arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.36731cs.CRcs.ARcs.OS

基于CHERI的高效链接式隔离模型

Efficient Linkage-Based Compartmentalization on CHERI

  • University of Cambridge(剑桥大学)
  • Ararat River Consulting(阿拉腊特河咨询公司)
  • Arm Limited(安谋投资有限公司)
  • Capabilities Limited(能力有限公司)
  • Google(谷歌)
  • MSB Associates(MSB协会)

机构由 AI 辅助整理,请以论文原文为准。

Dapeng Gao, John Baldwin, Jessica Clarke, Nicholas C. Connolly, Brooks Davis, Franz A. Fuchs, Alfredo Mazzinghi, Daniel Moghimi, Peter Rugg, Domagoj Stolfa, Kon… 展开作者

Dapeng Gao, John Baldwin, Jessica Clarke, Nicholas C. Connolly, Brooks Davis, Franz A. Fuchs, Alfredo Mazzinghi, Daniel Moghimi, Peter Rugg, Domagoj Stolfa, Konrad Witaszczyk, Simon W. Moore, Robert N. M. Watson

AI总结:

提出基于CHERI的链接式进程内隔离模型,支持细粒度隔离,可扩展至10K+隔离域,仅V8需少量源码适配,并在多种处理器上验证。

AI中文摘要:

我们提出了一种基于CHERI内存安全的高效链接式进程内隔离模型,该模型能够对整个UNIX用户空间进行细粒度隔离,在桌面系统上可扩展至10K+个隔离域。该模型沿现有库边界进行“一键式”隔离,对于Chromium等大型应用,每个进程通常可承载500+个隔离域,远超其他机制支持的并发可用保护域数量(例如Intel MPK最多支持16个)。自定义策略可进一步细分库。在测试的数千个C/C++程序中,仅V8 JavaScript引擎需要源码级适配(涉及垃圾回收和JIT编译的代码改动少于300行)。我们通过在编译器工具链和操作系统中的支持,为CHERI扩展的Armv8-A和RISC-V实现了该模型。案例研究展示了隔离域间内存的平滑委托、隔离域感知的调试与可视化,以及对复杂托管语言运行时的可扩展性,证明了我们单地址空间模型的优势。我们使用多个处理器进行评估,包括Arm的超标量Morello,以及首个商用的支持CHERI的RISC-V应用核心——Codasip的顺序双发射X730。

英文摘要:

We present an efficient linkage-based model for in-process compartmentalization built on CHERI memory safety, which enables fine-grained compartmentalization of the entire UNIX user-space, scaling to 10K+ compartments on desktop systems. The model's "push-button" compartmentalization along existing library boundaries regularly hosts 500+ compartments per process for large applications such as Chromium, far exceeding the number of concurrently available protection domains supported by other mechanisms (e.g., up to 16 for Intel MPK). Custom policies can further subdivide libraries. Of the thousands of C/C++ programs tested, only the V8 JavaScript engine required source-level adaptation (<300 lines of changed code concerning garbage collection and JIT compilation). We implement the model for CHERI-extended versions of Armv8-A and RISC-V through support in the compiler toolchain and operating system. Case studies illustrate the smooth delegation of memory between compartments, compartment-aware debugging and visualization, as well as extensibility to a complex managed language runtime, demonstrating the benefits of our single-address-space model. We evaluate using multiple processors, including Arm's superscalar Morello and, notably, the first commercial CHERI-enabled RISC-V application core---Codasip's in-order dual-issue X730.

补充信息

↑