Cerise: Program Verification on a Capability Machine in the Presence of Untrusted Code