Windows desktop: request policy attribution for a pre-process diagnostic rejection
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
Environment
- Windows 11 ARM64 running in Parallels.
- Codex desktop app; the previously recorded client version is
26.901.51231. It has not been freshly verified.
Existing rejection
A narrowly scoped, explicitly user-authorized diagnostic was rejected before process creation with blocked by policy.
The intended diagnostic was limited to compiling and loading a test interop DLL and importing a Filesystem module from a temporary mirror. It did not involve signing, Inno Setup, product installation, or permission changes.
The diagnostic did not start. It has not been retried as part of this reporting request. The specific enforcing component, matched rule, and configuration source are unknown; the error alone is not being attributed to PowerShell ExecutionPolicy or a particular Windows security control.
Requested clarification
Please help determine:
- Which component makes this rejection decision, and which implementation/version applies to the desktop app?
- Which rule was matched, and where does that rule or configuration originate?
- Is there a supported review channel for this specific operation, without broadly relaxing permissions or repeating the rejected command?
- If the existing event cannot be located from this summary, what is the minimum necessary event identifier, and how can it be provided without sharing session contents or raw logs?
This is a request to review an existing rejection, not a request for unrestricted access or re-execution.
Privacy boundary
No session records, raw logs, project source, DLLs, local paths, command arguments, environment contents, credentials, or attachments are included. Please specify the minimum necessary metadata before requesting additional diagnostic material.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No files, tests, or code entry points are identified in the issue. Start by identifying the desktop component responsible for the reported pre-process rejection and the relevant event or rule metadata; done means explaining the enforcing component, matched rule, configuration source, and minimum safe diagnostic identifier.
Written by the indexing model from the issue text.
Assessment
- Domain
- desktop, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100