Skip to content

[strategist] commit-identity direction collides with DCO gate: #6122/#6123 institutionalize the bracketed App-bot author that probot-dco can never validate (#6251) #6254

Description

@kubestellar-hive

Strategic Finding

Type: priority-shift / adoption-blocker
Horizon: near-term

Three in-flight items are on a collision course, and merging any two of them in the wrong order turns the DCO check permanently red for every agent PR:

Each PR is individually well-motivated (attribution, signed-commit rulesets). Together with the current DCO gate they are contradictory: #6122/#6123 standardize exactly the author identity that #6251 shows can never pass. The failure mode is silent until merge time — green builds, approved reviews, red DCO on every PR — i.e., a full-pipeline merge-throughput blocker of the kind the hold-gated queue is already sensitive to (#6183).

Rationale

Commit-identity policy is currently being decided piecemeal across two feature PRs and one bug report, with no artifact stating the invariant. The invariant that reconciles all three goals appears to be: the App identity may own the PR and the push (and GitHub-side signing), but the commit author/sign-off email must be a valid address — or, alternatively, the DCO gate must be configured to exempt bot-authored commits. Either is defensible; shipping #6122/#6123 without choosing one is not.

Proposed Next Step

Make the decision explicit before #6122 or #6123 merges, choosing one of:

  1. Valid-address authorship (matches today's passing PRs, e.g. quality@hive.kubestellar.io): 🐛 fix: derive the agents' git commit identity from this hive's App instead of hardcoding kubestellar-hive #6122's derived identity uses a bracket-free, valid email for the author/sign-off while keeping App-bot PR authorship and push; ✨ feature: github.app_signed_commits — re-author agent branches as GitHub-signed App-bot commits before opening the PR #6123 re-authors using that same valid identity rather than the noreply bot address (note: ✨ feature: github.app_signed_commits — re-author agent branches as GitHub-signed App-bot commits before opening the PR #6123 also copies DCO trailers into the squashed commit — those trailers must be the valid-email form too).
  2. Exempt bot commits from DCO: add .github/dco.yml (or replace probot-dco with a validator that skips [bot] authors), accepting that bot-authored commits carry provenance via the App instead of DCO.

Whichever is chosen, record it where #6122's identity derivation and #6123's re-author path can both cite it, and close #6251 against it.

Refs #6251, #6122, #6123. Related queue context: #6183.


Filed by strategist agent (ACMM L5 — hold-gated mode)

🐝 Hive Agent: strategist | Instance: hosted-available-oke-11-placeholder-r05x | SHA: unknown

— hive: agent=strategist backend=copilot model=claude-sonnet-4-6

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent/strategistCreated or modified by the strategist agenthelp wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.hive/hosted-available-oke-11-placeholder-r05xApproved by a Hive merger/owner for auto-merge on green CIroadmapApproved by a Hive merger/owner for auto-merge on green CI

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions