Isolation without taxation: near-zero-cost transitions for WebAssembly and SFI
Matthew Kolosick, Shravan Narayan, Evan Johnson, Conrad Watt, Michael LeMay, Deepak Garg, Ranjit Jhala, Deian Stefan
Abstract
Software sandboxing or software-based fault isolation (SFI) is a lightweight approach to building secure systems out of untrusted components. Mozilla, for example, uses SFI to harden the Firefox browser by sandboxing third-party libraries, and companies like Fastly and Cloudflare use SFI to safely co-locate untrusted tenants on their edge clouds. While there have been significant efforts to optimize and verify SFI enforcement, context switching in SFI systems remains largely unexplored: almost all SFI systems use heavyweight transitions that are not only error-prone but incur significant performance overhead from saving, clearing, and restoring registers when context switching. We identify a set of zero-cost conditions that characterize when sandboxed code has sufficient structured to guarantee security via lightweight zero-cost transitions (simple function calls). We modify the Lucet Wasm compiler and its runtime to use zero-cost transitions, eliminating the undue performance tax on systems that rely on Lucet for sandboxing (e.g., we speed up image and font rendering in Firefox by up to 29.7% and 10% respectively). To remove the Lucet compiler and its correct implementation of the Wasm specification from the trusted computing base, we (1) develop a static binary verifier , VeriZero, which (in seconds) checks that binaries produced by Lucet satisfy our zero-cost conditions, and (2) prove the soundness of VeriZero by developing a logical relation that captures when a compiled Wasm function is semantically well-behaved with respect to our zero-cost conditions. Finally, we show that our model is useful beyond Wasm by describing a new, purpose-built SFI system, SegmentZero32, that uses x86 segmentation and LLVM with mostly off-the-shelf passes to enforce our zero-cost conditions; our prototype performs on-par with the state-of-the-art Native Client SFI system.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8b09a8a3-a14c-4c3c-af90-c3ddd8acd5e8Cited by top-tier papers9
- Going beyond the Limits of SFI: Flexible and Secure Hardware-Assisted In-Process Isolation with HFIShravan Narayan, Tal Garfinkel, Mohammadkazem Taram, Joey Rudek et al.ASPLOS 2023 · 27 citations
- Iris-Wasm: Robust and Modular Verification of WebAssembly ProgramsXiaojia Rao, Aïna Linn Georges, Maxime Legoupil, Conrad Watt et al.PLDI 2023 · 19 citations
- SECOMP: Formally Secure Compilation of Compartmentalized C ProgramsJérémy Thibault, Roberto Blanco, Dongjae Lee, Sven Argo et al.CCS 2024 · 1 citation
- Mohabi: Disaggregating and Sandboxing the Firefox JavaScript EngineAbhishek Sharma, Anand Balaji, Zachary Yedidia, Anthony Du et al.OSDI 2026 · 1 citation
- SoK: On the Fragility of Memory Error Exploit MitigationsAdriaan Jacobs, Mahmoud Ammar, Stijn VolckaertUSENIX Security 2026
Builds on5
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- Shreds: Fine-Grained Execution Units with Private MemoryYaohui Chen, Sebassujeen Reymondjohnson, Zhichuang Sun, Long LuS&P 2016 · 116 citations
- Доверя'й, но проверя'й: SFI safety for native-compiled WasmEvan Johnson, David Thien, Yousef Alhessi, Shravan Narayan et al.NDSS 2021
- Retrofitting Fine Grain Isolation in the Firefox RendererShravan Narayan, Craig Disselkoen, Tal Garfinkel, Nathan Froyd et al.USENIX Security 2020
- Donky: Domain Keys - Efficient In-Process Isolation for RISC-V and x86David Schrammel, Samuel Weiser, Stefan Steinegger, Martin Schwarzl et al.USENIX Security 2020
Related papers
- Segue & ColorGuard: Optimizing SFI Performance and Scalability on Modern ArchitecturesShravan Narayan, Tal Garfinkel, Evan Johnson, Zachary Yedidia et al.ASPLOS 2025 · 1 citation
- Lightweight Fault Isolation: Practical, Efficient, and Secure Software SandboxingZachary YedidiaASPLOS 2024 · 17 citations
- WaVe: a verifiably secure WebAssembly sandboxing runtimeEvan Johnson, Evan Laufer, Zijie Zhao, Dan Gohman et al.S&P 2023
- Deterministic Client: Enforcing Determinism on Untrusted Machine CodeZachary Yedidia, Geoffrey Ramseyer, David MazièresOSDI 2025 · 1 citation
- Provably-Safe Multilingual Software Sandboxing using WebAssemblyJay Bosamiya, Wen Shih Lim, Bryan ParnoUSENIX Security 2022
