David Chisnall presents how the CHERI hardware architecture redefines pointer safety to solve isolation and sharing challenges in memory management. The talk covers how CHERI enables spatial and temporal memory safety for C/C++, scales down to microcontrollers via CHERIoT, and replaces costly OS-level RPC mechanisms with lightweight, auditable compartmentalization without requiring massive codebase rewrites.
Background
CHERI (Capability Hardware Enriched RISC Instructions) is a hardware architecture extension developed by the University of Cambridge that enriches pointers with capabilities to enforce memory safety and isolation at the hardware level. It is being adopted across a range of platforms from microcontrollers to servers.
- Source
- Lobsters
- Published
- Aug 13, 2026 at 10:30 PM
- Score
- 7.0 / 10