With application permissions or external constraints, this is not really helpful, because the application needs to do its setup.
However if the application can pledge not to do the setup things between the setup and the steady state, and it gets corrupted or owned during the steady state (e.g. because it’s a network daemon and there’s a bug), it becomes a lot harder to exploit since there should be very little the would-be exploiter can do or explore before the OS kills the program.
So this is not really about protecting the system against the application, it’s about the application participating in the system’s protection by dynamically reducing its own permissions while running.
After the process has told this to the kernel the process can then only do these things for its life time. You can pledge() again later, but you can only restrict your pledge never expand it.
This is a nice feature because it limits the number of processes that can potentially be security liabilities even if they have bugs.
unveil() is a similar feature but for file system paths.
It’s a feature of SerenityOS (inspired/borrowed from OpenBSD), and not a feature of C/C++.
Try reading the article, it’s pretty easy to follow :)
Pledge is not some external security feature but something that every program itself manages.
The idea is that every process should call each early when it starts running and, after that, if the process is ever compromised, it will not be able to do much harm since the files and syscalls it can interact with are limited.
For example, a browser should never access /etc/passwd or call the exec syscall. So, a browser, when run, should as early as possible call pledge and unveil to prevent itself from accessing /etc/passwd or calling exec if it ever becomes compromised.
FWICT, only sort of. It's like giving up permissions that you might already have (presumably to reduce potential security problems). And it's a bit more specific to the kernel.
Pledge: "I will at most use these kernel facilities" (don't let me do otherwise)
Unveil: "I will at most access these fs paths" (hide all other paths)
pledge() allows programs to declare up front what they’ll be doing. Functionality is divided into a reasonably small number of “promises” that can be combined. Each promise is basically a subset of the kernel’s syscalls.
Once you’ve pledged a set of promises, you can’t add more promises, only remove ones you’ve already made.
If a program then attempts to do something that it said it wouldn’t be doing, the kernel immediately terminates the program.