From: Souma Date: Sat, 03 Oct 2026 13:40:56 GMT Subject: [PATCH v5 0/2] history: sign rewritten commits Message-ID: <20261003134058.23494-1-git@5ouma.me> In-Reply-To: <20260703145037.69832-1-git@5ouma.me> History rewriting creates commits through two paths: the history commands write replacement commits directly, while the replay machinery recreates descendants above the rewritten range. Neither path currently honors `commit.gpgSign` or an explicit signing request, so rewriting signed history can leave the resulting commits unsigned. Add a signing-key option to the replay API, then have the history commands pass the selected signer through both paths. Expose the standard `-S`/`--gpg-sign[=]` and `--no-gpg-sign` options for `drop`, `fixup`, `reword`, `split`, and `squash`. This applies one signing policy to every commit created by the rewrite, including both commits from `split`, the commit from `squash`, and replayed descendants. The behavior follows rebase, cherry-pick, and revert: `commit.gpgSign` supplies the default, command-line options override it, and the last command-line option wins. The signature attests the current committer's rewrite while preserving the original author identity. Changes since v4: - Add Git completion coverage for `--gpg-sign` and `--no-gpg-sign` to the history subcommand option tests Souma (2): replay: allow callers to sign commits history: sign rewritten commits Documentation/git-history.adoc | 18 +++++-- builtin/history.c | 96 +++++++++++++++++++++++++--------- replay.c | 13 +++-- replay.h | 6 +++ t/t3451-history-reword.sh | 63 ++++++++++++++++++++++ t/t3452-history-split.sh | 44 ++++++++++++++++ t/t3453-history-fixup.sh | 39 ++++++++++++++ t/t3454-history-drop.sh | 50 ++++++++++++++++++ t/t3455-history-squash.sh | 61 +++++++++++++++++++++ t/t9902-completion.sh | 2 + 10 files changed, 358 insertions(+), 34 deletions(-) Range-diff against v4: 1: d45cce8e25 = 1: d45cce8e25 replay: allow callers to sign commits 2: 8b4766fc0e ! 2: 65f3de1562 history: sign rewritten commits @@ t/t3455-history-squash.sh: check_commit_author () { test_expect_success 'setup linear history touching two files' ' test_commit base file a start && GIT_AUTHOR_NAME=One GIT_AUTHOR_EMAIL=one@example.com \ + + ## t/t9902-completion.sh ## +@@ t/t9902-completion.sh: test_expect_success 'git history subcommand options' ' + test_completion "git history split main --" <<-\EOF && + --update-refs=Z + --dry-run Z ++ --gpg-sign Z ++ --no-... Z + --no-dry-run Z + EOF + test_completion "git history fixup --upd" "--update-refs=" && -- 2.56.0