{"thread":{"id":"64342","subject":"[BUG] protocol.file.allow=always not honored when --local","startedAt":"2025-10-17T02:29:24Z","lastAt":"2025-10-21T14:59:10Z","messageCount":3,"participants":["fence.borrowing375@passmail.net","Jeff King"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"529036","messageId":"176066758616.6.12811000416591629223.957743298@passmail.net","threadId":"64342","inReplyTo":null,"subject":"[BUG] protocol.file.allow=always not honored when --local","fromName":"","fromEmail":"fence.borrowing375@passmail.net","sentAt":"2025-10-17T02:19:38Z","receivedAt":"2025-10-17T02:29:24Z","isPatch":false,"sender":{"key":"fence.borrowing375@passmail.net","avatar":null},"body":"Thank you for filling out a Git bug report!\nPlease answer the following questions to help us understand your issue.\n\nWhat did you do before the bug happened? (Steps to reproduce your\nissue)\n\nCreated an empty directory, then initialized git:\n`mkdir ~/test && cd ~/test && git init`\n\nEnsured file:// transport protocol is default/unset value (file:// is\ndisabled by default):\n`git config --list | grep protocol`\n# no output\n\nEnabled file:// transport for local repository:\n`git config --local protocol.file.allow always`\n\nThen, attempted to add a git submodule:\n`git submodule add /path/to/module/.git`\n\n\nWhat did you expect to happen? (Expected behavior)\n\nSuccessful clone:\n```\nCloning into '/home/username/test/module'...\ndone.\n```\n\n\nWhat happened instead? (Actual behavior)\n\nFailed clone:\n```\nCloning into '/home/username/test/module'...\nfatal: transport 'file' not allowed\nfatal: clone of '/path/to/module/.git' into submodule path\n'/home/head/data/infra/src/test/git' failed\n```\n\n\nWhat's different between what you expected and what actually happened?\n\nThe default behavior of disabling the file:// protocol should have been\noverridden by the config, but was not. In contrast, it gets enabled as\nexpected when setting the config user-wide:\n`git config --global protocol.file.allow always`\n\nI do not want to enable file:// by default due to security\nimplications. I only want to enable it for specific repositories but\ncannot do so as this setting is not honored when --local.\n\n\nAnything else you want to add:\n\nA similar error message shows when attempting to update an existing\nsubmodule with only the --local config set.\n\nThis bug is also present in git version 2.39.5.\n\n\n[System Info]\ngit version:\ngit version 2.51.1.472.g4253630c6f\ncpu: x86_64\nbuilt from commit: 4253630c6f07a4bdcc9aa62a50e26a4d466219d1\nsizeof-long: 8\nsizeof-size_t: 8\nshell-path: /bin/sh\nrust: disabled\nlibcurl: 7.88.1\nOpenSSL: OpenSSL 3.0.17 1 Jul 2025\nzlib: 1.2.13\nSHA-1: SHA1_DC\nSHA-256: SHA256_BLK\ndefault-ref-format: files\ndefault-hash: sha1\ncompiler info: gnuc: 12.2\nlibc info: glibc: 2.36\n$SHELL (typically, interactive shell): /bin/bash\n\n\n"},{"id":"529043","messageId":"20251017071532.GA4073661@coredump.intra.peff.net","threadId":"64342","inReplyTo":"176066758616.6.12811000416591629223.957743298@passmail.net","subject":"Re: [BUG] protocol.file.allow=always not honored when --local","fromName":"Jeff King","fromEmail":"peff@peff.net","sentAt":"2025-10-17T07:15:32Z","receivedAt":"2025-10-17T07:15:34Z","isPatch":false,"sender":{"key":"peff@peff.net","avatar":"https://avatars.githubusercontent.com/u/45925?v=4"},"body":"On Fri, Oct 17, 2025 at 02:19:38AM +0000, fence.borrowing375@passmail.net wrote:\n\n> Created an empty directory, then initialized git:\n> `mkdir ~/test && cd ~/test && git init`\n> \n> Ensured file:// transport protocol is default/unset value (file:// is\n> disabled by default):\n> `git config --list | grep protocol`\n> # no output\n> \n> Enabled file:// transport for local repository:\n> `git config --local protocol.file.allow always`\n> \n> Then, attempted to add a git submodule:\n> `git submodule add /path/to/module/.git`\n\nI don't think this will work as you expect, because of the use of \"git\nconfig --local\". When we run git-clone under the hood to clone the new\nsubmodule, it is a new repository, and does not look at the config of\nthe containing repository at all[1].\n\nAs you noted, setting it in the user-level \"--global\" config file would\nwork. You can also override the config via the environment like:\n\n  git -c protocol.file.allow=always submodule add ...\n\nthough note that anybody cloning will need to do the same thing (and of\ncourse have the submodule available at the exact same local path!).\n\n-Peff\n\n[1] There have been discussions in the past on whether submodules should\n    receive some config from the superproject repository. But there are\n    a lot of complications, as it is the right thing for some config\n    keys but not for some others. I doubt we will change the behavior\n    anytime soon.\n"},{"id":"529298","messageId":"176105772451.7.13453872556381855079.964553330@passmail.net","threadId":"64342","inReplyTo":"20251017071532.GA4073661@coredump.intra.peff.net","subject":"Re: [BUG] protocol.file.allow=always not honored when --local","fromName":"","fromEmail":"fence.borrowing375@passmail.net","sentAt":"2025-10-21T14:41:55Z","receivedAt":"2025-10-21T14:59:10Z","isPatch":false,"sender":{"key":"fence.borrowing375@passmail.net","avatar":null},"body":"(I apologize for resending this, the first time I forgot to CC the\nmailing list.)\n\nThe -c flag works for my use case, but this raises a couple questions:\n\n- If submodules were ever to use the local config, would it be the\nright thing to honor the protocol.allow and protocol.<name>.allow keys?\n\n- Manpage GIT-SUBMODULE(1), under the add, init, and update\nsubcommands, notes that the local (superproject repository) config may\nbe updated when running these commands. In addition, the local config\nis used for certain purposes, such as determining the default remote of\na new submodule. Readers know the local config is used in some way.\nHowever, the manpage does not appear to state anywhere that, in\ngeneral, the local config is currently ignored. I found this confusing.\n\nIs this a documentation bug?\n\nOn Fri, 2025-10-17 at 03:15 -0400, Jeff King wrote:\n> On Fri, Oct 17, 2025 at 02:19:38AM +0000,\n> fence.borrowing375@passmail.net wrote:\n> \n> > Created an empty directory, then initialized git:\n> > `mkdir ~/test && cd ~/test && git init`\n> > \n> > Ensured file:// transport protocol is default/unset value (file://\n> > is\n> > disabled by default):\n> > `git config --list | grep protocol`\n> > # no output\n> > \n> > Enabled file:// transport for local repository:\n> > `git config --local protocol.file.allow always`\n> > \n> > Then, attempted to add a git submodule:\n> > `git submodule add /path/to/module/.git`\n> \n> I don't think this will work as you expect, because of the use of\n> \"git\n> config --local\". When we run git-clone under the hood to clone the\n> new\n> submodule, it is a new repository, and does not look at the config of\n> the containing repository at all[1].\n> \n> As you noted, setting it in the user-level \"--global\" config file\n> would\n> work. You can also override the config via the environment like:\n> \n>   git -c protocol.file.allow=always submodule add ...\n> \n> though note that anybody cloning will need to do the same thing (and\n> of\n> course have the submodule available at the exact same local path!).\n> \n> -Peff\n> \n> [1] There have been discussions in the past on whether submodules\n> should\n>     receive some config from the superproject repository. But there\n> are\n>     a lot of complications, as it is the right thing for some config\n>     keys but not for some others. I doubt we will change the behavior\n>     anytime soon.\n> \n\n\n\n"}]}