Skip to content

Host sandboxed CEF 6613 subprocesses in obs64 - #1781

Draft
summeroff wants to merge 8 commits into
stagingfrom
security/windows-cef-sandbox
Draft

summeroff wants to merge 8 commits into
stagingfrom
security/windows-cef-sandbox

Conversation

@summeroff

@summeroff summeroff commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

  • classify and dispatch CEF child invocations before normal OSN startup
  • export the versioned sandbox lifecycle ABI from obs64.exe and link the host to OBS::cef-sandbox
  • load only the packaged obs-browser.dll for child dispatch and reject malformed, unknown, duplicate, or --no-sandbox invocations
  • leave the CEF/browser DLL chain loaded after CefExecuteProcess returns, avoiding child-exit unload races
  • isolate the /MD Crashpad implementation in osn-crashpad-bridge.dll so the /MT CEF sandbox can link safely
  • scope /MT to obs64.exe and its static link closure; retain /MD and /MDd for the Electron addon and its IPC archive
  • add focused subprocess-classification, argument-logging, install-path, and CRT guards
  • rebase the implementation onto current staging (0.27.19 / Electron 43.7.6)
  • update the integration to the consolidated CEF 6613 obs-studio stack

Dependencies and test package

The older 32.1.1sl10cef2 test package from #1780 cannot build current staging: osn-screenshot.cpp now uses gs_save_png_file, which requires libobs sl12.

This PR remains draft until runtime evidence confirms restricted process tokens and job-object confinement for renderer, GPU, utility-service, and Crashpad children. Absence of --no-sandbox is not closure evidence.

CRT boundary

lib-streamlabs-ipc is built twice because it links into both the Electron addon and obs64.exe. The addon variant remains /MD or /MDd; the obs64.exe variant and host static closure use /MT. The Crashpad bridge exposes a C-only synchronous boundary: no CRT allocation, C++ object, FILE*, fd/HANDLE ownership, or errno state crosses it.

Validation

  • the 32.1.1sl12cef3 Windows build/publication and both macOS producer jobs passed
  • the public package downloads successfully and matches the size and SHA-256 above
  • 7z t passes; the archive contains CEF 128.0.6613.138, OBS::cef-sandbox, cef_sandbox.lib, the sandbox ABI and CEF headers, obs-browser.dll, libcef.dll, and gs_save_png_file
  • previous CI on 32.1.1sl12cef2 passed Windows and both macOS builds/tests
  • generated JavaScript is current and git diff --check passes after rebasing onto current staging
  • the earlier CI run demonstrated that the only Windows compile blocker with sl10cef2 was the expected missing gs_save_png_file API; this pin supplies it
  • prior local Release builds passed for lib-streamlabs-ipc-obs64, server unit tests, obs64.exe, and obs_studio_client.node; the server suite passed 25/25 and the focused CEF suite passed 5/5
  • generated projects confirmed Release addon /MD, Debug addon /MDd with _DEBUG retained, and the obs64.exe link closure /MT

Remaining release gates

  • replace the temporary libobs pin after Update libobs to v26.1.8 #775 merges and the final package is published
  • record token restrictions and job membership for every supported CEF child class, including service-sandbox-type=none and the embedded Crashpad handler
  • run a real Crashpad crash-report smoke test
  • measure per-renderer working set and browser-source startup latency now that children load the obs64.exe dependency chain
  • canonical install-path checks resist junction redirection but do not make an attacker-writable install root trustworthy

Supersedes #1779 after the source branch was renamed to remove an internal issue identifier.

@summeroff summeroff changed the title Host sandboxed CEF subprocesses in obs64 Host sandboxed CEF 6613 subprocesses in obs64 Oct 1, 2026
@summeroff
summeroff requested a balanced review from Copilot October 2, 2026 16:15

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Runtime sandbox-token, job-object, Crashpad, and performance validation remain explicit release gates.

Review effort: Balanced
Findings: None

What changed in this PR

Hosts Windows CEF subprocesses in obs64.exe with sandbox lifecycle support while isolating incompatible CRT dependencies.

Changes:

  • Adds strict CEF child classification and packaged browser-plugin dispatch.
  • Introduces a /MD Crashpad bridge while moving the host closure to /MT.
  • Adds focused tests, packaging updates, and a temporary CEF-enabled libobs pin.
File Description
.github/​workflows/​main.yml Pins the CEF-enabled libobs package.
CMakeLists.txt Configures CRT variants and duplicated IPC targets.
obs-studio-client/​CMakeLists.txt Preserves the Electron addon's dynamic CRT.
obs-studio-server/​CMakeLists.txt Links sandbox and Crashpad bridge targets.
obs-studio-server/​source/​main.cpp Dispatches CEF children before normal startup.
obs-studio-server/​source/​cef-subprocess.hpp Declares subprocess classification utilities.
obs-studio-server/​source/​cef-subprocess.cpp Implements validation, logging, and path checks.
obs-studio-server/​source/​cef-sandbox-host.hpp Declares Windows child dispatch.
obs-studio-server/​source/​cef-sandbox-host.cpp Loads and executes the packaged browser subprocess.
obs-studio-server/​source/​crashpad-bridge.h Defines the Crashpad bridge ABI.
obs-studio-server/​source/​crashpad-bridge.cpp Isolates Crashpad lifecycle and exception handling.
obs-studio-server/​source/​util-crashmanager.cpp Routes Windows Crashpad operations through the bridge.
obs-studio-server/​tests/​test-cef-subprocess.cpp Tests classification, logging, and path validation.
tests/​osn-tests/​src/​test_osn_module.ts Excludes packaged CEF runtime DLLs from module loading.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@summeroff

Copy link
Copy Markdown
Contributor Author

Following the Copilot closer-look review: I checked Chromium 128 Windows command-line parsing and found that the child classifier missed alternate switch prefixes and boundary whitespace that Chromium accepts. Commit 501575d now classifies native wide arguments with Chromium-compatible prefix, case, whitespace, and switch-terminator handling, with focused tests. All updated PR checks passed. The runtime token and job-object evidence, Crashpad smoke test, and performance measurements listed in the PR body remain release gates.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

The draft still requires runtime validation of sandbox confinement, Crashpad reporting, and performance.

Review effort: Balanced
Findings: None

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants