Skip to content

Enable the Windows CEF sandbox and update x64 to CEF 6613 - #775

Open
summeroff wants to merge 20 commits into
streamlabsfrom
security/windows-cef-sandbox
Open

summeroff wants to merge 20 commits into
streamlabsfrom
security/windows-cef-sandbox

Conversation

@summeroff

@summeroff summeroff commented Sep 20, 2026 •

Copy link
Copy Markdown

Summary

  • enable the Chromium sandbox for the Windows browser subprocess path and export the sandbox ABI through the installed libobs development package
  • update Windows x64 from CEF 6533 revision 4 to CEF 6613 while leaving macOS, Linux, and Windows ARM64 on their existing platform packages
  • expose CEF::Sandbox in-tree and relocatable OBS::cef-sandbox metadata for downstream hosts such as obs-studio-node
  • gate Windows x64 sandbox packaging by platform and pointer size, independent of the CMake generator
  • package the complete CEF runtime/resource manifest and validate all expected compatibility PDBs
  • add create/destroy link-smoke and sandbox-selection tests and pin Enable the CEF sandbox for Windows browser subprocesses obs-browser#56
  • add reproducible 4 KiB PDB relink/public-symbol tooling for the legacy symbol server
  • rebase the combined sandbox/CEF 6613 work onto current streamlabs (32.1.1sl12)

Dependencies

CEF 6613 artifact

The Windows x64 preset uses the published revision-3 archive:

The legacy Streamlabs Windows CI workflows also select revision 3.

Revision 3 rebuilds Release/libcef.dll with native pointers for the two SandboxInterfaceInfo service fields. This matches the layout of the separately built sandbox archive used by this package. The root-flat Release-only package retains the revision-2 runtime/resource paths, headers, wrapper library, sandbox archive, and eight private PDB paths; only Release/libcef.dll and its PDB changed from revision 2.

libobs integration package

Tag 32.1.1sl12cef1 provides the earlier revision-1 package used by OSN obsproject#1781; it has not been rebuilt with revision 3:

The public bytes match the GitHub Actions artifact. The archive passes 7z t and contains CEF 128.0.6613.138, OBS::cef-sandbox, cef_sandbox.lib, the sandbox ABI and CEF headers, obs-browser.dll, libcef.dll, and the current gs_save_png_file API required by OSN staging.

Symbol strategy

Chromium 128's bundled lld-link advertises /PDBSTRIPPED but rejects it as unimplemented. Its default 8 KiB-page PDB produces EC_FORMAT with the installed pdbcopy 14.00.23615. Relink-CefWithCompatiblePdb.ps1 safely repeats only the final link from Ninja's exact response file with 4 KiB PDB pages, without changing the source build outputs. Create-CefPublicPdb.ps1 then uses the supported Windows SDK pdbcopy -p flow, verifies GUID/age identity and stripped state with llvm-pdbutil, enforces the CAB size ceiling, and replaces only the symbol-server job's temporary copy. The private PDB remains in the downloadable artifacts.

Validation

  • rebased commit range is patch-equivalent to the original Enable the Windows CEF sandbox and update x64 to CEF 6613 #775 + Update Windows x64 to CEF 6613 #774 stack
  • before the revision-3 pin, cmake --preset windows-x64 succeeded against 32.1.1sl12, RelWithDebInfo builds passed for obs-browser, obs-browser-helper, obs-browser-sandbox-selection-test, and cef-sandbox-link-smoke, and both sandbox tests passed locally (2/2)
  • revision-3 public URL returns HTTP 200 with the expected content length; uploaded SHA-256 verified against the local package
  • revision-3 build completed all 35,267 Ninja actions; runtime and symbols archives pass 7z t, and all eight private PDB paths are retained
  • revision-3 DLL/private PDB match: GUID {BFB94E47-B7AB-03C6-4C4C-44205044422E}, age 1, 4 KiB PDB pages; symchk reports PDB Matched: TRUE
  • earlier revision-2 symbol work converted its 2,204,463,104-byte private PDB to a matching stripped 383,627,264-byte public PDB and a valid single-CAB symbol-server entry
  • the earlier 32.1.1sl12cef1 tag run passed Windows, both macOS builds, libobs publication, public CEF-symbol creation, and symbol-server ingestion
  • CI for the earlier pin passed Windows, both macOS builds, formatting, compatibility/services validation, and CodeQL; CI for revision 3 is pending

Remaining gates

Supersedes #773 after the source branch was renamed to remove an internal issue identifier.

@summeroff
summeroff force-pushed the security/windows-cef-sandbox branch from 346dba1 to 343b64d Compare October 1, 2026 23:14
@summeroff summeroff changed the title Package and export Windows CEF sandbox support Enable the Windows CEF sandbox and update x64 to CEF 6613 Oct 1, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The relink path can select the wrong linker, and an active tag workflow bypasses public-PDB conversion.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Enables Windows CEF sandbox integration, upgrades Windows x64 to CEF 6613, and adds downstream packaging and symbol tooling.

Changes:

  • Exports in-tree and installed CEF sandbox targets.
  • Packages complete CEF runtimes and validates symbols.
  • Adds compatible public-PDB generation and sandbox smoke tests.
File Description
.github/​actions/​streamlabs-windows-artifacts/​action.yaml Validates and packages CEF symbols.
.github/​actions/​upload-debug-symbols/​action.yaml Adds PDB exclusion support.
.github/​scripts/​Create-CefPublicPdb.ps1 Generates validated public PDBs.
.github/​scripts/​Relink-CefWithCompatiblePdb.ps1 Relinks CEF with 4 KiB PDB pages.
.github/​workflows/​main-streamlabs.yml Updates legacy CI to CEF 6613.
.github/​workflows/​main.yml Updates Windows CEF cache/build versions.
.github/​workflows/​streamlabs-windows-release.yaml Converts CEF symbols before upload.
CMakePresets.json Selects CEF 6613 for Windows x64.
cmake/​common/​buildspec_common.cmake Supports platform-specific dependency versions.
cmake/​finders/​FindCEF.cmake Defines the CEF sandbox target.
cmake/​windows/​cef-sandbox-link-smoke.cpp Tests sandbox lifecycle linking.
cmake/​windows/​helpers.cmake Packages CEF runtime and sandbox development files.
libobs/​cmake/​libobsConfig.cmake.in Exports relocatable sandbox metadata.
plugins/​obs-browser Pins the sandbox-enabled browser integration.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/workflows/main-streamlabs.yml Outdated
Comment thread .github/scripts/Relink-CefWithCompatiblePdb.ps1 Outdated
Comment thread cmake/finders/FindCEF.cmake Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Existing build trees can retain cached CEF 6533 paths and combine them with the newly selected 6613 sandbox.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (3)

Comment thread cmake/common/buildspec_common.cmake

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Package-discovery regressions, response-file overwrite risk, and incomplete test-target dependencies remain unresolved.

Review effort: Balanced
Findings: 3 High severity · 1 Medium severity

Open (4)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Add cef-sandbox-link-smoke to the BUILD_TESTING tests target

cmake/​windows/​helpers.cmake:225

Add cef-sandbox-link-smoke to the tests target when BUILD_TESTING is enabled. The documented Windows sequence builds only --target tests before running CTest (test/libobs/README.md:12–14,32–34). This executable is not in that dependency graph, so on a clean build CTest registers it but reports it as Not Run because the executable is missing.

Comment thread .github/scripts/Relink-CefWithCompatiblePdb.ps1 Outdated
Comment thread libobs/cmake/libobsConfig.cmake.in Outdated
Comment thread libobs/cmake/libobsConfig.cmake.in

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Sandbox confinement and downstream Crashpad validation remain outstanding, alongside unresolved discovery and PDB-preservation issues.

Review effort: Balanced
Findings: 3 High severity · 1 Medium severity

Open (4)
Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Load Windows runtime manifest for 32-bit configurations

cmake/​finders/​FindCEF.cmake:115

Windows browser packaging now requires CEF_BINARY_FILES and CEF_RESOURCE_FILES (cmake/windows/helpers.cmake:120), but this include loads them only when the 64-bit sandbox is required. A 32-bit Windows browser configuration therefore fails the new manifest check even when its CEF distribution supplies the manifest. Load the Windows runtime manifest independently of the sandbox requirement.

Comment thread .github/scripts/Create-CefPublicPdb.ps1
Comment thread cmake/finders/FindCEF.cmake

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Sandbox confinement and downstream Crashpad validation remain outstanding, alongside an unresolved installed-package lookup defect.

Review effort: Balanced
Findings: 1 High severity

Open (1)
Resolved since last review (4)

Comment thread libobs/cmake/libobsConfig.cmake.in

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Runtime sandbox confinement evidence and end-to-end Crashpad validation remain outstanding for this security-sensitive integration.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants