flâneur — a map of the web's best reading

Laurence Tratt: Two Stories for "What is CHERI?"

tratt.net · 5,751 words · saved by 1 readers

Having grappled with this myself, and having helped others grapple it, I think that the major reason is that the high-level story requires understanding quite a bit of detail — hardware, Operating Systems (OSs), programming languages (and some end user programs) all have to be adapted for CHERI [1]. Most people tend to focus at first solely on the CPU, but one can't form a coherent story from the CPU alone. Those who persist and piece together the other parts of CHERI can then get swept up in the novelty of the idea, and assume that CHERI magically secures everything it touches. However, CHERI is just a tool and, like all tools, it's better at some things than others — and, even then, only when used thoughtfully. In this blog post I'm going to explain just enough of CHERI to put together two coherent stories for what it is and where it might be used. I'm not going to try and cover all the possibilities, since, as you'll see, this post is long enough as it is! One reason for that is tha

Laurence Tratt: Two Stories for "What is CHERI?" Home > Blog ≡ Home > Blog email Bluesky Mastodon Twitter Bluesky Mastodon X Two Stories for "What is CHERI?" RSS feed: whole site or just the blog Recent posts Test-case Reducers Are Underappreciated Debugging Tools Retrofitting JIT Compilers into C Interpreters PLISS 2026 Upcoming Talk in London Async and Finaliser Deadlocks What Context Can Bring to Terminal Mouse Clicks Why Firsts Matter LLM Inflation Comparing the Glove80 and Maltron keyboards The LLM-for-software Yo-yo Blog archive Some readers might have heard of CHERI . Of those who’ve he

Explore this link on the map →

saved by

related reading