Skip to content

fix(native-host): register a .cmd host that Smart App Control allows - #43

Merged
wolfgang-aura merged 1 commit into
mainfrom
fix/native-host-cmd
Oct 5, 2026
Merged

wolfgang-aura merged 1 commit into
mainfrom
fix/native-host-cmd

Conversation

@wolfgang-aura

Copy link
Copy Markdown
Owner

Fixes #8.

Cause: scripts/install-native-host.ps1 compiled native-host/launcher.cs into an unsigned exe. Smart App Control blocks unsigned binaries and has no per-file allowlist, so Code Integrity logged 3033/3077 every 30 s (the extension's reconnect alarm) and the bridge never connected.

Fix:

  • Register a two-line ASCII .cmd that runs the signed node.exe (OpenJS Foundation). The installer removes the old exe and node-path.txt. launcher.cs is deleted.
  • The installer exits nonzero when it runs inside a packaged app's container. There, writes to %LOCALAPPDATA% and HKCU go to %LOCALAPPDATA%\Packages\<app>\LocalCache\..., which a normally started browser never sees. Before this change it printed success anyway.
  • A new check in test/native-host.test.mjs confirms the host exits and frees the pipe when the browser's stdin ends. That is now the only orphan guard.

Verified:

  • npm test, lint, and format pass.
  • Live (Brave, Smart App Control on, browser started inside the Claude app container): --ping answered by extension v1.6.5, and Code Integrity logged no blocks after the switch.
  • Not yet verified: an owner-started browser. That needs the installer run once from an ordinary PowerShell window.

🤖 Generated with Claude Code

The installer compiled native-host/launcher.cs into an unsigned exe, and
Smart App Control blocked it on every reconnect, so unattended capture
could never reach the extension. Register a two-line ASCII .cmd that runs
the signed node.exe instead, and remove the old exe on reinstall.

The note that Chromium is unreliable with .cmd hosts dates from a .cmd
registered through a BOM-prefixed manifest, which Chromium rejects on its
own; the manifest is BOM-free now.

The installer also refuses to report success when its shell runs inside
a packaged app's container (the Claude desktop app), where the files and
HKCU keys land in a private copy a normally started browser never sees.

Adds a regression check that the host exits and frees the pipe when the
browser's stdin ends, the orphan guard the launcher used to duplicate.

Fixes #8

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@wolfgang-aura
wolfgang-aura merged commit e5fdac5 into main Oct 5, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Unattended capture: Smart App Control blocks the unsigned native host exe

1 participant