Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

Windows sandbox hardening: LPAC, a separate desktop, safe DLL search and narrower grants

Open
#158 0 comments 0 reactions 0 assignees View on GitHub

Maintainers usually reply within 1 day

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
25/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
typescript
Domain
security

Research direction

Start by reading sandbox_windows.ts:157-183 for the PATH grants, then trace the Windows AppContainer sandbox setup and helper startup for the other audit items. The issue lists several independent hardening changes, including LPAC, desktop isolation, DLL search, environment-variable filtering, and grant revocation; determine scope and tests for each before taking one on. Done means implementing and validating the selected security change without widening sandbox access.

Written by the indexing model from the issue text.

Description

enhancement platform: windows priority: low security severity: low

Hardening items for the Windows AppContainer sandbox from the 2026-10-07 security audit. None is an escape on its own.

  • LPAC. Set PROC_THREAD_ATTRIBUTE_ALL_APPLICATION_PACKAGES_POLICY = PROCESS_CREATION_ALL_APPLICATION_PACKAGES_OPT_OUT. Today the sandbox inherits everything ALL APPLICATION PACKAGES can reach: system folders, HKLM read access, and in-box COM/ALPC/named-pipe endpoints. LPAC needs explicit grants but greatly reduces what the sandbox can talk to.
  • Separate desktop. Use a separate window station and desktop (CreateDesktopW plus lpDesktop). Commands share WinSta0\Default today, so screen capture and keyboard-state polling may be possible (not tested).
  • DLL search order. Call SetDefaultDllDirectories(LOAD_LIBRARY_SEARCH_SYSTEM32) at helper startup, or link with /DEPENDENTLOADFLAG:0x800. The per-user install folder is writable.
  • PATH grants. windowsPolicy.add grants recursive read access to PATH entries inside the home folder (sandbox_windows.ts:157-183). Limit this to folders that hold executables.
  • Env allow-list. sandboxEnvAllowList accepts names that isSecretEnvName matches. Refuse them or ask a second time.
  • Stale grants. Revoke project grants when the app starts for projects no longer in the recent list, and on uninstall.
Dominant language
TypeScript
Stars
2
Forks
2
Avg merge
5h 28m
Merged PRs (30d)
24

Getting set up

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from PierrunoYT/patch

All issues in PierrunoYT/patch

Similar issues

More TypeScript issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.