Skip to content

Commit 16d9b29

Browse files
Copilotseddonym
andauthored
Document Windows Application Control signing limitations
Co-authored-by: seddonym <236623+seddonym@users.noreply.github.com>
1 parent 69c02a7 commit 16d9b29

3 files changed

Lines changed: 37 additions & 0 deletions

File tree

‎AUTHORS.rst‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -13,3 +13,4 @@ Authors
1313
* Nathan McDougall - https://github.com/nathanjmcdougall
1414
* Oleksandr Zaiats - https://github.com/z4y4ts
1515
* Nikhil Dabas - https://github.com/ndabas
16+
* GitHub Copilot - https://github.com/copilot

‎CHANGELOG.rst‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,6 +5,8 @@ Changelog
55
latest
66
------
77

8+
* Document Windows Application Control limitations and protection-preserving
9+
alternatives (https://github.com/python-grimp/grimp/issues/319).
810
* Fix missing macOS wheels for regular (non-freethreaded) Python 3.14+
911
(https://github.com/python-grimp/grimp/issues/317).
1012

‎docs/installation.rst‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -5,3 +5,37 @@ Installation
55
At the command line::
66

77
pip install grimp
8+
9+
Windows Application Control
10+
===========================
11+
12+
Grimp requires a native Rust extension, ``grimp._rustgrimp``. On Windows this is
13+
a ``.pyd`` file. Smart App Control or another Windows Application Control policy
14+
may prevent Python from loading it, with an error such as::
15+
16+
ImportError: DLL load failed while importing _rustgrimp:
17+
An Application Control policy has blocked this file.
18+
19+
The current Windows wheel release process does not publisher-sign the native
20+
extension. Publisher signing would require a trusted code-signing certificate or
21+
signing service and changes to the release process; no signed release date is
22+
currently committed. A wheel's PyPI SHA-256 hash and its ``RECORD`` metadata
23+
can help verify file integrity, but are not Windows code signatures and do not
24+
establish that Windows will allow the extension to load.
25+
26+
There is no Grimp setting or pure-Python fallback that resolves an Application
27+
Control block. Upgrading or building from source does not guarantee that the
28+
resulting extension will be accepted by the policy. Even a valid code signature
29+
does not guarantee acceptance under every policy.
30+
31+
If your policy blocks the extension, there is currently no supported Grimp-only
32+
fix for running it in that Windows environment while retaining the policy.
33+
You can instead run Grimp and Import Linter in a Linux environment, such as a
34+
Linux CI runner, with the same source tree and architecture contracts. This
35+
leaves the Windows protections in place. Do not disable or bypass them to load
36+
the extension.
37+
38+
When reporting a block, please include the Grimp and Python versions, Windows
39+
version and architecture, the wheel filename and hash, and sanitized Code
40+
Integrity event details (for example, events 3077 and 3033). A block reported
41+
for one version does not establish whether another version will be blocked.

0 commit comments

Comments
 (0)