#cheri

6 posts · Last used 14d

My latest article for ACM Queue about CHERIoT is live! This describes the design decisions that we made in designing an aggressively privilege-separated OS with a single address space for embedded systems. It's part of a series of articles about designing single-address-space systems and aims to highlight which parts of CHERIoT are things that are a good idea everywhere and which are a good idea only for embedded systems. EDIT: Looks as if they mangled the title, it should read 'usable' not 'able'. EDIT2: And now they have fixed it. #CHERIoT #CHERI #ACMQueue
25
0
20
0
I wrote this post over a year ago, but it probably needs repeating periodically. From my perspective, CHERI isn't really about security, it's about making it possible to solve a bunch of interesting language-interoperability and end-user-programming problems that happen to need a bunch of security fixed as building blocks. And so we get a load of security stuff for free. But that's not why I worked on it. #CHERI #CHERIoT
37
2
20
0
When we originally created #CHERIoT, we added an instruction to make accessing globals uniform with respect to the rest of RISC-V. We fairly quickly realised it wasn’t a great design, but the toolchain changes required to eliminate it took a while. We’ve finally done it and I spent a bit of time this week writing up our journey. Removing this instruction is something we always planned to do before rebasing on the upcoming RV32YE base. #CHERI #RISCV
13
1
6
0
You've seen all posts