Friday, 2026-09-04

*** sfinucan is now known as stephenfin10:55
fungii've gotten a response from lf legal that signed-off-by in dco context is indeed expected to be an individual natural person. there are subtle hints to this in the dco text but could definitely benefit from clarification, especially for the benefit of non-english-fluent contributors who could miss that nuance of its wording15:33
fungii'll push up a draft resolution in a bit, accompanied by documentation changes that might help once the resolution is approved15:33
fungii'll make sure it's worded in such a way that it also covers concerns about autonomous "ai" agents while not excluding use by approved automation as an implementation detail15:34
JayFhmm. Automation is an interesting case. An auto-DCO after some non-deterministic automation would seem pretty bad to me, although it makes sense for script-based automation (inputs->outputs the same every time) 15:45
clarkbright which is all we have currently (take translations and put them in .po files. Take annotated strings and put them in .pot files. Update requirements etc15:46
fungiright, we've already discussed that situation ad nauseum, i just want to close the "signed-off-by as my company" gap while not painting ourselves into a corner with the current behavior of our own project automation15:47
JayFack15:51
fungithe antipatterns of a company or an autonomous machine agent adding signed-off-by share a common element in that neither is an individual natural person and so the dco is not for them, but as a project we also assert that when one of our approved scripts adds signed-off-by it's merely satisfying an inflexible check in our code review system not actually asserting the dco15:53
gouthamrhey good stuff fungi 16:55
gouthamr> there are subtle hints to this in the dco text but could definitely benefit from clarification, especially for the benefit of non-english-fluent contributors who could miss that nuance of its wording16:55
gouthamr++ thanks for this16:55
gouthamrdepending on what you're trying to say in the resolution, i'd like to see if my "common sense"/deterministic tooling case is covered if that needs to be a separate resolution/clarification somewhere in the contributor guide 16:56
gouthamrits the same case as you folks are discussing, except i think we need to go write it somewhere so we don't ask this question again, we can point people at something we've agreed on16:57
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0109: EC2-derived tokens retain full privileges  https://review.opendev.org/c/openstack/security-doc/+/100239218:04
opendevreviewJay Faulkner proposed openstack/security-doc master: OSSN-0110: Self-service password change does not revoke generators  https://review.opendev.org/c/openstack/security-doc/+/100241018:05
fungigouthamr: yes, i'd like to have something in writing that just covers all of this so we can point to a url the next time any of it comes up18:06

Generated by irclog2html.py 4.1.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!