OpenBSD’s unveil()

One of the key aspects of hardening the user-space side of an operating system is to provide mechanisms for restricting which parts of the filesystem hierarchy a given process can access. Linux has a number of mechanisms of varying capability and complexity for this purpose, but other kernels have taken a different approach. Over the last few months, OpenBSD has inaugurated a new system call named unveil() for this type of hardening that differs significantly from the mechanisms found in Linux.

8 Comments

  1. 2018-10-13 9:31 am
    • 2018-10-13 6:53 pm
  2. 2018-10-13 2:36 pm
    • 2018-10-14 11:01 am
      • 2018-10-14 6:23 pm
        • 2018-10-16 1:56 pm
          • 2018-10-16 4:06 pm
    • 2018-10-15 10:22 am