They have pledge(2) and unveil(2) instead.
People seem to have been experimenting with applying these restrictions from the outside, but it's generally hard to guess how a large program from ports will behave.
The rub being that SELinux is mandatory, so if you don't provide some kind of profile, it simply won't run.
They also do so at runtime, which means they can restrict themselves much more than a generic configuration can.
Once you’ve stated, for example, “this execution of this tool will only read standard input and write file F”, nothing you do, whether it is sloppy programming or the use of third party libraries with bugs, can change that.