Iris-MSWasm: Elucidating and Mechanising the Security Invariants of Memory-Safe WebAssembly
Maxime Legoupil, June Rousseau, Aïna Linn Georges, Jean Pichon-Pharabod, Lars Birkedal
Abstract
WebAssembly offers coarse-grained encapsulation guarantees via its module system, but does not support fine-grained sharing of its linear memory. MSWasm is a recent proposal which extends WebAssembly with fine-grained memory sharing via handles, a type of capability that guarantees spatial and temporal safety, and thus enables an expressive yet safe style of programming with flexible sharing. In this paper, we formally validate the pen-and-paper design of MSWasm. To do so, we first define MSWasmCert, a mechanisation of MSWasm that makes it a fully-defined, conservative extension of WebAssembly 1.0, including the module system. We then develop Iris-MSWasm, a foundational reasoning framework for MSWasm composed of a separation logic to reason about known code, and a logical relation to reason about unknown, potentially adversarial code. Iris-MSWasm thereby makes explicit a key aspect of the implicit universal contract of MSWasm: robust capability safety. We apply Iris-MSWasm to reason about key use cases of handles, in which the effect of calling an unknown function is bounded by robust capability safety. Iris-MSWasm thus works as a framework to prove complex security properties of MSWasm programs, and provides a foundation to evaluate the language-level guarantees of MSWasm.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers4
- Compositional Symbolic Execution for the Next 700 Memory ModelsAndreas Lööw, Seung Hoon Park, Daniele Nantes-Sobrinho, Sacha-Élie Ayoun et al.OOPSLA 2025 · 4 citations
- Iris-WasmFX: Modular Reasoning for Wasm Stack SwitchingMaxime Legoupil, Mathias Pedersen, Lars Birkedal, Sam Lindley et al.PLDI 2026
- Logical Relations for Formally Verified Authenticated Data StructuresSimon Oddershede Gregersen, Chaitanya Agarwal, Joseph TassarottiCCS 2025
- The Downgrading Semantics of Memory SafetyRené Rydhof Hansen, Andreas Stenbæk Larsen, Aslan AskarovPLDI 2026
Builds on6
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation processKyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony C. J. Fox et al.S&P 2020 · 43 citations
- Two Mechanisations of WebAssembly 1.0Conrad Watt, Xiaojia Rao, Jean Pichon-Pharabod, Martin Bodin et al.FM 2021 · 32 citations
- Efficient and provable local capability revocation using uninitialized capabilitiesAïna Linn Georges, Armaël Guéneau, Thomas Van Strydonck, Amin Timany et al.POPL 2021 · 30 citations
- MSWasm: Soundly Enforcing Memory-Safe Execution of Unsafe CodeAlexandra E. Michael, Anitha Gollamudi, Jay Bosamiya, Evan Johnson et al.POPL 2023 · 22 citations
- Iris-Wasm: Robust and Modular Verification of WebAssembly ProgramsXiaojia Rao, Aïna Linn Georges, Maxime Legoupil, Conrad Watt et al.PLDI 2023 · 19 citations
Related papers
- RichWasm: Bringing Safe, Fine-Grained, Shared-Memory Interoperability Down to WebAssemblyMichael Fitzgibbons, Zoe Paraskevopoulou, Noble Mushtak, Michelle Thalakottur et al.PLDI 2024 · 3 citations
- VMSL: A Separation Logic for Mechanised Robust Safety of Virtual Machines Communicating above FF-AZongyuan Liu, Sergei Stepanenko, Jean Pichon-Pharabod, Amin Timany et al.PLDI 2023 · 7 citations
- Le temps des cerises: efficient temporal stack safety on capability machines using directed capabilitiesAïna Linn Georges, Alix Trieu, Lars BirkedalOOPSLA 2022 · 17 citations
- Cerisier: A Program Logic for Attestation in a Capability MachineJune Rousseau, Denis Carnier, Thomas Van Strydonck, Steven Keuchel et al.PLDI 2026
- Endangered by the Language But Saved by the Compiler: Robust Safety via Semantic Back-TranslationNiklas Mück, Aïna Linn Georges, Derek Dreyer, Deepak Garg et al.POPL 2026
