Skip to content
STIMSMITH

SOURCE ARCHIVE

SHA256: 6f6a39843e76dce05cb9a641966d155fbf45bae95128650c43efdb649d42841f
TYPE: application/pdf
SIZE: 1555.0 KB
FETCHED: 6/21/2026, 10:10:53 PM
EXTRACTOR: liteparse
CHARS: 19,569

EXTRACTED CONTENT

19,569 chars
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Manfred Schlägl, Andreas Hinterdorfer, Daniel Große
Institute for Complex Systems (ICS)
Web: jku.at/ics
Email: manfred.schlaegl@jku.at

   ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Table of Contents

• Motivation • Simple Example • Capability Hardware Enhanced RISC Instructions (CHERI) • Virtual Prototypes • Goals and Contribution • RISC-V VP++ • Implementation of CHERI-RISC-V VP++ • Verification of CHERI-RISC-V VP++ • Case Studies: CheriBSD • Conclusion

2

    ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Motivation • Memory safety issues cause majority 0000 : ( ; of security vulnerabilities | ◦ Buffer overflows : ◦ Use-after-free Buffer overflow Use-after-free

        Hardware-supported
•  Software mitigations are partial and costly                         dy =i
•  Need: hardware-supported memory safety                              |
•  Solution: Capability Hardware Enhanced RISC Instructions (CHERI)     -

        Capability pointers, tagged
                                                                       Bounds / seal tags

J   JOHANNES KEPLER                                                      3
    UNIVERSITY LINZ

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Simple Example: Code

1 int main() { 2 int32_t array[5] = {0}; 3 uint64_t length = sizeof(array) / sizeof(array[0]); 4 int32_t ∗p_array = array; 5 // Intended read over the bounds 6 for (uint32_t i = 0; i <= length + 5; i++) { 7 printf("Count:␣%d,␣Value:␣%d\n", i, ∗(p_array + i)); 8 } 9 return 0; 10 }

           4

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Simple Example: Execution

Non-CHERI CHERI Count: 0, Value: 0 Count: 0, Value: 0 Count: 1, Value: 0 Count: 1, Value: 0 Count: 2, Value: 0 Count: 2, Value: 0 Count: 3, Value: 0 Count: 3, Value: 0 Count: 4, Value: 0 Count: 4, Value: 0 Count: 5, Value: 5 CHERI Exception: LengthViolation Count: 6, Value: 0 ” Count: 7, Value: 0 Read beyond bounds prevented Count: 8, Value: 33554364 Count: 9, Value: 9 Read beyond bounds Count: 10, Value: 5

J §) JOHANNES KEPLER 5 UNIVERSITY LINZ

      ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI – Capability Hardware Enhanced RISC Instructions

• Hardware-based approach • Developed by the University of Cambridge in 2010 Technical • Increase Memory Safety of RISC processors Report CAMBRIDGE • Extension of existing ISAs • ISA independent An Introduction to CHERI ◦ RISC-V ◦ MIPS Robert N. M. Watson, Simon W. Moore, Peter Sewell, Peter G. Neumann ◦ ARM (Morello) ◦ x86 • Large ecosystem available

  RiVersity ting    6

    ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Capabilities are an architectural primitive that compilers, systems software, and applications use to constrain their own future execution • Capabilities extend integer memory addresses (now 128 bit) • Metadata (bounds, permissions, …) control how it may be used • Tags protect capability integrity/derivation in registers + memory

→ Traditional Pointers in Programs are replaced by Capabilities


7

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Bounds: Encoding of base and top • Uses compression algorithm (relative to address)

8

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Flag (flag_cap_mode) • Required in Hybrid-Mode → CHERI aware and legacy code can run side by side

9

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Reserved

10

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Object type, the capability points to • Example: Validation of Object Method invocation (Data Capability + Execution Capability)

11

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Allows fine-grained memory protection • Examples: Load, Store, Execute, …

12

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Capabilities

• Tag Bit • Out-of-band: stored separately from normal data • Atomically bound to capability • Validates capability

13

    ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI: Consequences for Hardware

• General purpose registers become 129 bit (64 bit address + 64 bit metadata + 1 bit validity tag) • Program counter also extended w capability • Tagged memory protects capability-sized and -aligned words in DRAM by adding validity tag • Bus architecture extended to transport out-of-bound tags • ISA is extended with CHERI instructions • ISA instructions enforce monotonicity and guarded manipulation

14

   ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
                                                       Level

Virtual Prototypes System on

A Virtual Prototype (VP) is a executable software ny model of a hardware system that runs on a host computer. al"00, Sa ~J oeo / 2. oil • Modeled at the transaction level (TLM) NS ) • Binary compatible to real/physical hardware • Widely used by semiconductor global players → Industrial-proven ps • Modeled in SystemC (C++ class library, IEEE1666-2023) Y-diagram by Gajski; modified

Applications: Early design space exploration, parallelization of HW and SW development, and system evaluation and validation, … → Fast enough for near-realtime simulation → Accurate enough for early system-level evaluation

J U JOHANNES KEPLER 15 UNIVERSITY LINZ

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI Evaluation Platforms

RTL-Simulation Virtual Prototypes Emulation (QEMU) • Very slow • Faster than RTL • Fast • Deterministic • Deterministic • Nondeterministic • Cycle-accurate • Cycle-Approximate • Not cycle-accurate • High Observability • High Observability • Hard to inspect hardware model • Running software • Can run entire OS • Can run entire OS basically impossible

                                                    16

   ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Goals and Contributions

Goals: • Observable hardware simulation • CHERI-enabled SystemC VP ◦ Extension of existing VP • Running complex, CHERI-enabled software on VP • Enabling: Early software development, Design space exploration, Security analysis, …

Contributions: • First open-source SystemC/TLM VP with VMM supporting CHERI-RISC-V (v9) • Verification process via TestRIG • Case studies: CheriBSD with VMM runs on the VP, enabling detailed system-level evaluation

   17

    ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

RISC-V VP++ = oh

Extensible and configurable Ci SystemC based, open-source RISC-V virtual prototype : RISC-V VP++ • RISC-V 32 & 64 bit single/multi-core PTOC| MM Rio ◦ Fast Interpreter-Based ISS → up to 440 MIPS Lay ◦ Vector Extension (RVV) version 1.0 Zephyr • Small uC based systems (e.g. bare metal SW, RTOS) = • Complex application processor based systems | FreeBSD with virtual memory, graphics, network … (e.g. Linux) Tr

https://github.com/ics-jku/riscv-vp-plusplus.git EE wring [=] + = EX: E

    Linz | Bhi 18

        ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

CHERI-RISC-V VP++: Architectural Overview

    ISS        Capability                                         TLM TagExtension
    (RV64 Core)                                                   SystemC/TLM Extension for
                                                                  Transactions including Tags
                                 Decode/    fi   :                (no changes to SystemC
           Capabilities         Interpret/       d          |     necessary)
    General Purpose Registers    Execute                  TLB
           Capabilities      Instruction    :                 DMI Access
    Control & Status Registers  Execution                          :     ”
                                                                   8
        TLM Transactions                                  |           4  =
        »                                                              I]
    TLM 2.0 Bus        Memory Map                               Tagged
                                                                Memory

        CLINT                      PLIC                   UART,
        Timer/SW        Ext. Interrupts     Peripherals|  Mass Storage,
        Interrupts                                        Framebuffer,
                                                          Mouse,
    Interrupts        |      |      |                     Keyboard
     |unmodiied        |New                               Network.

J Vv JOHANNES KEPLER 19 UNIVERSITY LINZ

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Verification: TestRIG

                     DII .. Direct Instruction Injection
                     Inject instructions in simulation

                     RVFI .. RISC-V Formal Interface
                     Retrieve execution traces










   Reference    Design Under Test

CHERI RISC-V Sail model CHERI RISC-V VP++ → Extended with DII and RVFI

                         20

   ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
   Verification Engine (VEngine)

Verification: TestRIG Results

                                                                   [ Socket    Socket

• Test Cases Executed: RISC-V RISC-V 2+ million test cases run across various categories, Sal moc RISCAY including CHERI-specific extensions • Instruction Coverage: Executed 1.8+ billion instructions, averaging 860 instructions per test case • Code Coverage: Relevant CHERI-related code coverage: High, with most critical lines tested

• Planned: ◦ Adapt RVVTS (ICCAD 2024) for CHERI-RISC-V VP++

J JOHANNES KEPLER 21 UNIVERSITY LINZ

ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Simple Example Revisited: Source Code

1 int main() { 2 int32_t array[5] = {0}; 3 uint64_t length = sizeof(array) / sizeof(array[0]); 4 int32_t ∗p_array = array; // Capability pointing to array 5 // Intended read over the bounds 6 for (uint32_t i = 0; i <= length + 5; i++) { 7 printf("Count:␣%d,␣Value:␣%d\n", i, ∗(p_array + i)); 8 } 9 return 0; 10 } Capability p_array { Addr: 0x9FFFFFB8 Base: 0x9FFFFFB8 Top: 0x9FFFFFCC }

               22

                       ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Simple Example Revisited: Execution

No-CHERI CHERI Addr: Count: 0, Value: 0 @0x9FFFFFB8 Count: 0, Value: 0 Count: 1, Value: 0 @0x9FFFFFBC Count: 1, Value: 0 Count: 2, Value: 0 @0x9FFFFFC0 Count: 2, Value: 0 Count: 3, Value: 0 @0x9FFFFFC4 Count: 3, Value: 0 Count: 4, Value: 0 @0x9FFFFFC8 Count: 4, Value: 0 Count: 5, Value: 5 @0x9FFFFFCC CHERI Exception: LengthViolation Count: 6, Value: 0 ” Count: 7, Value: 0 Read beyond bounds prevented Count: 8, Value: 33554364 Count: 9, Value: 9 Read beyond bounds Capability p_array { Count: 10, Value: 5 Addr: … Base: 0x9FFFFFB8 Top: 0x9FFFFFCC } JOHANNES KEPLER 23 UNIVERSITY LINZ

   ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Case-Study: Booting CheriBSD on CHERI-RISC-V VP++

• CHERI-enabled FreeBSD # ./read_beyond_bounds ◦ Full-scale general purpose OS Count: 0, Value: 0 ◦ Unix-like Count: 1, Value: 0 • Boots in 25 seconds Count: 2, Value: 0 ◦ > 300 million instructions Count: 3, Value: 0 ◦ 20 million data loads Count: 4, Value: 0 ◦ 60 million data stores In−address space security exception ◦ 600 thousand capabilities stored (core dumped) • CHERI memory protection enforced #

                                       Operating system kills the program,
                                       but system still runs!


                                       24

                                                                          ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

      Case-Study: Benchmark Workloads on CheriBSD
                                                                                                                SW Overhead
  200                                                                                                           Peak: 1.83x        SW Overhead
                            —
                            nstruction Cla
      WE   Integer Access   WE Float Access     WEN   CHERI Access                                                                   AVG: 1.47x
  1.75     Integer Others       Float Others          CHERI Others

7 5 > 5² © >o A© ~ >N IESᴬ o Ng> 5 £

g12s 3 3 & & & & & & & & © hd hd hd hd hd hd hd hd hd hd hd 2 1.00₁ i 4 N £0.75 052 @&D oD 5 0.62 0. 2 Qn 052 054 a on 053 0.59 X 08 0.54, £ 050 0.42 0.55 2 0.48 0.49 0.51 059 045 $0.50 052 : kl 4 £

  025



  0.00  NES Loᴺ             &ᴺ LoNES                                                                        Ny
      oC    © oC            Nd oC f                   oCfoᴺ Nd&ᴺ   oCLoᴺ   fFᴺ       Loᴺ fFᴺ              NES  Loᴺ &ᴺ Koᴺ &    Loᴺ     N Loᴺ  N  LoNES
      DE                         EE                                        EE oC         oC      NN      oC              ©             oC NN
      CheriBSD   dhrystone      whetstone   peg                    linear  alg-mid   loops-all-mid  nnet_test  parser  radix2      sha      zip  MEAN
        boot                                rose7                  100x100-sp        10k-sp        125k                big         test     test
                                            preset                                                                     64k
            J                                              → More detailed discussion provided in paper
      JAZ JOHANNES KEPLER                                                                                                              25
                UNIVERSITY LINZ

    ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

Conclusion \

• First open-source SystemC/TLM VP with supporting CHERI-RISC-V (v9) • Verified robustness with TestRIG (DII/RIG/RVFI): 2+ million tests passed PAPER • Case study: CheriBSD boot + 10 benchmark workloads run on the VP, exercising 1 • the full CHERI trust/protection chain (ISA, MMU, memory, privilege, capability) Far = Measured average instruction overhead of 1.47 for CHERI-enabled workloads Ci → Validates the effectiveness of system-level VP approaches • Available as open-source on GitHub : RISC-V VP++ → https://github.com/ics-jku/riscv-vp-plusplus.git

RiVersity ting    26

    ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture

A RISC-V CHERI VP: Boni Enabling System-Level Evaluation of the Capability-Based CHERI Architecture PAPER

    Fg Fi
    = Ll



    : RISC-V VP++

    ©     P
Manfred Schlägl, Andreas Hinterdorfer, Daniel Große
Institute for Complex Systems (ICS)
Web: jku.at/ics
Email: manfred.schlaegl@jku.at