Merge "Only allow supplemental_process to execute from read-only locations" into tm-dev