"The biggest success of OpenBSD's mitigations is that all the other operating systems adopt them."
That just means they're popular, not successful against attackers.
"All the attacks that these techniques mitigate on other operating systems are proof "
This would be evidence if it's true. So, what attacks do they mitigate? Were those attacks designed to bypass the mitigation of not designed to bypass the mitigation? I find most assessments of mitigations focus on success against attacks not designed with mitigations in mind. Once it's important to attackers, they start focusing on the mitigations. Further, how do we assess whether hackers are having a hard time with the mitigations given they don't disclose most of their successes?
One guess I have is to look at exploit prices from firms such as Zerodium. I figure the prices will be much higher for targets that are harder to reliably exploit. If they're low, that might indicate they already have plenty of exploits for it. If it stays low or high, then that might show how consistently it was easy or hard to exploit. One variable to eliminate, though, was a vendor raising prices on one or more items just to further incentivize 0-day hunters. That happened at least once with Zerodium.
Let's look at the prices for desktops and servers:
https://zerodium.com/program.html
The highest payout is a Windows 0-day for remote code execution. There's no mention of Mac or Linux payouts for the same thing. Instead, they offer $50,000 for privilege escalation on both. They also have $100-500k payouts for RCE's on services that often run on Linux hosts. These do get lots of eyeballs from bug hunters, some getting hit for long time, which might drive prices up a bit. The combo suggests the attackers mostly hit a service/app on Mac and Linux followed by privilege escalation. In any case, the Linux boxes cost them anywhere from $150k-550k for exploits with Windows about a million.
If it counts as field evidence, that would argue strongly against what many might suspect is safest route to security. Whatever Linux is doing isn't working. Whatever Windows is doing is working really well. On mobile, iOS is the champ of comparable value. Note that they're not soliciting 0-days for OpenBSD on that page. That may or may not mean their clients don't care about it. If it did mean that, it would support my point about the OS being secure due to obscurity first, mitigations second.
So, I check another article to find they're offering $500k for UNIX exploits, esp BSD's:
https://securityaffairs.co/wordpress/74050/hacking/zerodium-...
They explain that how many systems are impacted with what level of interactivity largely determines the price. Implicitly corroborates what I said about attacker focus, too, if these incentives matter to them. For BSD's, I can't tell if the price is just to get a first-mover advantage against BSD's in their market or because they're harder to hack. Might have to wait a while. They did put a number on what Linux vulnerabilities were worth at the time: "as high as $45,000."
Maybe we ask Zerodium if they have an OpenBSD exploit with what level of interactivity. Although I doubt they'll say, maybe someone could sell them on the marketing benefit of it if they do have something. The OpenBSD devs might feel proud if they're consistently not on the list with the bounty going up every year or something.