Remix.run Logo
▲ afdbcreid 3 hours ago

Both only attach provenance to allocations. The common example is:

    struct User {
        char name[100];
        bool is_admin;
    };
Where a buffer overflow can still overwrite `is_admin`.

Both also require recompilation of everything, which might be possible for CHERI but not for Fil-C - which is why, for example, there cannot be Fil-C support for Windows or macOS.

▲cperciva 2 hours ago | parent | next [-]

No, CHERI supports sub-object capabilities.

▲afdbcreid an hour ago | parent [-]

Nice, didn't know that!

▲dwattttt an hour ago | parent [-]

It's a safe/stable operation to derive a more limited capability (pointer) from a more capable one. An example would be an arena allocator having a pointer valid for the whole arena, but then only handing out a derived pointer that's valid for the size requested.

You can also limit access permissions IIUC; I'm only going by old memory hear, but you'd be able to hand out a read-only pointer derived from an RWX pointer.

▲aw1621107 an hour ago | parent | prev [-]

IIRC Filip said that Fil-C can be modified fairly easily to catch those overflows, but that breaks a fair bit of C code.