Windows 11 Smart App Control blocks sharp's unsigned libvips DLL during hyperframes snapshot
Los mantenedores suelen responder en 1 día
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 4/5
- Tiempo estimado
- 3-5 días
- Aptitud para principiantes
- 48/100
- Tipo de issue
- Error
- Claridad
- Bastante claro
- Estado de actividad
- Activo
- Stack tecnológico
- node.js, typescript
Línea de trabajo
Start in packages/cli at the snapshot entry point and trace the step that uses sharp; reproduce with the documented npx hyperframes snapshot command on Windows 11 with Smart App Control enabled. Check the Code Integrity events and CLI output, then verify that a blocked native load is reported clearly and snapshot continues without sharp or completes the affected step.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Summary
On Windows 11 with Smart App Control (SAC) on, Windows Code Integrity refuses to let node.exe
load the libvips DLL bundled with sharp when hyperframes snapshot runs. Windows shows a Smart App
Control warning. render and check are not affected, and snapshot still writes its frame PNGs,
so the failure appears to be in a step that uses sharp, and it is silent in the CLI output.
The DLLs in @img/sharp-win32-x64/lib (libvips-42.dll, libvips-cpp-8.18.7.dll) are not
Authenticode-signed. SAC only lets unsigned code load when Microsoft's cloud reputation service
vouches for it, so the same files can load on one day and be refused on another.
Related to #4654 (studio server loads when sharp's native binary is missing): here the binary is
present but the OS refuses to load it.
Environment
- Windows 11, Smart App Control on
- hyperframes 0.8.91 via
npx - sharp 0.35.5 (dependency
sharp ^0.35.0ofpackages/cli),@img/sharp-win32-x64
Steps
- Windows 11 with Smart App Control on.
npx [email protected] snapshot <project> --at <t1>,<t2> --no-end --describe false
What happens
Windows' Code Integrity log (Microsoft-Windows-CodeIntegrity/Operational, events 3033 and 3077)
records that node.exe attempted to load
node_modules/@img/sharp-win32-x64/lib/libvips-cpp-8.18.7.dll and that it “did not meet the
Windows signing level requirements”. This happened on each snapshot run and on no render run.
The CLI reports no error.
Expected
Either the step works, or the CLI reports that sharp could not be loaded (and why) and continues
without it.
Suggestions
- Detect a failed native load of sharp, including this Code Integrity case, and report it clearly,
as #4654 does for the studio server. - Raise signing with sharp upstream: Microsoft's guidance for SAC is that all shipped binaries,
DLLs included, are signed with a certificate from the Microsoft Trusted Root Program. - Note the limitation in the Windows docs: SAC cannot allow-list a file, and the only user-side
workaround is turning SAC off, which cannot be undone without resetting Windows.
- Lenguaje dominante
- TypeScript
- Estrellas
- 54.1k
- Forks
- 4.9k
- Merge medio
- 7 h 18 min
- PR fusionados (30 d)
- 784
Preparar el entorno
Este proyecto no incluye contenedor de desarrollo, Dockerfile ni guía de contribución, así que la configuración corre por tu cuenta: empieza por su README y consulta nuestra guía para la primera contribución para los pasos generales.
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de heygen-com/hyperframes
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
heygen-com/hyperframes#5027 ·
Los mantenedores suelen responder en 1 día
-
fix(producer): propagate useGpu to HDR layered streaming encoderPosiblemente ocupada @Monster-GM la tomó hace 1 día. Abierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 87/100
heygen-com/hyperframes#5002 ·
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
heygen-com/hyperframes#4702 · 1 comentario · 1 reacción ·
Los mantenedores suelen responder en 1 día
-
Studio catalog prompt editor has no accessible namePosiblemente ocupada @lorenzozanee la tomó hace 12 días. Abiertobug difficulty/easy triage/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 78/100
heygen-com/hyperframes#4384 ·
Los mantenedores suelen responder en 1 día
-
lint: validate composition variables declared on supported root elementsQuizá libre de nuevo Un pull request para esta issue se cerró sin fusionarse. Abiertobug difficulty/easy triage/ready
Dificultad 2/5 1-3 horas Aptitud para principiantes 88/100
heygen-com/hyperframes#4383 ·
Los mantenedores suelen responder en 1 día
Todos los issues de heygen-com/hyperframes
Issues similares
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 83/100
Los mantenedores suelen responder en 1 día
-
Signals (Failure Detector): a tool call and its own execution are reported as a repeated callAbierto
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 68/100
Los mantenedores suelen responder en 1 día
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 85/100
platformatic/mcp#208 ·
Los mantenedores suelen responder en 1 día
-
🐛 bug
Dificultad 2/5 1-3 horas Aptitud para principiantes 66/100
margelo/react-native-vision-camera#4211 ·
Los mantenedores suelen responder en 4 días