=== CheriBSD 22.12 release Links: + link:https://www.cheribsd.org[CheriBSD] URL: link:https://www.cheribsd.org[https://www.cheribsd.org] + link:https://lists.cam.ac.uk/sympa/info/cl-cheribsd-announce[CheriBSD Announcements list] URL: link:https://lists.cam.ac.uk/sympa/info/cl-cheribsd-announce[https://lists.cam.ac.uk/sympa/info/cl-cheribsd-announce] Contact: Brooks Davis + Contact: Edward Tomasz Napierala + Contact: George Neville-Neil + Contact: Jessica Clarke + Contact: John Baldwin + Contact: Robert Watson + Contact: Ruslan Bukin CheriBSD extends FreeBSD to implement memory protection and software compartmentalization features supported by the CHERI instruction-set extensions. There are two active architectural implementations of the CHERI protection model: CHERI-RISC-V and Arm's Morello. A sketch of CHERI-x86 is also under development. CheriBSD is a research operating system with a stable baseline implementation into which various new research features have been, or are currently being, merged. We have published the 22.12 release of CheriBSD including: * A general update of the baseline FreeBSD OS to August 2022. * Memory-safe adaptation of Direct Rendering Manager (DRM) and Panfrost device driver, which enable a Morello-based desktop system using on-board GPU and HDMI. These drivers may be used with hybrid or pure-capability kernels. * An initial set of graphics and desktop CheriABI software packages such as Wayland and portions of KDE to get you up and running with a memory-safe desktop environment. These components remain under active development, and we anticipate continuing package updates after the CheriBSD release. * An early research prototype of link:https://github.com/CTSRD-CHERI/cheripedia/wiki/Library-based-Compartmentalisation[library-based compartmentalization], which implements an alternative run-time linker running shared objects in libraries. This implementation is very much a work-in-progress, and is provided to enable research at other collaborator institutions needing easy access to the prototype. It is neither complete nor intended to be secure. * Improved pluggability of experimental heap temporal memory-safety support, which is not yet merged into the main development branch, but will now be easier to use by downloading an alternative kernel and heap allocator libraries provided by Microsoft. * An updated version of GDB with support for Morello instructions and inspecting memory tags. * Alpha support for ZFS file systems including support for boot environments.