Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

Windows 11 Smart App Control blocks sharp's unsigned libvips DLL during hyperframes snapshot

オープン
#4,845 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る

メンテナーはふだん 1 日以内に返信

まだ誰も着手していません。

評価

難易度
4/5
見積もり時間
3〜5日
初心者へのやさしさ
48/100
issue の種類
バグ
明瞭さ
おおむね明確
活発さ
活発
技術スタック
node.js, typescript
領域
backend, cli

調査の方向性

Start in packages/cli at the snapshot entry point and trace the step that uses sharp; reproduce with the documented npx hyperframes snapshot command on Windows 11 with Smart App Control enabled. Check the Code Integrity events and CLI output, then verify that a blocked native load is reported clearly and snapshot continues without sharp or completes the affected step.

索引モデルが issue の本文から書いたものです。

説明

Summary

On Windows 11 with Smart App Control (SAC) on, Windows Code Integrity refuses to let node.exe
load the libvips DLL bundled with sharp when hyperframes snapshot runs. Windows shows a Smart App
Control warning. render and check are not affected, and snapshot still writes its frame PNGs,
so the failure appears to be in a step that uses sharp, and it is silent in the CLI output.

The DLLs in @img/sharp-win32-x64/lib (libvips-42.dll, libvips-cpp-8.18.7.dll) are not
Authenticode-signed. SAC only lets unsigned code load when Microsoft's cloud reputation service
vouches for it, so the same files can load on one day and be refused on another.

Related to #4654 (studio server loads when sharp's native binary is missing): here the binary is
present but the OS refuses to load it.

Environment

  • Windows 11, Smart App Control on
  • hyperframes 0.8.91 via npx
  • sharp 0.35.5 (dependency sharp ^0.35.0 of packages/cli), @img/sharp-win32-x64

Steps

  1. Windows 11 with Smart App Control on.
  2. npx [email protected] snapshot <project> --at <t1>,<t2> --no-end --describe false

What happens

Windows' Code Integrity log (Microsoft-Windows-CodeIntegrity/Operational, events 3033 and 3077)
records that node.exe attempted to load
node_modules/@img/sharp-win32-x64/lib/libvips-cpp-8.18.7.dll and that it “did not meet the
Windows signing level requirements”. This happened on each snapshot run and on no render run.
The CLI reports no error.

Expected

Either the step works, or the CLI reports that sharp could not be loaded (and why) and continues
without it.

Suggestions

  1. Detect a failed native load of sharp, including this Code Integrity case, and report it clearly,
    as #4654 does for the studio server.
  2. Raise signing with sharp upstream: Microsoft's guidance for SAC is that all shipped binaries,
    DLLs included, are signed with a certificate from the Microsoft Trusted Root Program.
  3. Note the limitation in the Windows docs: SAC cannot allow-list a file, and the only user-side
    workaround is turning SAC off, which cannot be undone without resetting Windows.
主要言語
TypeScript
スター
54.1k
フォーク
4.9k
平均マージ
7時間 18分
マージ済み PR(30日)
784

環境構築

このプロジェクトには開発コンテナ、Dockerfile、コントリビューションガイドがありません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

heygen-com/hyperframes のほかの issue

heygen-com/hyperframes の issue をすべて見る

似ている issue

TypeScript の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。