Description:
I would like to focus on lessons learned integrating pledge into 500 programs.
Probably emphasize how programs were subtly modified to fit the restrictive
model, with some examples. For instance, we further strengthened existing
privsep designs along the way because pledge showed the way. Another
conversation is about a dev process we call “hoisting”, invariant code found in
the main loop was pulled into pre-pledge initialization.
Speaker biography:
Theo is the founder and long time contributor to the OpenBSD project.