Start up network service syscall broker process.

This does no actual sandboxing, but ensures that all the file open
calls can indeed be proxied via the same technique as used in the GPU.

AllowAllPolicy becomes unused as a result and is removed.

Bug: 715679
Cq-Include-Trybots: master.tryserver.chromium.linux:linux_mojo
Change-Id: Id7a0ee51d8c98c0bd3f59b2e468dc2a3eb11f50e
Reviewed-on: https://chromium-review.googlesource.com/764539
Reviewed-by: Robert Sesek <rsesek@chromium.org>
Reviewed-by: John Abd-El-Malek <jam@chromium.org>
Commit-Queue: Tom Sepez <tsepez@chromium.org>
Cr-Original-Commit-Position: refs/heads/master@{#516931}
Cr-Mirrored-From: https://chromium.googlesource.com/chromium/src
Cr-Mirrored-Commit: 322a049cf1e90d6711d7715ddde03130a09a00c7
1 file changed
tree: 057300350e9965b6a0b5f0218c026d8308aaeb50
  1. linux/
  2. mac/
  3. win/
  4. BUILD.gn
  5. features.gni
  6. ipc.dict
  7. OWNERS
  8. sandbox_export.h