Skip to content

Update Windows x64 to CEF 6613 - #774

Closed
summeroff wants to merge 0 commit into
security/windows-cef-sandboxfrom
deps/cef-6613-windows-x64
Closed

summeroff wants to merge 0 commit into
security/windows-cef-sandboxfrom
deps/cef-6613-windows-x64

Conversation

@summeroff

@summeroff summeroff commented Sep 18, 2026 •

Copy link
Copy Markdown

Folded into #775. The CEF 6613 commits were rebased with the sandbox stack onto current streamlabs and are now reviewed and built from #775. This stacked PR is closed with no remaining diff.

Summary

  • update only the Windows x64 CEF dependency from 6533 v4 to 6613
  • add a backward-compatible per-platform dependency version override so macOS, Linux, and Windows ARM64 remain on their existing CEF packages
  • teach Windows symbol validation to use the selected platform-specific CEF version
  • generate a GUID/age-matched public libcef PDB in the symbol-upload staging tree, while retaining private symbols in the downloadable artifact
  • add a reproducible link-only helper that converts Chromium's 8 KiB PDB layout to 4 KiB before public-symbol extraction
  • update the legacy Windows cache key to 6613

Artifact

CEF 6613 revision 2 is built and locally verified, but is not yet uploaded to the public CEF bucket:

  • cef_binary_6613_windows_x64_v2.zip
  • size: 875,213,740 bytes
  • SHA-256: C8FA34997506FC09712EDDDA65E029A3BCC8B673B45E12EEE7A091142F61A8E2
  • companion symbols: 403,431,623 bytes, SHA-256 A93F4C3B29149971C7BFC3E069D14E9A97F0C25B739666A3B68E6EB5C204624E

The preset intentionally remains on revision 1 until the v2 runtime archive is uploaded and its public URL returns HTTP 200. The final revision-2 hash above must then replace the revision-1 value before this PR is marked ready.

Dependency

Symbol strategy

Chromium 128's bundled lld-link advertises /PDBSTRIPPED but rejects it as unimplemented. Its default 8 KiB-page PDB also produces EC_FORMAT with the installed pdbcopy 14.00.23615. Relink-CefWithCompatiblePdb.ps1 safely repeats only the final link from Ninja's exact response file with 4 KiB PDB pages, without changing the source build outputs. Create-CefPublicPdb.ps1 then uses the supported Windows SDK pdbcopy -p flow, verifies GUID/age identity and stripped state with llvm-pdbutil, enforces the CAB size ceiling, and replaces only the symbol-server job's temporary copy. The original private PDB remains in both downloadable artifacts.

Validation

  • Release-only CEF 6613 build with symbol_level=1; no Debug payload
  • final runtime archive is root-flat and has the same 1,097 paths as revision 1; only Release/libcef.dll and its PDB changed
  • both runtime and symbols archives pass 7z t; all eight PDB paths are retained and byte-identical between archives
  • relinked DLL/private PDB match: GUID {345868A3-286C-82CA-4C4C-44205044422E}, age 1, 4 KiB blocks
  • exact 2,204,463,104-byte private PDB converts to a matching stripped 383,627,264-byte public PDB
  • the public PDB compresses to one valid 55,858,032-byte CAB
  • end-to-end symstore.exe add /compress accepts it and creates the expected GUID/age-keyed 55,858,025-byte single-file store entry
  • libcef import and export sets are unchanged by the link-only page-size conversion
  • revision 1 configured and built successfully with CEF 128.0.0, including Debug and RelWithDebInfo browser/sandbox targets and tests

Remaining gates

  • upload revision 2 and verify the public URL/hash before updating CMakePresets.json
  • run the tag release workflow to exercise the complete public-PDB symbol upload
  • retain draft status until the complete sandbox stack has real restricted-token and job-object evidence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant