Gradient: Gradual Compartmentalization via Object Capabilities Tracked in Types
Aleksander Boruch-Gruszecki, Adrien Ghosn, Mathias Payer, Clément Pit-Claudel
Abstract
Modern software needs fine-grained compartmentalization, i.e., intra-process isolation. A particularly important reason for it are supply-chain attacks, the need for which is aggravated by modern applications depending on hundreds or even thousands of libraries. Object capabilities are a particularly salient approach to compartmentalization, but they require the entire program to assume a lack of ambient authority. Most of existing code was written under no such assumption; effectively, existing applications need to undergo a rewrite-the-world migration to reap the advantages of ocap. We propose gradual compartmentalization , an approach which allows gradually migrating an application to object capabilities, component by component in arbitrary order, all the while continuously enjoying security guarantees. The approach relies on runtime authority enforcement and tracking the authority of objects the type system. We present Gradient, a proof-of- concept gradual compartmentalization extension to Scala which uses Enclosures and Capture Tracking as its key components. We evaluate our proposal by migrating the standard XML library of Scala to Gradient.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 152a344f-e139-489f-91f6-33bed4ca0c25Builds on7
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- Enforcing Least Privilege Memory Views for Multithreaded ApplicationsTerry Ching-Hsiang Hsu, Kevin J. Hoffman, Patrick Eugster, Mathias PayerCCS 2016 · 71 citations
- Rudra: Finding Memory Safety Bugs in Rust at the Ecosystem ScaleYechan Bae, Youngsuk Kim, Ammar Askar, Jungwon Lim et al.SOSP 2021 · 61 citations
- Enclosure: language-based restriction of untrusted librariesAdrien Ghosn, Marios Kogias, Mathias Payer, James R. Larus et al.ASPLOS 2021 · 33 citations
- Effects, capabilities, and boxes: from scope-based reasoning to type-based reasoning and backJonathan Immanuel Brachthäuser, Philipp Schuster, Edward Lee, Aleksander Boruch-GruszeckiOOPSLA 2022 · 24 citations
Related papers
- DroidCap: OS Support for Capability-based Permissions in AndroidAbdallah Dawoud, Sven BugielNDSS 2019 · 17 citations
- Secure Caches for Compartmentalized SoftwareKerem Arikan, Huaxin Tang, Williams Zhang Cen, Yu David Liu et al.USENIX Security 2025
- Classifying CapabilitiesCao Nguyen Pham, Oliver Bračevac, Yichen Xu, Yaoyu Zhao et al.OOPSLA 2026
- Mind the Heap: Preventing Capability Leakage Across CHERI CompartmentsSeyedhamed Ghavamnia, Maurice D. Hanisch, Julien VanegueCCS 2026
- What's in the Box: Ergonomic and Expressive Capture Tracking over Generic Data StructuresYichen Xu, Oliver Bracevac, Cao Nguyen Pham, Martin OderskyOOPSLA 2025 · 4 citations
