feat(linux): use privileged EGL worker thread - #5709
Open
psyke83 wants to merge 2 commits into
Open
Conversation
psyke83
force-pushed
the
privileged_egl_worker
branch
from
September 14, 2026 02:41
5ff7c4b to
746ed49
Compare
|
Delegate eglCreateContext to a privileged EGL worker thread and confine CAP_SYS_NICE to this thread. This serves the dual purpose of hardening non-sandboxed Sunshine installations against unintended child process inheritance of CAP_SYS_NICE while also allowing EGL high-priority contexts to be used with Portal capture in conjunction with VAAPI encoding. Portal capture previously required Sunshine to drop CAP_SYS_NICE so that xdg-desktop-portal could access Sunshine's /proc/pid/root. This prevented VAAPI from creating high-priority EGL contexts, which could cause the encoder to throttle if host GPU usage is high. Keeping CAP_SYS_NICE confined to the privileged EGL worker removes this tradeoff. The privileged EGL context creation path is used by CUDA, VAAPI, kmsgrab and wlgrab; all relevant capture methods and encoders will support high priority contexts, but sandboxed installation types cannot avail of CAP_SYS_NICE due to the security policies enforced by their respective environments. This limitation mainly applies to Flatpak and AppImage installs.
Also rename "warning" bool variable to avoid collision with BOOST_LOG level.
ReenigneArcher
force-pushed
the
privileged_egl_worker
branch
from
September 14, 2026 17:44
746ed49 to
61e122e
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Description
Delegate eglCreateContext to a privileged EGL worker thread and confine CAP_SYS_NICE to this thread.
This serves the dual purpose of hardening non-sandboxed Sunshine installations against unintended child process inheritance of CAP_SYS_NICE while also allowing EGL high-priority contexts to be used with Portal capture in conjunction with VAAPI encoding.
Portal capture previously required Sunshine to drop CAP_SYS_NICE so that xdg-desktop-portal could access Sunshine's /proc/pid/root. This prevented VAAPI from creating high-priority EGL contexts, which could cause the encoder to throttle if host GPU usage is high. Keeping CAP_SYS_NICE confined to the privileged EGL worker removes this tradeoff.
The privileged EGL context creation path is used by CUDA, VAAPI, kmsgrab and wlgrab; all relevant capture methods and encoders will support high priority contexts, but sandboxed installation types cannot avail of CAP_SYS_NICE due to the security policies enforced by their respective environments. This limitation mainly applies to Flatpak and AppImage installs.
Screenshot
Issues Fixed or Closed
Roadmap Issues
Type of Change
Checklist
AI Usage
See our AI usage policy.