A Measurement Study on the Adoption of Pledges and Unveils in the OpenBSD Operating System

2026-07-03Software Engineering

Software EngineeringCryptography and Security
AI summary

The authors studied how a security feature called pledge and unveil, used to limit what programs can do, was adopted in the OpenBSD operating system over 19 versions. They found that many programs started using these features even before they were officially released, and the use has steadily increased over time. Programs in certain system folders used these calls more, but the size of the program didn't really affect their usage. The authors also saw that common actions like reading and writing were often restricted, showing broad use of the security features. Overall, their results suggest that adding these sandboxing tools may be easier than previously thought.

OpenBSDpledge system callunveil system callsandboxingsystem callssecuritysoftware adoptioninput/output operationsprogram modification
Authors
Jukka Ruohonen, Krzysztof Sierszecki, Abhishek Tiwari
Abstract
The paper presents a longitudinal measurement study on the adoption of the pledge and unveil system calls in OpenBSD. These system calls are used to sandbox programs and libraries. Given a dataset covering 19 releases, many programs and libraries were modified to use the system calls already before their introductions in official releases. The adoption rates have also steadily grown; a linear trend provides a coarse but sensible heuristic. Although particularly programs residing in /usr/bin and /usr/sbin have been modified to use the system calls, the sizes of programs and libraries do not correlate well with the amounts of pledge and unveil system calls invoked. Regarding the pledges made, standard input and output operations have frequently been requested, although the full fine-grained arsenal offered by pledge has generally been utilized in OpenBSD. The same observation is seen in that particularly read operations to given paths have frequently been unveiled. All in all, the measurement results indicate that the adoption of system call minimization and sandboxing techniques is not necessarily as troublesome as has often been discussed in the literature.