USENIX Security2026Top-tier venue
kSFS: Repurposing a Microkernel-like Interface for Fast and Secure In-Kernel Linux File Systems
Dinglan Peng, Pedro Fonseca
Abstract
File systems are widely-used and crucial but notoriously complex and a major source of vulnerabilities in operating systems. Recent works have proposed introducing in-kernel sandboxing techniques to isolate kernel components including file systems. However, a well-defined and secure boundary, where all interactions between untrusted and trusted kernel components should be validated against a strong threat model, is often ignored. This lack of secure boundary particularly applies to Linux file systems, which rely on a large and complex interface and interact with many kernel subsystems such as VFS and block devices. Defining such an interface is a challenging prerequisite of sandboxed kernel file systems. We address this challenge with kSFS, a framework for in-kernel sandboxed file systems. kSFS repurposes the FUSE protocol, which is a microkernel-like interface originally designed for user-space file systems in Linux, as a secure interface for untrusted sandboxed kernel file systems that has strong isolation guarantees. Furthermore, kSFS generalizes WebAssembly to kernel space as a generic sandboxing mechanism and achieves compatibility with existing user-space file system implementations with minimal porting effort. For instance, porting the NTFS and exFAT implementations from user space with kSFS required modifying fewer than 300 LoC. While achieving better security and reliability than Linux file system implementations, kSFS achieves significantly better performance than their user-space counterparts. For the real-world applications tar and RocksDB, the kSFS NTFS implementation achieves up to 29% and 60× better performance than the user-space baseline, respectively, and only 0% to 52% lower performance than the insecure Linux implementation.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e7f6e908-be09-4f70-9ff3-981f20f83938Builds on31
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 382 citations
- ERIM: Secure, Efficient In-process Isolation with Protection Keys (MPK)Anjo Vahldiek-Oberwagner, Eslam Elnikety, Nuno O. Duarte, Michael Sammler et al.USENIX Security 2019 · 247 citations
- CAn't Touch This: Software-only Mitigation against Rowhammer Attacks targeting Kernel MemoryFerdinand Brasser, Lucas Davi, David Gens, Christopher Liebchen et al.USENIX Security 2017 · 146 citations
- XRP: In-Kernel Storage Functions with eBPFYuhong Zhong, Haoyu Li, Yu Jian Wu, Ioannis Zarkadas et al.OSDI 2022 · 100 citations
Related papers
- RFUSE: Modernizing Userspace Filesystem Framework through Scalable Kernel-Userspace CommunicationKyu-Jin Cho, Jaewon Choi, Hyungjoon Kwon, Jin-Soo KimFAST 2024 · 9 citations
- High Velocity Kernel File Systems with BentoSamantha Miller, Kaiyuan Zhang, Mengqi Chen, Ryan Jennings et al.FAST 2021 · 28 citations
- XFUSE: An Infrastructure for Running Filesystem Services in User SpaceQianbo Huai, Windsor Hsu, Jiwei Lu, Hao Liang et al.USENIX ATC 2021 · 21 citations
- Scale and Performance in a Filesystem Semi-MicrokernelJing Liu, Anthony Rebello, Yifan Dai, Chenhao Ye et al.SOSP 2021 · 14 citations
- Empowering WebAssembly with Thin Kernel InterfacesArjun Ramesh, Tianshu Huang, Ben L. Titzer, Anthony RoweEuroSys 2025 · 7 citations
