Urgent.News

What's breaking now, across thousands of outlets.

Tech

Adopting Memory-Safety and Fine-Grained Compartmentalisation with CHERI

David Chisnall, Co-Founder and Director of Systems Architecture at SCI Semiconductor, delivered a presentation on adopting memory-safety and fine-grained compartmentalisation with CHERI at QCon London. Chisnall explained how CHERI hardware architecture redefines pointer safety to solve isolation and sharing challenges, making it possible to run multiple workloads without massive codebase rewrites.

To provide context, Chisnall first clarified that isolation has been possible for decades using MMUs for process and VM separation, but the difficulty arises when workloads need to communicate. He emphasized that CPUs are now cheap enough that running two fully isolated workloads on different computers is often the cheapest solution.

When discussing the CHERI ISA, Chisnall stressed that there isn't one; instead, CHERI is an abstract set of ideas localized to different ISAs, such as NEON or SVE on ARM, SSE or AVX on Intel, and CHERIoT on RISC-V. He explained that CHERI unifies two disparate research ideas: capability systems and fat pointers.

Capability systems have roots in the 1960s, using unforgeable tokens of authority to delegate permissions and reduce access levels. On the other hand, fat pointers add metadata to traditional language-level pointers, storing bounds and types alongside the address. CHERI merges these concepts to teach hardware about pointers, making them a thing rather than just a language-level abstraction.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at infoq.com →

More in Tech

More from Thursday 13 August →