Hi Guys,
A silver lining here: I was looking around at memory-safety related mitigations for FreeBSD, and came across this:
Bringing memory safety to BSD (https://2026.asiabsdcon.org/entry/talk/LHKQG9/)
It seems like this chap, Brooks Davis, is going to supply his Capability Model work from CheriBSD to FreeBSD in version 16 of the OS. I imagine opnsense will inherit this memory protection system as well. Seems a lot less work than FreeBSD considering wholesale adoption Rust...
Good find. Just note that CHERI's hardware-enforced memory safety requires CHERI-capable hardware — mainly Arm Morello or CHERI-RISC-V — not existing x86‑64 systems. So on a regular AMD64/Intel machine it is interesting to follow, but it will not provide those benefits directly..
Morello boards were not generally available for purchase; CHERI-RISC-V/CHERIoT boards are more accessible, but they are development/embedded platforms rather than practical firewall hardware.
Ah, I see...
And there I was getting my hopes up!
Thanks for the clarification, though. Fingers crossed that something like this can make it to the world of x86-64, but if I understand you correctly, any mitigation of this type may require specialised hardware support.