Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

[Bug]: Windows Smart App Control blocks Herd PHP 8.4/8.5 unsigned DLLs

Open
#1,757 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
5/5
Estimated time
Over a week
Newbie friendliness
30/100
Issue type
Bug
Clarity
Mostly clear
Activity status
Active
Tech stack
php

Research direction

Start by reproducing the failure with Smart App Control enabled and inspect Windows Event Viewer’s CodeIntegrity Operational log, especially Event ID 3077. Check the Herd PHP executable and extension DLLs under .config\herd\bin\php84 and the corresponding PHP 8.5 path; done means the reported extensions load without requiring Smart App Control to be disabled.

Written by the indexing model from the issue text.

Description

windows
Platform

Windows

Operating system version

Windows 11 25H2

System architecture

Windows

Herd Version

1.30.0

PHP Version

No response

Bug description

When Windows 11 Smart App Control is enabled, PHP installed through Laravel Herd fails to load its extensions because Windows Code Integrity blocks the PHP DLLs.

This affects both PHP 8.4 and PHP 8.5, so it does not appear to be specific to PHP 8.5.

Environment
Windows 11 25H2
Laravel Herd for Windows
PHP 8.4 and PHP 8.5
Smart App Control: Enabled
Symptoms

Running PHP produces errors such as:

PHP Warning: PHP Startup: Unable to load dynamic library 'gd'
(tried: ext\gd (The specified module could not be found),
ext\php_gd.dll (An Application Control policy has blocked this file))

The same occurs with multiple extensions, including:

php_bz2.dll
php_fileinfo.dll
php_gd.dll
php_intl.dll
php_mbstring.dll
php_mysqli.dll
php_openssl.dll
php_pgsql.dll
php_soap.dll
php_sockets.dll

The PHP executable itself starts successfully and reports the expected PHP version.

Disabling Windows Smart App Control immediately resolves the problem.

Code Integrity evidence

Windows Event Viewer → Applications and Services Logs → Microsoft → Windows → CodeIntegrity → Operational reports Event ID 3077.

For example:

Code Integrity determined that a process
(\Device\HarddiskVolume3\Users...\ .config\herd\bin\php84\php-cgi.exe)
attempted to load
\Device\HarddiskVolume3\Users...\ .config\herd\bin\php84\ext\php_gmp.dll
that did not meet the Enterprise signing level requirements
or violated code integrity policy
(Policy ID:{0283AC0F-FFF1-49AE-ADA1-8A933130CAD6}).

The same policy blocks multiple other PHP extensions, including php_mbstring.dll, php_fileinfo.dll, php_ffi.dll, php_opcache.dll, php_zip.dll, php_sqlite3.dll, php_sodium.dll, php_soap.dll, and php_pgsql.dll.

The Herd PHP executable and extension DLLs are not Authenticode-signed.

Expected behavior

Herd's PHP installation should work with Windows Smart App Control enabled, without requiring users to disable a Windows security feature.

Additional information

The issue also occurs with PHP 8.4, not only PHP 8.5. This suggests that the problem may be related to the signing/reputation of Herd's PHP binaries and extensions rather than a PHP 8.5-specific issue.

Disabling Smart App Control allows PHP and all of the extensions to load normally.

Could you please investigate whether Herd's Windows PHP binaries/extensions can be signed or otherwise made compatible with Windows Smart App Control?

Dominant language
No language data
Stars
123
Forks
1
PR merge metrics
No merged PRs in 30d

Getting set up

This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from beyondcode/herd-community

All issues in beyondcode/herd-community

Similar issues

More Operating Systems issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.