From: Souma <git@5ouma.me>
To: git@vger.kernel.org
Cc: gitster@pobox.com, ps@pks.im, Souma <git@5ouma.me>
Subject: [PATCH v5 0/2] history: sign rewritten commits
Date: Sat, 3 Oct 2026 22:40:56 +0900 [thread overview]
Message-ID: <20261003134058.23494-1-git@5ouma.me> (raw)
In-Reply-To: <20260703145037.69832-1-git@5ouma.me>
History rewriting creates commits through two paths: the history commands
write replacement commits directly, while the replay machinery recreates
descendants above the rewritten range. Neither path currently honors
`commit.gpgSign` or an explicit signing request, so rewriting signed history
can leave the resulting commits unsigned.
Add a signing-key option to the replay API, then have the history commands
pass the selected signer through both paths. Expose the standard
`-S`/`--gpg-sign[=<key-id>]` and `--no-gpg-sign` options for `drop`, `fixup`,
`reword`, `split`, and `squash`. This applies one signing policy to every
commit created by the rewrite, including both commits from `split`, the
commit from `squash`, and replayed descendants.
The behavior follows rebase, cherry-pick, and revert:
`commit.gpgSign` supplies the default, command-line options override it, and
the last command-line option wins. The signature attests the current
committer's rewrite while preserving the original author identity.
Changes since v4:
- Add Git completion coverage for `--gpg-sign` and `--no-gpg-sign` to the
history subcommand option tests
Souma (2):
replay: allow callers to sign commits
history: sign rewritten commits
Documentation/git-history.adoc | 18 +++++--
builtin/history.c | 96 +++++++++++++++++++++++++---------
replay.c | 13 +++--
replay.h | 6 +++
t/t3451-history-reword.sh | 63 ++++++++++++++++++++++
t/t3452-history-split.sh | 44 ++++++++++++++++
t/t3453-history-fixup.sh | 39 ++++++++++++++
t/t3454-history-drop.sh | 50 ++++++++++++++++++
t/t3455-history-squash.sh | 61 +++++++++++++++++++++
t/t9902-completion.sh | 2 +
10 files changed, 358 insertions(+), 34 deletions(-)
Range-diff against v4:
1: d45cce8e25 = 1: d45cce8e25 replay: allow callers to sign commits
2: 8b4766fc0e ! 2: 65f3de1562 history: sign rewritten commits
@@ t/t3455-history-squash.sh: check_commit_author () {
test_expect_success 'setup linear history touching two files' '
test_commit base file a start &&
GIT_AUTHOR_NAME=One GIT_AUTHOR_EMAIL=one@example.com \
+
+ ## t/t9902-completion.sh ##
+@@ t/t9902-completion.sh: test_expect_success 'git history subcommand options' '
+ test_completion "git history split main --" <<-\EOF &&
+ --update-refs=Z
+ --dry-run Z
++ --gpg-sign Z
++ --no-... Z
+ --no-dry-run Z
+ EOF
+ test_completion "git history fixup --upd" "--update-refs=" &&
--
2.56.0
next prev parent reply other threads:[~2026-10-03 13:41 UTC|newest]
Thread overview: 30+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-03 14:50 [PATCH 0/3] history: sign rewritten commits Souma
2026-07-03 14:50 ` [PATCH 1/3] builtin/history: " Souma
2026-07-16 10:18 ` Patrick Steinhardt
2026-07-03 14:50 ` [PATCH 2/3] doc: document history signing options Souma
2026-07-16 10:18 ` Patrick Steinhardt
2026-07-03 14:50 ` [PATCH 3/3] t345x: cover signed history rewrites Souma
2026-07-17 14:51 ` [PATCH v2 0/2] history: support signing rewritten commits Souma
2026-07-17 14:51 ` [PATCH v2 1/2] replay: allow callers to sign commits Souma
2026-09-11 7:57 ` Patrick Steinhardt
2026-07-17 14:51 ` [PATCH v2 2/2] builtin/history: sign rewritten commits Souma
2026-09-11 7:57 ` Patrick Steinhardt
2026-09-12 16:00 ` [PATCH v3 0/2] history: support signing " Souma
2026-09-12 16:00 ` [PATCH v3 1/2] replay: allow callers to sign commits Souma
2026-09-28 7:40 ` Patrick Steinhardt
2026-09-12 16:00 ` [PATCH v3 2/2] history: sign rewritten commits Souma
2026-09-28 7:32 ` Patrick Steinhardt
2026-09-28 15:00 ` Junio C Hamano
2026-09-28 18:52 ` Junio C Hamano
2026-09-28 23:39 ` Souma
2026-10-02 13:27 ` [PATCH v4 0/2] " Souma
2026-10-02 22:47 ` Junio C Hamano
2026-10-03 13:38 ` Souma
2026-10-02 13:27 ` [PATCH v4 1/2] replay: allow callers to sign commits Souma
2026-10-02 13:27 ` [PATCH v4 2/2] history: sign rewritten commits Souma
2026-10-03 13:40 ` Souma [this message]
2026-10-04 14:17 ` [PATCH v5 0/2] " Junio C Hamano
2026-10-05 6:59 ` Souma
2026-10-06 15:58 ` Junio C Hamano
2026-10-03 13:40 ` [PATCH v5 1/2] replay: allow callers to sign commits Souma
2026-10-03 13:40 ` [PATCH v5 2/2] history: sign rewritten commits Souma
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261003134058.23494-1-git@5ouma.me \
--to=git@5ouma.me \
--cc=git@vger.kernel.org \
--cc=gitster@pobox.com \
--cc=ps@pks.im \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox