On Fri, Jul 17, 2026 at 02:51:41PM +0000, Souma wrote:
Sorry for taking so long to review this, I lost track of this series.
The replay machinery creates commits directly through
`commit_tree_extended()`, but callers cannot currently request
signatures. Commands that replay rewritten history consequently cannot
carry their signing policy through to descendant commits.
Add `sign_commit` to `replay_revisions_options` and thread it through
commit creation. `NULL` preserves the existing unsigned behavior, an
empty string selects the default signing key, and a non-empty string
selects an explicit key. Existing callers zero-initialize the options
structure, so their behavior is unchanged.
Nit: I feel like documenting the exact behaviour of that parameter here
is a bit excessive. You document it in-code, which is sufficient.
The changes themselves look good to me.
Patrick