[PATCH v2 1/2] replay: allow callers to sign commits
- From
- Souma <git@5ouma.me>
- Date
- Jul 17, 2026, 14:51 UTC
- Message-ID
- <20260717145142.39478-2-git@5ouma.me>
- In-Reply-To
- <20260703145037.69832-1-git@5ouma.me>
The replay machinery creates commits directly through `commit_tree_extended()`, but callers cannot currently request signatures. Commands that replay rewritten history consequently cannot carry their signing policy through to descendant commits.
Add `sign_commit` to `replay_revisions_options` and thread it through commit creation. `NULL` preserves the existing unsigned behavior, an empty string selects the default signing key, and a non-empty string selects an explicit key. Existing callers zero-initialize the options structure, so their behavior is unchanged.
Signed-off-by: Souma <git@5ouma.me> --- replay.c | 13 ++++++++----- replay.h | 6 ++++++ 2 files changed, 14 insertions(+), 5 deletions(-)
diff --git a/replay.c b/replay.c index aac9178875..19a6402bf0 100644 --- a/replay.c +++ b/replay.c @@ -81,13 +81,13 @@ static struct commit *create_commit(struct repository *repo, struct tree *tree, struct commit *based_on, struct commit *parent, - enum replay_mode mode) + enum replay_mode mode, + const char *sign_commit) { struct object_id ret; struct object *obj = NULL; struct commit_list *parents = NULL; char *author = NULL; - char *sign_commit = NULL; /* FIXME: cli users might want to sign again */ struct commit_extra_header *extra = NULL; struct strbuf msg = STRBUF_INIT; const char *out_enc = get_commit_output_encoding(); @@ -270,7 +270,8 @@ static struct commit *pick_regular_commit(struct repository *repo, struct merge_options *merge_opt, struct merge_result *result, enum replay_mode mode, - enum replay_empty_commit_action empty) + enum replay_empty_commit_action empty, + const char *sign_commit) { struct commit *base, *replayed_base; struct tree *pickme_tree, *base_tree, *replayed_base_tree; @@ -341,7 +342,8 @@ static struct commit *pick_regular_commit(struct repository *repo, } } - return create_commit(repo, result->tree, pickme, replayed_base, mode); + return create_commit(repo, result->tree, pickme, replayed_base, mode, + sign_commit); } void replay_result_release(struct replay_result *result) @@ -431,7 +433,8 @@ int replay_revisions(struct rev_info *revs, last_commit = pick_regular_commit(revs->repo, commit, replayed_commits, mode == REPLAY_MODE_REVERT ? last_commit : onto, - &merge_opt, &result, mode, opts->empty); + &merge_opt, &result, mode, opts->empty, + opts->sign_commit); if (!last_commit) break; diff --git a/replay.h b/replay.h index 491db145e3..6ed0608911 100644 --- a/replay.h +++ b/replay.h @@ -57,6 +57,12 @@ struct replay_revisions_options { */ int contained; + /* + * Key used to sign newly-created commits. An empty string requests the + * default configured signing key, and NULL disables signing. + */ + const char *sign_commit; + /* * Controls what to do when a replayed commit becomes empty. * Defaults to REPLAY_EMPTY_COMMIT_DROP.
-- 2.55.0