> I've been trying to engage in good faith,
You put words in my mouth and seemed to be misconstruing my point. I didn't assume bad faith, but I didn't assume good faith either given that.
> you have a lot of dismissive, low to no-content replies
Yeah, probably. A lot of people are saying ignorant things, like the people claiming if someone got root on SELinux they could just change the SELinux policies.
> you don't have a great way to gauge my knowledge on this
When people say something egregiously wrong, it's helps gauge. It's like if someone is telling me something about the English President I'm probably not going to put too much weight in anything they say about geopolitics.
> I'm not really defending pledge, and I'm not offended by the prospect that SELinux might provide superior security.
Well, that's great, because that's been my only real point, yet plenty of people do seem to be offended by exactly what you say you personally are not.
> I'm just trying to have a discussion with you.
I apologize profusely for being more hostile than is warranted then. I much prefer to discuss this stuff as I am passionate about it. But there are a ton of people responding emotionally with tired arguments, and it becomes a chore to reply when no good faith discussion is taking place.
> I will suggest that there may be other axes on which to evaluate a security solution. For example, maybe I don't want the complexity of SELinux (it is, by any measure, complex) and OpenBSD's security lets me address my threat model while avoiding SELinux' complexity. Or in other words, maybe I don't care that I can't restrict nginx to only bind to a specific port, I just don't want it serving up arbitrary files out of my filesystems: chroot to the rescue.
I wouldn't dispute that for a second. I agree SELinux or similar isn't needed for every use case. My point was that OBSD, if it wants to be a security focused OS and taken seriously as such, should offer something along those lines. It doesn't have to be as complex, but they should have something.
Instead, you have people suggesting and advocating for things that are not remotely similar, but are the closest and best OpenBSD has to offer along those lines, which IMO are not good enough.
> "Hrmph, I'm just sure it's possible because of the power of root",
Pretty much, yeah, except it's hardly a stretch like you are making it seem. If I can run code as root, I can find those files as devices if I'm determined enough, absolutely, even if I have to interact with devices directly and bypass the filesystem.
> Hrmph, I'm just sure there's tons of junk bugs in the monstrous SELinux code base, not to mention unintended interactions with features and other subsystems
Sure, although unlikely. Pretty sure SELinux (not Linux) has a better track record than OBSD for serious bugs, and none that have allowed full compromise unlike with OpenBSD.
The point, again, is not so much to advocate for SELinux (I prefer RSBAC myself anyway), but that OpenBSD should have something that fills the same niche. It doesn't have to be as complex, it doesn't have to be a full implementation, but they should have something. And they don't.
> "cute" and "play some tricks" are dismissive
Yes, because I'm dismissive of those technologies in the context they were brought up in.
> "toys" is dismissive.
Yup.
> Multiple people have tried to engage with you to try to discuss SELinux vs. OpenBSD's other security features, and your replies have uniformly been, "do some more reading on SELinux", only more rude.
OSS OSes like OBSD are tribal. People defend them out of emotion very often, just as much as people defend sports teams or religions. A lot of the replies are bad. There are people defending OpenBSD claiming it does what SELinux, or trying to discredit SELinux without seemingly even knowing core basics about it.
As far as I'm concerned, the quality of my replies is proportional to the comments I am replying to.