Memory Safety: CHERI Hardware Capabilities & Pointer Provenance Studio
Explore the future of hardware-enforced spatial and temporal memory safety. Inspect the internal structure of 128-bit unforgeable CHERI capabilities, simulate silicon-level tag bit invalidation, and discover how Rust's strict pointer provenance eliminates undefined behavior without software sanitizers.
1. 128-Bit Capability Hardware Register Inspector (C0)
0x0000000000001000
0x0000000000001000
0x0000000000001040 (64 Bytes)
[Read, Write, LoadCap, StoreCap]
2. Hardware MMU Execution Trace & Silicon Trap Status
// ❌ Legacy Undefined Behavior (Breaks CHERI & Aliasing) let addr = ptr as usize; // Strips capability metadata! let rogue_ptr = addr as *mut u8; // Tag bit = 0 -> CRASH! // ✅ Modern Rust Strict Provenance (CHERI-Compliant) let addr = ptr.addr(); // Reads integer without stripping let valid_ptr = ptr.with_addr(new_addr); // Preserves capability bounds & tag!
⚠️ 5 Fatal Traps in Capability Architectures & Pointer Provenance
1. 'uintptr_t' Integer Pointer Casts Inverting Tag Bits
C and C++ code bases frequently store pointers inside integer data types (uintptr_t) or hash table arrays. When casting back from uintptr_t to a pointer on CHERI, the hardware tag is lost ($Tag = 0$), causing instantaneous hardware segmentation faults on first dereference.
2. Unaligned Capability Memory Reads in Custom Allocators
Because 128-bit capabilities require strict 16-byte memory alignment to map correctly to DRAM tag bit arrays, reading or writing a capability at an unaligned address (e.g. offset +8) strips the tag bit or triggers an unaligned hardware bus fault.
3. Sub-Object Bounds Narrowing Failures in C Structs
If a compiler allocates a composite C struct with multiple nested char arrays (e.g. struct { char buf1[16]; char buf2[16]; }) under coarse capability bounds spanning the full struct (32 bytes), an overflow in buf1 will overwrite buf2 without triggering a hardware fault unless sub-object bounds narrowing is enabled.
4. Overlooking In-Flight Register Dangling Pointers During Revocation
When memory is freed and the Cornucopia revocation engine sweeps DRAM pages to clear capability tag bits, it must also perform thread context synchronization. If a CPU core holds a freed capability inside a hardware register (e.g. C1..C31), that thread can still execute a Use-After-Free write until thread registers are reloaded or flushed.
5. Raw Serialization of Capability Pointers Over IPC or Network
Writing capabilities directly to disk files, shared memory pipes, or network sockets copies only the 16 bytes of data. The out-of-band DRAM tag bit cannot be serialized onto a network wire. When read back by another process or machine, the tag is missing, rendering all deserialized pointers unusable.