arXiv · 2606.02651
From Rocq to Metal: A Pipeline for Formally Verified Microcontroller Firmware
Abstract
Enforcing invariants in safety-critical firmware is increasingly urgent as generated code becomes widespread, but standard extraction targets for proof assistants require runtimes too large for many embedded devices. We present a pipeline for running formally verified Rocq firmware logic on Cortex-M microcontrollers. The pipeline extracts Gallina to Scheme, compiles it with Encore!, a bare-metal Continuation Passing Style (CPS) bytecode virtual machine, and embeds the result in no_std Rust firmware. We structure applications as pure state-transition functions, so the business logic is proved in Rocq while the event/effect boundary, host callbacks, compiler, and VM remain explicit trusted components. On ST33-class targets with a 50 KB RAM lower bound, Encore! executes Rocq-extracted code end-to-end, stays within the target memory budget on our benchmarks, and validates a transaction-signing application on physical Ledger Flex hardware.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Valentin Bergeron, Karolina Gorna. 2026-09-21. From Rocq to Metal: A Pipeline for Formally Verified Microcontroller Firmware. https://arxiv.org/abs/2606.02651
Cite the original work for its findings. Save a collection to share your selection of sources.