Neat, I didn't know that the MPU fault handler was complete enough to allow for restarts.
Now that the source is available, I took a look at what hubris does - it is not actually anything fancy, just a static list of up to 8 MPU regions per task [1].
It seems that leases aren't actually shared memory, but rather just grant permission for a memcpy-like syscall [2]. This is slightly better than plain message passing as the recipient gets to decide what memory it wants to access, but is still a memcpy.
[1] https://github.com/oxidecomputer/hubris/blob/8833cc1dcfdbf10...