Skip to content

Enable the Windows CEF sandbox and update x64 to CEF 6613 - #775

Open
summeroff wants to merge 18 commits into
streamlabsfrom
security/windows-cef-sandbox
Open

summeroff wants to merge 18 commits into
streamlabsfrom
security/windows-cef-sandbox

Conversation

@summeroff

@summeroff summeroff commented Sep 20, 2026 •

Copy link
Copy Markdown

Summary

  • enable the Chromium sandbox for the Windows browser subprocess path and export the sandbox ABI through the installed libobs development package
  • update Windows x64 from CEF 6533 revision 4 to CEF 6613 while leaving macOS, Linux, and Windows ARM64 on their existing platform packages
  • expose CEF::Sandbox in-tree and relocatable OBS::cef-sandbox metadata for downstream hosts such as obs-studio-node
  • gate Windows x64 sandbox packaging by platform and pointer size, independent of the CMake generator
  • package the complete CEF runtime/resource manifest and validate all expected compatibility PDBs
  • add create/destroy link-smoke and sandbox-selection tests and pin Enable the CEF sandbox for Windows browser subprocesses obs-browser#56
  • add reproducible 4 KiB PDB relink/public-symbol tooling for the legacy symbol server
  • rebase the combined sandbox/CEF 6613 work onto current streamlabs (32.1.1sl12)

Dependencies

CEF 6613 artifacts

This PR currently uses the published revision-1 archive:

A smaller revision-2 build with symbol_level=1 and compatible 4 KiB PDB pages is locally complete but not yet uploaded:

  • cef_binary_6613_windows_x64_v2.zip: 875,213,740 bytes, SHA-256 C8FA34997506FC09712EDDDA65E029A3BCC8B673B45E12EEE7A091142F61A8E2
  • cef_binary_6613_windows_x64_v2_symbols.7z: 403,431,623 bytes, SHA-256 A93F4C3B29149971C7BFC3E069D14E9A97F0C25B739666A3B68E6EB5C204624E

The preset must move to revision 2 only after its public URL returns HTTP 200 and the uploaded hash is verified.

libobs integration package

Tag 32.1.1sl12cef1 provides the temporary package used by OSN obsproject#1781:

The public bytes match the GitHub Actions artifact. The archive passes 7z t and contains CEF 128.0.6613.138, OBS::cef-sandbox, cef_sandbox.lib, the sandbox ABI and CEF headers, obs-browser.dll, libcef.dll, and the current gs_save_png_file API required by OSN staging.

Symbol strategy

Chromium 128's bundled lld-link advertises /PDBSTRIPPED but rejects it as unimplemented. Its default 8 KiB-page PDB produces EC_FORMAT with the installed pdbcopy 14.00.23615. Relink-CefWithCompatiblePdb.ps1 safely repeats only the final link from Ninja's exact response file with 4 KiB PDB pages, without changing the source build outputs. Create-CefPublicPdb.ps1 then uses the supported Windows SDK pdbcopy -p flow, verifies GUID/age identity and stripped state with llvm-pdbutil, enforces the CAB size ceiling, and replaces only the symbol-server job's temporary copy. The private PDB remains in the downloadable artifacts.

Validation

  • rebased commit range is patch-equivalent to the original Enable the Windows CEF sandbox and update x64 to CEF 6613 #775 + Update Windows x64 to CEF 6613 #774 stack
  • cmake --preset windows-x64 succeeds against current 32.1.1sl12
  • RelWithDebInfo builds pass for obs-browser, obs-browser-helper, obs-browser-sandbox-selection-test, and cef-sandbox-link-smoke
  • both sandbox tests pass locally (2/2)
  • CEF 6613 revision-1 public URL and SHA-256 verified
  • CEF 6613 revision-2 runtime and symbols archives pass 7z t; all eight PDB paths are retained and byte-identical between archives
  • relinked DLL/private PDB match: GUID {345868A3-286C-82CA-4C4C-44205044422E}, age 1, 4 KiB blocks
  • the 2,204,463,104-byte private PDB converts to a matching stripped 383,627,264-byte public PDB and a valid single-CAB symbol-server entry
  • the 32.1.1sl12cef1 tag run passed Windows, both macOS builds, libobs publication, public CEF-symbol creation, and symbol-server ingestion
  • refreshed PR CI passes Windows, both macOS builds, formatting, compatibility/services validation, and CodeQL

Remaining gates

  • upload CEF 6613 revision 2 and verify the public URL/hash before switching the preset

  • record restricted-token and job-object evidence for every supported CEF child class; absence of --no-sandbox alone is not closure evidence

  • run a real Crashpad crash-report smoke test in the complete downstream stack

Supersedes #773 after the source branch was renamed to remove an internal issue identifier.

@summeroff
summeroff force-pushed the security/windows-cef-sandbox branch from 346dba1 to 343b64d Compare October 1, 2026 23:14
@summeroff summeroff changed the title Package and export Windows CEF sandbox support Enable the Windows CEF sandbox and update x64 to CEF 6613 Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The relink path can select the wrong linker, and an active tag workflow bypasses public-PDB conversion.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Enables Windows CEF sandbox integration, upgrades Windows x64 to CEF 6613, and adds downstream packaging and symbol tooling.

Changes:

  • Exports in-tree and installed CEF sandbox targets.
  • Packages complete CEF runtimes and validates symbols.
  • Adds compatible public-PDB generation and sandbox smoke tests.
File Description
.github/​actions/​streamlabs-windows-artifacts/​action.yaml Validates and packages CEF symbols.
.github/​actions/​upload-debug-symbols/​action.yaml Adds PDB exclusion support.
.github/​scripts/​Create-CefPublicPdb.ps1 Generates validated public PDBs.
.github/​scripts/​Relink-CefWithCompatiblePdb.ps1 Relinks CEF with 4 KiB PDB pages.
.github/​workflows/​main-streamlabs.yml Updates legacy CI to CEF 6613.
.github/​workflows/​main.yml Updates Windows CEF cache/build versions.
.github/​workflows/​streamlabs-windows-release.yaml Converts CEF symbols before upload.
CMakePresets.json Selects CEF 6613 for Windows x64.
cmake/​common/​buildspec_common.cmake Supports platform-specific dependency versions.
cmake/​finders/​FindCEF.cmake Defines the CEF sandbox target.
cmake/​windows/​cef-sandbox-link-smoke.cpp Tests sandbox lifecycle linking.
cmake/​windows/​helpers.cmake Packages CEF runtime and sandbox development files.
libobs/​cmake/​libobsConfig.cmake.in Exports relocatable sandbox metadata.
plugins/​obs-browser Pins the sandbox-enabled browser integration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/main-streamlabs.yml
Comment thread .github/scripts/Relink-CefWithCompatiblePdb.ps1 Outdated
Comment thread cmake/finders/FindCEF.cmake Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Existing build trees can retain cached CEF 6533 paths and combine them with the newly selected 6613 sandbox.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (3)

Comment thread cmake/common/buildspec_common.cmake

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Package-discovery regressions, response-file overwrite risk, and incomplete test-target dependencies remain unresolved.

Review effort: Balanced
Findings: 3 High severity · 1 Medium severity

Open (4)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Add cef-sandbox-link-smoke to the BUILD_TESTING tests target

cmake/​windows/​helpers.cmake:225

Add cef-sandbox-link-smoke to the tests target when BUILD_TESTING is enabled. The documented Windows sequence builds only --target tests before running CTest (test/libobs/README.md:12–14,32–34). This executable is not in that dependency graph, so on a clean build CTest registers it but reports it as Not Run because the executable is missing.

Comment thread .github/scripts/Relink-CefWithCompatiblePdb.ps1 Outdated
Comment thread libobs/cmake/libobsConfig.cmake.in Outdated
Comment thread libobs/cmake/libobsConfig.cmake.in

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Sandbox confinement and downstream Crashpad validation remain outstanding, alongside unresolved discovery and PDB-preservation issues.

Review effort: Balanced
Findings: 3 High severity · 1 Medium severity

Open (4)
Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Load Windows runtime manifest for 32-bit configurations

cmake/​finders/​FindCEF.cmake:115

Windows browser packaging now requires CEF_BINARY_FILES and CEF_RESOURCE_FILES (cmake/windows/helpers.cmake:120), but this include loads them only when the 64-bit sandbox is required. A 32-bit Windows browser configuration therefore fails the new manifest check even when its CEF distribution supplies the manifest. Load the Windows runtime manifest independently of the sandbox requirement.

Comment thread .github/scripts/Create-CefPublicPdb.ps1
Comment thread cmake/finders/FindCEF.cmake

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Sandbox confinement and downstream Crashpad validation remain outstanding, alongside an unresolved installed-package lookup defect.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (4)

Comment thread libobs/cmake/libobsConfig.cmake.in

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Runtime sandbox confinement evidence and end-to-end Crashpad validation remain outstanding for this security-sensitive integration.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants