Formal Mechanised Semantics of CHERI C: Capabilities, Undefined Behaviour, and Provenance
Vadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke, Brooks Davis, Alexander Richardson, David Chisnall, Brian Campbell, Ian Stark, Robert N. M. Watson, Peter Sewell
Abstract
Memory safety issues are a persistent source of security vulnerabilities, with conventional architectures and the C codebase chronically prone to exploitable errors. The CHERI research project has shown how one can provide radically improved security for that existing codebase with minimal modification, using unforgeable hardware capabilities in place of machine-word pointers in CHERI dialects of C, implemented as adaptions of Clang/LLVM and GCC. CHERI was first prototyped as extensions of MIPS and RISC-V; it is currently being evaluated by Arm and others with the Arm Morello experimental architecture, processor, and platform, to explore its potential for mass-market adoption, and by Microsoft in their CHERIoT design for embedded cores.
There is thus considerable practical experience with CHERI C implementation and use, but exactly what CHERI C's semantics is (or should be) remains an open question. In this paper, we present the first attempt to rigorously and comprehensively define CHERI C semantics, discuss key semantics design questions relating to capabilities, provenance,
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e5b798e4-ed0b-4fa1-a804-60d68772b071Cited by top-tier papers2
- Compositional Symbolic Execution for the Next 700 Memory ModelsAndreas Lööw, Seung Hoon Park, Daniele Nantes-Sobrinho, Sacha-Élie Ayoun et al.OOPSLA 2025 · 4 citations
- Generically Automating Separation Logic by Functors, Homomorphisms, and ModulesQiyuan Xu, David Sanán, Zhe Hou, Xiaokun Luan et al.POPL 2025
Builds on3
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- Gillian, Part II: Real-World Verification for JavaScript and CPetar Maksimovic, Sacha-Élie Ayoun, José Fragoso Santos, Philippa GardnerCAV 2021 · 21 citations
- Don't Look UB: Exposing Sanitizer-Eliding Compiler OptimizationsRaphael Isemann, Cristiano Giuffrida, Herbert Bos, Erik van der Kouwe et al.PLDI 2023 · 5 citations
Related papers
- Morello-Cerise: A Proof of Strong Encapsulation for the Arm Morello Capability Hardware ArchitectureAngus Hammond, Ricardo Almeida, Thomas Bauereiss, Brian Campbell et al.PLDI 2025 · 2 citations
- Mon CHERI: Mitigating Uninitialized Memory Access with Conditional CapabilitiesMerve Gülmez, Håkan Englund, Jan Tobias Mühlberg, Thomas NymanS&P 2025
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation processKyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony C. J. Fox et al.S&P 2020 · 43 citations
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
- CapOpt: Capability-Aware Superoptimization for Secure and Provably Faster CodeXiaoyang Sun, Dejice Jacob, Huanting Wang, Jeremy Singer et al.OOPSLA 2026
