Only allow supplemental_process to execute from read-only locations

Test: atest SupplementalProcessTest
Bug: 215105355

Ignore-AOSP-First: Cherry picking internally first to rename. Will be cherry-picked to AOSP right after.

Change-Id: I1b6d1a778cb658bdfd930b684e4ba0640031b226
Merged-In: I1b6d1a778cb658bdfd930b684e4ba0640031b226
(cherry picked from commit 8ea8587abb208d6cfb0261dc5743a1c008c6d05d)
1 file changed