Skip to content
Book Open access

We Need to Talk About the Actual Guarantees of Rust-based Systems

Sep 2026 · Proceedings of the 14th Workshop on Programming Languages and Operating Systems · 0 citations · 43 references

TL;DR

This paper identifies a common weakness in Rust-based systems: extensions, even those that may be considered “safe,” may fail to uphold the language properties on which these systems rely.

Abstract

Over the past decade, systems research has leveraged Rust to build systems that enforce valuable security and isolation guarantees over user-provided code in extensions. This paper identifies a common weakness in these Rust-based systems: extensions, even those that may be considered “safe,” may fail to uphold the language properties on which these systems rely. We present case studies where this mismatch breaks system guarantees and “safe” extensions corrupt kernel state in RedLeaf [35] and leak private data in Sesame [13]. As a path forward, we propose tooling to detect possible violations of system invariants in extension code. An early prototype static analysis tool suggests that this approach detects guarantee-breaking code with low false-positive rates.

Read PDF

Similar papers

Book Open access Sep 2026

Beyond Zero-Cost: Understanding Rust Safety Overheads in Systems Code

Rust is increasingly used as a viable alternative to C and C++ for systems development. A central appeal of Rust is its “zero-cost” abstractions and, specifically, its ability to enforce safety without the overhead of garbage collection. In practice, however, only a subset of safety properties can be enforced staticall...

Soham Bagchi, Manvik Nanda, A. Burtsev · 0 citations
Preprint Sep 2026

C-to-Rust Fallacy: Automatic Refactoring != Memory Security

Rust has emerged as the leading system programming language, offering strong memory and type safety guarantees without compromising performance. This positions it as a compelling alternative to traditional languages like C and C++, which are susceptible to memory security bugs. However, manually transforming C to Rust...

Hung-Mao Chen, Xu He, Bo Lu et al. · 0 citations
Open access Oct 2026

Bringing Foundational Verification to Real-World Rust Code

Rust is a modern systems programming language that, thanks to its strong memory safety guarantees, is well-suited to the domain of safety-critical systems. Since memory safety alone is not ultimately enough for safety-critical systems, there have emerged in recent years a number of tools for deductive verification of f...

Lennard Gäher, Vincent Lafeychine, Sascha Kehrli et al. · 0 citations
Preprint Sep 2026

SCHERI: Provably Secure Speculation Under the Constant-Time Policy for CHERI (Extended Version)

Capability-based architectures such as CHERI provide strong support for the architectural isolation of software components. To additionally protect against microarchitectural leakage, software can be written in a constant-time fashion. Modern processors, however, rely heavily on speculative execution, which can invalid...

Shi-Xin Song, Davide Davoli, Elias Storme et al. · 0 citations
Preprint Aug 2026

SysComb: Fine-Grained Transparent System Call Filtering for Attack Surface Reduction

Restricting the system calls available to applications shrinks the kernel's attack surface and greatly mitigates the impact of compromised programs. Recent approaches showcase techniques to generate system call filters, however, all existing solutions require either kernel or application modifications to activate them...

Matthew Rossi, Marco Abbadini, M. Beretta et al. · 0 citations
Book Open access Sep 2026

zBulk: Towards Automatic Compartmentalization in Rust with Zero Manual Retrofitting

Memory safety is a dominant driver in security and systems research. Rust has become a viable alternative to C/C++ for systems programming because of its strong memory safety guarantees. However, it is not a silver bullet. Unsafe sections, foreign code, and compiler-soundness bugs still pose vulnerabilities. Compartmen...

Maxim Ritter von Onciul, Phillip Raffeck, Peter Wägemann et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.