Files
hermes-agent/hermes_cli
Ben Barclay 7ffd454df6 feat(telemetry): derive the transmitted install identity via keyed HMAC
Step 3 of the shared-metrics exporter.

The shared-metrics doc commits that a remote exporter 'must not reuse
the persistent local identifier by default'. install_id is therefore
never transmitted: each package carries
HMAC-SHA256(local-only rotation salt, install_id) instead.

Within a 30-day rotation window the value is stable, so distinct
installs remain countable — the first question the data has to answer.
Across windows it changes, bounding long-term linkability. The
derivation is one-way, so the service cannot recover install_id.

The salt lives in telemetry_state next to install_id, so removing the
shared-metrics directory resets both together and the documented reset
behaviour keeps working with no second cleanup path.

Rotation is deliberately not a bare 'age > interval' check: a clock
that jumps backwards must not read as an expired salt, and an
unparseable issued-at reissues instead of raising.

substitute_install_id replaces exactly one field and copies rather than
mutating, so payload schema evolution stays a sender-side concern.

Tests: 19, including that install_id never survives substitution, that
no other field changes, and — the property that keeps retries
contract-compliant — that a package rebuilt from a FROZEN derived id is
byte-stable across a salt rotation while a fresh derivation is not.
2026-08-26 15:41:18 +10:00
..
2026-08-21 05:16:27 -07:00
…