Building Bridges: Safe Interactions with Foreign Languages through Omniglot
Leon Schuermann, Jack Toubes, Tyler Potyondy, Pat Pannuto, Mae Milano, Amit Levy
Abstract
Memory-and type-safe languages promise to eliminate entire classes of systems vulnerabilities by construction. In practice, though, even clean-slate systems often need to incorporate libraries written in other languages with fewer safety guarantees. Because these interactions threaten the soundness of safe languages, they can reintroduce the exact vulnerabilities that safe languages prevent in the first place.
This paper presents Omniglot: the first framework to efficiently uphold safety and soundness of Rust in the presence of unmodified and untrusted foreign libraries. Omniglot facilitates interactions with foreign code by integrating with a memory isolation primitive and validation infrastructure, and avoids expensive operations such as copying or serialization.
We implement Omniglot for two systems: we use it to integrate kernel components in a highly-constrained embedded operating system kernel, as well as to interface with conventional Linux userspace libraries. Omniglot performs comparably to approaches that deliver weaker guarantees and significantly better than those with similar safety guarantees.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 60c87447-bb0f-40c9-92f4-6d822ec2e3c0Cited by top-tier papers2
- Tock: From Research To Securing 10 Million ComputersLeon Schuermann, Brad Campbell, Branden Ghena, Philip Alexander Levis et al.SOSP 2025
- SafeFFI: Efficient Sanitization at the Boundary Between Safe and Unsafe Code in Rust and Mixed-Language ApplicationsOliver Braunsdorf, Tim Lange, Konrad Hohentanner, Julian Horsch et al.USENIX Security 2026
Builds on15
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- XRP: In-Kernel Storage Functions with eBPFYuhong Zhong, Haoyu Li, Yu Jian Wu, Ioannis Zarkadas et al.OSDI 2022 · 100 citations
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel et al.OSDI 2020 · 86 citations
- Theseus: an Experiment in Operating System Structure and State ManagementKevin Boos, Namitha Liyanage, Ramla Ijaz, Lin ZhongOSDI 2020 · 67 citations
- PKRU-safe: automatically locking down the heap between safe and unsafe languagesPaul Kirth, Mitchel Dickerson, Stephen Crane, Per Larsen et al.EuroSys 2022 · 41 citations
Related papers
- TRust: A Compilation Framework for In-process Isolation to Protect Safe Rust against Untrusted CodeInyoung Bang, Martin Kayondo, Hyungon Moon, Yunheung PaekUSENIX Security 2023
- Securing unsafe rust programs with XRustPeiming Liu, Gang Zhao, Jeff HuangICSE 2020 · 28 citations
- Is rust used safely by software developers?Ana Nora Evans, Bradford Campbell, Mary Lou SoffaICSE 2020 · 57 citations
- Rust for Embedded Systems: Current State and Open ProblemsAyushi Sharma, Shashank Sharma, Sai Ritvik Tanksalkar, Santiago Torres-Arias et al.CCS 2024 · 12 citations
- An Empirical Study of Rust-for-Linux: The Success, Dissatisfaction, and CompromiseHongyu Li, Liwei Guo, Yexuan Yang, Shangguang Wang et al.USENIX ATC 2024 · 29 citations
