Cornucopia Reloaded: Load Barriers for CHERI Heap Temporal Safety
Nathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Jessica Clarke, Peter Rugg, Brooks Davis, Mark Johnston, Robert M. Norton, David Chisnall, Simon W. Moore, Peter G. Neumann, Robert N. M. Watson
摘要
Violations of temporal memory safety ("use after free", "UAF") continue to pose a significant threat to software security. The CHERI capability architecture has shown promise as a technology for C and C++ language reference integrity and spatial memory safety. Building atop CHERI, prior works -CHERIvoke and Cornucopia -have explored adding heap temporal safety. The most pressing limitation of Cornucopia was its impractical "stop-the-world" pause times.
We present Cornucopia Reloaded, a re-designed drop-in replacement implementation of CHERI temporal safety, using a novel architectural feature -a per-page capability load barrier, added in Arm's Morello prototype CPU and CHERI-RISC-V -to nearly eliminate application pauses. We analyze the performance of Reloaded as well as Cornucopia and CHERIvoke on Morello, using the CHERI-compatible SPEC CPU2006 INT workloads to assess its impact on batch workloads and using pgbench and gRPC QPS as surrogate interactive workloads. Under Reloaded, applications no longer experience significant revocation-induced stop-the-world periods, without additional wall-or CPU-time cost over Cornucopia and with median 87% of Cornucopia's DRAM traffic overheads across SPEC CPU2006 and < 50% for pgbench.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- PICASSO: Scaling CHERI Use-After-Free Protection to Millions of Allocations using Colored CapabilitiesMerve Gülmez, Ruben Sturm, Hossam ElAtali, Håkan Englund 等USENIX Security 2026 · 被引用 5 次
- PoisonCap: Efficient Hierarchical Temporal Safety for CHERIYuecheng Wang, Jonathan Woodruff, Alfredo Mazzinghi, Peter Rugg 等CCS 2026 · 被引用 3 次
- Morello-Cerise: A Proof of Strong Encapsulation for the Arm Morello Capability Hardware ArchitectureAngus Hammond, Ricardo Almeida, Thomas Bauereiss, Brian Campbell 等PLDI 2025 · 被引用 2 次
- Securing Mixed Rust with Hardware CapabilitiesJason Zhijingcheng Yu, Fangqi Han, Kaustab Choudhury, Trevor E. Carlson 等CCS 2025 · 被引用 1 次
- SoK: Capability Operating Systems: Is the Future Finally Here?Noah Mauthe, Eric Ackermann, Sven BugielUSENIX Security 2026
它引用的顶会 Paper5
- Oscar: A Practical Page-Permissions-Based Scheme for Thwarting Dangling PointersThurston H. Y. Dang, Petros Maniatis, David A. WagnerUSENIX Security 2017 · 被引用 77 次
- Cornucopia: Temporal Safety for CHERI HeapsNathaniel Wesley Filardo, Brett F. Gutstein, Jonathan Woodruff, Sam Ainsworth 等S&P 2020 · 被引用 71 次
- A Robust and Efficient Defense against Use-after-Free Exploits via Concurrent Pointer SweepingDaiping Liu, Mingwei Zhang, Haining WangCCS 2018 · 被引用 43 次
- CRCount: Pointer Invalidation with Reference Counting to Mitigate Use-after-free in Legacy C/C++Jangseop Shin, Donghyun Kwon, Jiwon Seo, Yeongpil Cho 等NDSS 2019 · 被引用 37 次
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo 等MICRO 2023 · 被引用 22 次
相关 Paper
- Mon CHERI: Mitigating Uninitialized Memory Access with Conditional CapabilitiesMerve Gülmez, Håkan Englund, Jan Tobias Mühlberg, Thomas NymanS&P 2025
- Formal Mechanised Semantics of CHERI C: Capabilities, Undefined Behaviour, and ProvenanceVadim Zaliva, Kayvan Memarian, Ricardo Almeida, Jessica Clarke 等ASPLOS 2024 · 被引用 6 次
- Capstone: A Capability-based Foundation for Trustless Secure Memory AccessJason Zhijingcheng Yu, Conrad Watt, Aditya Badole, Trevor E. Carlson 等USENIX Security 2023
- Top of the Heap: Efficient Memory Error Protection of Safe Heap ObjectsKaiming Huang, Mathias Payer, Zhiyun Qian, Jack Sampson 等CCS 2024 · 被引用 3 次
- Efficient Linkage-Based Compartmentalization on CHERIDapeng Gao, John Baldwin, Jessica Clarke, Nicholas C. Connolly 等CCS 2026
