I am too lazy to research it and still wondering. Can someone give me a basic explanation of it?

  • dsemy@lemm.ee
    link
    fedilink
    English
    arrow-up
    3
    ·
    4 months ago

    They developed new system calls (pledge and unveil) which restrict they system calls and file access of programs (here’s a good writeup by Andreas Kling after he added support in SerenityOS: https://awesomekling.github.io/pledge-and-unveil-in-SerenityOS/). As an example, the Firefox port for OpenBSD uses them to heavily restrict what random websites can do or get from your system.

    Just one example since you’ve somehow yet to see any.