USENIX Security2026Top-tier venue
SoK: Capability Operating Systems: Is the Future Finally Here?
Noah Mauthe, Eric Ackermann, Sven Bugiel
Abstract
Capability operating systems have existed for six decades, yet we do not have a systematic way to compare them and their different design aspects. We even lack a consensus on the purpose of capabilities in these systems. Given the recent resurgence of interest in capability systems in different domains, we provide a definition of such systems and a set of characteristics to describe and distinguish them. Applying our characteristics to seminal capability systems, we then provide a taxonomy of fundamental design approaches that emerged over the last sixty years. Our results lead us to discuss further research in this field and highlight open challenges in creating pure object-capability systems.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Builds on8
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
- DroidCap: OS Support for Capability-based Permissions in AndroidAbdallah Dawoud, Sven BugielNDSS 2019 · 17 citations
- Cornucopia Reloaded: Load Barriers for CHERI Heap Temporal SafetyNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Jessica Clarke et al.ASPLOS 2024 · 16 citations
- CHERIoT RTOS: An OS for Fine-Grained Memory-Safe Compartments on Low-Cost Embedded DevicesSaar Amar, Tony Chen, David Chisnall, Nathaniel Wesley Filardo et al.SOSP 2025 · 1 citation
Related papers
- Type, Ability, and Effect Systems: Perspectives on Purity, Semantics, and ExpressivenessYuyan Bao, Tiark RompfOOPSLA 2026
- Effects, capabilities, and boxes: from scope-based reasoning to type-based reasoning and backJonathan Immanuel Brachthäuser, Philipp Schuster, Edward Lee, Aleksander Boruch-GruszeckiOOPSLA 2022 · 24 citations
- Rows and Capabilities as Modal EffectsWenhao Tang, Sam LindleyPOPL 2026 · 1 citation
- The Hitchhiker's Guide to Operating SystemsYanyan JiangUSENIX ATC 2023
- Effects as capabilities: effect handlers and lightweight effect polymorphismJonathan Immanuel Brachthäuser, Philipp Schuster, Klaus OstermannOOPSLA 2020 · 62 citations
