Skip to content

Windows Application Control blocks Grimp native extension — signed Windows wheels? #319

Description

@aibidapo

Hello Grimp maintainers,

We encountered a Windows Application Control block when Import Linter loaded Grimp’s native extension.

Environment

  • Windows with Smart App Control enabled
  • Python 3.12, Windows x64
  • Import Linter 2.14
  • Grimp 3.16

Observed error

ImportError: DLL load failed while importing _rustgrimp:
An Application Control policy has blocked this file.

Windows Code Integrity events 3077 and 3033 identified _rustgrimp.cp312-win_amd64.pyd as the blocked file. Its hash and size match the installed package’s RECORD metadata; Windows reports it as unsigned.

We also inspected the published Grimp 3.17 CPython 3.12 Windows x64 wheel after verifying its PyPI SHA-256. Its native extension has no embedded PE certificate table. We have not installed or executed 3.17, so we cannot confirm whether Windows would block that version. Catalog signatures and cloud reputation were not evaluated.

Could you advise whether:

  1. Publisher-signed Windows wheels are available or planned?
  2. There is a supported way to use Grimp with Smart App Control enabled that does not require disabling or bypassing Windows protections?

We would like to retain Grimp and our existing architecture contracts. We can provide artifact hashes and sanitized Code Integrity event details if helpful.

Thank you.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions