[Bug]: Windows Smart App Control blocks Herd PHP 8.4/8.5 unsigned DLLs
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 5/5
- Tiempo estimado
- Más de una semana
- Aptitud para principiantes
- 30/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- php
- Área
- operating-systems, security
Línea de trabajo
Start by reproducing the failure with Smart App Control enabled and inspect Windows Event Viewer’s CodeIntegrity Operational log, especially Event ID 3077. Check the Herd PHP executable and extension DLLs under .config\herd\bin\php84 and the corresponding PHP 8.5 path; done means the reported extensions load without requiring Smart App Control to be disabled.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Platform
Windows
Operating system version
Windows 11 25H2
System architecture
Windows
Herd Version
1.30.0
PHP Version
No response
Bug description
When Windows 11 Smart App Control is enabled, PHP installed through Laravel Herd fails to load its extensions because Windows Code Integrity blocks the PHP DLLs.
This affects both PHP 8.4 and PHP 8.5, so it does not appear to be specific to PHP 8.5.
Environment
Windows 11 25H2
Laravel Herd for Windows
PHP 8.4 and PHP 8.5
Smart App Control: Enabled
Symptoms
Running PHP produces errors such as:
PHP Warning: PHP Startup: Unable to load dynamic library 'gd'
(tried: ext\gd (The specified module could not be found),
ext\php_gd.dll (An Application Control policy has blocked this file))
The same occurs with multiple extensions, including:
php_bz2.dll
php_fileinfo.dll
php_gd.dll
php_intl.dll
php_mbstring.dll
php_mysqli.dll
php_openssl.dll
php_pgsql.dll
php_soap.dll
php_sockets.dll
The PHP executable itself starts successfully and reports the expected PHP version.
Disabling Windows Smart App Control immediately resolves the problem.
Code Integrity evidence
Windows Event Viewer → Applications and Services Logs → Microsoft → Windows → CodeIntegrity → Operational reports Event ID 3077.
For example:
Code Integrity determined that a process
(\Device\HarddiskVolume3\Users...\ .config\herd\bin\php84\php-cgi.exe)
attempted to load
\Device\HarddiskVolume3\Users...\ .config\herd\bin\php84\ext\php_gmp.dll
that did not meet the Enterprise signing level requirements
or violated code integrity policy
(Policy ID:{0283AC0F-FFF1-49AE-ADA1-8A933130CAD6}).
The same policy blocks multiple other PHP extensions, including php_mbstring.dll, php_fileinfo.dll, php_ffi.dll, php_opcache.dll, php_zip.dll, php_sqlite3.dll, php_sodium.dll, php_soap.dll, and php_pgsql.dll.
The Herd PHP executable and extension DLLs are not Authenticode-signed.
Expected behavior
Herd's PHP installation should work with Windows Smart App Control enabled, without requiring users to disable a Windows security feature.
Additional information
The issue also occurs with PHP 8.4, not only PHP 8.5. This suggests that the problem may be related to the signing/reputation of Herd's PHP binaries and extensions rather than a PHP 8.5-specific issue.
Disabling Smart App Control allows PHP and all of the extensions to load normally.
Could you please investigate whether Herd's Windows PHP binaries/extensions can be signed or otherwise made compatible with Windows Smart App Control?
- Lenguaje dominante
- Sin datos de lenguaje
- Estrellas
- 123
- Forks
- 1
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de beyondcode/herd-community
-
[Bug]: PHP 8.3 php.ini missing auto_prepend_file and herd-ext extension lines (dump() undefined)AbiertomacOS
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
beyondcode/herd-community#1693 ·
-
macOS
Dificultad 2/5 1-3 horas Aptitud para principiantes 72/100
beyondcode/herd-community#1602 ·
-
fixed-in-next-release macOS
Dificultad 3/5 1-2 días Aptitud para principiantes 58/100
beyondcode/herd-community#1760 ·
-
macOS
Dificultad 4/5 3-5 días Aptitud para principiantes 35/100
beyondcode/herd-community#1755 ·
-
macOS
Dificultad 3/5 1-2 días Aptitud para principiantes 64/100
beyondcode/herd-community#1753 ·
Todos los issues de beyondcode/herd-community
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 88/100
Los mantenedores suelen responder en 1 día
-
area:runtime bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 82/100
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
crmne/zapfast#446 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
ChrisTitusTech/winutil#5145 ·
Los mantenedores suelen responder en 6 días
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 85/100