Posted by mococa 3 hours ago
The closest you can get to that model on Linux is the strict mode in seccomp, which disallows every syscall except read(), write(), exit() and sigreturn(). It's more or less a way to restrict a process to being "pure compute/memory". If the process then wants to poke and prod at the outside world, it can only do so by reading/writing the file descriptors it inherited prior to the seccomp call. You can build a RPC on top of that to emulate the "whitelist", with access control and restrictions/policies enforced by whatever is listening on the other end.
Not sure why her TLS cert expired months ago. Ted Unangst (OpenBSD dev) also seems to have disappeared, which is concerning.
#ifdef OpenBSD
if(pledge("stdio rpath wpath cpath",NULL) == -1)
err(1,"pledge\n");
#endif
Very easy, all the other examples seem rather complex to me. unveil(2) is just as easy.