44c6a07ddf
Findings from an independent review of this branch. The exit-time flush was gated by its own cooldown. beforeExit called the same flush() that opens with a retryNotBefore check, so after any failed delivery a process exiting inside the 2s to 60s window sent nothing and the queue died with it. That is precisely the loss this branch exists to stop, and timer.unref makes beforeExit often the only remaining chance. flush(force) now skips the cooldown and beforeExit passes it. Overflow kept the newest and evicted the batch being retried, which threw away exactly the events the retry exists to save. Both the failure path and capture() now keep the backlog and drop the new event instead, matching Python's record(), which refuses new events once the spool is full. That change needs a bound, so delivery now gives up after five attempts, as the Python core does. Without one a payload the server will never accept would be retried for the whole session and, with the backlog now preferred, would hold the queue against everything behind it. Events carry a capture-time timestamp. They now sit through backoff and across an entire outage, so without one PostHog records them at whatever moment delivery happened to succeed. It also matters for the uuid dedupe, whose key includes the event date. openclaw wiped a resolved account on any capture without an apiKey: the fingerprint comparison was `undefined === ""`, so a keyless call looked like a key change. Guarded on a real key being present. Masked today because every call site supplies one, which is why only a test found it. Two smaller ones. opencode's PostHog source was "plugin", which named no particular plugin and matched no vocabulary; it is now OPENCODE_PLUGIN like every other surface, and a saved insight filtering source = "plugin" needs repointing. And an em dash in opencode's published description had been rewritten to a — escape by my own json.dumps when adding the test script; restored. One openclaw test asserted only not.toThrow() under a name claiming it checked the identity, and under the fingerprint gate the path it exercised no longer uses the email at all. It now pins the real condition. core 35, openclaw 432, opencode 35, pi-agent 89, deepseek 47. The wire e2e still passes 9 of 9 against a real local server, and the identity e2e 7 of 7. Claude-Session: https://claude.ai/code/session_01C7tEmH86HAr7GoAAKCEHZb
84 lines
2.9 KiB
TypeScript
84 lines
2.9 KiB
TypeScript
import { createHash } from "node:crypto";
|
|
import { readFileSync } from "node:fs";
|
|
import { release } from "node:os";
|
|
|
|
import {
|
|
createTelemetry,
|
|
isTelemetryEnabled,
|
|
} from "../agent-plugin-core/typescript/src/telemetry.ts";
|
|
|
|
export { isTelemetryEnabled };
|
|
|
|
const POSTHOG_API_KEY = "phc_hgJkUVJFYtmaJqrvf6CYN67TIQ8yhXAkWzUn9AMU4yX";
|
|
const PLUGIN_VERSION = (() => {
|
|
for (const relative of ["./package.json", "../package.json"]) {
|
|
try {
|
|
const pkg = JSON.parse(readFileSync(new URL(relative, import.meta.url), "utf-8"));
|
|
if (pkg?.name === "@mem0/opencode-plugin" && pkg.version) return pkg.version;
|
|
} catch {
|
|
// Try the source or bundled location.
|
|
}
|
|
}
|
|
return "unknown";
|
|
})();
|
|
|
|
let currentDistinctId = "";
|
|
const telemetry = createTelemetry({
|
|
host: "opencode",
|
|
// Shaped like the platform's EventSource values, as every other surface is.
|
|
// "plugin" said nothing about which plugin and matched no vocabulary.
|
|
source: "OPENCODE_PLUGIN",
|
|
version: PLUGIN_VERSION,
|
|
distinctId: () => currentDistinctId,
|
|
eventName: (event) => `plugin.${event}`,
|
|
commonProperties: {
|
|
platform: "opencode",
|
|
os_version: release(),
|
|
sample_rate: 1.0,
|
|
},
|
|
});
|
|
|
|
function distinctId(apiKey: string): string {
|
|
return createHash("sha256").update(apiKey).digest("hex").slice(0, 32);
|
|
}
|
|
|
|
/**
|
|
* Salted so the hash is not enumerable.
|
|
*
|
|
* An unsalted SHA-256 of a project id is reversible by anyone who can guess the
|
|
* id, which for a project identifier is a small space. The API key is the salt:
|
|
* it is already in play here (distinctId is a digest of it), it is high entropy,
|
|
* and using it needs no per-install file and so no write race to get wrong. The
|
|
* hash is therefore per account rather than per machine, which also keeps joins
|
|
* working for one user across machines. It resets when the key rotates, which is
|
|
* consistent, because distinctId resets with it.
|
|
*
|
|
* Both are omitted without a key. An event cannot be built without a distinctId
|
|
* anyway, so this costs nothing.
|
|
*/
|
|
function projectHash(projectId?: string, apiKey?: string): Record<string, string> {
|
|
if (!projectId || !apiKey) return {};
|
|
return { project_hash: createHash("sha256").update(`${apiKey}:${projectId}`).digest("hex") };
|
|
}
|
|
|
|
export function buildEvent(
|
|
eventType: string,
|
|
properties: Record<string, unknown>,
|
|
apiKey: string | undefined,
|
|
projectId?: string,
|
|
): Record<string, unknown> | null {
|
|
currentDistinctId = apiKey ? distinctId(apiKey) : "";
|
|
const event = telemetry.build(eventType, { ...properties, ...projectHash(projectId, apiKey) });
|
|
return event ? { api_key: POSTHOG_API_KEY, ...event } : null;
|
|
}
|
|
|
|
export function captureEvent(
|
|
eventType: string,
|
|
properties: Record<string, unknown>,
|
|
apiKey: string | undefined,
|
|
projectId?: string,
|
|
): void {
|
|
currentDistinctId = apiKey ? distinctId(apiKey) : "";
|
|
telemetry.capture(eventType, { ...properties, ...projectHash(projectId, apiKey) });
|
|
}
|