Skip to content

🏗️🔧:refuse a sign-off that names a tool - #67

Merged
openinf-commit-queue[bot] merged 1 commit into
mainfrom
claude/project-thread-wvk7mo
Sep 22, 2026
Merged

openinf-commit-queue[bot] merged 1 commit into
mainfrom
claude/project-thread-wvk7mo

Conversation

@DerekNonGeneric

@DerekNonGeneric DerekNonGeneric commented Sep 19, 2026 •

Copy link
Copy Markdown
Member

Requested by DerekNonGeneric

Before: this repository carries its own copy of build/shared/commit-message.mts
rather than importing it, so the hole fixed in OpenINF/.github#924 was open here
too. An agent committing under its own git identity is the author of what it
commits, -s copies that identity into the sign-off, and checkSignOff — which
only asks whether the sign-off matches the author — found the two in agreement.
pnpm run lint:commits passed a commit whose Developer Certificate of Origin
had been certified by a program.

After: a Signed-off-by: naming an assistant or a bot account is refused
whoever the author is, by the same pattern that already refuses one as a
co-author. An agent-authored commit now has no spelling that lands: sign off as
itself and the trailer names a tool, sign off as anybody else and it is not the
author.

How: a straight port of OpenINF/.github#924. TOOL_COAUTHOR becomes
TOOL_IDENTITY and is applied to Signed-off-by as well as Co-authored-by,
in checkTrailers rather than in checkSignOff, so the rule also covers the
message the commit queue validates before landing. [bot] is read where an
account name ends, so it cannot match inside a person's name — a false positive
there would block a sign-off, which unlike a co-author credit cannot be dropped.
The same seven tests come with it. CONTRIBUTING.md gains the sentence the hole
was made of — the author of a commit has to be a person, and an agent committing
on somebody's behalf commits as them.

All three repositories — this one, OpenINF/.github and
OpenINF/openinf.github.io — carry a byte-identical copy of this file, and
nothing syncs them. They are identical again, which is worth keeping in mind
when any of them is next touched. OpenINF/openinf.github.io#1907 is the third.

Verified with node --test build/shared/*.test.mts (94 pass),
pnpm run lint:format, lint:md, lint:spelling, lint:types and
lint:commits on this branch.

Summary by CodeRabbit

  • Documentation

    • Updated commit-message guidance to distinguish agent-authored commits from commits made on behalf of a person.
    • Clarified when to use Assisted-by:, Signed-off-by:, and Co-authored-by: trailers.
  • Bug Fixes

    • Improved validation to reject bot and tool identities in person-only trailers.
    • Ensured sign-offs identify the commit author, while agent contributions use Assisted-by:.
    • Improved handling of bot-account suffixes and folded email addresses.
  • Tests

    • Added coverage for assistant, bot, folded-address, self-signing, and human sign-off scenarios.

@coderabbitai

coderabbitai Bot commented Sep 19, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Essentials

Run ID: 9e567fcd-fc98-4779-99f0-3ebca5301034

📥 Commits

Reviewing files that changed from the base of the PR and between a0db68e and 4052636.

📒 Files selected for processing (2)
  • build/shared/commit-message.mts
  • build/shared/commit-message.test.mts

Included review availability: 4 reviews are currently available. Your included PR review attempts over the past 7 days set your current allowance at 5 reviews per hour.


📝 Walkthrough

Walkthrough

Commit trailer guidance and validation now distinguish agent and bot identities from human identities. Tool identities are rejected in both Co-authored-by: and Signed-off-by: trailers. Tests cover assistant, bot, folded-address, author-mismatch, and valid human sign-offs.

Changes

Commit trailer validation

Layer / File(s) Summary
Identity rules and contributor guidance
CONTRIBUTING.md, build/shared/commit-message.mts
The identity matcher now applies to co-author and sign-off trailers. Contributor guidance documents agent-authored and delegated commit rules.
Sign-off enforcement and tests
build/shared/commit-message.mts, build/shared/commit-message.test.mts
Signed-off-by: values that match tool or bot identities are rejected. Tests cover assistant, bot, folded-address, author-mismatch, and valid human sign-offs.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~15 minutes

Change: Bug fix

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly describes the main change: rejecting Signed-off-by trailers that name a tool. The emoji and separator add noise, but the title remains specific and understandable.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 2 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

This repository carries its own copy of the commit message rules, so a
hole in them is a hole in two places. Ported from OpenINF/.github.

`Co-authored-by:` was taught to refuse a tool. The other trailer that
names a person was left to `checkSignOff`, which asks one question:
does the sign-off match the commit's author.

That catches a tool signing on somebody else's behalf and nothing else.
An agent committing under its own git identity is the author, and `-s`
copies that identity into the trailer, so the two agree and the
Developer Certificate of Origin is certified by a program.

So the pattern that already refuses a tool as a co-author refuses one
as a signer too, whoever the author is. The two together leave an
agent-authored commit no spelling that lands: sign off as itself and
the trailer names a tool, sign off as anybody else and it is not the
author.

`[bot]` is read where an account name ends — before the `@` of an
address, or at the end of the value, with or without an angle-bracketed
address after it — rather than anywhere in the value. GitHub reserves
the suffix so that no account can be named with it, but a trailer is
free text and not an account name, so matching it anywhere also found
one sitting inside a person's: `Ada [bot] Smith <ada@example.com>`.
That cost little while only `Co-authored-by:` was read this way, and
costs more now that a sign-off is: a miscredited co-author can be
dropped from the message and the commit still lands, while a false
positive on a sign-off leaves a contributor with nothing to write.

`CONTRIBUTING.md` had said an assistant signs nothing and left the rest
to be inferred. It now says the author has to be a person as well,
which is the sentence whose absence the hole was made of.

Signed-off-by: Derek Lewis <DerekNonGeneric@inf.is>
Assisted-by: Claude-Code:claude-opus-5
@claude
claude Bot force-pushed the claude/project-thread-wvk7mo branch from 4393aef to 4052636 Compare September 22, 2026 00:41
@DerekNonGeneric DerekNonGeneric added the 🚀 Status: Commit Queue Land this pull request when its checks pass label Sep 22, 2026
@openinf-commit-queue
openinf-commit-queue Bot merged commit c48c79c into main Sep 22, 2026
9 checks passed
@openinf-commit-queue openinf-commit-queue Bot removed the 🚀 Status: Commit Queue Land this pull request when its checks pass label Sep 22, 2026
@openinf-commit-queue
openinf-commit-queue Bot deleted the claude/project-thread-wvk7mo branch September 22, 2026 01:15
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant