CHERI
CHERI Clang/LLVM and LLD
CHERI Clang/LLVM and LLD are adaptations of the open-source Clang/LLVM compiler and LLD linker to support the CHERI-RISC-V—and, historically, CHERI-MIPS—ISAs. Morello and CHERIoT Clang/LLVM and LLD are further adaptations to support their respective ISAs, and Codasip Clang/LLVM and LLD is a further adaptation by Codasip to support the upcoming standard RISC-V "Y" base CHERI ISA. They collectively implement the CHERI C/C++ programming language, described in the CHERI C/C++ Programming Guide, as well as CHERI Hybrid C/C++. This includes support for strong referential and spatial memory protection, as well as providing foundations for temporal memory protection. In addition, they provide provide support for CHERI software compartmentalization, an area of ongoing active research, for which CHERI/C++ is a critical foundation.
Exploring CHERI code generation with Compiler Explorer
We maintain a CHERI Compiler Explorer web service, which allows you to experiment with various forms of CHERI code generation. This includes baseline, hybrid, and pure-capability code generation for CHERI-RISC-V, Morello, and CHERI-MIPS.
Obtaining CHERI Clang/LLVM and LLD
If you are using a Morello board with CheriBSD, we recommend using a pre-built CheriBSD release, where you can install Morello Clang/LLVM and LLD as a package without needing to build it yourself. Instructions for this can be found in our Getting Started with CheriBSD guide.
The best way to get started with CHERI Clang/LLVM and LLD for CHERI-RISC-V, or Morello Clang/LLVM and LLD for Morello if not using our pre-built CheriBSD and associated packages, is using our cheribuild tool. cheribuild will download any necessary source code, build our cross-development environment, the CheriBSD OS, and any necessary emulators, create disk images, and run the emulation tool, CHERI QEMU. For Morello, you can also opt to use Arm's Morello FVP model, which cheribuild will download automatically.
Get started with CHERI Clang/LLVM and LLD for CHERI-RISC-V in one command line:
./cheribuild.py --include-dependencies llvm
Get started with Morello Clang/LLVM and LLD for Morello in one command line:
./cheribuild.py --include-dependencies morello-llvm
In practice, however, the CHERI compiler suite is most useful if you also have an OS image and emulator. The following command line builds CheriBSD/RISC-V, CHERI QEMU, and the complete toolchain including tools such as CHERI GDB, and runs the resulting image in QEMU:
./cheribuild.py --include-dependencies run-riscv64-purecap
The following command line builds CheriBSD/Morello, CHERI QEMU, and the complete toolchain including tools such as CHERI GDB, and runs the resulting image in QEMU:
./cheribuild.py --include-dependencies run-morello-purecap
The CHERI Clang/LLVM and LLD source code can be found in the CHERI Clang/LLVM and LLD GitHub repository. We also use a GitHub issue tracker to track bugs and feature requests for CHERI Clang/LLVM and LLD.
For Morello, the source code can be found in Arm's Morello Clang/LLVM and LLD GitLab repository.
For CHERIoT, the source code can be found in the CHERIoT Platform's CHERIoT Clang/LLVM and LLD GitHub repository.
For Codasip, the source code can be found in the their Codasip Clang/LLVM and LLD GitHub repository branch.
Note that neither CHERIoT nor Codasip Clang/LLVM and LLD are maintained by the University of Cambridge; any bugs and feature requests for them should be directed to their respective owners.
Papers and documentation
CHERI Clang/LLVM was used as the foundation toolchain for our various publications at ISCA 2014, ASPLOS 2015, IEEE S&P 2015, ASPLOS 2019, and Oakland 2020 papers on CHERI memory protection, which can be found on the CHERI publications list.
Our paper on CheriABI explains CheriBSD's memory-safe process environment, which is the principal target execution environment for CHERI C/C++ code. The CHERI C/C++ Programming Guide documents CHERI C and C++.