Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Windows sandbox hardening: LPAC, a separate desktop, safe DLL search and narrower grants

Abierto
#158 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

Nadie ha tomado este issue todavía.

Evaluación

Dificultad
5/5
Tiempo estimado
Más de una semana
Aptitud para principiantes
25/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
typescript
Área
security

Línea de trabajo

Start by reading sandbox_windows.ts:157-183 for the PATH grants, then trace the Windows AppContainer sandbox setup and helper startup for the other audit items. The issue lists several independent hardening changes, including LPAC, desktop isolation, DLL search, environment-variable filtering, and grant revocation; determine scope and tests for each before taking one on. Done means implementing and validating the selected security change without widening sandbox access.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

enhancement platform: windows priority: low security severity: low

Hardening items for the Windows AppContainer sandbox from the 2026-10-07 security audit. None is an escape on its own.

  • LPAC. Set PROC_THREAD_ATTRIBUTE_ALL_APPLICATION_PACKAGES_POLICY = PROCESS_CREATION_ALL_APPLICATION_PACKAGES_OPT_OUT. Today the sandbox inherits everything ALL APPLICATION PACKAGES can reach: system folders, HKLM read access, and in-box COM/ALPC/named-pipe endpoints. LPAC needs explicit grants but greatly reduces what the sandbox can talk to.
  • Separate desktop. Use a separate window station and desktop (CreateDesktopW plus lpDesktop). Commands share WinSta0\Default today, so screen capture and keyboard-state polling may be possible (not tested).
  • DLL search order. Call SetDefaultDllDirectories(LOAD_LIBRARY_SEARCH_SYSTEM32) at helper startup, or link with /DEPENDENTLOADFLAG:0x800. The per-user install folder is writable.
  • PATH grants. windowsPolicy.add grants recursive read access to PATH entries inside the home folder (sandbox_windows.ts:157-183). Limit this to folders that hold executables.
  • Env allow-list. sandboxEnvAllowList accepts names that isSecretEnvName matches. Refuse them or ask a second time.
  • Stale grants. Revoke project grants when the app starts for projects no longer in the recent list, and on uninstall.
Lenguaje dominante
TypeScript
Estrellas
2
Forks
2
Merge medio
5 h 28 min
PR fusionados (30 d)
24

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de PierrunoYT/patch

Todos los issues de PierrunoYT/patch

Issues similares

Más issues de TypeScript

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.