Skip to content

Allow /currentuser to override privilege escalation - #751

Closed
mrclary wants to merge 2 commits into
git-for-windows:mainfrom
mrclary:currentuser
Closed

mrclary wants to merge 2 commits into
git-for-windows:mainfrom
mrclary:currentuser

Conversation

@mrclary

@mrclary mrclary commented Sep 29, 2026 •

Copy link
Copy Markdown

Currently, the installer will install Git for all users (registered in HKLM) if a user is a member of the administrators group, even if privileges are not elevated when the installer is invoked. /currentuser has no effect in this regard, effectively prohibiting members of admin group from installing for the their current user only.

Adding PrivilegesRequiredOverridesAllowed=dialog should allow the /currentuser flag to override privilege escalation and install for the current user without a UAC prompt. This will also extend the option to users using the GUI.

Signed-off-by: Ryan Clary <9618975+mrclary@users.noreply.github.com>
Signed-off-by: Ryan Clary <9618975+mrclary@users.noreply.github.com>
@dscho

dscho commented Sep 30, 2026

Copy link
Copy Markdown
Member

I'm afraid that there are multiple misunderstandings here:

  • When you sign off on a commit and put a bogus email address, it immediately breaks the intention of that sign-off. The idea of the sign-off is that you can be contacted about this change. A bogus email won't allow that.
  • Git for Windows does not support user installations. They must be system-wide. One major reason for that is integration with third-party software that uses MinGit. MinGit needs to be able to re-use the system config of the installed Git for Windows, which is not possible with user wide installations. It's only possible with installations in C:\Program Files\Git, Otherwise, the relatively simplistic syntax of Git's config include rules won't allow the configuration that the user chose in Git for Windows while installing to be shared with MinGit.

So I am afraid that I cannot accept this change. It would elevate something that we cannot support to a supported status. I cannot allow that.

@dscho dscho closed this Sep 30, 2026
@mrclary

mrclary commented Sep 30, 2026

Copy link
Copy Markdown
Author
  • When you sign off on a commit and put a bogus email address, it immediately breaks the intention of that sign-off. The idea of the sign-off is that you can be contacted about this change. A bogus email won't allow that.

Sorry about that.

  • Git for Windows does not support user installations. They must be system-wide. One major reason for that is integration with third-party software that uses MinGit. MinGit needs to be able to re-use the system config of the installed Git for Windows, which is not possible with user wide installations. It's only possible with installations in C:\Program Files\Git, Otherwise, the relatively simplistic syntax of Git's config include rules won't allow the configuration that the user chose in Git for Windows while installing to be shared with MinGit.

Thank you for clarifying.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants