Everything, Everywhere
Verified Specification | Standardized Formulas | Instant Precision
Secure & Private (Zero Data Retention) Free Access • No Sign-Up
Arm Morello / RISC-V CHERI 128-bit Hardware Capabilities Rust Strict Pointer Provenance

Memory Safety: CHERI Hardware Capabilities & Pointer Provenance Studio

Explore the future of hardware-enforced spatial and temporal memory safety. Inspect the internal structure of 128-bit unforgeable CHERI capabilities, simulate silicon-level tag bit invalidation, and discover how Rust's strict pointer provenance eliminates undefined behavior without software sanitizers.

1. 128-Bit Capability Hardware Register Inspector (C0)

Register: C0 (Capability Pointer to 64-byte Buffer) Hardware Tag: 1 (VALID CAPABILITY)
Virtual Address (Cursor):
0x0000000000001000
Base Address:
0x0000000000001000
Limit Address:
0x0000000000001040 (64 Bytes)
Hardware Permissions:
[Read, Write, LoadCap, StoreCap]

2. Hardware MMU Execution Trace & Silicon Trap Status

System ready. Click an operation above to test capability safety.
// ❌ Legacy Undefined Behavior (Breaks CHERI & Aliasing)
let addr = ptr as usize; // Strips capability metadata!
let rogue_ptr = addr as *mut u8; // Tag bit = 0 -> CRASH!

// ✅ Modern Rust Strict Provenance (CHERI-Compliant)
let addr = ptr.addr(); // Reads integer without stripping
let valid_ptr = ptr.with_addr(new_addr); // Preserves capability bounds & tag!

⚠️ 5 Fatal Traps in Capability Architectures & Pointer Provenance

1. 'uintptr_t' Integer Pointer Casts Inverting Tag Bits

C and C++ code bases frequently store pointers inside integer data types (uintptr_t) or hash table arrays. When casting back from uintptr_t to a pointer on CHERI, the hardware tag is lost ($Tag = 0$), causing instantaneous hardware segmentation faults on first dereference.

2. Unaligned Capability Memory Reads in Custom Allocators

Because 128-bit capabilities require strict 16-byte memory alignment to map correctly to DRAM tag bit arrays, reading or writing a capability at an unaligned address (e.g. offset +8) strips the tag bit or triggers an unaligned hardware bus fault.

3. Sub-Object Bounds Narrowing Failures in C Structs

If a compiler allocates a composite C struct with multiple nested char arrays (e.g. struct { char buf1[16]; char buf2[16]; }) under coarse capability bounds spanning the full struct (32 bytes), an overflow in buf1 will overwrite buf2 without triggering a hardware fault unless sub-object bounds narrowing is enabled.

4. Overlooking In-Flight Register Dangling Pointers During Revocation

When memory is freed and the Cornucopia revocation engine sweeps DRAM pages to clear capability tag bits, it must also perform thread context synchronization. If a CPU core holds a freed capability inside a hardware register (e.g. C1..C31), that thread can still execute a Use-After-Free write until thread registers are reloaded or flushed.

5. Raw Serialization of Capability Pointers Over IPC or Network

Writing capabilities directly to disk files, shared memory pipes, or network sockets copies only the 16 bytes of data. The out-of-band DRAM tag bit cannot be serialized onto a network wire. When read back by another process or machine, the tag is missing, rendering all deserialized pointers unusable.

Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement