For security reasons, we need to sandbox the CDM.  This bug focuses on Linux sandboxing.
The EME CDM is a GeckoMediaPlugin, so it's sandboxed on Linux as of bug 1012951 and bug 1043733.  This bug can track important followup work like bug 1054621.
