We Need to Talk About the Actual Guarantees of Rust-based Systems
Abstract
Over the past decade, systems research has leveraged Rust to build systems that enforce valuable security and isolation guarantees over user-provided code in extensions. This paper identifies a common weakness in these Rust-based systems: extensions, even those that may be considered “safe,” may fail to uphold the language properties on which these systems rely. We present case studies where this mismatch breaks system guarantees and “safe” extensions corrupt kernel state in RedLeaf [35] and leak private data in Sesame [13]. As a path forward, we propose tooling to detect possible violations of system invariants in extension code. An early prototype static analysis tool suggests that this approach detects guarantee-breaking code with low false-positive rates.