logoalt Hacker News

afdbcreid • today at 5:31 AM • 1 reply • view on HN

Both only attach provenance to allocations. The common example is:

    struct User {
        char name[100];
        bool is_admin;
    };
Where a buffer overflow can still overwrite `is_admin`.

Both also require recompilation of everything, which might be possible for CHERI but not for Fil-C - which is why, for example, there cannot be Fil-C support for Windows or macOS.


Replies

cperciva • today at 6:25 AM

No, CHERI supports sub-object capabilities.

➕ show 1 reply