SOURCE ARCHIVE
EXTRACTED CONTENT
19,569 charsASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Manfred Schlägl, Andreas Hinterdorfer, Daniel Große
Institute for Complex Systems (ICS)
Web: jku.at/ics
Email: manfred.schlaegl@jku.at
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Table of Contents
• Motivation • Simple Example • Capability Hardware Enhanced RISC Instructions (CHERI) • Virtual Prototypes • Goals and Contribution • RISC-V VP++ • Implementation of CHERI-RISC-V VP++ • Verification of CHERI-RISC-V VP++ • Case Studies: CheriBSD • Conclusion
2
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Motivation • Memory safety issues cause majority 0000 : ( ; of security vulnerabilities | ◦ Buffer overflows : ◦ Use-after-free Buffer overflow Use-after-free
Hardware-supported
• Software mitigations are partial and costly dy =i
• Need: hardware-supported memory safety |
• Solution: Capability Hardware Enhanced RISC Instructions (CHERI) -
Capability pointers, tagged
Bounds / seal tags
J JOHANNES KEPLER 3
UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Simple Example: Code
1 int main() { 2 int32_t array[5] = {0}; 3 uint64_t length = sizeof(array) / sizeof(array[0]); 4 int32_t ∗p_array = array; 5 // Intended read over the bounds 6 for (uint32_t i = 0; i <= length + 5; i++) { 7 printf("Count:␣%d,␣Value:␣%d\n", i, ∗(p_array + i)); 8 } 9 return 0; 10 }
4
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Simple Example: Execution
Non-CHERI CHERI Count: 0, Value: 0 Count: 0, Value: 0 Count: 1, Value: 0 Count: 1, Value: 0 Count: 2, Value: 0 Count: 2, Value: 0 Count: 3, Value: 0 Count: 3, Value: 0 Count: 4, Value: 0 Count: 4, Value: 0 Count: 5, Value: 5 CHERI Exception: LengthViolation Count: 6, Value: 0 ” Count: 7, Value: 0 Read beyond bounds prevented Count: 8, Value: 33554364 Count: 9, Value: 9 Read beyond bounds Count: 10, Value: 5
J §) JOHANNES KEPLER 5 UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI – Capability Hardware Enhanced RISC Instructions
• Hardware-based approach • Developed by the University of Cambridge in 2010 Technical • Increase Memory Safety of RISC processors Report CAMBRIDGE • Extension of existing ISAs • ISA independent An Introduction to CHERI ◦ RISC-V ◦ MIPS Robert N. M. Watson, Simon W. Moore, Peter Sewell, Peter G. Neumann ◦ ARM (Morello) ◦ x86 • Large ecosystem available
RiVersity ting 6
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Capabilities are an architectural primitive that compilers, systems software, and applications use to constrain their own future execution • Capabilities extend integer memory addresses (now 128 bit) • Metadata (bounds, permissions, …) control how it may be used • Tags protect capability integrity/derivation in registers + memory
→ Traditional Pointers in Programs are replaced by Capabilities
7
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Bounds: Encoding of base and top • Uses compression algorithm (relative to address)
8
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Flag (flag_cap_mode) • Required in Hybrid-Mode → CHERI aware and legacy code can run side by side
9
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Reserved
10
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Object type, the capability points to • Example: Validation of Object Method invocation (Data Capability + Execution Capability)
11
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Allows fine-grained memory protection • Examples: Load, Store, Execute, …
12
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Capabilities
• Tag Bit • Out-of-band: stored separately from normal data • Atomically bound to capability • Validates capability
13
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI: Consequences for Hardware
• General purpose registers become 129 bit (64 bit address + 64 bit metadata + 1 bit validity tag) • Program counter also extended w capability • Tagged memory protects capability-sized and -aligned words in DRAM by adding validity tag • Bus architecture extended to transport out-of-bound tags • ISA is extended with CHERI instructions • ISA instructions enforce monotonicity and guarded manipulation
14
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Level
Virtual Prototypes System on
A Virtual Prototype (VP) is a executable software ny model of a hardware system that runs on a host computer. al"00, Sa ~J oeo / 2. oil • Modeled at the transaction level (TLM) NS ) • Binary compatible to real/physical hardware • Widely used by semiconductor global players → Industrial-proven ps • Modeled in SystemC (C++ class library, IEEE1666-2023) Y-diagram by Gajski; modified
Applications: Early design space exploration, parallelization of HW and SW development, and system evaluation and validation, … → Fast enough for near-realtime simulation → Accurate enough for early system-level evaluation
J U JOHANNES KEPLER 15 UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI Evaluation Platforms
RTL-Simulation Virtual Prototypes Emulation (QEMU) • Very slow • Faster than RTL • Fast • Deterministic • Deterministic • Nondeterministic • Cycle-accurate • Cycle-Approximate • Not cycle-accurate • High Observability • High Observability • Hard to inspect hardware model • Running software • Can run entire OS • Can run entire OS basically impossible
16
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Goals and Contributions
Goals: • Observable hardware simulation • CHERI-enabled SystemC VP ◦ Extension of existing VP • Running complex, CHERI-enabled software on VP • Enabling: Early software development, Design space exploration, Security analysis, …
Contributions: • First open-source SystemC/TLM VP with VMM supporting CHERI-RISC-V (v9) • Verification process via TestRIG • Case studies: CheriBSD with VMM runs on the VP, enabling detailed system-level evaluation
17
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
RISC-V VP++ = oh
Extensible and configurable Ci SystemC based, open-source RISC-V virtual prototype : RISC-V VP++ • RISC-V 32 & 64 bit single/multi-core PTOC| MM Rio ◦ Fast Interpreter-Based ISS → up to 440 MIPS Lay ◦ Vector Extension (RVV) version 1.0 Zephyr • Small uC based systems (e.g. bare metal SW, RTOS) = • Complex application processor based systems | FreeBSD with virtual memory, graphics, network … (e.g. Linux) Tr
→ https://github.com/ics-jku/riscv-vp-plusplus.git EE wring [=] + = EX: E
Linz | Bhi 18
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
CHERI-RISC-V VP++: Architectural Overview
ISS Capability TLM TagExtension
(RV64 Core) SystemC/TLM Extension for
Transactions including Tags
Decode/ fi : (no changes to SystemC
Capabilities Interpret/ d | necessary)
General Purpose Registers Execute TLB
Capabilities Instruction : DMI Access
Control & Status Registers Execution : ”
8
TLM Transactions | 4 =
» I]
TLM 2.0 Bus Memory Map Tagged
Memory
CLINT PLIC UART,
Timer/SW Ext. Interrupts Peripherals| Mass Storage,
Interrupts Framebuffer,
Mouse,
Interrupts | | | Keyboard
|unmodiied |New Network.
J Vv JOHANNES KEPLER 19 UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Verification: TestRIG
DII .. Direct Instruction Injection
Inject instructions in simulation
RVFI .. RISC-V Formal Interface
Retrieve execution traces
Reference Design Under Test
CHERI RISC-V Sail model CHERI RISC-V VP++ → Extended with DII and RVFI
20
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Verification Engine (VEngine)
Verification: TestRIG Results
[ Socket Socket
• Test Cases Executed: RISC-V RISC-V 2+ million test cases run across various categories, Sal moc RISCAY including CHERI-specific extensions • Instruction Coverage: Executed 1.8+ billion instructions, averaging 860 instructions per test case • Code Coverage: Relevant CHERI-related code coverage: High, with most critical lines tested
• Planned: ◦ Adapt RVVTS (ICCAD 2024) for CHERI-RISC-V VP++
J JOHANNES KEPLER 21 UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Simple Example Revisited: Source Code
1 int main() { 2 int32_t array[5] = {0}; 3 uint64_t length = sizeof(array) / sizeof(array[0]); 4 int32_t ∗p_array = array; // Capability pointing to array 5 // Intended read over the bounds 6 for (uint32_t i = 0; i <= length + 5; i++) { 7 printf("Count:␣%d,␣Value:␣%d\n", i, ∗(p_array + i)); 8 } 9 return 0; 10 } Capability p_array { Addr: 0x9FFFFFB8 Base: 0x9FFFFFB8 Top: 0x9FFFFFCC }
22
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Simple Example Revisited: Execution
No-CHERI CHERI Addr: Count: 0, Value: 0 @0x9FFFFFB8 Count: 0, Value: 0 Count: 1, Value: 0 @0x9FFFFFBC Count: 1, Value: 0 Count: 2, Value: 0 @0x9FFFFFC0 Count: 2, Value: 0 Count: 3, Value: 0 @0x9FFFFFC4 Count: 3, Value: 0 Count: 4, Value: 0 @0x9FFFFFC8 Count: 4, Value: 0 Count: 5, Value: 5 @0x9FFFFFCC CHERI Exception: LengthViolation Count: 6, Value: 0 ” Count: 7, Value: 0 Read beyond bounds prevented Count: 8, Value: 33554364 Count: 9, Value: 9 Read beyond bounds Capability p_array { Count: 10, Value: 5 Addr: … Base: 0x9FFFFFB8 Top: 0x9FFFFFCC } JOHANNES KEPLER 23 UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Case-Study: Booting CheriBSD on CHERI-RISC-V VP++
• CHERI-enabled FreeBSD # ./read_beyond_bounds ◦ Full-scale general purpose OS Count: 0, Value: 0 ◦ Unix-like Count: 1, Value: 0 • Boots in 25 seconds Count: 2, Value: 0 ◦ > 300 million instructions Count: 3, Value: 0 ◦ 20 million data loads Count: 4, Value: 0 ◦ 60 million data stores In−address space security exception ◦ 600 thousand capabilities stored (core dumped) • CHERI memory protection enforced #
Operating system kills the program,
but system still runs!
24
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Case-Study: Benchmark Workloads on CheriBSD
SW Overhead
200 Peak: 1.83x SW Overhead
—
nstruction Cla
WE Integer Access WE Float Access WEN CHERI Access AVG: 1.47x
1.75 Integer Others Float Others CHERI Others
7
5
>
5² © >o A© ~ >N IESᴬ o Ng> 5
£
g12s 3 3 & & & & & & & & © hd hd hd hd hd hd hd hd hd hd hd 2 1.00₁ i 4 N £0.75 052 @&D oD 5 0.62 0. 2 Qn 052 054 a on 053 0.59 X 08 0.54, £ 050 0.42 0.55 2 0.48 0.49 0.51 059 045 $0.50 052 : kl 4 £
025
0.00 NES Loᴺ &ᴺ LoNES Ny
oC © oC Nd oC f oCfoᴺ Nd&ᴺ oCLoᴺ fFᴺ Loᴺ fFᴺ NES Loᴺ &ᴺ Koᴺ & Loᴺ N Loᴺ N LoNES
DE EE EE oC oC NN oC © oC NN
CheriBSD dhrystone whetstone peg linear alg-mid loops-all-mid nnet_test parser radix2 sha zip MEAN
boot rose7 100x100-sp 10k-sp 125k big test test
preset 64k
J → More detailed discussion provided in paper
JAZ JOHANNES KEPLER 25
UNIVERSITY LINZ
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
Conclusion \
• First open-source SystemC/TLM VP with supporting CHERI-RISC-V (v9) • Verified robustness with TestRIG (DII/RIG/RVFI): 2+ million tests passed PAPER • Case study: CheriBSD boot + 10 benchmark workloads run on the VP, exercising 1 • the full CHERI trust/protection chain (ISA, MMU, memory, privilege, capability) Far = Measured average instruction overhead of 1.47 for CHERI-enabled workloads Ci → Validates the effectiveness of system-level VP approaches • Available as open-source on GitHub : RISC-V VP++ → https://github.com/ics-jku/riscv-vp-plusplus.git
RiVersity ting 26
ASP-DAC 2026, A RISC-V CHERI VP: Enabling System-Level Evaluation of the Capability-Based CHERI Architecture
A RISC-V CHERI VP: Boni Enabling System-Level Evaluation of the Capability-Based CHERI Architecture PAPER
Fg Fi
= Ll
: RISC-V VP++
© P
Manfred Schlägl, Andreas Hinterdorfer, Daniel Große
Institute for Complex Systems (ICS)
Web: jku.at/ics
Email: manfred.schlaegl@jku.at