CHERI is a hardware approach to memory safety that improves system security at runtime by extending established ISAs, such as ARM, RISC-V, and x86, with new architectural features. This cross-architecture project adapts the Linux Kernel and userspace software to benefit from CHERI’s memory protection and software compartmentalization features.
POSIX man page extensions, setup guides, Debian userspace and test suite work
by Paul Metzger
During the development of CheriBSD and CHERI support for Linux, POSIX interfaces had to be extended for CHERI. The two efforts made differing design decisions, hurting portability and motivating a …
CVA6 support, a test suite for POSIX-based OSes and work on glibc
by Paul Metzger
Hesham Almatary’s work at Capabilities Ltd has reached a significant milestone in the platform bring-up of CHERI-CVA6. As a reminder, CHERI-CVA6 is a 64-bit CHERI-RISC-V CPU that’s being …