commit 15209ad9ed6d1c8a506a7406fb32e35f1fd105bf from: Omar Polo date: Thu Jan 21 08:51:17 2021 UTC typo commit - ce79c944bcbc49b1874e6207a0546a4297571dfc commit + 15209ad9ed6d1c8a506a7406fb32e35f1fd105bf blob - d41aa12c637e71604c0b2579e5e29285476f470d blob + 68fbebb9a18a759718939f27414c34661cf781b7 --- README.md +++ README.md @@ -75,7 +75,7 @@ sandboxed. When a CGI script needs to be executed, th (outside of the sandbox) sets up a pipe and gives one end to the listener, while the other is bound to the CGI script standard output. This way, is still possible to execute CGI scripts without restriction -even if the presence of a sandbox. +even in the presence of a sandbox. On OpenBSD, the listener process runs with the `stdio recvfd rpath inet` pledges and has `unveil(2)`ed only the directories that it