3 ms·
CHERI (http://cheri-cpu.org http://cheri-cpu.org) provides a spatially-safe C and C++, and also heap temporal safety (specifically it prevents use-after-realloc
by jrtc27 6y ago
CHERI (http://cheri-cpu.org http://cheri-cpu.org) provides a spatially-safe C and C++, and also heap temporal safety (specifically it prevents use-after-reallocation, which is the actual vulnerability, since use-after-free doesn't matter if freed memory is never reallocated). Most code requires few, if any, changes (0.17% LoC in our fork of FreeBSD, which includes the kernel itself and all the low-level runtime libraries), with the changes tending to be due to people conflating pointers and integers (i.e. use uintptr_t not unsigned long/uint64_t for storing a union of a pointer and an integer, or a real union, and use size_t not uintptr_t when you mean a plain integer, though the latter can sometimes still work, just a little less efficiently and likely with some compiler warnings). It doesn't solve the concurrency issues, but unlike CHERI C/C++ those require invasive changes to the language and thus code.
We have a technical report that gives an overview of CHERI and describes how to write good C/C++ that doesn't use dodgy idioms that break in CHERI C/C++ if you're interested at https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-947.html https://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-947.html. Arm are also working on a prototype of Armv8-A with CHERI, dubbed Morello: https://www.morello-project.org https://www.morello-project.org.