The goal of this bug is to Add Process Sandboxing w/ Chromium Sandbox in tree and to create the needed build-config and min-dependencies. For OSX we don't need anything since there is built-in support (App Sandbox Design Guide). For Linux we're already using seccomp in-tree via m-c/security/sandbox. In Windows we'd like to have support for Security Sandboxing which allows: Job object control, inte