> The safest default would be fork+exec though we need to implement the 
> fork+exec code as a C extension module or have it use subprocess (as I 
> noted in the mb_fork_exec.patch review).

That was an old version of the patch.

In the branch

_posixsubprocess is used instead of fork+exec, and all unnecessary fds are closed.  See
