| Version | Supported | Notes |
|---|---|---|
| 0.1.x | Yes | Current active release line |
To protect vulnerable assistive technology users and maintain high host application stability:
- No Unsafe DLL Search Paths: The plugin strictly refuses to load native DLLs from
%PATH%, the working directory, or temporary directories. Only verified absolute paths from official Windows Services and installation roots are considered. - Strict PE64 Architecture Verification: Candidate libraries must validate as 64-bit AMD64 PE binaries prior to invoking
LoadLibraryExW. - Authenticode Code-Signing Trust Verification: Discovered
tobii_stream_engine.dllbinaries are verified using the Win32WinVerifyTrustAPI (WINTRUST_ACTION_GENERIC_VERIFY_V2), verifying file integrity and confirming that the certificate belongs to Tobii AB. - Safe Parameterless Instantiation: The plugin constructor executes zero native calls or dynamic allocations, ensuring safe reflection loading by OptiKey.
- Bounded Shutdown & Memory Isolation: Native worker threads run with bounded join timeouts. If native threads are stuck, handle cleanup is safely bypassed to avoid use-after-free host crashes.
If you discover a security vulnerability or code-execution vector:
- Do NOT disclose the issue in public GitHub issues or discussions.
- Send a confidential report detailing reproduction steps to:
yuanweize@users.noreply.github.com. - I aim to acknowledge valid security reports as soon as practical, investigate the root cause, and coordinate a patch.