Kage: Google Experimenting With Linux Driver Isolation Using In-Kernel LFI Sandboxes
Curated from Phoronix
Device drivers remain the primary attack surface for kernel exploits, often forcing administrators to choose between performance and security. Google’s exploration of in-kernel sandboxes using LLVM’s Lightweight Fault Isolation offers a novel approach to this dilemma. Rather than relying solely on out-of-kernel virtualization, which adds latency, this experiment aims to contain driver faults within the kernel itself. For SREs managing large-scale infrastructure, this is significant because it targets the root cause of many privilege escalation vectors without the overhead of traditional containerization or hardware-assisted virtualization. The practical takeaway is to monitor the evolution of LFI in upstream kernels, as early adoption of such isolation primitives could eventually reduce your reliance on complex user-space workarounds for untrusted driver modules.
Google engineers are experimenting with Linux kernel device driver isolation using in-kernel sandboxes leveraging LLVM's Lightweight Fault Isolation (LFI) functionality...
— Phoronix