FlexOS: towards flexible OS isolation
Hugo Lefeuvre, Vlad-Andrei Badoiu, Alexander Jung, Stefan Lucian Teodorescu, Sebastian Rauch, Felipe Huici, Costin Raiciu, Pierre Olivier
Abstract
At design time, modern operating systems are locked in a specific safety and isolation strategy that mixes one or more hardware/software protection mechanisms (e.g. user/kernel separation); revisiting these choices after deployment requires a major refactoring effort. This rigid approach shows its limits given the wide variety of modern applications' safety/performance requirements, when new hardware isolation mechanisms are rolled out, or when existing ones break.
We present FlexOS, a novel OS allowing users to easily specialize the safety and isolation strategy of an OS at compilation/deployment time instead of design time. This modular LibOS is composed of finegrained components that can be isolated via a range of hardware protection mechanisms with various data sharing strategies and additional software hardening. The OS ships with an exploration technique helping the user navigate the vast safety/performance design space it unlocks. We implement a prototype of the system and demonstrate, for several applications (Redis/Nginx/SQLite), FlexOS' vast configuration space as well as the efficiency of the exploration technique: we evaluate 80 FlexOS configurations for Redis and show how that space can be probabilistically subset to the 5 safest ones under a given performance budget. We also show that, under equivalent configurations, FlexOS performs similarly or better than existing solutions which use fixed safety configurations.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 2f0e567e-e982-4fb9-a69a-f4b2d02c8384Cited by top-tier papers12
- You shall not (by)pass!: practical, secure, and fast PKU-based sandboxingAlexios Voulimeneas, Jonas Vinck, Ruben Mechelinck, Stijn VolckaertEuroSys 2022 · 33 citations
- Microkernel Goes General: Performance and Compatibility in the HongMeng Production MicrokernelHaibo Chen, Xie Miao, Ning Jia, Nan Wang et al.OSDI 2024 · 13 citations
- ISA-Grid: Architecture of Fine-grained Privilege Control for Instructions and RegistersShulin Fan, Zhichao Hua, Yubin Xia, Haibo Chen et al.ISCA 2023 · 9 citations
- AlloyStack: A Library Operating System for Serverless Workflow ApplicationsJianing You, Kang Chen, Laiping Zhao, Yiming Li et al.EuroSys 2025 · 7 citations
- UIEE: Secure and Efficient User-space Isolated Execution Environment for Embedded TEE SystemsHuaiyu Yan, Zhen Ling, Xuandong Chen, Xinhui Shao et al.NDSS 2026 · 4 citations
Builds on12
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Meltdown: Reading Kernel Memory from User SpaceMoritz Lipp, Michael Schwarz, Daniel Gruss, Thomas Prescher et al.USENIX Security 2018 · 1,456 citations
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- Unikraft: fast, specialized unikernels the easy waySimon Kuenzer, Vlad-Andrei Badoiu, Hugo Lefeuvre, Sharan Santhanam et al.EuroSys 2021 · 116 citations
- Using Safety Properties to Generate Vulnerability PatchesZhen Huang, David Lie, Gang Tan, Trent JaegerS&P 2019 · 91 citations
Related papers
- CubicleOS: a library OS with software componentisation for practical isolationVasily A. Sartakov, Lluís Vilanova, Peter R. PietzuchASPLOS 2021 · 38 citations
- Fast, Flexible, and Practical Kernel ExtensionsKumar Kartikeya Dwivedi, Rishabh R. Iyer, Sanidhya KashyapSOSP 2024 · 7 citations
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel et al.OSDI 2020 · 86 citations
- MELF: Multivariant Executables for a Heterogeneous WorldDominik Töllner, Christian Dietrich, Illia Ostapyshyn, Florian Rommel et al.USENIX ATC 2023 · 8 citations
- Turning Linux into a High-Performance Library OS with FluxKaifu Tian, Youjie Zheng, Yiren Zhang, Yuyang You et al.SOSP 2026
