Mind the Heap: Preventing Capability Leakage Across CHERI Compartments
Seyedhamed Ghavamnia, Maurice D. Hanisch, Julien Vanegue
Abstract
CAPability Warding by Automatically Restricting Dereference. Artifact for Mind the Heap: Preventing Capability Propagation Across CHERI Compartments. CHERI's library compartmentalization isolates code, but not the heap: a pointer handed across a compartment boundary remains a fully dereferenceable capability, so a compromised compartment can read and write any object it has ever been given. CAPWARD closes that gap automatically. It analyses a program's LLVM IR to find every struct type shared across a compartment boundary, decides which of them the non-owning compartment never actually dereferences, and rewrites the IR to seal those pointers with CHERI hardware seal/unseal operations at the boundary. A sealed capability can be stored and passed around but not dereferenced, so a pointer that leaks into a compromised compartment is inert there. The repository contains the analysis and instrumentation toolchain, the orchestration needed to apply it to real applications, the Rocq formalization, and the measurements reported in the paper.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 2e59f8f9-ef18-420f-a182-608f84b0f059Related papers
- Efficient and provable local capability revocation using uninitialized capabilitiesAïna Linn Georges, Armaël Guéneau, Thomas Van Strydonck, Amin Timany et al.POPL 2021 · 30 citations
- Formal Mechanised Semantics of CHERI C: Capabilities, Undefined Behaviour, and ProvenanceVadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke et al.ASPLOS 2024 · 6 citations
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERIYuecheng Wang, Jonathan Woodruff, Alfredo Mazzinghi, Peter Rugg et al.CCS 2026 · 3 citations
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson et al.USENIX Security 2023
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
