CHERI Architecture: Porting Linux to Capability-Based Hardware for Enhanced Security
By
pykello
Hand-rolled, kettle-boiled, baked to perfection. Worth every minute at the bakery.
Summary
The article discusses the Capability Hardware Enhanced RISC Instructions (CHERI) project, a computer architecture redesign focused on improving system security through capabilities-based access control. It covers Carl Shaw's presentation at Linux Security Summit Europe about CHERI and efforts to port Linux to this architecture. The content explores the history of capabilities, their implementation in CHERI, and the technical challenges and progress in getting Linux to run on CHERI hardware.
Key quotes
· 3 pulledThe Capability Hardware Enhanced RISC Instructions (CHERI) project is a rethinking of computer architecture in order to improve system security.
Capabilities are a mechanism for access control, and outlined their history, which goes back...
Carl Shaw gave a presentation at Linux Security Summit Europe (LSS EU) about CHERI and the efforts to get Linux running on it.
You might also wanna read

Technical Analysis of macOS Boot Chain and Security Architecture on Apple Silicon
This technical article provides a comprehensive reverse engineering analysis of the macOS boot chain and security architecture on Apple Sili
ReactOS Achieves Experimental ARM64 Support, Boots on Apple Silicon via QEMU
ReactOS, the open-source project aiming for binary compatibility with Microsoft Windows, has achieved experimental support for running on 64
Understanding the Linux TTY Subsystem: History, Architecture, and Implementation
A comprehensive technical deep-dive into the TTY (teletype) subsystem in Linux and UNIX systems. The article traces the historical origins o
linusakesson.net·12d agoProgress on Haiku arm64 Port: Running Stably in QEMU, Targeting M1 MacBook Air
A developer is working on improving the arm64 port of Haiku, an open-source operating system, with the goal of eventually running it on an M
Haiku Project Releases Nightly Builds and April 2026 Activity Report
The Haiku Project provides nightly builds of its open-source operating system for testing purposes, offering bleeding-edge versions with the
Reefy: A Lightweight OS That Turns Any PC Into a Private AI Server
Reefy is a lightweight operating system that transforms any PC, laptop, mini PC, or GPU box into a private AI server with minimal setup. Use
