OpenBSD Journal

Kristaps Dzonsons on pledge(2)

Contributed by rueda on from the the joy of pledge(2) dept.

Kristaps Dzonsons, of mandoc and acme-client (and more) fame, has written a detailed article entitled "why pledge(2) …or, how I learned to love web application sandboxing".

The tl;dr section starts:

For practical web applications, pledge(2) presents the best compromise of development simplicity and security coverage. This alone gives BCHS applications even more of a boost beyond the many other advantages of programming on OpenBSD.

The article discusses the advantages of pledge(2) over other sandboxing systems.

(Comments are closed)


Comments
  1. By bmarshall (50.69.74.186) on

    Hacker News discussion:

    https://news.ycombinator.com/item?id=13037442

Credits

Copyright © - Daniel Hartmeier. All rights reserved. Articles and comments are copyright their respective authors, submission implies license to publish on this web site. Contents of the archive prior to as well as images and HTML templates were copied from the fabulous original deadly.org with Jose's and Jim's kind permission. This journal runs as CGI with httpd(8) on OpenBSD, the source code is BSD licensed. undeadly \Un*dead"ly\, a. Not subject to death; immortal. [Obs.]