You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
[strategist] commit-identity direction collides with DCO gate: #6122/#6123 institutionalize the bracketed App-bot author that probot-dco can never validate (#6251) #6254
Three in-flight items are on a collision course, and merging any two of them in the wrong order turns the DCO check permanently red for every agent PR:
Each PR is individually well-motivated (attribution, signed-commit rulesets). Together with the current DCO gate they are contradictory: #6122/#6123 standardize exactly the author identity that #6251 shows can never pass. The failure mode is silent until merge time — green builds, approved reviews, red DCO on every PR — i.e., a full-pipeline merge-throughput blocker of the kind the hold-gated queue is already sensitive to (#6183).
Rationale
Commit-identity policy is currently being decided piecemeal across two feature PRs and one bug report, with no artifact stating the invariant. The invariant that reconciles all three goals appears to be: the App identity may own the PR and the push (and GitHub-side signing), but the commit author/sign-off email must be a valid address — or, alternatively, the DCO gate must be configured to exempt bot-authored commits. Either is defensible; shipping #6122/#6123 without choosing one is not.
Proposed Next Step
Make the decision explicit before #6122 or #6123 merges, choosing one of:
Exempt bot commits from DCO: add .github/dco.yml (or replace probot-dco with a validator that skips [bot] authors), accepting that bot-authored commits carry provenance via the App instead of DCO.
Whichever is chosen, record it where #6122's identity derivation and #6123's re-author path can both cite it, and close #6251 against it.
Strategic Finding
Type: priority-shift / adoption-blocker
Horizon: near-term
Three in-flight items are on a collision course, and merging any two of them in the wrong order turns the DCO check permanently red for every agent PR:
<slug>[bot]@users.noreply.github.comas a malformed email — the[]in the local-part fail its validity check. A matchingSigned-off-bycannot fix it, a second human sign-off cannot fix it, and there is no.github/dco.yml, so remediation commits are unavailable. Any commit authored as the App-bot identity fails DCO, always.<github.app_slug>[bot]the default derived git commit identity for every agent on a hive with a usable App.createCommitOnBranchbefore PR creation (to satisfyrequired_signaturesrulesets).Each PR is individually well-motivated (attribution, signed-commit rulesets). Together with the current DCO gate they are contradictory: #6122/#6123 standardize exactly the author identity that #6251 shows can never pass. The failure mode is silent until merge time — green builds, approved reviews, red DCO on every PR — i.e., a full-pipeline merge-throughput blocker of the kind the hold-gated queue is already sensitive to (#6183).
Rationale
Commit-identity policy is currently being decided piecemeal across two feature PRs and one bug report, with no artifact stating the invariant. The invariant that reconciles all three goals appears to be: the App identity may own the PR and the push (and GitHub-side signing), but the commit author/sign-off email must be a valid address — or, alternatively, the DCO gate must be configured to exempt bot-authored commits. Either is defensible; shipping #6122/#6123 without choosing one is not.
Proposed Next Step
Make the decision explicit before #6122 or #6123 merges, choosing one of:
quality@hive.kubestellar.io): 🐛 fix: derive the agents' git commit identity from this hive's App instead of hardcoding kubestellar-hive #6122's derived identity uses a bracket-free, valid email for the author/sign-off while keeping App-bot PR authorship and push; ✨ feature: github.app_signed_commits — re-author agent branches as GitHub-signed App-bot commits before opening the PR #6123 re-authors using that same valid identity rather than the noreply bot address (note: ✨ feature: github.app_signed_commits — re-author agent branches as GitHub-signed App-bot commits before opening the PR #6123 also copies DCO trailers into the squashed commit — those trailers must be the valid-email form too)..github/dco.yml(or replace probot-dco with a validator that skips[bot]authors), accepting that bot-authored commits carry provenance via the App instead of DCO.Whichever is chosen, record it where #6122's identity derivation and #6123's re-author path can both cite it, and close #6251 against it.
Refs #6251, #6122, #6123. Related queue context: #6183.
Filed by strategist agent (ACMM L5 — hold-gated mode)
🐝 Hive Agent:
strategist| Instance:hosted-available-oke-11-placeholder-r05x| SHA:unknown— hive: agent=strategist backend=copilot model=claude-sonnet-4-6