gouthamr | clarkb: i'm not sure i could articulate the problems well.. I *think* the problems here are: | 03:24 |
---|---|---|
gouthamr | - a committer could delete a "signed-off-by" declaration from a different committer or author | 03:24 |
gouthamr | - a web-ui editor can omit specifying a "signed-off-by" | 03:24 |
gouthamr | correct? | 03:24 |
opendevreview | Merged openstack/openstack-manuals master: Remove information about SUSE / openSUSE https://review.opendev.org/c/openstack/openstack-manuals/+/950247 | 11:16 |
opendevreview | Merged openstack/openstack-manuals master: Add redirects to latest version https://review.opendev.org/c/openstack/openstack-manuals/+/946951 | 11:19 |
opendevreview | OpenStack Proposal Bot proposed openstack/security-doc master: Updated from openstack-manuals https://review.opendev.org/c/openstack/security-doc/+/950207 | 11:20 |
clarkb | gouthamr: I think it is more nuanced than that. You still need a signed-off-by in all cases with the feature turned on. But you only need one that matches the email address of the commit author or the commit committer or the person making the edits/pushing the change | 15:27 |
clarkb | a web ui editor can't omit a signed off by. There must still be one. But that signed off by may not match themselves if it matches the author | 15:27 |
fungi | and apparently google/gerrit upstream considered that sufficient attestation | 15:30 |
fungi | in preparation for the end of next month, we've started working through what scripted automation will need updating: https://review.opendev.org/q/hashtag:dco-signed-off-by+OR+topic:dco-signed-off-by | 16:17 |
fungi | also i've tried to follow them all up with adding generated-by trailers in all the same places: https://review.opendev.org/q/hashtag:generated-by | 16:18 |
fungi | there are probably more places we'll need to update, so if anybody spots another candidate please either submit a patch and add the same hashtag(s) for tracking purposes, or ping me and i'll take care of it | 16:22 |
clarkb | fungi: you can search message:signed-off-by and owner:$bot-name to find all the places using it once your changes start landing. add a - to the front of the query to see if you missed any | 16:25 |
fungi | yeah, i guess we reuse/share a limited number of gerrit accounts for automation | 16:26 |
fungi | though a lot of these are used so infrequently (some as little as once per development cycle) that trying to catch recent examples won't be comprehensive | 16:28 |
Generated by irclog2html.py 4.0.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!