Skip to content

Carve-outs via subtree split strip every commit signature (lol, #680) — procedure must choose squash-import or a ruled exception #1101

Description

@hyperpolymath

Finding (Part F signing audit, 2026-09-30)

A carve-out that splits history out of a subdirectory strips every commit signature.

hyperpolymath/lol holds 8 unsigned commits on main whose subjects end in standards PR numbers (#611…#660) and which have no PR in lol. Each is a re-creation of a signed standards squash. For example, lol c4b056b has the same author, the same committer (GitHub) and the same second as standards#660's signed 1441c354. Its tree abbafb60 is byte-identical to 1441c354:lol.

So they came from the #680 carve-out ("evict a2ml, lol and the repo-guardian pair") via git subtree split or filter-repo. Rewriting a commit object necessarily drops its gpgsig.

This is one-off rather than a live producer, but it will recur on every future carve-out. Under the D215/D233 zero-bypass floor, the target repo would refuse the push outright.

Acceptance criteria

  • The carve-out procedure (wherever carve-out: evict a2ml, lol and the repo-guardian pair (#490 #494 #492) #680's recipe lives) states the signature consequence and picks one of two paths:
    • (a) import into the new repo as one signed commit (history kept by a link or tag back to the standards SHA), or
    • (b) a named, owner-ruled one-time exception applied before the floor goes on.
  • Any carve-out tool in the estate warns when the destination repo has required_signatures.
  • No action on lol's existing history. Re-signing rewrites SHAs, and SIGNING-SETUP.md §3 forbids it.

Write-up: llm-coding-configs/claude-code/signing/PART-F-SIGNING-AUDIT.md §5d, item 4. Rulings: #787 (D254).

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions