Good work to OpenBSD team. Especially on pledge. Widespread changes are risky and often fail. Just speaks even more about the quality of work they do.
What it means in practice is (for example) a daemon running under firejail must be able to open log for writing and open sockets. An application which uses seccomp natively can first do those things and then block all further open/socket syscalls.