Skip to content

Enable the CEF sandbox for Windows browser subprocesses - #55

Closed
summeroff wants to merge 2 commits into
streamlabsfrom
security/h1-2490115-sandbox
Closed

summeroff wants to merge 2 commits into
streamlabsfrom
security/h1-2490115-sandbox

Conversation

@summeroff

@summeroff summeroff commented Sep 18, 2026 •

Copy link
Copy Markdown

Summary

  • add a versioned host/plugin ABI for Windows CEF sandbox ownership
  • run CEF child processes through the host executable while retaining the legacy helper only for hosts without the ABI
  • fail closed for incomplete or incompatible advertised sandbox support
  • signal browser-init completion on every failure so frontend waiters do not hang
  • share the subprocess implementation with the legacy helper and add focused selection tests

Validation

  • Debug and RelWithDebInfo obs-browser builds
  • Debug and RelWithDebInfo sandbox-selection tests
  • Debug and RelWithDebInfo CEF sandbox link smoke in the matching obs-studio integration
  • clang-format 19.1.5 over all eight changed C/C++ files

Security gate

Source and command-line checks do not prove that Chromium children received restricted tokens and job-object confinement. Merge readiness for the complete stack still requires process-token and job-object evidence from the runtime matrix.

@summeroff summeroff closed this Sep 20, 2026
@summeroff
summeroff deleted the security/h1-2490115-sandbox branch September 20, 2026 09:37
@summeroff

Copy link
Copy Markdown
Author

Superseded by #56 after renaming the source branch to remove the internal issue identifier. The commits and review fixes are preserved there.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant