Skip to content

Package and export Windows CEF sandbox support - #773

Closed
summeroff wants to merge 5 commits into
streamlabsfrom
security/h1-2490115-sandbox
Closed

summeroff wants to merge 5 commits into
streamlabsfrom
security/h1-2490115-sandbox

Conversation

@summeroff

@summeroff summeroff commented Sep 18, 2026 •

Copy link
Copy Markdown

Summary

  • consume the CEF 6533 Windows x64 revision 4 archive with the complete sandbox library
  • expose CEF::Sandbox in-tree and relocatable OBS::cef-sandbox metadata in the installed development package
  • gate Windows x64 sandbox packaging by platform and pointer size, independent of the CMake generator
  • install the CEF headers, sandbox ABI header, and Release sandbox library required by downstream hosts
  • package the complete CEF runtime/resource manifest and validate compatibility PDBs in CI
  • add a create/destroy link-smoke target and pin obs-browser PR Check if the replay buffer was saved sucessfully #55
  • skip only the 5.52 GB libcef.dll.pdb during legacy CAB symbol-server ingestion; it remains in the downloadable debug-symbol artifact

Dependency

Published test artifact

Validation

  • cmake --preset windows-x64
  • Debug and RelWithDebInfo builds of obs-browser, the legacy helper, sandbox link smoke, and sandbox-selection test
  • both sandbox-selection and link-smoke executables pass in both configurations
  • full local build/install and downstream package-consumer checks
  • generator-independent package export reviewed for Visual Studio and Ninja compatibility

Security gate

Source and command-line checks do not prove that Chromium children received restricted tokens and job-object confinement. Merge readiness for the complete stack still requires process-token and job-object evidence from the runtime matrix.

@summeroff summeroff closed this Sep 20, 2026
@summeroff
summeroff deleted the security/h1-2490115-sandbox branch September 20, 2026 09:38
@summeroff

Copy link
Copy Markdown
Author

Superseded by #775 after renaming the source branch to remove the internal issue identifier. The commits and review fixes are preserved there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant