go-sql-driver/mysql · error
local file ' ' is not registered
Error message
local file '%s' is not registered
What it means
For plain file paths in LOAD DATA LOCAL INFILE (not Reader::), the driver requires the file be on its allowlist (mysql.RegisterLocalFile) OR the DSN set allowAllFiles=true. Without either, it refuses to read the file from the client machine for security.
Solutions
- Register the exact path with mysql.RegisterLocalFile before the Exec, matching the path the server echoes (it may absolutize it).
- Set '?allowAllFiles=true' in the DSN only in trusted environments where you accept reading any client-side file.
- Ensure the path matches exactly (quotes are trimmed by the driver; watch absolute vs relative).
Example fix
// before
db.Exec("LOAD DATA LOCAL INFILE '/tmp/data.csv' INTO TABLE t")
// after (option A: allowlist)
mysql.RegisterLocalFile("/tmp/data.csv")
db.Exec("LOAD DATA LOCAL INFILE '/tmp/data.csv' INTO TABLE t")
// after (option B: allow all, trusted only)
sql.Open("mysql", "user@tcp(127.0.0.1:3306)/db?allowAllFiles=true") Defensive patterns
Strategy: validation
Validate before calling
// Track which files you allowlisted; match the path used in SQL.
func isAllowed(p string) bool {
abs, _ := filepath.Abs(p)
_, ok := allowedFiles[abs]
return ok
} Type guard
null
Try / catch
// Surface from Exec and guide the user to register or enable allowAllFiles.
if _, err := db.Exec(q); err != nil {
if strings.Contains(err.Error(), "is not registered") {
mysql.RegisterLocalFile(path) // then retry once
}
} Prevention
- Prefer RegisterLocalFile over allowAllFiles for least privilege.
- Register the absolute path to match what the server echoes.
- Avoid allowAllFiles=true in shared/untrusted environments.
When it happens
Trigger: Executing "LOAD DATA LOCAL INFILE '/path/file.csv'" without mysql.RegisterLocalFile("/path/file.csv") and without '?allowAllFiles=true' in the DSN.
Common situations: Forgetting the security allowlist; path mismatch (the server may return an absolute path while you registered a relative one, or vice-versa); default-deny surprising new developers.
Related errors
- reader ' ' is
- reader ' ' is not registered
- invalid value for server pub key name
- invalid value for TLS config name
- key ' ' is reserved
AI-assisted analysis of go-sql-driver/mysql@03d76c7e07 (2026-08-07).
Data as JSON: /api/errors/fb3b1badbd3fe997.
Report an issue: GitHub.
Appendix: source
Thrown at infile.go:141
_, exists := fileRegister[name]
fileRegisterLock.RUnlock()
if mc.cfg.AllowAllFiles || exists {
var file *os.File
var fi os.FileInfo
if file, err = os.Open(name); err == nil {
defer deferredClose(&err, file)
// get file size
if fi, err = file.Stat(); err == nil {
rdr = file
if fileSize := int(fi.Size()); fileSize < packetSize {
packetSize = fileSize
}
}
}
} else {
err = fmt.Errorf("local file '%s' is not registered", name)
}
}
// send content packets
var data []byte
// if packetSize == 0, the Reader contains no data
if err == nil && packetSize > 0 {
data = make([]byte, 4+packetSize)
var n int
for err == nil {
n, err = rdr.Read(data[4:])
if n > 0 {
if ioErr := mc.conn().writePacket(data[:4+n]); ioErr != nil {
return ioErr
}
}
}View on GitHub (pinned to 03d76c7e07)