All of lore.kernel.org
 help / color / mirror / Atom feed
From: Souma <git@5ouma.me>
To: git@vger.kernel.org
Cc: gitster@pobox.com, ps@pks.im, Souma <git@5ouma.me>
Subject: [PATCH v5 0/2] history: sign rewritten commits
Date: Sat,  3 Oct 2026 22:40:56 +0900	[thread overview]
Message-ID: <20261003134058.23494-1-git@5ouma.me> (raw)
In-Reply-To: <20260703145037.69832-1-git@5ouma.me>

History rewriting creates commits through two paths: the history commands
write replacement commits directly, while the replay machinery recreates
descendants above the rewritten range. Neither path currently honors
`commit.gpgSign` or an explicit signing request, so rewriting signed history
can leave the resulting commits unsigned.

Add a signing-key option to the replay API, then have the history commands
pass the selected signer through both paths. Expose the standard
`-S`/`--gpg-sign[=<key-id>]` and `--no-gpg-sign` options for `drop`, `fixup`,
`reword`, `split`, and `squash`. This applies one signing policy to every
commit created by the rewrite, including both commits from `split`, the
commit from `squash`, and replayed descendants.

The behavior follows rebase, cherry-pick, and revert:
`commit.gpgSign` supplies the default, command-line options override it, and
the last command-line option wins. The signature attests the current
committer's rewrite while preserving the original author identity.

Changes since v4:

 - Add Git completion coverage for `--gpg-sign` and `--no-gpg-sign` to the
   history subcommand option tests

Souma (2):
  replay: allow callers to sign commits
  history: sign rewritten commits

 Documentation/git-history.adoc | 18 +++++--
 builtin/history.c              | 96 +++++++++++++++++++++++++---------
 replay.c                       | 13 +++--
 replay.h                       |  6 +++
 t/t3451-history-reword.sh      | 63 ++++++++++++++++++++++
 t/t3452-history-split.sh       | 44 ++++++++++++++++
 t/t3453-history-fixup.sh       | 39 ++++++++++++++
 t/t3454-history-drop.sh        | 50 ++++++++++++++++++
 t/t3455-history-squash.sh      | 61 +++++++++++++++++++++
 t/t9902-completion.sh          |  2 +
 10 files changed, 358 insertions(+), 34 deletions(-)

Range-diff against v4:
1:  d45cce8e25 = 1:  d45cce8e25 replay: allow callers to sign commits
2:  8b4766fc0e ! 2:  65f3de1562 history: sign rewritten commits
    @@ t/t3455-history-squash.sh: check_commit_author () {
      test_expect_success 'setup linear history touching two files' '
      	test_commit base file a start &&
      	GIT_AUTHOR_NAME=One GIT_AUTHOR_EMAIL=one@example.com \
    +
    + ## t/t9902-completion.sh ##
    +@@ t/t9902-completion.sh: test_expect_success 'git history subcommand options' '
    + 	test_completion "git history split main --" <<-\EOF &&
    + 	--update-refs=Z
    + 	--dry-run Z
    ++	--gpg-sign Z
    ++	--no-... Z
    + 	--no-dry-run Z
    + 	EOF
    + 	test_completion "git history fixup --upd" "--update-refs=" &&
-- 
2.56.0

  parent reply	other threads:[~2026-10-03 13:41 UTC|newest]

Thread overview: 30+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-03 14:50 [PATCH 0/3] history: sign rewritten commits Souma
2026-07-03 14:50 ` [PATCH 1/3] builtin/history: " Souma
2026-07-16 10:18   ` Patrick Steinhardt
2026-07-03 14:50 ` [PATCH 2/3] doc: document history signing options Souma
2026-07-16 10:18   ` Patrick Steinhardt
2026-07-03 14:50 ` [PATCH 3/3] t345x: cover signed history rewrites Souma
2026-07-17 14:51 ` [PATCH v2 0/2] history: support signing rewritten commits Souma
2026-07-17 14:51 ` [PATCH v2 1/2] replay: allow callers to sign commits Souma
2026-09-11  7:57   ` Patrick Steinhardt
2026-07-17 14:51 ` [PATCH v2 2/2] builtin/history: sign rewritten commits Souma
2026-09-11  7:57   ` Patrick Steinhardt
2026-09-12 16:00 ` [PATCH v3 0/2] history: support signing " Souma
2026-09-12 16:00 ` [PATCH v3 1/2] replay: allow callers to sign commits Souma
2026-09-28  7:40   ` Patrick Steinhardt
2026-09-12 16:00 ` [PATCH v3 2/2] history: sign rewritten commits Souma
2026-09-28  7:32   ` Patrick Steinhardt
2026-09-28 15:00     ` Junio C Hamano
2026-09-28 18:52       ` Junio C Hamano
2026-09-28 23:39         ` Souma
2026-10-02 13:27 ` [PATCH v4 0/2] " Souma
2026-10-02 22:47   ` Junio C Hamano
2026-10-03 13:38     ` Souma
2026-10-02 13:27 ` [PATCH v4 1/2] replay: allow callers to sign commits Souma
2026-10-02 13:27 ` [PATCH v4 2/2] history: sign rewritten commits Souma
2026-10-03 13:40 ` Souma [this message]
2026-10-04 14:17   ` [PATCH v5 0/2] " Junio C Hamano
2026-10-05  6:59     ` Souma
2026-10-06 15:58       ` Junio C Hamano
2026-10-03 13:40 ` [PATCH v5 1/2] replay: allow callers to sign commits Souma
2026-10-03 13:40 ` [PATCH v5 2/2] history: sign rewritten commits Souma

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20261003134058.23494-1-git@5ouma.me \
    --to=git@5ouma.me \
    --cc=git@vger.kernel.org \
    --cc=gitster@pobox.com \
    --cc=ps@pks.im \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.