We have at least one case on Windows (bug 1336703) where opening a file in the file content process still will not work without removing all sandbox restrictions.

We should open the file in the parent (or another privileged) process and pass the handle down to the child.

We could stream the data over IPC, but that probably adds extra complexity for no real benefit.

This is a more specialised case of bug 922481.
Although the solution may involve the more general case.
