Rust and CHERI
The programming language Rust and the CHERI hardware architecture provide complementary approaches to memory safety. Rust catches many memory errors at compile‑time through its ownership system, while CHERI enforces fine‑grained bounds on pointers at runtime with hardware-backed capabilities. Rather than competing, the two technologies reinforce each other: Rust reduces the number of bugs that make it to production, and CHERI prevents exploits of the remaining bugs【785327860471465†L158-L174】.
Rewriting all existing software in Rust is impractical. The CHERI architecture can bring memory safety to legacy C/C++ code and allow Rust programs to interoperate safely with older components【785327860471465†L175-L182】. By isolating components and enforcing unforgeable capabilities, CHERI protects against supply‑chain attacks and supports compartmentalised software design, providing security by design【785327860471465†L186-L199】. The CHERIoT project applies these principles to microcontroller-class devices, building on CHERI to provide rich compartmentalisation for embedded systems【785327860471465†L203-L205】.
In practice, developers should use Rust for new code and leverage CHERI hardware to protect both new and existing codebases. This combined approach offers a robust defence against memory-safety vulnerabilities.
