Describe the bug
Stock cefsimple opens a window but does not complete document navigation under Ubuntu 26.04/Xvfb.
For loopback HTTP/HTTPS navigation, CEF creates TCP connections and, with HTTPS, completes TLS handshakes, but an instrumented fixture receives no HTTP plaintext bytes or request lines during a bounded nine-second observation.
A separate external HTTPS control against https://example.com/ progresses further: CEF creates a main-frame URL_REQUEST and completes TLS connections, but records no HTTP header events and does not complete the page load within the same observation period.
The original loopback behavior reproduces with CEF 151.3.24 and CEF 146.0.12 in the same Linux VM. A CEF 151 regression has therefore not been established.
To Reproduce
- Build stock
cefsimple from the official Linux x64 CEF standard distribution with USE_SANDBOX=ON. Configure the supplied chrome-sandbox as root:root, mode 4755.
- Start Xvfb with a
1024x768x24 display and select that display.
- Start a loopback HTTP fixture:
/redirect redirects to /final.
/final returns a small HTML page with status 200.
- Verify that Python
urllib can fetch /final.
- Run:
cefsimple \
--url=http://127.0.0.1:<port>/redirect \
--no-first-run \
--disable-gpu
- Observe the window and fixture for nine seconds. Repeat with
--use-native.
- Repeat with HTTPS, using a fixture CA trusted by the OS and NSS stores.
Original stock-sample results:
CEF 151.3.24 / HTTP
- Views: 3 TCP accepts, 0 recorded HTTP GETs
- Native: 3 TCP accepts, 0 recorded HTTP GETs
CEF 151.3.24 / HTTPS
- Views: 3 TCP accepts, 2 TLS handshakes, 0 recorded HTTP GETs
- Native: 3 TCP accepts, 2 TLS handshakes, 0 recorded HTTP GETs
CEF 146.0.12 / HTTPS
- Views: 3 TCP accepts, 2 TLS handshakes, 0 recorded HTTP GETs
- Native: 3 TCP accepts, 2 TLS handshakes, 0 recorded HTTP GETs
The original fixture counted GET handlers only. Follow-up instrumentation described below closes that measurement gap for new CEF 151 runs.
Adding --disable-request-handling-for-testing to the CEF 151 HTTPS runs produced the same original counts in both modes. The switch did not change the observed behavior; this does not establish which internal component is responsible.
Expected behavior
cefsimple should request /redirect, follow the redirect to /final, and display the returned page.
Instead, loopback navigation does not produce a document request at the fixture during the bounded observation. Native mode opens an Untitled - Chromium window.
Additional diagnostics
All-method and plaintext-byte loopback observation
The loopback fixture was instrumented to record:
- every parsed request method and raw request line;
- plaintext bytes received before HTTP parsing, after TLS decryption for HTTPS.
The observer self-check successfully detected:
- an
OPTIONS /observer-check request;
- an incomplete
OPTI request.
Python successfully fetched /final before each browser run. Those preflight connections were excluded from the browser counters.
Stock CEF 151 results over nine seconds:
HTTP / Views
- 3 TCP accepts
- 0 plaintext bytes
- no request lines
HTTP / Native
- 3 TCP accepts
- 0 plaintext bytes
- no request lines
HTTPS / Views
- 2 TCP accepts
- 2 successful TLS handshakes
- 0 plaintext bytes
- no request lines
HTTPS / Native
- 3 TCP accepts
- 2 successful TLS handshakes
- 0 plaintext bytes
- no request lines
No OPTIONS or other HTTP method was hidden by the original GET-only counter in these new runs.
This claim is limited to plaintext bytes received by the fixture during the bounded observation.
External HTTPS control
Stock CEF 151 cefsimple was also run against:
in both Views and native modes, using the same Xvfb environment and retaining:
--no-first-run
--disable-gpu
Sandboxing remained enabled.
Python fetched https://example.com/ successfully with status 200 before each CEF run.
Neither CEF run displayed the Example Domain page within nine seconds. Native mode remained Untitled - Chromium.
Unlike the loopback traces, both external-run CEF netlogs contained a main-frame URL_REQUEST_START_JOB for https://example.com/ and recorded two successful TLS connections.
However:
- no recorded target-request NetLog event contained an HTTP header event;
- no completed page load was established;
- the target request's captured progression ended after
COMPUTED_PRIVACY_MODE.
The external case therefore progresses further than the loopback case but still does not complete document loading.
The netlogs also contain connection-refused attempts, so this diagnostic does not isolate a particular failing component.
SIGTERM was used after the bounded observation and left the NetLog files without their final JSON delimiters. The original files were retained; only the missing delimiters were reconstructed in memory for analysis. No events after termination are claimed.
Screenshots
No screenshots attached. Exact command lines, X11 window observations, fixture counters, plaintext/request-line observations, callback logs, and NetLogs were captured.
Versions
- OS: Ubuntu 26.04.1 LTS, x86_64, disposable VM
- Kernel:
7.0.0-31-generic
- Display: Xvfb,
1024x768x24
- Compiler used for both CEF 151 and CEF 146 sample builds:
/usr/bin/c++
- Compiler version:
c++ (Ubuntu 15.2.0-16ubuntu1) 15.2.0
- CEF binary version:
151.3.24+g2384915+chromium-151.0.7922.174
- CEF revision:
2384915b7b1f0fe5ad1107e48d80c34e86b698d7
- Comparison version:
146.0.12+g6214c8e+chromium-146.0.7680.179
The compiler version was verified from the CMake compiler metadata for both sample builds.
Additional context
- Same-version CEF sample: Reproduces with stock
cefsimple in both Views and native-window modes. cefclient has not been tested.
- Same-version Google Chrome: Not tested.
- The same minimal CEF client source was built against both SDKs. It reproduces the loopback failure with HTTP and HTTPS, including in a mode without request handlers.
- In the instrumented minimal client, loopback navigation reaches
OnBeforeBrowse but does not reach OnBeforeResourceLoad.
- When navigating from
about:blank, the main-frame URL remains about:blank.
- An earlier CEF 151 minimal-client loopback NetLog showed target preconnect activity without a page
URL_REQUEST.
- The newer external HTTPS control differs: it does create a main-frame
URL_REQUEST, but no completed HTTP response/page load is observed.
- No
--no-sandbox switch was used.
- No certificate-verification-bypass switch was used.
- No
NetworkServiceSandbox override was used.
- Without
--no-first-run, CEF 151 displayed a Chromium terms window. That initial run was treated as inconclusive.
- These results do not establish a loopback-only or Local Network Access-specific problem.
- These results do not establish
NetworkServiceSandbox as the cause.
- These results do not establish a CEF 151 regression.
Question for CEF maintainers
What could allow stock cefsimple and a minimal CefClient to create a browser and begin network navigation, but fail to complete the document request?
In loopback tests, CEF establishes TCP/TLS connections but sends no HTTP plaintext during the bounded observation. In an external HTTPS control, CEF creates a main-frame URL_REQUEST and completes TLS, but no HTTP header events or completed page load are observed.
Is there a known Ubuntu 26.04/Xvfb startup, sandbox, session, or command-line requirement that could explain this behavior?
The identical loopback behavior on CEF 146 and CEF 151 does not establish a CEF 151 regression.
The reproduction steps, commands, measurements, and reported results were executed and verified by the reporter. AI tools assisted with diagnostic planning and editing of this report.
Assisted-by: OpenAI Codex
Assisted-by: ChatGPT
Describe the bug
Stock
cefsimpleopens a window but does not complete document navigation under Ubuntu 26.04/Xvfb.For loopback HTTP/HTTPS navigation, CEF creates TCP connections and, with HTTPS, completes TLS handshakes, but an instrumented fixture receives no HTTP plaintext bytes or request lines during a bounded nine-second observation.
A separate external HTTPS control against
https://example.com/progresses further: CEF creates a main-frameURL_REQUESTand completes TLS connections, but records no HTTP header events and does not complete the page load within the same observation period.The original loopback behavior reproduces with CEF 151.3.24 and CEF 146.0.12 in the same Linux VM. A CEF 151 regression has therefore not been established.
To Reproduce
cefsimplefrom the official Linux x64 CEF standard distribution withUSE_SANDBOX=ON. Configure the suppliedchrome-sandboxasroot:root, mode4755.1024x768x24display and select that display./redirectredirects to/final./finalreturns a small HTML page with status 200.urllibcan fetch/final.--use-native.Original stock-sample results:
The original fixture counted GET handlers only. Follow-up instrumentation described below closes that measurement gap for new CEF 151 runs.
Adding
--disable-request-handling-for-testingto the CEF 151 HTTPS runs produced the same original counts in both modes. The switch did not change the observed behavior; this does not establish which internal component is responsible.Expected behavior
cefsimpleshould request/redirect, follow the redirect to/final, and display the returned page.Instead, loopback navigation does not produce a document request at the fixture during the bounded observation. Native mode opens an
Untitled - Chromiumwindow.Additional diagnostics
All-method and plaintext-byte loopback observation
The loopback fixture was instrumented to record:
The observer self-check successfully detected:
OPTIONS /observer-checkrequest;OPTIrequest.Python successfully fetched
/finalbefore each browser run. Those preflight connections were excluded from the browser counters.Stock CEF 151 results over nine seconds:
No
OPTIONSor other HTTP method was hidden by the original GET-only counter in these new runs.This claim is limited to plaintext bytes received by the fixture during the bounded observation.
External HTTPS control
Stock CEF 151
cefsimplewas also run against:in both Views and native modes, using the same Xvfb environment and retaining:
Sandboxing remained enabled.
Python fetched
https://example.com/successfully with status 200 before each CEF run.Neither CEF run displayed the Example Domain page within nine seconds. Native mode remained
Untitled - Chromium.Unlike the loopback traces, both external-run CEF netlogs contained a main-frame
URL_REQUEST_START_JOBforhttps://example.com/and recorded two successful TLS connections.However:
COMPUTED_PRIVACY_MODE.The external case therefore progresses further than the loopback case but still does not complete document loading.
The netlogs also contain connection-refused attempts, so this diagnostic does not isolate a particular failing component.
SIGTERM was used after the bounded observation and left the NetLog files without their final JSON delimiters. The original files were retained; only the missing delimiters were reconstructed in memory for analysis. No events after termination are claimed.
Screenshots
No screenshots attached. Exact command lines, X11 window observations, fixture counters, plaintext/request-line observations, callback logs, and NetLogs were captured.
Versions
7.0.0-31-generic1024x768x24/usr/bin/c++c++ (Ubuntu 15.2.0-16ubuntu1) 15.2.0151.3.24+g2384915+chromium-151.0.7922.1742384915b7b1f0fe5ad1107e48d80c34e86b698d7146.0.12+g6214c8e+chromium-146.0.7680.179The compiler version was verified from the CMake compiler metadata for both sample builds.
Additional context
cefsimplein both Views and native-window modes.cefclienthas not been tested.OnBeforeBrowsebut does not reachOnBeforeResourceLoad.about:blank, the main-frame URL remainsabout:blank.URL_REQUEST.URL_REQUEST, but no completed HTTP response/page load is observed.--no-sandboxswitch was used.NetworkServiceSandboxoverride was used.--no-first-run, CEF 151 displayed a Chromium terms window. That initial run was treated as inconclusive.NetworkServiceSandboxas the cause.Question for CEF maintainers
What could allow stock
cefsimpleand a minimal CefClient to create a browser and begin network navigation, but fail to complete the document request?In loopback tests, CEF establishes TCP/TLS connections but sends no HTTP plaintext during the bounded observation. In an external HTTPS control, CEF creates a main-frame
URL_REQUESTand completes TLS, but no HTTP header events or completed page load are observed.Is there a known Ubuntu 26.04/Xvfb startup, sandbox, session, or command-line requirement that could explain this behavior?
The identical loopback behavior on CEF 146 and CEF 151 does not establish a CEF 151 regression.
The reproduction steps, commands, measurements, and reported results were executed and verified by the reporter. AI tools assisted with diagnostic planning and editing of this report.
Assisted-by: OpenAI Codex
Assisted-by: ChatGPT