# \[ANN\] Openbsd 1.0

**URL:** <https://discuss.ocaml.org/t/ann-openbsd-1-0/15434>\
**Category:** Community\
**Tags:** announce\
**Created:** [October 12, 2024, 7:12am UTC](https://discuss.ocaml.org/t/ann-openbsd-1-0/15434 "2024-10-12T07:12:05Z")\
**Posts on this page:** 1\
**Showing post:** 1

<div class="post-metadata">

**Author:** ![semarie](https://sea2.discourse-cdn.com/flex020/user_avatar/discuss.ocaml.org/semarie/32/5531_2.png) [@semarie](https://discuss.ocaml.org/u/semarie)\
**Post date:** [October 12, 2024, 7:12am UTC](https://discuss.ocaml.org/t/ann-openbsd-1-0/15434/1 "2024-10-12T07:12:05Z")

</div>

I would like to announce a new (somehow niche) package [Openbsd](https://ocaml.org/p/openbsd/latest), which provides bindings for some specifics OpenBSD syscalls [pledge(2)](https://man.openbsd.org/pledge.2) and [unveil(2)](https://man.openbsd.org/unveil.2).

These syscalls lets the kernel OS to know what the running processus is expected to do, and so it is possible to restrict a processus to do only filesystem or only network or only pure computation…

The package is designed to be installable on any platform and provides simple method to check if `Pledge` or `Unveil` are supported. This way, it is possible to easily write portable code using the package, as it could be a turned on “no-operation” on Windows or Linux hosts (or provides alternative code path for sandboxing).

* * *

- Homepage : [https://codeberg.org/semarie/ocaml-openbsd/](https://codeberg.org/semarie/ocaml-openbsd/)
- License : [ISC](https://en.wikipedia.org/wiki/ISC_license)
- Documented Interface : [lib/openbsd.mli](https://codeberg.org/semarie/ocaml-openbsd/src/tag/1.0/lib/openbsd.mli)

* * *

### Examples

```auto
let open Openbsd in
if Pledge.supported then
  Pledge.promises "stdio rpath"

```

```auto
let open Openbsd in
if Unveil.supported then (
  Unveil.add "./lib" "r";
  Unveil.add "./logs" "rwc";
  Unveil.lock ())

```

---

_[View the full topic](https://discuss.ocaml.org/t/ann-openbsd-1-0/15434)._
