[PATCH v5 0/2] history: sign rewritten commits
- From
- Souma <git@5ouma.me>
- Date
- Oct 3, 2026, 13:40 UTC
- Message-ID
- <20261003134058.23494-1-git@5ouma.me>
- In-Reply-To
- <20260703145037.69832-1-git@5ouma.me>
History rewriting creates commits through two paths: the history commands write replacement commits directly, while the replay machinery recreates descendants above the rewritten range. Neither path currently honors `commit.gpgSign` or an explicit signing request, so rewriting signed history can leave the resulting commits unsigned.
Add a signing-key option to the replay API, then have the history commands pass the selected signer through both paths. Expose the standard `-S`/`--gpg-sign[=<key-id>]` and `--no-gpg-sign` options for `drop`, `fixup`, `reword`, `split`, and `squash`. This applies one signing policy to every commit created by the rewrite, including both commits from `split`, the commit from `squash`, and replayed descendants.
The behavior follows rebase, cherry-pick, and revert: `commit.gpgSign` supplies the default, command-line options override it, and the last command-line option wins. The signature attests the current committer's rewrite while preserving the original author identity.
Changes since v4:
- Add Git completion coverage for `--gpg-sign` and `--no-gpg-sign` to the history subcommand option tests
Souma (2): replay: allow callers to sign commits history: sign rewritten commits
Documentation/git-history.adoc | 18 +++++-- builtin/history.c | 96 +++++++++++++++++++++++++--------- replay.c | 13 +++-- replay.h | 6 +++ t/t3451-history-reword.sh | 63 ++++++++++++++++++++++ t/t3452-history-split.sh | 44 ++++++++++++++++ t/t3453-history-fixup.sh | 39 ++++++++++++++ t/t3454-history-drop.sh | 50 ++++++++++++++++++ t/t3455-history-squash.sh | 61 +++++++++++++++++++++ t/t9902-completion.sh | 2 + 10 files changed, 358 insertions(+), 34 deletions(-)
Range-diff against v4:
1: d45cce8e25 = 1: d45cce8e25 replay: allow callers to sign commits
2: 8b4766fc0e ! 2: 65f3de1562 history: sign rewritten commits
@@ t/t3455-history-squash.sh: check_commit_author () {
test_expect_success 'setup linear history touching two files' '
test_commit base file a start &&
GIT_AUTHOR_NAME=One GIT_AUTHOR_EMAIL=one@example.com \
+
+ ## t/t9902-completion.sh ##
+@@ t/t9902-completion.sh: test_expect_success 'git history subcommand options' '
+ test_completion "git history split main --" <<-\EOF &&
+ --update-refs=Z
+ --dry-run Z
++ --gpg-sign Z
++ --no-... Z
+ --no-dry-run Z
+ EOF
+ test_completion "git history fixup --upd" "--update-refs=" &&-- 2.56.0