This is a Media related service, and a sandbox extension should be issued to the WebContent process based on GPU runtime settings.
<rdar://problem/69168801>
Created attachment 414078 [details] Patch
Created attachment 414079 [details] Patch
Created attachment 414082 [details] Patch
Comment on attachment 414082 [details] Patch r=me When we enable GPU Process for media, we plan to deny access to lskdd and the other media related mach services. But before we deny access to a service, we prefer to gather telemetry on its use. How will we gather telemetry on the media related mach services before we deny them outright?
(In reply to Geoffrey Garen from comment #5) > Comment on attachment 414082 [details] > Patch > > r=me > > When we enable GPU Process for media, we plan to deny access to lskdd and > the other media related mach services. But before we deny access to a > service, we prefer to gather telemetry on its use. How will we gather > telemetry on the media related mach services before we deny them outright? I think we should create a temporary rule, where we allow Media services, but with telemetry. This is what we currently do for GPU related IOKit classes. Thanks for reviewing!
Committed r269792: <https://trac.webkit.org/changeset/269792> All reviewed patches have been landed. Closing bug and clearing flags on attachment 414082 [details].