Skip to content

README: make the collected-data list match what is sent - #23

Merged
mattpodwysocki merged 1 commit into
mainfrom
readme-telemetry-list
Sep 15, 2026
Merged

mattpodwysocki merged 1 commit into
mainfrom
readme-telemetry-list

Conversation

@mattpodwysocki

Copy link
Copy Markdown
Contributor

Follow-up to #17. Three mismatches between the Privacy section's collected-data list and telemetry::telemetry_markers, which is the whole of what goes out:

let mut markers = vec![os_marker(), arch_marker()];
markers.extend(ci_marker());
markers.extend(agent_detect::detect_agent().map(|a| format!("agent/{a}")));
markers.push(terminal_marker());
if let Some(group) = command_group { markers.push(format!("command/{group}")); }

Terminal state was collected and not disclosed — the direction that matters. terminal_marker() sends stdin_tty/… stdout_tty/… on every request; the list didn't mention it. The docs.mapbox.com page does, so the two disclosures disagreed and this was the one that under-stated.

Exit codes aren't collected. The User-Agent is assembled before a command runs, so there's no exit code in existence to send — nothing in telemetry.rs or http.rs reads one.

It's the service, not the command name. The marker is set in exactly one place — http::client_for(Some(op.service.as_str())) in executor::dispatch — so the value is styles or geocoder, never styles list. The old example was auth login, which is the one thing that can't appear: auth is hand-written rather than generated, never reaches dispatch, and uses client_for(None).

The new phrasing keeps that distinction rather than just deleting the wrong words, because the distinction is the reassuring part — which service was used, never the operation or its arguments.

Scope

Only that one sentence changed. Retention, third-party access, what we don't collect and the opt-out are all byte-identical — I checked by splitting the section into sentences with whitespace collapsed and diffing the sets, rather than by eye:

sentences removed: 1 (the What We Collect bullet)
sentences added:   1 (its replacement)

Some lines rewrap around the edit; no other wording moves. That was deliberate: the surrounding text reads like reviewed copy, so this sticks to claims that can be checked against the code.

Worth considering separately

Nothing stops this drifting again — the list is prose and the markers are code. A blunt guard in the spirit of tests/source_guards.rs would catch it: assert the number of markers telemetry_markers can emit, so adding one fails a test that names the README as the thing to update. Happy to add it if you want; it's a different kind of change from this one.

Three mismatches between the Privacy section's list and
`telemetry::telemetry_markers`, which is the whole of what goes out:

    let mut markers = vec![os_marker(), arch_marker()];
    markers.extend(ci_marker());
    markers.extend(agent_detect::detect_agent().map(|a| format!("agent/{a}")));
    markers.push(terminal_marker());
    if let Some(group) = command_group { markers.push(format!("command/{group}")); }

**Terminal state was collected and not disclosed**, which is the direction
that matters. `terminal_marker()` sends `stdin_tty/… stdout_tty/…` on every
request and the list did not mention it. Added.

**Exit codes are not collected.** Removed. The User-Agent is assembled before
a command runs, so there is no exit code in existence to send — nothing in
`telemetry.rs` or `http.rs` reads one.

**It is the service, not the command name.** The marker is set in one place,
`http::client_for(Some(op.service.as_str()))` in `executor::dispatch`, so the
value is `styles` or `geocoder` — never `styles list`. The old example was
`auth login`, which is the one thing that cannot appear: `auth` is
hand-written rather than generated, never reaches `dispatch`, and uses
`client_for(None)`.

The corrected phrasing keeps the distinction rather than just deleting the
wrong words, because the distinction is the reassuring part: which service was
used, never the operation or its arguments.

Nothing else in the section is touched. Retention, third-party access, what we
do not collect and the opt-out are byte-identical — checked by comparing the
section sentence by sentence with whitespace collapsed, not by eye. Some lines
rewrap around the edit; no other wording moves.
@mattpodwysocki
mattpodwysocki requested a review from a team as a code owner September 15, 2026 17:01
@mattpodwysocki
mattpodwysocki merged commit f29e6b2 into main Sep 15, 2026
8 checks passed
@mattpodwysocki
mattpodwysocki deleted the readme-telemetry-list branch September 15, 2026 17:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants