Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern Architectures
Shravan Narayan, Tal Garfinkel, Evan Johnson, Zachary Yedidia, Yingchen Wang, Andrew Brown, Anjo Vahldiek-Oberwagner, Michael LeMay, Wenyong Huang, Xin Wang, Mingqiu Sun, Dean M. Tullsen, Deian Stefan
Abstract
Software-based fault isolation (SFI) enables in-process isolation through compiler instrumentation of memory accesses, and is a critical part of WebAssembly (Wasm). We present two optimizations that improve SFI performance and scalability: Segue uses x86-64 segmentation to reduce the cost of instrumentation on memory accesses, e.g., it eliminates 44.7% of Wasm's overhead on a Wasm-compatible subset of SPEC CPU 2006, and reduces overhead of Wasm-sandboxed font rendering in Firefox by 75%; ColorGuard leverages memory tagging (e.g., MPK), to enable up to a 15× increase in the number of Wasm instances that can run concurrently in a single address space, improving efficiency for high scale server-side workloads. We also explore the challenges of deploying these optimizations in three production toolchains: Wasm2c, WAMR and Wasmtime.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 335d576f-99ad-410a-b0fa-be33ae7d180cCited by top-tier papers5
- Rex: Closing the language-verifier gap with safe and usable kernel extensionsJinghao Jia, Ruowen Qin, Milo Craun, Egor Lukiyanov et al.USENIX ATC 2025 · 11 citations
- Deterministic Client: Enforcing Determinism on Untrusted Machine CodeZachary Yedidia, Geoffrey Ramseyer, David MazièresOSDI 2025 · 1 citation
- Mohabi: Disaggregating and Sandboxing the Firefox JavaScript EngineAbhishek Sharma, Anand Balaji, Zachary Yedidia, Anthony Du et al.OSDI 2026 · 1 citation
- ARM MTE Performance in PracticeTaehyun Noh, Yingchen Wang, Tal Garfinkel, Mahesh Madhav et al.USENIX Security 2026
- kSFS: Repurposing a Microkernel-like Interface for Fast and Secure In-Kernel Linux File SystemsDinglan Peng, Pedro FonsecaUSENIX Security 2026
Builds on20
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 382 citations
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- Swivel: Hardening WebAssembly against SpectreShravan Narayan, Craig Disselkoen, Daniel Moghimi, Sunjay Cauligi et al.USENIX Security 2021 · 74 citations
- PKRU-safe: automatically locking down the heap between safe and unsafe languagesPaul Kirth, Mitchel Dickerson, Stephen Crane, Per Larsen et al.EuroSys 2022 · 41 citations
Related papers
- Isolation without taxation: near-zero-cost transitions for WebAssembly and SFIMatthew Kolosick, Shravan Narayan, Evan Johnson, Conrad Watt et al.POPL 2022 · 14 citations
- Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIShravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek et al.ASPLOS 2023 · 27 citations
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 17 citations
- Flexible Non-intrusive Dynamic Instrumentation for WebAssemblyBen L. Titzer, Elizabeth Gilbert, Bradley Wei Jie Teo, Yash Anand et al.ASPLOS 2024 · 7 citations
- Indexed Types for a Statically Safe WebAssemblyAdam T. Geller, Justin Frank, William J. BowmanPOPL 2024 · 4 citations
