Hi everyone,

Patches have just landed on mozilla-inbound to turn on the content process 
sandbox on Windows by default.
This means that anyone running on Windows with e10s enabled, will also be using 
the Chromium sandbox.

The policy is only weak at the moment, to try and ensure that it doesn't break 
anything.
So, the only thing it sets is a USER_NON_ADMIN restricted access token.

You can run with a more strict version of the policy by setting the pref:
security.sandbox.windows.content.moreStrict=true

This will require a restart.
Many things should still work with this policy.
Although some things will hang or crash, in particular pages that play media.

If you have any questions you can find me in #boxing or possibly in person next 
week!

Cheers,
Bob
_______________________________________________
dev-platform mailing list
dev-platform@lists.mozilla.org
https://lists.mozilla.org/listinfo/dev-platform

Reply via email to