Skip to content
Book Open access

zBulk: Towards Automatic Compartmentalization in Rust with Zero Manual Retrofitting

Sep 2026 · Proceedings of the 14th Workshop on Programming Languages and Operating Systems · 0 citations · 12 references

Abstract

Memory safety is a dominant driver in security and systems research. Rust has become a viable alternative to C/C++ for systems programming because of its strong memory safety guarantees. However, it is not a silver bullet. Unsafe sections, foreign code, and compiler-soundness bugs still pose vulnerabilities. Compartmentalization splits a program into pieces and executes these in isolated, collaborating contexts. This way, the impact of a software vulnerability can, ideally, be limited to a single compartment. However, manual compartmentalization approaches are considered labor-intensive and error-prone, and require deep system expertise. We present zBulk, an automatic compartmentalization system that requires zero retrofitting to application code and paves the way for flexible fine-grained compartmentalization. We achieve this high degree of automation by leveraging static type- and call information, and language constructs that declare mutability and ownership. We show how to design zBulk, leveraging rustc's intermediate representations. We verify the approach by fully automatically compartmentalizing a relatively small systems application with a single dependency into up to eight compartments. We discuss how this number can be increased for even more flexibility. We report overhead measurements for Intel SGX as a first isolation mechanism, with more to follow.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.