> So yes, if you pledge(2) a shell. It can call exec, but directly it can't call socket/connect(2), and the reduction of kernel attack surface is still significant.
Why is that significant if I can fork and exec nc(1)?
Why is that significant if I can fork and exec nc(1)?
Having something be capcicumized (?) and exec capable seems to be mutually exclusive.