mingw: try to create symlinks without elevated permissions

As of Windows 10 Build 14972 in Developer Mode, a new flag is supported by `CreateSymbolicLink()` to create symbolic links even when running outside of an elevated session (which was previously required). This new flag is called `SYMBOLIC_LINK_FLAG_ALLOW_UNPRIVILEGED_CREATE` and has the numeric value 0x02. Previous Windows 10 versions will not understand that flag and return an `ERROR_INVALID_PARAMETER`, therefore we have to be careful to try passing that flag only when the build number indicates that it is supported. For more information about the new flag, see this blog post: https://blogs.windows.com/buildingapps/2016/12/02/symlinks-windows-10/ Signed-off-by: Johannes Schindelin <johannes.schindelin@gmx.de> Signed-off-by: Junio C Hamano <gitster@pobox.com>

Johannes Schindelin committed Jan 9, 2026 at 20:05 UTC 6206f7aeb0c584c91d226e32d446d6d062fa9674
1 file changed +24 -2
compat/mingw.c
+24 -2
@@ -331,6 +331,8 @@ static const wchar_t *make_relative_to(const wchar_t *path,
331 return out;
332 }
333
334 +static DWORD symlink_file_flags = 0, symlink_directory_flags = 1;
335 +
336 enum phantom_symlink_result {
337 PHANTOM_SYMLINK_RETRY,
338 PHANTOM_SYMLINK_DONE,
@@ -381,7 +383,8 @@ process_phantom_symlink(const wchar_t *wtarget, const wchar_t *wlink)
383 return PHANTOM_SYMLINK_DONE;
384
385 /* otherwise recreate the symlink with directory flag */
384 - if (DeleteFileW(wlink) && CreateSymbolicLinkW(wlink, wtarget, 1))
386 + if (DeleteFileW(wlink) &&
387 + CreateSymbolicLinkW(wlink, wtarget, symlink_directory_flags))
388 return PHANTOM_SYMLINK_DIRECTORY;
389
390 errno = err_win_to_posix(GetLastError());
@@ -2846,7 +2849,7 @@ int symlink(const char *target, const char *link)
2849 wtarget[len] = '\\';
2850
2851 /* create file symlink */
2849 - if (!CreateSymbolicLinkW(wlink, wtarget, 0)) {
2852 + if (!CreateSymbolicLinkW(wlink, wtarget, symlink_file_flags)) {
2853 errno = err_win_to_posix(GetLastError());
2854 return -1;
2855 }
@@ -3523,6 +3526,24 @@ static void maybe_redirect_std_handles(void)
3526 GENERIC_WRITE, FILE_FLAG_NO_BUFFERING);
3527 }
3528
3529 +static void adjust_symlink_flags(void)
3530 +{
3531 + /*
3532 + * Starting with Windows 10 Build 14972, symbolic links can be created
3533 + * using CreateSymbolicLink() without elevation by passing the flag
3534 + * SYMBOLIC_LINK_FLAG_ALLOW_UNPRIVILEGED_CREATE (0x02) as last
3535 + * parameter, provided the Developer Mode has been enabled. Some
3536 + * earlier Windows versions complain about this flag with an
3537 + * ERROR_INVALID_PARAMETER, hence we have to test the build number
3538 + * specifically.
3539 + */
3540 + if (GetVersion() >= 14972 << 16) {
3541 + symlink_file_flags |= 2;
3542 + symlink_directory_flags |= 2;
3543 + }
3544 +
3545 +}
3546 +
3547 #ifdef _MSC_VER
3548 #ifdef _DEBUG
3549 #include <crtdbg.h>
@@ -3558,6 +3579,7 @@ int wmain(int argc, const wchar_t **wargv)
3579 #endif
3580
3581 maybe_redirect_std_handles();
3582 + adjust_symlink_flags();
3583
3584 /* determine size of argv and environ conversion buffer */
3585 maxlen = wcslen(wargv[0]);