Le temps des cerises: efficient temporal stack safety on capability machines using directed capabilities
Aïna Linn Georges, Alix Trieu, Lars Birkedal
Abstract
Capability machines are a type of CPUs that support fine-grained privilege separation using capabilities , machine words that include forms of authority. Formal models of capability machines and associated calling conventions have so far focused on establishing two forms of stack safety properties, namely local state encapsulation and well-bracketed control flow. We introduce a novel kind of directed capabilities and show how to use them to make an earlier suggested calling convention more efficient. In contrast to earlier work on capability machine models we do not only consider integrity properties but also confidentiality properties; we provide a unary logical relation to reason about the former and a binary logical relation to reason about the latter, each expressive enough to reason about temporal stack safety. While the logical relations are useful for reasoning about concrete examples, they do not on their own demonstrate that stack safety holds for a large class of programs. Therefore, we also show full abstraction of a compiler from an overlay semantics that internalizes the calling convention as a single call step and explicitly keeps track of the call stack and frame lifetimes to a base capability machine. All results have been mechanized in Coq.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ffe9870e-bb7a-4942-bf44-19114f6f1281Cited by top-tier papers10
- Asynchronous Probabilistic Couplings in Higher-Order Separation LogicSimon Oddershede Gregersen, Alejandro Aguirre, Philipp G. Haselwarter, Joseph Tassarotti et al.POPL 2024 · 23 citations
- Trillium: Higher-Order Concurrent and Distributed Separation Logic for Intensional RefinementAmin Timany, Simon Oddershede Gregersen, Léo Stefanesco, Jonas Kastberg Hinrichsen et al.POPL 2024 · 14 citations
- Proof Automation for Linearizability in Separation LogicIke Mulder, Robbert KrebbersOOPSLA 2023 · 8 citations
- VMSL: A Separation Logic for Mechanised Robust Safety of Virtual Machines Communicating above FF-AZongyuan Liu, Sergei Stepanenko, Jean Pichon-Pharabod, Amin Timany et al.PLDI 2023 · 7 citations
- Morello-Cerise: A Proof of Strong Encapsulation for the Arm Morello Capability Hardware ArchitectureAngus Hammond, Ricardo Almeida, Thomas Bauereiss, Brian Campbell et al.PLDI 2025 · 2 citations
Builds on5
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth et al.S&P 2020 · 71 citations
- Rigorous engineering for hardware security: Formal modelling and proof in the CHERI design and implementation processKyndylan Nienhuis, Alexandre Joannou, Thomas Bauereiss, Anthony C. J. Fox et al.S&P 2020 · 43 citations
- When Good Components Go Bad: Formally Secure Compilation Despite Dynamic CompromiseCarmine Abate, Arthur Azevedo de Amorim, Roberto Blanco, Ana Nora Evans et al.CCS 2018 · 43 citations
- Protecting the Stack with Metadata Policies and Tagged HardwareNick Roessler, André DeHonS&P 2018 · 37 citations
- Efficient and provable local capability revocation using uninitialized capabilitiesAïna Linn Georges, Armaël Guéneau, Thomas Van Strydonck, Amin Timany et al.POPL 2021 · 30 citations
Related papers
- Endangered by the Language But Saved by the Compiler: Robust Safety via Semantic Back-TranslationNiklas Mück, Aïna Linn Georges, Derek Dreyer, Deepak Garg et al.POPL 2026
- The Logical Essence of Well-Bracketed Control FlowAmin Timany, Armaël Guéneau, Lars BirkedalPOPL 2024 · 5 citations
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson et al.USENIX Security 2023
- Iris-MSWasm: Elucidating and Mechanising the Security Invariants of Memory-Safe WebAssemblyMaxime Legoupil, June Rousseau, Aïna Linn Georges, Jean Pichon-Pharabod et al.OOPSLA 2024 · 5 citations
- Security Reasoning via Substructural Dependency TrackingHemant Gouni, Frank Pfenning, Jonathan AldrichPOPL 2026 · 1 citation
