent-required/generation fences for every new channel. Disable clears local ID, counts and measurement history while retaining the voluntary label; already-sent data cannot be recalled.
  • Add fixed /v1/installation snapshots and additive D1 migration 0005; higher revisions replace counts, never accumulate snapshots. Retain existing endpoints and ID-free aggregates. Linked rows remain operator-only.

Validation at final head

134 Python and 81 TypeScript/client/collector tests pass, including real CLI/HTTP, HTTP-to-SQLite SQL, independent immutable numeric-timing comparison, UTC endpoint sweep, replay/restart, suppression/generation races and invalid input/corrupt-store no-effects. Canonical packaged Workspace build and actual browser context-save/reload/readback pass with sending disabled. Control-plane types, Ruff, semantic advisory, diff hygiene and public-boundary scan pass; the existing large-chunk build warning remains. Native premerge executes all 19 selected checks and five direct checks successfully, with no failures, skips or manual holds; exact-scope quality is valid. PR CI was not queried under the configured review policy.

Release sequencing and rollback

Before notice-6 client publication: back up D1, apply 0005 once, then deploy the compatible Worker. No historical backfill or old-table deletion. Worker/client rollback keeps the additive table and old endpoints. This code review does not claim production deployment, complete historical measurement, an installed cross-day rollout or a protected dashboard; those remain existing release/rollout acceptance work.

Author: model_agent, OpenAI Codex. Review/refinement and merge were explicitly authorized by the owner.

@huangruiteng
huangruiteng requested a review from maxliux5 as a code owner October 2, 2026 15:10
@huangruiteng
huangruiteng force-pushed the codex/telemetry-local-clocks-20261002 branch from 3a2cd79 to 9da078e Compare October 2, 2026 15:51

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; GPT-6; OpenAI; runtime_reported

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

APPROVE at exact head 9da078e7397c8fce4ce4a3896ed5b76e632c9a79, base 3cecb0d7cbf3d247cfd996267d7fc64627bd6e49. Owner explicitly authorized review, refinement and merge before release. No blocking findings remain.

动机

既有 ID-free 汇总不能回答安装级功能使用;真实已完成 Codex Turn 的数值 provider 时间可能漏计,延迟 token 记录又可能夸大时长。依照不可变基准 3cecb0d7cbf3d247cfd996267d7fc64627bd6e49 的 docs/reference/usage-ping.md 的告知、隐私和独立计时契约,修复统计真实性和可操作设置,不把安装标识当人、把活动跨度当在线或把统计当执行权。

契约逐项映射:Usage-disclosure 覆盖重新告知和所有抑制;Usage-fixed-fields 覆盖固定字段/无内容边界;Usage-independent-clocks 覆盖部分观测和三个独立计时,均由上述实际入口和独立回归验证。

改动思路

扩展既有 TypeScript usage-statistics owner,Python/Workspace/collector 保持适配器。沿用 consent、generation、锁与固定诊断 family;新增受限的安装级每日概要。三个计时口径各自跨 Goal 求并集、UTC 拆日、累计后向下取整,不能相加。仅完成/中止包络定义 Codex 轮次;去掉 token prefix/confirmed 推断,无 watchdog、补账或历史回填。

具体改动

关键代码讲解

configureContext 保存自愿设备标签,环境变量优先,修改标签不启用统计、不换标识、不改历史日标签。此次 refine 将场景词表收回现有纯 usage_statistics_contract.ts:前端选项直接复用;CLI/HTTP 由 TS 统一验证,类型化 input error 保留 HTTP400/CLI2,而损坏 store 保持503且不覆盖。diagnostics 保留既有 CONTEXTS export,兼容现有消费者;有效选项、页面布局和既有已批准文案未改。

recordInstallation 消费现有完成区间,分别合并三种口径,并限制缓存、行数、载荷和保留窗口。每天版本/标签固定;更高 revision 的全量 snapshot 替换计数,不叠加。缺观测是未知,重放、乱序和跨日不凭空增长。

readCodexTiming 支持有限 Unix 秒和历史 ISO 字段;任务未结束或仅有 token 记录不产生时长。独立相同合成329秒已结束包络,在不可变基线遗漏、当前 head 正确329000ms,65秒 recorder 延迟不会算入。

Collector handle/固定校验、增量迁移0005与查询模板支持 /v1/installation。既有 v0/v1、ID-free counters 保留;linked rows 仅供授权 D1/受保护 operator 使用,不加入公开 per-ID 列表。SQL 模板不是已上线看板。

Notice 升为6:关联随机安装标识、固定 family、版本、UTC 日期、自愿标签和已观测分钟的范围有明确中英告知。原 CI、DNT、禁用、consent-required 和 generation fences覆盖所有新通道;标签不是 consent/工作权。关闭删除本地 ID/计数/测量历史,保留自愿标签,无法撤回已发送内容。

语义与验证

28个公开源码、文档与回归文件;未包含私人状态或原始运行记录。新增 profile 是既有 optional usage capability 的版本化 transport,不新建能力或 Python 决策 owner。所有 family/measurement/context 采用固定类型和结构校验,没有新增 substring denylist 或 Goal-specific 强制义务。可选标签是指导,告知/抑制/校验是机器约束;默认变更已明确披露。

134项 Python、81项 TS/客户端/collector 测试通过,包括真实 CLI、HTTP→SQLite、独立端点扫描、UTC midnight/短区间/重放/重启、无效字段/体积、CI/DNT、关闭与 generation 并发。不可变 base/head 真实 CLI 比较证明旧版不接受 context,当前保存并保持 sending=false。最终 head control-plane typecheck、Ruff/diff/semantic 检查和 canonical packaged Chat 构建通过;既有大 chunk warning 保留。按 Goal 策略不查询 PR CI。

实际编译页面以隔离合成状态走「设置→能力中心→基础统计→用途」;选择 maintainer 后重载及独立 GET 均保存该值,仍关闭且无 payload。未启用外发,未改本机安装。整屏沿用原设置层级;可选选择直接保存,不增加确认或重填。负向真实设置验证 HTTP400、cross-origin403、损坏 store503/CLI invalid exit2,以及拒绝后状态字节不变。

对主干的风险

主要风险是告知范围扩展、旧 collector 尚未支持新 profile,以及混合计时被误解成 uptime。相同现有 consent/generation fence、独立三口径 oracle、严格 fixed schema、operator-only 范围及明确限制覆盖这些风险。既有聚合/公开接口保持;不可遗漏的上线顺序是备份 D1、应用 additive0005、部署 Worker,再发布 notice6 客户端。回滚客户端/Worker保留增量表,不 drop 既有数据。生产部署、实际跨天使用和保护看板没有在本 PR 本地验证中声称完成;属于既有发布/上线验收。

精确 scope quality 收据有效;风险预合并19/19检查全部执行通过,另5项直接检查通过;失败0、跳过0、人工hold0。全量最终 release qualification 仍在实际合入提交执行,不能用本 PR 局部通过代替。

我的整体评价

APPROVE:这是有真实误计证据、完整本地用户路径与严格隐私边界的可逆增量。未来修整已在当前 PR完成:单一 context 词表、TS 输入 owner和明确错误分类;未加泛化框架或第二份 consent 规则。当前用户明确授权自合并,仍须 unchanged-head published review、closeout 和 native merge-readiness ready 后才合入。Collector-first 部署是客户端发布条件,后续跨天 readback保持原任务,不因代码合并而关闭。

English verdict: APPROVE - exact head 9da078e. Existing typed usage-statistics ownership now provides truthful bounded installation profiles and completed numeric timing; context validation is single-sourced without enabling telemetry. 134 Python and81 TypeScript/client/real HTTP-SQLite cases, independent immutable baseline comparison, packaged browser persistence, canonical build and static checks pass. Collector migration/deployment precedes client release; production cross-day rollout is not claimed complete.

… clocks

Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
@huangruiteng
huangruiteng force-pushed the codex/telemetry-local-clocks-20261002 branch from 9da078e to c1e0abe Compare October 2, 2026 16:08

@huangruiteng huangruiteng left a comment

Copy link
Copy Markdown
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewer: model_agent; GPT-6; OpenAI; runtime_reported

Approval conclusion (author-owned PR; GitHub blocks formal self-approval)

APPROVE at exact head c1e0abe179b8595eb9db1cae8ecf5d02f418dcf7, base 0e7e34fdec6ff1ca175f48f072a152adf16890ff. Owner explicitly authorized review, refinement and merge before release. No blocking findings remain.

动机

既有 ID-free 汇总不能回答安装级功能使用;真实已完成 Codex Turn 的数值 provider 时间可能漏计,延迟 token 记录又可能夸大时长。依照不可变基准 0e7e34fdec6ff1ca175f48f072a152adf16890ff 的 docs/reference/usage-ping.md 的告知、隐私和独立计时契约,修复统计真实性和可操作设置,不把安装标识当人、把活动跨度当在线或把统计当执行权。

契约逐项映射:Usage-disclosure 覆盖重新告知和所有抑制;Usage-fixed-fields 覆盖固定字段/无内容边界;Usage-independent-clocks 覆盖部分观测和三个独立计时,均由上述实际入口和独立回归验证。

改动思路

扩展既有 TypeScript usage-statistics owner,Python/Workspace/collector 保持适配器。沿用 consent、generation、锁与固定诊断 family;新增受限的安装级每日概要。三个计时口径各自跨 Goal 求并集、UTC 拆日、累计后向下取整,不能相加。仅完成/中止包络定义 Codex 轮次;去掉 token prefix/confirmed 推断,无 watchdog、补账或历史回填。

具体改动

关键代码讲解

configureContext 保存自愿设备标签,环境变量优先,修改标签不启用统计、不换标识、不改历史日标签。此次 refine 将场景词表收回现有纯 usage_statistics_contract.ts:前端选项直接复用;CLI/HTTP 由 TS 统一验证,类型化 input error 保留 HTTP400/CLI2,而损坏 store 保持503且不覆盖。diagnostics 保留既有 CONTEXTS export,兼容现有消费者;有效选项、页面布局和既有已批准文案未改。

recordInstallation 消费现有完成区间,分别合并三种口径,并限制缓存、行数、载荷和保留窗口。每天版本/标签固定;更高 revision 的全量 snapshot 替换计数,不叠加。缺观测是未知,重放、乱序和跨日不凭空增长。

readCodexTiming 支持有限 Unix 秒和历史 ISO 字段;任务未结束或仅有 token 记录不产生时长。独立相同合成329秒已结束包络,在不可变基线遗漏、当前 head 正确329000ms,65秒 recorder 延迟不会算入。

Collector handle/固定校验、增量迁移0005与查询模板支持 /v1/installation。既有 v0/v1、ID-free counters 保留;linked rows 仅供授权 D1/受保护 operator 使用,不加入公开 per-ID 列表。SQL 模板不是已上线看板。

Notice 升为6:关联随机安装标识、固定 family、版本、UTC 日期、自愿标签和已观测分钟的范围有明确中英告知。原 CI、DNT、禁用、consent-required 和 generation fences覆盖所有新通道;标签不是 consent/工作权。关闭删除本地 ID/计数/测量历史,保留自愿标签,无法撤回已发送内容。

语义与验证

28个公开源码、文档与回归文件;未包含私人状态或原始运行记录。新增 profile 是既有 optional usage capability 的版本化 transport,不新建能力或 Python 决策 owner。所有 family/measurement/context 采用固定类型和结构校验,没有新增 substring denylist 或 Goal-specific 强制义务。可选标签是指导,告知/抑制/校验是机器约束;默认变更已明确披露。

134项 Python、81项 TS/客户端/collector 测试通过,包括真实 CLI、HTTP→SQLite、独立端点扫描、UTC midnight/短区间/重放/重启、无效字段/体积、CI/DNT、关闭与 generation 并发。不可变 base/head 真实 CLI 比较证明旧版不接受 context,当前保存并保持 sending=false。最终 head control-plane typecheck、Ruff/diff/semantic 检查和 canonical packaged Chat 构建通过;既有大 chunk warning 保留。按 Goal 策略不查询 PR CI。

实际编译页面以隔离合成状态走「设置→能力中心→基础统计→用途」;选择 maintainer 后重载及独立 GET 均保存该值,仍关闭且无 payload。未启用外发,未改本机安装。整屏沿用原设置层级;可选选择直接保存,不增加确认或重填。负向真实设置验证 HTTP400、cross-origin403、损坏 store503/CLI invalid exit2,以及拒绝后状态字节不变。

对主干的风险

主要风险是告知范围扩展、旧 collector 尚未支持新 profile,以及混合计时被误解成 uptime。相同现有 consent/generation fence、独立三口径 oracle、严格 fixed schema、operator-only 范围及明确限制覆盖这些风险。既有聚合/公开接口保持;不可遗漏的上线顺序是备份 D1、应用 additive0005、部署 Worker,再发布 notice6 客户端。回滚客户端/Worker保留增量表,不 drop 既有数据。生产部署、实际跨天使用和保护看板没有在本 PR 本地验证中声称完成;属于既有发布/上线验收。

精确 scope quality 收据有效;风险预合并19/19检查全部执行通过,另5项直接检查通过;失败0、跳过0、人工hold0。全量最终 release qualification 仍在实际合入提交执行,不能用本 PR 局部通过代替。

我的整体评价

APPROVE:这是有真实误计证据、完整本地用户路径与严格隐私边界的可逆增量。未来修整已在当前 PR完成:单一 context 词表、TS 输入 owner和明确错误分类;未加泛化框架或第二份 consent 规则。当前用户明确授权自合并,仍须 unchanged-head published review、closeout 和 native merge-readiness ready 后才合入。Collector-first 部署是客户端发布条件,后续跨天 readback保持原任务,不因代码合并而关闭。

English verdict: APPROVE - exact head c1e0abe. Existing typed usage-statistics ownership now provides truthful bounded installation profiles and completed numeric timing; context validation is single-sourced without enabling telemetry. 134 Python and81 TypeScript/client/real HTTP-SQLite cases, independent immutable baseline comparison, packaged browser persistence, canonical build and static checks pass. Collector migration/deployment precedes client release; production cross-day rollout is not claimed complete.

@huangruiteng
huangruiteng merged commit 2fca4a9 into main Oct 2, 2026
7 checks passed
@huangruiteng
huangruiteng deleted the codex/telemetry-local-clocks-20261002 branch October 2, 2026 16:14
@huangruiteng

Copy link
Copy Markdown
Collaborator Author

Post-merge process correction for #5477

The final reviewed head c1e0abe179b8595eb9db1cae8ecf5d02f418dcf7 had a valid published whole-PR review, 134 Python/81 TypeScript-client-collector regressions, 19/19 native premerge checks and an exact-scope quality receipt. However, the immediate merge-readiness check returned ready=false, merge_state=BEHIND after #5354 advanced main. The shell sequence did not stop on that nonzero result and incorrectly invoked admin merge. This violated the native readiness gate; the merge itself is not evidence of readiness.

Root cause is execution orchestration, not a false native result. The correction is a fail-closed dispatcher: validate the successful exact-head readiness response in one checked process, then invoke merge only from its passing branch. Negative validation must prove that a false result or nonzero command cannot reach GitHub mutation. No instruction-only waiver or retroactive ready claim.

The merged commit is 2fca4a97fab7022cef6d98c4240a032a39dfee20. All 28 touched #5477 source files are byte-identical to the reviewed head; the additional integration is #5354 documentation/example delivery. Actual merged-source validation and the final release qualification will be repeated; production collector deployment and client publication remain held until that evidence passes. The failed premerge observation is retained.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant