Skip to content

Enable the CEF sandbox for Windows browser subprocesses - #56

Open
summeroff wants to merge 4 commits into
streamlabsfrom
security/windows-cef-sandbox
Open

summeroff wants to merge 4 commits into
streamlabsfrom
security/windows-cef-sandbox

Conversation

@summeroff

@summeroff summeroff commented Sep 20, 2026 •

Copy link
Copy Markdown

Summary

  • add a versioned host/plugin ABI for Windows CEF sandbox ownership
  • run CEF child processes through the host executable while retaining the legacy helper only for hosts without the ABI
  • fail closed for incomplete or incompatible advertised sandbox support
  • signal browser-init completion on every failure so frontend waiters do not hang
  • share the subprocess implementation with the legacy helper and add focused selection tests

Validation

  • Debug and RelWithDebInfo obs-browser builds
  • Debug and RelWithDebInfo sandbox-selection tests
  • Debug and RelWithDebInfo CEF sandbox link smoke in the matching obs-studio integration
  • clang-format 19.1.5 over all changed C/C++ files

Security gate

Source and command-line checks do not prove that Chromium children received restricted tokens and job-object confinement. Merge readiness for the complete stack still requires process-token and job-object evidence from the runtime matrix.

Supersedes #55 after the source branch was renamed to remove an internal issue identifier.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Sandbox confinement still requires the stated runtime process-token and job-object evidence.

Review effort: Balanced
Findings: 1 Low severity

Open (1)
What changed in this PR

Enables Windows CEF sandbox ownership through a versioned host/plugin ABI while preserving legacy-host compatibility.

Changes:

  • Adds sandbox ABI discovery, lifecycle handling, and fail-closed initialization.
  • Routes subprocess execution through shared Windows code and adds selection tests.
  • Improves initialization signaling and updates Windows build/CI configuration.
File Description
tests/​obs-browser-sandbox-selection-test.cpp Tests sandbox mode selection.
panel/​browser-panel.cpp Checks explicit initialization state.
obs-browser-subprocess-win.hpp Declares shared subprocess entry point.
obs-browser-subprocess-win.cpp Implements Windows CEF subprocess execution.
obs-browser-sandbox.h Defines the sandbox ABI.
obs-browser-sandbox-selection.hpp Declares sandbox selection helpers.
obs-browser-sandbox-selection.cpp Implements fail-closed selection logic.
obs-browser-plugin.cpp Integrates sandbox and lifecycle handling.
obs-browser-page/​obs-browser-page-main.cpp Reuses shared subprocess implementation.
cmake/​os-windows.cmake Configures sources, runtime, and tests.
browser-client.cpp Formatting-only change.
browser-app.hpp Formatting-only change.
browser-app.cpp Formatting-only change.
.github/​workflows/​pr-pull.yaml Enables PR checks for streamlabs.
.github/​actions/​run-clang-format/​action.yaml Trusts the formatting-tool tap.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread obs-browser-plugin.cpp Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Runtime evidence for restricted tokens and job-object confinement remains required by the stated security gate.

Review effort: Balanced
Findings: None

Resolved since last review (1)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants