[seL4] User-level proofs and capability revocation