mirror of
https://github.com/mozilla/gecko-dev.git
synced 2025-02-25 20:01:50 +00:00

This patch enables pre-spawn CIG in the RDD process. If CIG prevents a module in the executable's Import Directory Table, Windows totally fails to launch a process. So we add a policy rule of `SUBSYS_SIGNED_BINARY` for all files under the directory containing the executable such as mozglue.dll, and modules injected via Import Directory Table. The latter ones will be blocked by our blocklist with `REDIRECT_TO_NOOP_ENTRYPOINT` (bug 1659438). Differential Revision: https://phabricator.services.mozilla.com/D96933