Urgent.News

What's breaking now, across thousands of outlets.

Tech

Presentation: Adopting Memory-Safety and Fine-Grained Compartmentalisation with CHERI

David Chisnall discusses how the CHERI hardware architecture redefines pointer safety to solve isolation and sharing challenges. He explains how CHERI enables spatial and temporal memory safety for C/C++, scales down to microcontrollers with CHERIoT, and replaces costly OS-level RPC mechanisms with lightweight, auditable compartmentalization - all without requiring massive codebase rewrites. By…

David Chisnall, Co-Founder and Director of Systems Architecture at SCI Semiconductor, delivered a presentation on adopting memory-safety and fine-grained compartmentalisation with CHERI at QCon London. Chisnall explained how CHERI hardware architecture redefines pointer safety to solve isolation and sharing challenges, making it possible to run multiple workloads without massive codebase rewrites.

To provide context, Chisnall first clarified that isolation has been possible for decades using MMUs for process and VM separation, but the difficulty arises when workloads need to communicate. He emphasized that CPUs are now cheap enough that running two fully isolated workloads on different computers is often the cheapest solution.

When discussing the CHERI ISA, Chisnall stressed that there isn't one; instead, CHERI is an abstract set of ideas localized to different ISAs, such as NEON or SVE on ARM, SSE or AVX on Intel, and CHERIoT on RISC-V. He explained that CHERI unifies two disparate research ideas: capability systems and fat pointers.

Capability systems have roots in the 1960s, using unforgeable tokens of authority to delegate permissions and reduce access levels. On the other hand, fat pointers add metadata to traditional language-level pointers, storing bounds and types alongside the address. CHERI merges these concepts to teach hardware about pointers, making them a thing rather than just a language-level abstraction.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at infoq.com →

More in Tech

More from Wednesday 12 August →