feat(telemetry): qualify installation usage and runtime clocks - #5477
Conversation
3a2cd79 to
9da078e
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; GPT-6; OpenAI; runtime_reported
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
APPROVE at exact head 9da078e7397c8fce4ce4a3896ed5b76e632c9a79, base 3cecb0d7cbf3d247cfd996267d7fc64627bd6e49. Owner explicitly authorized review, refinement and merge before release. No blocking findings remain.
动机
既有 ID-free 汇总不能回答安装级功能使用;真实已完成 Codex Turn 的数值 provider 时间可能漏计,延迟 token 记录又可能夸大时长。依照不可变基准 3cecb0d7cbf3d247cfd996267d7fc64627bd6e49 的 docs/reference/usage-ping.md 的告知、隐私和独立计时契约,修复统计真实性和可操作设置,不把安装标识当人、把活动跨度当在线或把统计当执行权。
契约逐项映射:Usage-disclosure 覆盖重新告知和所有抑制;Usage-fixed-fields 覆盖固定字段/无内容边界;Usage-independent-clocks 覆盖部分观测和三个独立计时,均由上述实际入口和独立回归验证。
改动思路
扩展既有 TypeScript usage-statistics owner,Python/Workspace/collector 保持适配器。沿用 consent、generation、锁与固定诊断 family;新增受限的安装级每日概要。三个计时口径各自跨 Goal 求并集、UTC 拆日、累计后向下取整,不能相加。仅完成/中止包络定义 Codex 轮次;去掉 token prefix/confirmed 推断,无 watchdog、补账或历史回填。
具体改动
关键代码讲解
configureContext 保存自愿设备标签,环境变量优先,修改标签不启用统计、不换标识、不改历史日标签。此次 refine 将场景词表收回现有纯 usage_statistics_contract.ts:前端选项直接复用;CLI/HTTP 由 TS 统一验证,类型化 input error 保留 HTTP400/CLI2,而损坏 store 保持503且不覆盖。diagnostics 保留既有 CONTEXTS export,兼容现有消费者;有效选项、页面布局和既有已批准文案未改。
recordInstallation 消费现有完成区间,分别合并三种口径,并限制缓存、行数、载荷和保留窗口。每天版本/标签固定;更高 revision 的全量 snapshot 替换计数,不叠加。缺观测是未知,重放、乱序和跨日不凭空增长。
readCodexTiming 支持有限 Unix 秒和历史 ISO 字段;任务未结束或仅有 token 记录不产生时长。独立相同合成329秒已结束包络,在不可变基线遗漏、当前 head 正确329000ms,65秒 recorder 延迟不会算入。
Collector handle/固定校验、增量迁移0005与查询模板支持 /v1/installation。既有 v0/v1、ID-free counters 保留;linked rows 仅供授权 D1/受保护 operator 使用,不加入公开 per-ID 列表。SQL 模板不是已上线看板。
Notice 升为6:关联随机安装标识、固定 family、版本、UTC 日期、自愿标签和已观测分钟的范围有明确中英告知。原 CI、DNT、禁用、consent-required 和 generation fences覆盖所有新通道;标签不是 consent/工作权。关闭删除本地 ID/计数/测量历史,保留自愿标签,无法撤回已发送内容。
语义与验证
28个公开源码、文档与回归文件;未包含私人状态或原始运行记录。新增 profile 是既有 optional usage capability 的版本化 transport,不新建能力或 Python 决策 owner。所有 family/measurement/context 采用固定类型和结构校验,没有新增 substring denylist 或 Goal-specific 强制义务。可选标签是指导,告知/抑制/校验是机器约束;默认变更已明确披露。
134项 Python、81项 TS/客户端/collector 测试通过,包括真实 CLI、HTTP→SQLite、独立端点扫描、UTC midnight/短区间/重放/重启、无效字段/体积、CI/DNT、关闭与 generation 并发。不可变 base/head 真实 CLI 比较证明旧版不接受 context,当前保存并保持 sending=false。最终 head control-plane typecheck、Ruff/diff/semantic 检查和 canonical packaged Chat 构建通过;既有大 chunk warning 保留。按 Goal 策略不查询 PR CI。
实际编译页面以隔离合成状态走「设置→能力中心→基础统计→用途」;选择 maintainer 后重载及独立 GET 均保存该值,仍关闭且无 payload。未启用外发,未改本机安装。整屏沿用原设置层级;可选选择直接保存,不增加确认或重填。负向真实设置验证 HTTP400、cross-origin403、损坏 store503/CLI invalid exit2,以及拒绝后状态字节不变。
对主干的风险
主要风险是告知范围扩展、旧 collector 尚未支持新 profile,以及混合计时被误解成 uptime。相同现有 consent/generation fence、独立三口径 oracle、严格 fixed schema、operator-only 范围及明确限制覆盖这些风险。既有聚合/公开接口保持;不可遗漏的上线顺序是备份 D1、应用 additive0005、部署 Worker,再发布 notice6 客户端。回滚客户端/Worker保留增量表,不 drop 既有数据。生产部署、实际跨天使用和保护看板没有在本 PR 本地验证中声称完成;属于既有发布/上线验收。
精确 scope quality 收据有效;风险预合并19/19检查全部执行通过,另5项直接检查通过;失败0、跳过0、人工hold0。全量最终 release qualification 仍在实际合入提交执行,不能用本 PR 局部通过代替。
我的整体评价
APPROVE:这是有真实误计证据、完整本地用户路径与严格隐私边界的可逆增量。未来修整已在当前 PR完成:单一 context 词表、TS 输入 owner和明确错误分类;未加泛化框架或第二份 consent 规则。当前用户明确授权自合并,仍须 unchanged-head published review、closeout 和 native merge-readiness ready 后才合入。Collector-first 部署是客户端发布条件,后续跨天 readback保持原任务,不因代码合并而关闭。
English verdict: APPROVE - exact head 9da078e. Existing typed usage-statistics ownership now provides truthful bounded installation profiles and completed numeric timing; context validation is single-sourced without enabling telemetry. 134 Python and81 TypeScript/client/real HTTP-SQLite cases, independent immutable baseline comparison, packaged browser persistence, canonical build and static checks pass. Collector migration/deployment precedes client release; production cross-day rollout is not claimed complete.
… clocks Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
Signed-off-by: huangruiteng <huangrt01@163.com>
9da078e to
c1e0abe
Compare
huangruiteng
left a comment
There was a problem hiding this comment.
Reviewer: model_agent; GPT-6; OpenAI; runtime_reported
Approval conclusion (author-owned PR; GitHub blocks formal self-approval)
APPROVE at exact head c1e0abe179b8595eb9db1cae8ecf5d02f418dcf7, base 0e7e34fdec6ff1ca175f48f072a152adf16890ff. Owner explicitly authorized review, refinement and merge before release. No blocking findings remain.
动机
既有 ID-free 汇总不能回答安装级功能使用;真实已完成 Codex Turn 的数值 provider 时间可能漏计,延迟 token 记录又可能夸大时长。依照不可变基准 0e7e34fdec6ff1ca175f48f072a152adf16890ff 的 docs/reference/usage-ping.md 的告知、隐私和独立计时契约,修复统计真实性和可操作设置,不把安装标识当人、把活动跨度当在线或把统计当执行权。
契约逐项映射:Usage-disclosure 覆盖重新告知和所有抑制;Usage-fixed-fields 覆盖固定字段/无内容边界;Usage-independent-clocks 覆盖部分观测和三个独立计时,均由上述实际入口和独立回归验证。
改动思路
扩展既有 TypeScript usage-statistics owner,Python/Workspace/collector 保持适配器。沿用 consent、generation、锁与固定诊断 family;新增受限的安装级每日概要。三个计时口径各自跨 Goal 求并集、UTC 拆日、累计后向下取整,不能相加。仅完成/中止包络定义 Codex 轮次;去掉 token prefix/confirmed 推断,无 watchdog、补账或历史回填。
具体改动
关键代码讲解
configureContext 保存自愿设备标签,环境变量优先,修改标签不启用统计、不换标识、不改历史日标签。此次 refine 将场景词表收回现有纯 usage_statistics_contract.ts:前端选项直接复用;CLI/HTTP 由 TS 统一验证,类型化 input error 保留 HTTP400/CLI2,而损坏 store 保持503且不覆盖。diagnostics 保留既有 CONTEXTS export,兼容现有消费者;有效选项、页面布局和既有已批准文案未改。
recordInstallation 消费现有完成区间,分别合并三种口径,并限制缓存、行数、载荷和保留窗口。每天版本/标签固定;更高 revision 的全量 snapshot 替换计数,不叠加。缺观测是未知,重放、乱序和跨日不凭空增长。
readCodexTiming 支持有限 Unix 秒和历史 ISO 字段;任务未结束或仅有 token 记录不产生时长。独立相同合成329秒已结束包络,在不可变基线遗漏、当前 head 正确329000ms,65秒 recorder 延迟不会算入。
Collector handle/固定校验、增量迁移0005与查询模板支持 /v1/installation。既有 v0/v1、ID-free counters 保留;linked rows 仅供授权 D1/受保护 operator 使用,不加入公开 per-ID 列表。SQL 模板不是已上线看板。
Notice 升为6:关联随机安装标识、固定 family、版本、UTC 日期、自愿标签和已观测分钟的范围有明确中英告知。原 CI、DNT、禁用、consent-required 和 generation fences覆盖所有新通道;标签不是 consent/工作权。关闭删除本地 ID/计数/测量历史,保留自愿标签,无法撤回已发送内容。
语义与验证
28个公开源码、文档与回归文件;未包含私人状态或原始运行记录。新增 profile 是既有 optional usage capability 的版本化 transport,不新建能力或 Python 决策 owner。所有 family/measurement/context 采用固定类型和结构校验,没有新增 substring denylist 或 Goal-specific 强制义务。可选标签是指导,告知/抑制/校验是机器约束;默认变更已明确披露。
134项 Python、81项 TS/客户端/collector 测试通过,包括真实 CLI、HTTP→SQLite、独立端点扫描、UTC midnight/短区间/重放/重启、无效字段/体积、CI/DNT、关闭与 generation 并发。不可变 base/head 真实 CLI 比较证明旧版不接受 context,当前保存并保持 sending=false。最终 head control-plane typecheck、Ruff/diff/semantic 检查和 canonical packaged Chat 构建通过;既有大 chunk warning 保留。按 Goal 策略不查询 PR CI。
实际编译页面以隔离合成状态走「设置→能力中心→基础统计→用途」;选择 maintainer 后重载及独立 GET 均保存该值,仍关闭且无 payload。未启用外发,未改本机安装。整屏沿用原设置层级;可选选择直接保存,不增加确认或重填。负向真实设置验证 HTTP400、cross-origin403、损坏 store503/CLI invalid exit2,以及拒绝后状态字节不变。
对主干的风险
主要风险是告知范围扩展、旧 collector 尚未支持新 profile,以及混合计时被误解成 uptime。相同现有 consent/generation fence、独立三口径 oracle、严格 fixed schema、operator-only 范围及明确限制覆盖这些风险。既有聚合/公开接口保持;不可遗漏的上线顺序是备份 D1、应用 additive0005、部署 Worker,再发布 notice6 客户端。回滚客户端/Worker保留增量表,不 drop 既有数据。生产部署、实际跨天使用和保护看板没有在本 PR 本地验证中声称完成;属于既有发布/上线验收。
精确 scope quality 收据有效;风险预合并19/19检查全部执行通过,另5项直接检查通过;失败0、跳过0、人工hold0。全量最终 release qualification 仍在实际合入提交执行,不能用本 PR 局部通过代替。
我的整体评价
APPROVE:这是有真实误计证据、完整本地用户路径与严格隐私边界的可逆增量。未来修整已在当前 PR完成:单一 context 词表、TS 输入 owner和明确错误分类;未加泛化框架或第二份 consent 规则。当前用户明确授权自合并,仍须 unchanged-head published review、closeout 和 native merge-readiness ready 后才合入。Collector-first 部署是客户端发布条件,后续跨天 readback保持原任务,不因代码合并而关闭。
English verdict: APPROVE - exact head c1e0abe. Existing typed usage-statistics ownership now provides truthful bounded installation profiles and completed numeric timing; context validation is single-sourced without enabling telemetry. 134 Python and81 TypeScript/client/real HTTP-SQLite cases, independent immutable baseline comparison, packaged browser persistence, canonical build and static checks pass. Collector migration/deployment precedes client release; production cross-day rollout is not claimed complete.
|
Post-merge process correction for #5477 The final reviewed head Root cause is execution orchestration, not a false native result. The correction is a fail-closed dispatcher: validate the successful exact-head readiness response in one checked process, then invoke merge only from its passing branch. Negative validation must prove that a false result or nonzero command cannot reach GitHub mutation. No instruction-only waiver or retroactive ready claim. The merged commit is |
Outcome and boundary
Installation-level feature use was unavailable from ID-free summaries, and numeric Codex provider timestamps could omit completed runtime or include delayed token recording. Extend the existing TypeScript usage-statistics owner with truthful, bounded daily installation profiles and a voluntary device setting; Python, Workspace and collector remain adapters.
quota_cycle,codex_turnandhost_call, split UTC days and floor after union. Missing or unfinished work stays unobserved; these clocks cannot be added or interpreted as uptime, completion or billing./v1/installationsnapshots and additive D1 migration0005; higher revisions replace counts, never accumulate snapshots. Retain existing endpoints and ID-free aggregates. Linked rows remain operator-only.Validation at final head
134 Python and 81 TypeScript/client/collector tests pass, including real CLI/HTTP, HTTP-to-SQLite SQL, independent immutable numeric-timing comparison, UTC endpoint sweep, replay/restart, suppression/generation races and invalid input/corrupt-store no-effects. Canonical packaged Workspace build and actual browser context-save/reload/readback pass with sending disabled. Control-plane types, Ruff, semantic advisory, diff hygiene and public-boundary scan pass; the existing large-chunk build warning remains. Native premerge executes all 19 selected checks and five direct checks successfully, with no failures, skips or manual holds; exact-scope quality is valid. PR CI was not queried under the configured review policy.
Release sequencing and rollback
Before notice-6 client publication: back up D1, apply
0005once, then deploy the compatible Worker. No historical backfill or old-table deletion. Worker/client rollback keeps the additive table and old endpoints. This code review does not claim production deployment, complete historical measurement, an installed cross-day rollout or a protected dashboard; those remain existing release/rollout acceptance work.Author: model_agent, OpenAI Codex. Review/refinement and merge were explicitly authorized by the owner.