Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



arrow_back View All Dates
Wednesday, October 7
 

07:30 CEST

Welcome Coffee
Wednesday October 7, 2026 07:30 - 09:00 CEST

Wednesday October 7, 2026 07:30 - 09:00 CEST
TBA

07:30 CEST

Solutions Showcase
Wednesday October 7, 2026 07:30 - 17:25 CEST
The Solutions Showcase is your hub to network, explore sponsor exhibits, and learn how these organizations are shaping the future of the ecosystem.

**In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.**
Wednesday October 7, 2026 07:30 - 17:25 CEST
Solutions Showcase, Floor 2 & 3 Foyers

07:30 CEST

Registration & Badge Pick-Up
Wednesday October 7, 2026 07:30 - 18:30 CEST

Wednesday October 7, 2026 07:30 - 18:30 CEST
Congress Hall Foyer 0A (Floor 0)

08:00 CEST

Hacker Space
Wednesday October 7, 2026 08:00 - 18:30 CEST
Discover a space, where you can collaborate, create, and explore new ideas with fellow attendees. Whether you’re here to learn or build, our space is open for everyone to enjoy throughout the conference!


Wednesday October 7, 2026 08:00 - 18:30 CEST
Terrace 2B (Floor 2)

08:00 CEST

Zen Zone
Wednesday October 7, 2026 08:00 - 18:30 CEST
All attendees may feel free to use the Zen Zone as needed. This is a quiet space for sensory relaxation, meditation, and worship. It is not to be used for conversations or as a workspace.

Wednesday October 7, 2026 08:00 - 18:30 CEST
TBA

09:00 CEST

Welcome & Opening Remarks - Welcome & Opening Remarks - Jim Zemlin, Chief Executive Officer, The Linux Foundation, Thierry Carrez, General Manager, OIF & LF Europe & Ramón Roche, Executive Director, Dronecode Foundation
Wednesday October 7, 2026 09:00 - 09:45 CEST

Speakers
avatar for Thierry Carrez

Thierry Carrez

General Manager, OIF & LF Europe

avatar for Ramon Roche

Ramon Roche

Executive Director - Dronecode Foundation, The Linux Foundation
avatar for Jim Zemlin

Jim Zemlin

Chief Executive Officer, The Linux Foundation
Jim Zemlin’s career spans three of the largest technology trends to rise over the last decade: mobile computing, cloud computing, and open source software. Today, as Chief Executive Officer of The Linux Foundation, he uses this experience to accelerate innovation in technology through... Read More →
Wednesday October 7, 2026 09:00 - 09:45 CEST
Congress Hall (Floor 2)

09:05 CEST

Embedded Linux Kernel Testing With Pytest - Fabrizio Castro & Chris Paterson, Renesas Electronics Europe GmbH
Wednesday October 7, 2026 09:05 - 09:45 CEST
Testing drivers reliably across several versions of Linux (mainline, linux-next, stable, linux-cip, etc.) and several SoCs can be a challenging task, and it gets even more challenging if the whole process needs to be automated.

In this talk we introduce a testing framework centered around pytest, that makes heavy use of pytest markers to describe the test SW and HW requirements, and we combine this with other open-source projects (like Yocto, LAVA, and GitLab CI/CD) to fully automate Linux kernel testing on embedded devices.
Speakers
avatar for Fabrizio Castro

Fabrizio Castro

Principal Software Engineer, Renesas Electronics Europe GmbH
I fell in love with software and hardware when I was a boy. I've had the privilege of working with brilliant people on exciting projects across several industries and universities. For the past 15 years, I have dedicated my professional life to Embedded Linux and products based on... Read More →
avatar for Chris Paterson

Chris Paterson

Engineer, Renesas Electronics Europe GmbH
Chris Paterson is a Senior Staff Software Engineer focused on embedded Linux and making CI work on real hardware, where things rarely go to plan. He works with tools like LAVA and KernelCI, and contributes to the Civil Infrastructure Platform (CIP) project.
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

09:05 CEST

Marrying Device Tree and SCMI - Geert Uytterhoeven, GLIDER bv
Wednesday October 7, 2026 09:05 - 09:45 CEST
Traditionally, Linux has been fully responsible for and in full control of all hardware components in an embedded system, as described by its Device Tree (DT). With the advent of heterogeneous System-on-Chips (SoCs) with multiple CPU cores (Application and Real-Time) and security technologies (Secure Boot, Trusted Environments, Virtualization), this is no longer the case. To avoid compromising system integrity, Linux must now be prevented from controlling system resources used by other CPU cores, and cannot be tasked with control of shared system resources, while Linux still needs to access these resources.

The Arm System Control and Management Interface (SCMI) is intended to solve this, by providing a firmware interface to handle access to system resources like clocks and power domains.

In this presentation, targeting Embedded Linux Developers and System Architects, Geert will give an overview of SCMI, and its impact on DT hardware description. He will discuss the challenges of supporting multiple evolving firmware versions and lineages, and possible solutions, based on experience gained while upstreaming Linux support for R-Car X5H, Renesas' fifth-generation automotive SoC.
Speakers
avatar for Geert Uytterhoeven

Geert Uytterhoeven

Embedded Linux Kernel Hacker, GLIDER bv
Geert Uytterhoeven became involved with Linux 30 years ago, when he started hacking the Linux kernel to make it work better on his Amiga. This paved the way for a long string of contributions to Linux.
In 2013, Geert founded Glider bv (http://glider.be/), to build upon the (embed... Read More →
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

09:05 CEST

Triaging CVEs for the Linux Kernel - Christoph Steiger & Negar Masoudifar, Siemens AG
Wednesday October 7, 2026 09:05 - 09:45 CEST
The Linux kernel currently sees around 60 CVEs per week. With the EU Cyber Resilience Act (CRA) rapidly approaching this creates a serious challenge for anyone shipping commercial products based on it: a lot of additional vulnerability management and compliance work.

In this talk, we will introduce kernel-cve-triage, a tool developed under the umbrella of the Civil Infrastructure Platform (CIP). It addresses these compliance challenges with a unique approach, using the kernel’s Kconfig build configuration to determine which reported CVEs actually apply. With this method, we base our assessment only on the kernel source tree and its configuration and are build-system independent. This reduces false-positive CVEs by up to 95%, depending on the exact configuration and the set of vulnerabilities considered.

We will also cover the key differences compared to another major kernel CVE automation tool: the Yocto Project and its cve-check. Finally, we will give an outlook and suggestions on how to improve the current situation for the Linux kernel's users.
Speakers
avatar for Christoph Steiger

Christoph Steiger

Embedded Linux Engineer, Siemens AG
Open Source enthusiast who is working on embedded Linux systems. He focuses on all things Linux Kernel: from driver implementation to real-time applications and supply chain security.
avatar for Negar Masoudifar

Negar Masoudifar

Working Student – Embedded Linux, Siemens AG
Negar Masoudifar is a working student at Siemens focused on Linux kernel development and embedded systems. She works on the CIP kernel CVE triage project, building tools to help figure out which vulnerabilities actually matter for a given kernel setup.
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:05 CEST

Zephyr at 10: Scaling an Open Source RTOS for the Next Decade - Anas Nashif, Intel
Wednesday October 7, 2026 09:05 - 09:45 CEST
Over the last decade, Zephyr has grown from a focused open source RTOS into one of the most widely adopted platforms for connected, secure, and portable embedded systems. That success brings new challenges: more architectures, more boards, more vendors, more contributors, more downstream users, and higher expectations around quality, security, safety, documentation, testing, and long-term maintenance.

This talk looks at Zephyr’s evolution through the lens of project sustainability. It will highlight where the current model is working, where scaling pressure is becoming visible, and what the community needs to address to keep Zephyr healthy for the next 10 years. Topics include maintainer bandwidth, review latency, infrastructure load, test and sample growth, vendor enablement, downstream compatibility, long-term support, security updates, dependency management, and the tension between a unified upstream and the need for product- and platform-specific innovation.
Speakers
avatar for Anas Nashif

Anas Nashif

Senior Prinicipal Engineer, Intel
Senior Principal Software Engineer at Intel and TSC chair of the Zephyr project.
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

09:50 CEST

Keynote: Technical Documentation for Everyone (And Their AI Agents, Too) - Erin McKean, Staff Developer Relations Engineer, Google Open Source Programs Office, Google
Wednesday October 7, 2026 09:50 - 10:00 CEST
In this session, you'll learn about the history and future of the Docsy technical documentation project, why you should care about documentation EVEN MORE in the age of AI, and how everyone can and should contribute to open source documentation. 
Speakers
avatar for Erin McKean

Erin McKean

Staff Developer Relations Engineer, Google Open Source Programs Office, Google
Erin McKean helps Googlers create, share, and contribute to open source projects in Google's Open Source Programs Office. She is also the founder of the not-for-profit Wordnik.com, the world’s biggest online dictionary. Before founding Wordnik, she was the editor-in-chief of American... Read More →
Wednesday October 7, 2026 09:50 - 10:00 CEST
Congress Hall (Floor 2)

09:50 CEST

An Approach To Managing CVEs With Vendor Kernels - Jan Pfiffner, Grossenbacher Systeme AG
Wednesday October 7, 2026 09:50 - 10:30 CEST
Managing vulnerabilities in the kernel has gotten more attention but also needs more effort due to the exploding number of CVEs. With the kernel now being a CNA since 2024, options have evolved, and most recently, since 596ad6c on openembedded-core/master, it has gotten "easy".

But this is not working for vendor kernels, as they lag mainline and a rebase is impractical, if not impossible, due to the vendor delta.
As vendor kernels are heavily used in the industry and a switch to linux-yocto is often not possible due to budget, timeline or vendor lock-in, a solution is needed.

I've built a solution that locates the fix for each detected CVE on the matching stable branch, emits a candidate backport patch, verifies it applies cleanly, checks (via koverage, at line granularity) whether the affected code is compiled, and classifies results into actionable buckets.
Output is a list of unaffected CVEs and a collection of patches for review. In my opinion, this is verified and evidence-backed patching rather than just a cherry-picked list.

I'd like to present a solution (layer) which includes this workflow and start a broader discussion about the issue with vendor kernels.
Speakers
avatar for Jan Pfiffner

Jan Pfiffner

Head of Software Engineering, Grossenbacher Systeme AG
I'm Head of Software Engineering at Grossenbacher Systeme AG (GESYS), a Swiss embedded systems manufacturer. After several years in PLC and machine vision software development, I moved into embedded and have spent the last four years working with Yocto, building, producing and maintaining... Read More →
Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:50 CEST

Asymmetric Multi-Processing (AMP) for Embedded - Where Are We? - Wolfram Sang, Renesas / Consultant
Wednesday October 7, 2026 09:50 - 10:30 CEST
Modern SoCs have a variety of CPU cores on board - e.g. on ARM we often see Cortex A, plus Cortex M, plus System Controllers. The number of cores is as increasing as the demands. Concepts like 'Software Defined Vehicle' (SDV) from the automotive sector is just one example for such complex demands. One obvious requirement is to run other OS than Linux on dedicated cores. Which means that resources like memory, clocks, pin control, power domains, etc. may not be under the sole control of Linux anymore. They now need to be shared and synchronized between all the participants. How does this work in practice? How do technologies like remoteproc, rpmsg, mailboxes, hardware spinlocks, virtio, and devicetree come into play here? How is their status-quo? And what about the non-Linux sides? What is open, what is proprietary, and how does this affect actual solutions? This talk is the result of a journey trying to support LinuxZephyr based AMP using a complete FreeSoftware stack on a Renesas community board.
Speakers
avatar for Wolfram Sang

Wolfram Sang

Kernel Upstream IO Team Lead, Renesas / Consultant
Wolfram became a Linux Kernel developer in 2008. He maintained the I2C subsystem for 13.5 years and works as a consultant and mentor, mainly for the Renesas Upstream Kernel Team. Programming since his childhood, he still hacks his machines from the 80s, especially the C64. When not... Read More →
Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

09:50 CEST

Reproducible Embedded Linux Testing From Laptop To CI To Scale - Anders Roxell, Linaro
Wednesday October 7, 2026 09:50 - 10:30 CEST
Kernel and embedded Linux engineers often need to reproduce a build or test from someone else. In practice this is still harder than it should be.

A kernel may be built with one toolchain. The rootfs may come from a local build. Firmware may have changed. A model may need specific variables. Continuous Integration (CI) and lab runs may hide setup steps in scripts or jobs.

Then someone asks:

Can I reproduce this?

Too often the answer is: not easily.

This talk shows a practical way to make this better with modern open source tooling, and to show useful workflows that kernel and embedded engineers may not know about yet.

We show how to build the kernel in a repeatable way, provide a known rootfs, boot the target, run tests, and collect logs.

Then we use two Arm examples. One is an OP-TEE flow, where TF-A, U-Boot, and OP-TEE are part of the setup. The other is a CCA flow on QEMU-arm64 and FVP-aemva, where the model setup and software stack also matter.

We use open source tools from the TuxSuite ecosystem, but the focus is the workflow. The same workflow can run on a laptop, in CI, in lab infrastructure, or at scale.
Speakers
avatar for Anders Roxell

Anders Roxell

Senior Engineer, Linaro
Anders Roxell is a Linux kernel engineer at Linaro, focused on testing and platform validation. He's a KernelCI and TuxSuite contributor, and works currently on the Linux kernel builds and tests workflows.
Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

09:50 CEST

Community Awards
Wednesday October 7, 2026 09:50 - 10:30 CEST

Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 2 B (Floor 2)

10:05 CEST

Keynote: Open Standards for Trusted Agentic Workloads - Laura Tacho, Senior Principal Technologist, Developer Experience, AWS
Wednesday October 7, 2026 10:05 - 10:15 CEST
Agentic workloads must securely connect to tools, data, and other agents while operating within consistent authorization and security boundaries. Open standards make this possible. We'll discuss how technologies like MCP and Cedar create an "agent trust stack" for interoperable and scalable agentic systems so that developers have the freedom to compose and extend their agentic architectures securely, wherever they want to build.
Speakers
avatar for Laura Tacho

Laura Tacho

Senior Principal Technologist, Developer Experience, AWS
Wednesday October 7, 2026 10:05 - 10:15 CEST
Congress Hall (Floor 2)

10:15 CEST

Keynote: Open Source at a Crossroads: Geopolitics, Sovereignty, and the Fight to Stay Open - Nithya Ruff, Chair, Linux Foundation Board & Johan Linaker, Senior Researcher, RISE Research Institutes of Sweden & Adjunct Assistant Professor, Lund University
Wednesday October 7, 2026 10:15 - 10:30 CEST
Open source was built on one belief: code has no passport. Nation-states are testing whether that holds.
The EU’s Cyber Resilience Act burdens the ecosystem it depends on. US export controls threaten to erase the line between open and proprietary code — a protection open source has relied on for decades. China has made open source AI a national strategy pillar, building a parallel ecosystem resilient to Western sanctions. The 2024 removal of Russian Linux kernel maintainers showed that open source is no longer above the law of nations.

None of these actors set out to break the commons. But their decisions often made without open source expertise create tensions governance was never designed to handle: sovereignty-through-openness vs. sovereignty-through-restriction; what “open source first” means for companies that relicensed; what neutrality means when contributors face conflicting national laws; and whether open source AI becomes a geopolitical battleground or shared resource.

Engage policymakers before they damage the ecosystem, build governance for a fragmented world, and recommit to the principle that openness is not a vulnerability — it is the source of our strength.
Speakers
avatar for Nithya Ruff

Nithya Ruff

Chair, Linux Foundation Board, Independent
Nithya has been in open source leader for over 25 years. She is a bridge builder working with companies large and small to create productive and strategic paths to working with open source. She led the Amazon OSPO & prior to Amazon, she started and grew Comcast and SanDisk's OSPO... Read More →
avatar for Johan Linaker

Johan Linaker

Senior Researcher at RISE Research Institutes of Sweden and an Adjunct Assistant Professor at Lund University, RISE Research Institutes of Sweden
Johan Linåker is a Senior Researcher at RISE Research Institutes of Sweden and an Adjunct Assistant Professor at Lund University, working at the intersection of empirical software engineering, open technologies, and digital sovereignty. His work focuses on how public and private... Read More →
Wednesday October 7, 2026 10:15 - 10:30 CEST
Congress Hall (Floor 2)

10:35 CEST

Coffee Break
Wednesday October 7, 2026 10:35 - 11:20 CEST

Wednesday October 7, 2026 10:35 - 11:20 CEST
TBA

11:20 CEST

How Uber Uses Intelligent Agents for Open Source Governance - Chris Howard, Uber
Wednesday October 7, 2026 11:20 - 11:40 CEST
Open Source compliance is no longer just about coping with legal headaches; between navigating the Cyber Resilience Act & managing strict SBOM mandates it is a critical regulatory hurdle. Enforcing these standards without slowing developer velocity is a giant challenge. To solve this, the Uber OSPO overhauled our ecosystem of 6 Monorepos, 4k microrepos & over 35k dependencies to move away from manual audits & remove the friction placed on our engineers.
We built a system that scans our entire codebase every 24 hours, but detection is only half the battle. By integrating agentic tooling with our compliance policies & historical exception data, our system now makes calculated judgments on resolution versus escalation. The OSPO agent autonomously raises tickets, remediates issues & learns how to handle complex scenarios that would have required legal insight. This has automated our checks and eradicated high risk libraries from our codebase.
It’s not all as complex as it looks though. With clear policies, legal alignment, and a commitment to learning by doing, any organisation can do this. I'll share Uber's blueprint for turning open source governance into an automated & smart engine.
Speakers
avatar for Chris Howard

Chris Howard

Head of Open Source, Uber
Chris is a specialist Open Source strategist and community builder dedicated to fostering healthy developer ecosystems.
As Head of the OSPO at Uber, he leads global strategy for open-source consumption, contribution, and Developer Relations. He previously spearheaded the OSPO at EPAM, where he focused on maturing open-source programs and scaling contributions for global clients... Read More →
Wednesday October 7, 2026 11:20 - 11:40 CEST
Conference Hall (Floor 4)

11:20 CEST

Open Source Security as the Foundation of European Sovereignty - Madalin Neag & Mirko Boehm, The Linux Foundation
Wednesday October 7, 2026 11:20 - 11:40 CEST
European digital policy is often discussed through frameworks such as NIS2, the CRA, DORA, the CSA, and the broader Tech Sovereignty agenda. Yet these initiatives share a common objective: securing the software supply chains underpinning Europe’s critical digital infrastructure.

OSS is the foundation of modern technology stacks, from cloud services and critical infrastructure to financial systems and AI. It is also inherently global, developed and maintained by a distributed ecosystem across borders. As reliance on OSS grows, the challenge is no longer whether it is used, but how it is integrated, governed, and secured throughout its lifecycle within this global dependency network.

This session explores software supply chain security as the common thread across Europe’s cyber and digital policy landscape. It examines how regulations converge on transparency, dependency management, vulnerability handling, provenance, and secure development practices.

Finally, it connects these developments to EU Tech Sovereignty goals, arguing that secure and standardized consumption of globally developed open source is key to Europe’s resilience, competitiveness, and technological sovereignty.
Speakers
avatar for Mirko Boehm

Mirko Boehm

Community Development, Linux Foundation Europe

avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, OpenSSF/The Linux Foundation
Madalin is the EU Policy Advisor at OpenSSF, working at the intersection of cybersecurity, open source software, and European technology policy. He helps connect open source technical communities and policymakers, supporting the development of practical regulatory frameworks, aligning... Read More →
Wednesday October 7, 2026 11:20 - 11:40 CEST
Chamber Hall (Floor 3)

11:20 CEST

Evolving the YAML Family (without Breaking the World) - Ingy döt Net, YAML LLC
Wednesday October 7, 2026 11:20 - 12:00 CEST
YAML turned 25 this year.
It is essential to Kubernetes, Docker, Ansible, CI pipelines, and config files for everything in between.
That ubiquity is both a gift and a curse: every change risks breaking something, somewhere, silently.
So how do you grow a data language that a billion files depend on without risk of catastrophe?

Ingy döt Net helped invent YAML and he now maintains the YAML Specification and The YAML Family (libyaml, go-yaml, PyYAML, YAMLStar, YAMLScript etc).
In this talk he'll show how he plans to grow YAML by extension: a plugin system that can deeply affect YAML behavior in completely configurable ways.
Plugin APIs include schema association, tab indent, standard functions, comment support include i18n.
This is being delivered first to go-yaml with the rest of the Family to follow.
The work and its real world feedback will guide future changes to the specification.
Speakers
avatar for Ingy dot Net

Ingy dot Net

Invented YAML, YAML LLC
Ingy döt Net is one of the original inventors of the YAML data language, and its primary maintainer. He is also the active maintainer of go-yaml, the YAML framework trusted by Kubernetes and much of its ecosystem,
Wednesday October 7, 2026 11:20 - 12:00 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:20 CEST

FIT Happens: How Secure Boot Wasn't - Ahmad Fatoum, Pengutronix e.K.
Wednesday October 7, 2026 11:20 - 12:00 CEST
Flat Image Tree (FIT) is Das U-Boot’s preferred boot image format and underpins billions of embedded Linux boot flows, with adoption extending into other bootloaders such as barebox.

Its core idea of using the flattened device tree format for flexibility and code reuse, enabled widespread adoption, but also became a fertile source of subtle security flaws.

This talk traces FIT’s evolution from a pragmatic design choice to a widely trusted format, highlighting how its structure led to recurring weaknesses, culminating in CVE-2026-33243, a decade-old vulnerability whose exploitation bypassed verified boot for millions of devices.

Finally, Ahmad presents a proposal to improve FIT: a backwards-compatible scheme for whole-image signing that requires limited parsing, aiming to deliver stronger security guarantees without the format’s historical pitfalls.
Speakers
avatar for Ahmad Fatoum

Ahmad Fatoum

Kerningenieur, Pengutronix e.K.
Ahmad joined the kernel team at Pengutronix in 2018 to work full-time on furthering Linux world domination. He does so by helping automotive and industrial customers build embedded Linux systems based on the mainline Linux kernel.
Having a knack for digging in low-level guts, his... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

11:20 CEST

Making Your CI Lab More Reliable - Patrick Titiano, Baylibre SAS
Wednesday October 7, 2026 11:20 - 12:00 CEST
If you've ever built your own CI Lab, you've probably already faced some of these issues:
- Remote power cycling of the boards (particularly when it requires pressing a push-button)
- Managing remote debug console
- Handling inrush current/power outage and surges
- Handling boards with heterogeneous form factors
- Handling remote GPIOS/accessories
- Handling remote displays/ KVMs
- Handling non-disruptive lab/board maintenance
- Handling distributed CI labs

At Baylibre, we've been dealing with CI Lab maintenance for many years, starting from 'scratch' (boards laying on shelves with wires all over the place) to standardised labs in server racks. In this presentation, we will share all the solutions we've found and developed to tackle all these issues, with the objective of improving the quality of our FOSS projects by making our CI labs reliable and easy to maintain.
Speakers
avatar for Patrick Titiano

Patrick Titiano

Co-founder, System Power Management Expert at BayLibre, Baylibre SAS
Patrick Titiano has 20 years of engineering experience in embedded technologies. Patrick spent 9 years at Texas Instruments as an OMAP Power Management Expert (from architecture to use-case power optimization). Patrick also developed embedded diagnostic open source tools (“omapconf... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

11:20 CEST

When PWM Meets the Common Clock Framework: How To Write a (not So) Simple Linux PWM Driver - Richard Genoud, Bootlin
Wednesday October 7, 2026 11:20 - 12:00 CEST
Over time, Pulse Width Modulators went from simple devices with only an input clock and a prescaler to more complex ones.
Nowadays, we can find PWM with several input clocks, several channels, shared and unshared prescalers among channels, and even bypasses which permits the PWM to act as a clock provider itself.

This talk covers a presentation of PMW basics, how to write a kernel driver with the new PWM waveform internal API.
Then, we will present a complex real life PWM device (Allwinner H616 PWM) and show how to leverage the power of the Common Clock Framework to help writing the kernel driver.
We'll continue with use cases of the H616 PWM internal bypass, which short-cuts the PWM logic and outputs a sine wave.
And finally, we'll show how to handle this bypass in the PWM driver and in the device tree.
Speakers
avatar for Richard Genoud

Richard Genoud

Embedded Linux and kernel engineer, Bootlin
Richard Genoud joined Bootlin as an embedded Linux and kernel engineer in 2024 and has more than 20 years of experience in embedded Linux engineering.
His areas of expertise include bootloader, kernel device driver development, up to user space applications.
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:20 CEST

What Is Linux Doing With My RAM? - Vlastimil Babka, SUSE Labs
Wednesday October 7, 2026 11:20 - 12:00 CEST
This talk will cover several memory management concepts and underlying principles to give the audience a better understanding about what happens to the RAM on a Linux system, and how to determine that on their own system, namely:

- how much memory is used by userspace processes, the page cache, and the kernel itself
- how to determine accurately how much memory is used by individual processes
- why free memory is always eventually exhausted and what happens then
- how to observe what the kernel is doing to make memory available for allocations, and recognize when it's struggling
- what is the role of swap and why not fear swapping

This includes explaining some key parts of files like /proc/meminfo and /proc/vmstat.
Speakers
avatar for Vlastimil Babka

Vlastimil Babka

Linux Kernel Developer, SUSE Labs
Vlastimil works as a kernel developer at SUSE Labs since 2013, focusing on the memory management subsystem. He currently co-maintains the slab and page allocators, and is a reviewed for several other parts of mm. He is also interesting in performance improvements, debugging features... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
Panorama Hall (Floor 1)
  Linux

11:20 CEST

Context Engineering: Connecting the Dots With Graphs - Stephen Chin, Neo4j
Wednesday October 7, 2026 11:20 - 12:00 CEST
AI systems need more than intelligence; they need context. Without it, even the most advanced models can misinterpret information, lose track of details, or arrive at conclusions that don’t hold up. Context engineering is emerging as a discipline that shapes how AI perceives, recalls, and reasons about information.

This talk will explore how context provides the foundation for reasoning, problem solving, and explainability in AI. We will look at techniques such as connected memory, contextual retrieval, and graph-based knowledge representation that give large language models a more reliable way to connect information and draw logical conclusions.

Attendees will come away with a practical understanding of how to design effective context pipelines that align AI with real-world knowledge and user intent, and why context engineering is becoming a central part of building trustworthy and impactful AI systems.
Speakers
avatar for Stephen Chin

Stephen Chin

VP of Developer Relations, Neo4j
Stephen Chin is VP of Developer Relations at Neo4j, conference chair of the LF AI & Data Foundation, and author of numerous titles including the upcoming GraphRAG: The Definitive Guide for O'Reilly. He has given keynotes and main stage talks at numerous conferences around the world... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
Forum Hall (Floor 2)
  Open AI & Data
  • Audience Experience Level Any

11:20 CEST

Containers as an Illusion - Michael Kerrisk, man7.org Training and Consulting
Wednesday October 7, 2026 11:20 - 12:00 CEST
One goal of containers is to provide an illusion: that a group of
processes are in a world of their own, and that there are no other processes on the system. In this session1, we'll look at the nature of that illusion and–through a series of experiments and live demonstrations–examine the various Linux mechanisms–namespaces, capabilities, cgroups (control groups), and seccomp–are used to support the creation of that illusion. (Bring a laptop with a recent Linux distro installed!)
Speakers
avatar for Michael Kerrisk

Michael Kerrisk

Trainer/author/programmer, man7.org Training and Consulting
Michael Kerrisk is a trainer, programmer, and author of "The Linux Programming Interface", a widely acclaimed book on Linux (and UNIX) system programming. From 2004 to 2021, he maintained the Linux "man-pages" project, which provides the primary documentation for Linux system calls... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
Terrace 2A (Floor 2)
  Open Source 101

11:20 CEST

Ten Years of Zephyr: Replace Linux, or Work With It? - Iuliana Prodan, NXP Semiconductors
Wednesday October 7, 2026 11:20 - 12:00 CEST
A decade after its launch, Zephyr has grown from a small RTOS into a capable, MMU-aware, userspace-supporting system running on application-class cores. So people keep asking: can it replace Linux? A better question is how the two can work together - and Zephyr already has what it needs to do that.

This talk shows how Linux and Zephyr run side by side on the same SoC, using parts Zephyr ships today: the IPC service layer, OpenAMP and RPMsg for messaging between the two cores, mailbox and shared-memory backends, and the mechanisms that let Linux start and stop Zephyr firmware. Based on real work on NXP i.MX and i.MX RT platforms, I'll show how these pieces fit, and where the hard parts are - memory layout, buffer sizes, address translation, and shutdown order.

The takeaway: after ten years, the interesting frontier isn't replacement. It's connecting the two so each kernel does what it's best at on the same chip.
Speakers
avatar for Iuliana Prodan

Iuliana Prodan

Software Engineer, NXP Semiconductors
Software Engineer at NXP and the company's Zephyr Technical Ambassador. With a background in Linux, particularly the audio subsystem and Sound Open Firmware, though main focus is now Zephyr. Maintains Zephyr's IPC subsystem, OpenAMP, and libmetal, and works on asymmetric multipro... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

11:40 CEST

How Open Source Communities and OSPOs Are Responding To AI Assisted Contributions - Norio Kobota & Alin Jerpelea, Sony
Wednesday October 7, 2026 11:40 - 12:00 CEST
Open source communities are entering a new phase as more contributions are created with AI assistance. This raises a practical question for the ecosystem: how should projects, maintainers, and companies handle AI-assisted contributions while preserving accountability, trust, and review quality?

This session brings together two complementary perspectives:
1. An outside-in view of how open source communities are responding, including early observations on how such contributions are being identified and categorized, and
2. An inside-out view of what this shift means for OSPO strategy, compliance, and coordination across engineering, legal, IP, and security stakeholders.

Rather than debating AI in the abstract, the talk focuses on concrete issues communities and companies are already facing, including human accountability, maintainer workload, traceability, stewardship, and software supply chain quality.

Attendees will leave with a practical framework for discussing AI-assisted contributions inside their projects, OSPOs, and cross-functional governance teams.
Speakers
avatar for Norio Kobota

Norio Kobota

Senior Open Source Strategist, Sony Group Corporation
Norio Kobota is a Senior Open Source Strategist in Sony Group Corporation. He is the chair of Open Source Software License Committee in Sony and works to improve OSS compliance and relationships with OSS communities.
He represents Sony as a board member of OpenChain Project. And he is participating the SPDX Project and contributing the SPDX Lite profile... Read More →
avatar for Alin Jerpelea

Alin Jerpelea

Senior Architect, Sony
Alin Jerpelea is a senior software architect and a local OSPO member at Sony, located in Lund, Sweden.
He has been part of Sony since 2010 when he joined Sony Mobile as a community manager for the Xperia Open Source initiative and has since worked in numerous projects and Open So... Read More →
Wednesday October 7, 2026 11:40 - 12:00 CEST
Conference Hall (Floor 4)

11:40 CEST

ORBIT Launchpad: Building the Due Diligence Bridge Between Manufacturers and Open Source - Nicole Bates-Callaghan, Microsoft & Sarah Evans, Dell Technologies
Wednesday October 7, 2026 11:40 - 12:00 CEST
The EU Cyber Resilience Act requires manufacturers to exercise due diligence when integrating open source components — but what does that actually look like in practice? ORBIT Launchpad is an OpenSSF initiative building the catalogs, criteria, and tooling that help manufacturers demonstrate they've done the work.

This talk covers how ORBIT Launchpad bridges the gap between regulatory intent and operational reality. We'll share how the CRAB-FOSC and CRAB-FOMA catalogs translate CRA obligations into actionable criteria that manufacturers can evaluate against, how we're aligning with complementary efforts across foundations to avoid duplication, and what the open source ecosystem needs to provide so that due diligence doesn't become an unfunded mandate on maintainers.

Attendees will leave with a practical understanding of: what due diligence means for manufacturers consuming open source under the CRA; how ORBIT Launchpad's open catalogs and tooling reduce that burden; and how standards bodies and open source communities can work together to make compliance achievable.
Speakers
avatar for Nicole B

Nicole B

Principal Technical Program Manager, Microsoft
Nicole Bates is a Principal Technical Program Manager on Microsoft's Azure OCTO Open Source Ecosystem team, where she focuses on open source supply chain security strategy. She co-chairs the IETF SCITT Working Group, ORBIT Launchpad SIG, and Supply Chain Integrity Working Group at... Read More →
avatar for Sarah Evans

Sarah Evans

Distinguished Engineer, Dell Technologies
Sarah Evans is a Distinguished Engineer and security applied research program lead at Dell Technologies, driving technical innovation for secure business outcomes. She is a recognized leader focusing on extending secure operations and supply chain principles to securing AI and agentic... Read More →
Wednesday October 7, 2026 11:40 - 12:00 CEST
Chamber Hall (Floor 3)

12:00 CEST

Lunch (Provided Onsite for All Attendees)
Wednesday October 7, 2026 12:00 - 13:30 CEST

Wednesday October 7, 2026 12:00 - 13:30 CEST
TBA

12:00 CEST

Women & Non-Binary Lunch
Wednesday October 7, 2026 12:00 - 13:30 CEST
We’d like to invite all attendees who identify as women or non-binary to join each other for a networking lunch at the event. We will begin with a brief introduction and then attendees will be free to enjoy lunch and mingle with one another. All attendees must identify as a woman or non-binary and must be registered for the conference to attend.

*We will do our best to accommodate all interested attendees, but please note that participation is on a first-come, first-served basis.
Wednesday October 7, 2026 12:00 - 13:30 CEST
Congress Hall Foyer 4B

13:30 CEST

Presentation From the European Commission Open Source Observatory (OSOR) - Éléonore Daxhelet, OpenForum Europe
Wednesday October 7, 2026 13:30 - 13:50 CEST
This presentation gives an overview of the European Commission’s Open Source Observatory’s (OSOR) activities and latest Paper on Progress and Trends. The report examines how open source software has evolved within public administrations, based on the country reports published in 2025. It covers 18 EU member states and includes for the first time five candidate countries from the Western Balkan region, namely Albania, Bosnia and Herzegovina, Kosovo, Serbia and North Macedonia. The session provides insights into the state of open source adoption and regulation in Europe, with a particular focus on findings from the Balkan countries, providing insights into how EU integration shapes digital policy in candidate countries.
Speakers
avatar for Éléonore Daxhelet

Éléonore Daxhelet

Policy Analyst, OpenForum Europe
Éléonore Daxhelet is a policy analyst at OpenForum Europe, where she has worked on the Open Source Observatory (OSOR) since July 2025. She holds a Master's degree in Political Science from the Free University of Brussels and a Master's in Security, Intelligence and Strategic Studies... Read More →
Wednesday October 7, 2026 13:30 - 13:50 CEST
Chamber Hall (Floor 3)

13:30 CEST

How Git Clone Took Down Our CI for 20 Days - Yathartha Goenka, Mercari, Inc.
Wednesday October 7, 2026 13:30 - 14:10 CEST
One morning, CI across ~1,800 repos ground to a near-total halt. HTTP 401 from github.com, everywhere. Deterministic, not flaky. Valid tokens, healthy rate limits. GitHub support said "anti-abuse." We said "which abuse?"

Twenty days and 17,863,537 log records later, we'd gone deeper into git's open source plumbing than we ever intended: how git negotiates HTTP auth, what it leaks in user-agents, which config knobs actually matter under load, and how its defaults — sensible on a laptop — behave pathologically behind Kubernetes NAT at 50,000 CI runs a day.

This talk is a forensic walkthrough of git's HTTP transport, told through an outage: the red herrings, the tcpdumps, the fixes that didn't work, the fix that did. You'll leave knowing what git clone really does when you're not looking — and how to configure it so it never makes you look guilty.

Bring popcorn.
Speakers
avatar for Yathartha Goenka

Yathartha Goenka

Platform Engineer, Mercari, Inc.
A platform engineer at Mercari Japan, leading projects around DX, distributed systems and AI. Been working with backend development using Golang, CI/CD, cloud infrastructure, and scalable system design. Been learning more about the quiet ways a platform can fall over than I ever meant... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

13:30 CEST

20 Years of Quality Assurance for Embedded Linux Systems - The Good, the Bad, the Unexpected - Jan Altenberg, Open Source Automation Development Lab (OSADL) eG
Wednesday October 7, 2026 13:30 - 14:10 CEST
More than 20 years ago the idea of transforming Linux into a real-time operating system resulted in the birth of the PREEMPT_RT development. But how could the real-time properties of such a complex system be tested? Due to the complexity of modern operating systems, such as Linux, and due to the fact that modern processors operate in a performant but non-deterministic way, appropriate methods for evaluating the real-time behaviour of a given system had to be established: That's why the OSADL QA Farm was born. While the initial focus of the QA Farm was (and still is) the long-term evaluation of the real-time properties of Embedded Linux systems, 20 years of operation with more than 100 systems have also brought many other insights to light - expected and unexpected. This presentation provides an overview of the quality assurance methods used at the OSADL QA Farm, the insights gained from numerous long-term measurements and latest developments, such as the integration of Zephyr systems.
Speakers
avatar for Jan Altenberg

Jan Altenberg

Director R&D, Open Source Automation Development Lab (OSADL) eG
Jan Altenberg has more than 20 years of experience in developing and maintaining Embedded Linux systems. Since October 2021 Jan works as Senior Open Source Consultant and Embedded Systems Integrator at the Open Source Automation Development Lab (OSADL) eG and since 2024, he also serves... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

13:30 CEST

Journey of a Massive Internal Kernel Rework - Luca Ceresoli, Bootlin
Wednesday October 7, 2026 13:30 - 14:10 CEST
While changes to the internal kernel APIs and design are possible, that doesn't mean they are easy.

In preparation for a larger work to make the DRM subsystem support video output pipelines with hot-pluggable components, we have been working for the past two years to change the lifetime of `struct drm_bridge` in the DRM subsystem. This required changing the semantics of a dozen internal APIs and adaptations to more than 50 drivers.

This talk is not about the content of the changes but rather about the process to achieve it: the initial steps to find the best strategy, the continuation to convert all APIs, bugs introduced and reacting to them, working on lots of drivers without the chance to test them, dead ends encountered, tools used, the time required for the whole process, and the community interactions in the whole time span.

The focus will be on lessons learnt and which strategies worked better, and ultimately how to make a similar kind of massive conversion in the most efficient (and least frustrating!) way.
Speakers
avatar for Luca Ceresoli

Luca Ceresoli

Embedded Linux and Kernel engineer, Bootlin
Luca is an embedded Linux and kernel engineer at Bootlin, primarily working on device drivers and recently active mostly on DRM bridges to support hotplugging of non-discoverable devices.

He contributed several improvements the Linux kernel and other open source projects.

Luca... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

13:30 CEST

Secure by Default in Embedded Linux: The Features You Are Probably Not Using - Marta Rybczynska, Ygreky
Wednesday October 7, 2026 13:30 - 14:10 CEST
Linux offers an impressive collection of security mechanisms, and recent years have added even more to the stack. Yet when reviewing embedded Linux products, I repeatedly run into a different problem: security features that are available, mature, and practical are simply not enabled.

Many embedded projects still start from vendor examples, reference BSPs, or existing products. As a result, design decisions made years ago often become the default for the next generation of devices. This talk focuses on a set of practical security mechanisms that embedded developers can deploy from the beginning of a project with relatively little effort.

Using examples from Yocto Project-based systems, we will examine features and tools such as:
- overlayfs with its advanced features
- filesystem permission hardening
- seccomp-based system call filtering
- fs-verity for file integrity protection
- fscrypt for protecting data belonging to different users and use cases.

We will discuss why they should be part of a base configuration and and show practical examples on how to do it.
Speakers
avatar for Marta Rybczynska

Marta Rybczynska

Founder and CEO, Ygreky
Marta Rybczynska has a network security background, with 20 years of experience in Open Source.
She has worked with embedded operating systems like Linux and various real-time OSes, and with
system libraries and frameworks up to user interfaces. Contributed to various projects in... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

13:30 CEST

Building Your Own Linux Kernel CI on Commodity Platforms - Shung-Hsi Yu, SUSE
Wednesday October 7, 2026 13:30 - 14:10 CEST
While Continuous Integration (CI) has become a standard for most software projects via platforms like GitHub, testing massive, highly complex repositories like the Linux kernel has traditionally required bespoke environments. This limitation creates significant friction for new kernel contributors, out-of-tree module maintainers, and low-level system library authors attempting to validate compatibility against the latest development branches.

This session details a practical architecture for running the latest development kernels entirely within commodity CI environments. There are two key components: a highly optimized, VM-tuned kernel configuration, and vmtest, an open-source utility that abstracts away the complexities of QEMU configuration, seamlessly maps the CI workspace as the virtual machine's root filesystem via the 9P protocol, and propagates test command return codes back to the runner.

By the end of the session, attendees will gain the knowledge to build custom kernel CI workflows, leaving with a boilerplate GitHub Actions .yml from danobi/vmtest-action-demo to immediately deploy their own testing pipelines.
Speakers
avatar for Shung-Hsi Yu

Shung-Hsi Yu

Kernel Engineer, SUSE
Mainly working on maintaining the eBPF stack of SUSE Linux Enterprise Server (SLES) distribution.
Currently drawn to the inner working of eBPF verifier and formal verification.
Wednesday October 7, 2026 13:30 - 14:10 CEST
Panorama Hall (Floor 1)
  Linux

13:30 CEST

Off the Laptop, Into Production: An Open Source Stack for AI Agents on Kubernetes - Brian Hammons & Nirmal Mehta, Amazon Web Services
Wednesday October 7, 2026 13:30 - 14:10 CEST
AI agents are fast becoming how modern software gets built. But taking one from prototype to safe, production-grade operation is still genuinely challenging, and how they behave at scale remains largely uncharted. Agents are stochastic, so testing becomes continuous evaluation. They run code nobody wrote, so a shared kernel stops being a boundary you can trust. They decide their own network calls at runtime, so egress is no longer predictable. And they still need what any service needs: source control, CI/CD, observability, memory, and tool access.

This session walks the full lifecycle of running agents on Kubernetes, open source the whole way. The "outer loop" (build, deploy, trace, evaluate) runs on tools like GitLab, Argo, Langfuse, Milvus, and MCP gateways. The "inner loop" (isolated execution) runs on the kubernetes-sigs Agent Sandbox CRD, gVisor, and FQDN-aware egress via Cilium. We'll show what maps cleanly from the platform you run, what changes for agents, and the production gotchas no quickstart warns you about, drawn from building these in the open with teams running from a handful of developer sandboxes to the hundreds of thousands that frontier-scale RL spins up.
Speakers
avatar for Brian Hammons

Brian Hammons

Principal Solutions Architect, AWS
Brian Hammons is a Principal Architect at AWS, focused on Kubernetes-native AI agent development and platform engineering. He led the first AWS-backed contribution of the kubernetes-sigs Agent Sandbox CRD into the open source awslabs/ai-on-eks project. An Amazon EKS launch-team member... Read More →
avatar for Nirmal Mehta

Nirmal Mehta

World Wide Tech Leader - Containers, Amazon Web Services
Nirmal Mehta is the World Wide Tech Leader for Containers at AWS and a Principal Specialist SA in the Worldwide Application Modernization team. He is experienced in open source platform engineering, kubernetes, MLOps, agentic devops and executive org strategy. He has presented at... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Forum Hall (Floor 2)
  Open AI & Data

13:30 CEST

Making the Kernel Chat: How To Get Debug Output - Richard Weinberger, sigma star gmbh
Wednesday October 7, 2026 13:30 - 14:10 CEST
When starting with Linux kernel development, beginners quickly encounter a frustrating roadblock: system crashes that produce absolutely no output, neither on the screen nor in the logs. Fortunately, Linux provides a rich toolbox designed to extract debug information even in the most desperate situations. The main challenge is knowing which tool fits a specific scenario and what data to expect.

In this talk, Richard shares practical guidance on the debugging mechanisms he has relied on over his past decade of working inside the Linux kernel. Attendees will learn how to break through the silence by deploying the right tool for the right type of crash. Besides well known mechanisms such as earlyprintk, pstore, and ftrace, Richard will reveal lesser known Linux debugging gems used to capture logs from freezing systems, trace internal behavior, and retrieve postmortem panic data.

By the end of the talk, beginners will have a clear and actionable roadmap for diagnosing actual kernel issues, ensuring they know exactly what to do the next time the kernel suddenly goes quiet.
Speakers
avatar for Richard Weinberger

Richard Weinberger

CTO, sigma star gmbh
Richard Weinberger is co-founder of sigma star gmbh where he offers consulting services around Linux and IT security. Upstream he maintains various subsystems of the Linux kernel such as UserModeLinux and UBIFS. Beside of low level and security aspects of computers he enjoys growing... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Terrace 2A (Floor 2)
  Open Source 101

13:30 CEST

Panel Discussion: The Latest From TODO Group: Advocacy, Community, and Our AI Initiatives - Natali Vlatko, Cisco; Georg Kunz, Ericsson; Ana Jiménez Santamaría, Linux Foundation; Annania Melaku, F5 NGINX
Wednesday October 7, 2026 13:30 - 14:10 CEST
The TODO Group’s mission is to empower and educate open source management best practices inside organizations through effective Open Source Program Offices (OSPOs) and similar initiatives. With the latest developments in AI, as well as the shift of importance in open source across different industries, several new initiatives have been spun up that the community has embraced with fresh energy.

Join the TODO Group Steering Committee as they present the latest updates from the community, including a new Working Group focused on agentic AI tooling for OSPOs, changes to how our content is created and shared, as well as the growth in local events by TODO Group Ambassadors from around the world. The Steering Committee will also share the data they’re collecting in partnership with LF Research that informs ecosystem trends worth exploring and what the TODO Group community wants to focus on most in terms of learnings and growth.

Plan on attending if you’re in an OSPO, looking to create one at your organization, or interested in helping to spin up new open source initiatives!
Speakers
avatar for Annania Melaku

Annania Melaku

Lead, Open Ecosystem Programs, F5
Annania Melaku leads Open Ecosystem Programs at F5, spanning open source, open standards, open source AI, and cross-ecosystem collaboration. She also serves on the steering committee of the TODO Group, the Linux Foundation community for Open Source Program Offices. With a background... Read More →
avatar for Georg Kunz

Georg Kunz

Director Open Source Software, Ericsson
Georg is a director in Ericsson's Open Source Program Office. He is a passionate advocate for open source software and a long term contributor to a wide range of open source projects. He currently serves on the Technical Advisory Council and the Governing Board of the Open Source... Read More →
avatar for Ana Jiménez Santamaría

Ana Jiménez Santamaría

Senior Project Manager, Linux Foundation
Ana Jiménez Santamaría is an open source community leader and data scientist with 5+ years of experience at the Linux Foundation, working as Sr. project manager supporting global, multi-stakeholder IT ecosystems. She is also an Agentic AI Foundation Ambassador, helping developers... Read More →
avatar for Natali Vlatko

Natali Vlatko

Director of Open Source Software Engineering, Cisco
Natali Vlatko (she/her) is a Director of Open Source Software Engineering at Cisco, specializing in open software, policy, and governance. She is a SIG Docs Co-Chair for Kubernetes and a member of the TODO Group Steering Committee. She plays on the fun computer in her spare time... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Conference Hall (Floor 4)

13:30 CEST

From Reset To Main(): Porting Infineon TriCore AURIX To Zephyr - Parthiban N, Linumiz & Christoph Seitz, Infineon Technologies AG
Wednesday October 7, 2026 13:30 - 14:10 CEST
Infineon's AURIX family of automotive microcontrollers is based on the TriCore architecture and is widely used across automotive systems, from powertrain and chassis control to safety-critical ECUs. This talk presents the upstream effort to add TriCore architecture support and enable Infineon AURIX TC3x and TC4x devices in Zephyr (https://github.com/zephyrproject-rtos/zephyr/pull/107516).

Starting from CPU reset, we will walk through the key architecture bring-up steps required to reach the first Zephyr thread, including trap and interrupt handling, Context Save Area (CSA)-based context switching, and system timer integration. We will also cover the work required beyond the architecture layer, including SoC support, board enablement, and QEMU-based development and testing.

Finally, we will discuss the challenges of upstreaming a new architecture into Zephyr, from toolchain and CI integration to HAL dependencies and ecosystem support, along with the remaining work needed for automotive and safety-critical systems.
Speakers
avatar for Parthiban

Parthiban

Director of Engineering, Linumiz
With over 14 years of experience in software engineering, Parthiban founded Linumiz, a company that provides domain-neutral software services for U-Boot, Linux, and Zephyr, ranging from board bringup, board supported package, customization, device drivers, to over the air software... Read More →
avatar for Christoph Seitz

Christoph Seitz

Field Application Engineer, Infineon Technologies AG
Started out designing FPGA-based high-speed data platforms — where open source first got under my skin. Now at Infineon, I drive adoption of Ethernet-based solutions in the automotive segment across EMEA, with a deep understanding of hardware-software interaction and industry standards... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

13:50 CEST

The Japan-Type OSS Model: Native Species, Seeding Strategy, and Rules as Code - Kazuki Imamura, IPA: Innovation Platform Agency, Japan
Wednesday October 7, 2026 13:50 - 14:10 CEST
Open source is now social infrastructure, rarely recognized until it fails. To shape a forward-looking strategy, we must know where we stand. In 2025, IPA ran two foundational surveys: a software-trends survey of domestic firms, and a GitHub study of 30,298 public-sector repositories across seven countries.

The findings show modest but clear momentum. Corporate OSS policy adoption rose from 32.0% to 36.7% (normalized), and vague "don't know" answers gave way to concrete work on security and talent development—a shift from awareness to practice. Japan's government OSS repositories rank alongside Germany, Singapore, and Estonia, with GIS and geospatial strengths grown from frontline needs—now a uniquely AI-ready foundation.

We propose a "Japan-Type OSS Model" with three axes: cultivating "native species" OSS rooted in real needs; a "seeding strategy" where the public sector publishes building blocks industry scales into services; and "Rules as Code," making institutions machine-readable for trustworthy AI.

This session shares what one country learned from mapping its terrain—and calls for cross-border collaboration on how open source will underpin digital sovereignty worldwide.
Speakers
avatar for Kazuki Imamura

Kazuki Imamura

Open Source Promotion, IPA: Innovation Platform Agency, Japan
Born in 1974. I started my current job in March 2024. Prior to that, I worked in web development for 13 years. I started activities as a civic tech contributor in 2018.
Wednesday October 7, 2026 13:50 - 14:10 CEST
Chamber Hall (Floor 3)

14:25 CEST

Open Source as a Government Goal: Berlin’s Strategy for Digital Sovereignty – Lessons Learned - Marcel Scholze, PwC Germany & Florian Ebel, Senatskanzlei Berlin
Wednesday October 7, 2026 14:25 - 14:45 CEST
Everyone is talking about digital sovereignty - but what happens when a federal state takes this concept seriously? In 2025, Berlin adopted an Open Source strategy to achieve innovation and digital independence through OSS, open standards, and collaboration.
We report on how this strategy came about and what its implementation means in a complex administrative landscape. Seven measures form the backbone—from establishing an OSPO at ITDZ Berlin to identifying critical software dependencies to giving Open Source priority in procurement law. Behind each measure lie organizational, cultural, and legal challenges.
What are the low-hanging fruits? Where do strategies reach their limits? And how do you keep a “learning” strategy alive - rather than letting it fizzle out? An honest account of progress and setbacks that shows what others - whether government agencies or companies - can learn from Berlin’s Open Source journey.
Speakers
avatar for Florian Ebel

Florian Ebel

Head of Strategy and Governance Unit (CDO-Department), Senatskanzlei Berlin

avatar for Marcel Scholze

Marcel Scholze

Director, PricewaterhouseCoopers GmbH Wirtschaftsprüfungsgesellschaft
Marcel Scholze is a Director at PwC Germany leading the firm's Open Source and Digital Sovereignty practice. He has shaped OSS strategies and enablement programs for organizations across the public sector and industry. With a background in large-scale IT sourcing, he brings a pragmatic... Read More →
Wednesday October 7, 2026 14:25 - 14:45 CEST
Conference Hall (Floor 4)

14:25 CEST

Kata at Scale: The Hidden Cost of Running VMs Behind Every Container - Kavitha Daula & Ann Wallace, Edera
Wednesday October 7, 2026 14:25 - 15:05 CEST
There is a big difference between getting Kata Containers running in a proof of concept and operating a large multi-tenant Kata environment for years.

This talk is a practical, vendor-neutral look at what becomes hard after the demo works. Once every pod carries a lightweight VM lifecycle behind it, platform teams are no longer operating only Kubernetes. They are also operating guest kernels, guest images, VMMs, hypervisor behavior, virtio devices, runtime and agent version skew, and a second debugging surface under the container platform.

We will walk through production issues that show up at scale: guest kernel CVEs and regressions, host/guest kernel drift, CNI and tap-device networking, virtio-fs and storage durability semantics, fragmented observability, boot storms, vCPU oversubscription, memory accounting drift, NUMA behavior, GPU passthrough, VFIO/IOMMU lifecycle, upgrade matrices, and incident ownership.

This is not a criticism of Kata. Kata solves a real open source isolation problem. The goal is to help operators understand the operational work required to run VM-isolated containers safely and sustainably in production.
Speakers
avatar for Kavitha Daula

Kavitha Daula

VP of Engineering, Edera
Kavitha Daula is the VP of Engineering at Edera, where she leads the development of secure, high-performance container runtime technologies. Previously, she was Senior Director at GEICO, driving innovations in OS, containers, and language runtimes, including a custom Linux distro... Read More →
avatar for Ann Wallace

Ann Wallace

VP of Customer Experience, Edera
Ann Wallace is the VP of Customer Experience at Edera. Before Edera, she held leadership and architecture roles in security and cloud at Okta, Shopify, Google, and Nike. Ann speaks regularly at conferences on topics like compliance, container security, and using storytelling to make... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

14:25 CEST

Debugging Heisenbugs: The Nightmare of Every Embedded Engineer - Beleswar Prasad Padhi, Texas Instruments
Wednesday October 7, 2026 14:25 - 15:05 CEST
Defined as bugs which disappear or change behavior when observed, every embedded engineer has come across one at some point. Some classic examples include bugs that stop reproducing after adding printk() statements, introducing new variables, connecting a debugger or even simply recompiling the same source code. The root causes of Heisenbugs range all the way from race conditions, memory corruption, alignment issues, cache incoherency, incorrect linker configurations to even hardware bugs.

This talk walks through the debugging techniques which could be applied for debugging these Heisenbugs like static code analysis, memory analysis, diagnostic data collection, tracing and instrumentation, selective elimination of unrelated code paths, modifying assembly instructions at runtime; all without probing the observer’s effect. Beyond techniques, the talk aims to develop the intuition and thought process needed when confronting these bugs. The talk discusses how to distinguish between mere workarounds that mask the underlying issue vs actual fixes. Practical experiences in debugging real Heisenbugs will be shared along with their root causes, investigation approaches and the fixes.
Speakers
avatar for Beleswar Prasad Padhi

Beleswar Prasad Padhi

Senior Software Engineer at Texas Instruments, Texas Instruments
Beleswar is a Senior Software Engineer at Texas Instruments, actively working on Upstream Linux Kernel and U-Boot. His work mainly focuses on Remoteproc, RPMsg, Mailbox, Virtio subsystems, as well as boot-time optimizations. He was listed among the top contributors for Linux 6.18... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

14:25 CEST

Enabling High-Performance SPI NAND in Linux: PHY Tuning, DDR, and Beyond - Santhosh Kumar K, Texas Instruments & Miquèl Raynal, Bootlin
Wednesday October 7, 2026 14:25 - 15:05 CEST
Modern OSPI NAND devices are pushing the Linux SPI memory stack beyond its original assumptions. Features such as DDR transfers, continuous read modes, multi-frequency operation, and PHY tuning promise substantial performance improvements, but at the cost of added complexity. Furthermore, there is no well-established standard for these implementations, leading vendors to adopt different approaches and assumptions that software must accommodate.

This talk will walk through recent upstreaming efforts to enable advanced OSPI NAND capabilities in Linux. We will focus on one of the most challenging aspects: the introduction of fine-grained PHY tuning, which allows operating frequencies to be doubled or even tripled, enabling significantly faster transactions between the NAND device and the host controller.

Introducing such features has raised a number of architectural challenges. We will discuss both the specifics of PHY tuning and the broader subsystem considerations required to support increasingly sophisticated flash devices. Particular attention will be given to integration challenges across the SPI-MEM and MTD stacks, as well as the lessons learned while upstreaming the solution.
Speakers
avatar for Santhosh Kumar K

Santhosh Kumar K

Embedded Linux Engineer, Texas Instruments
Santhosh Kumar K joined Texas Instruments in 2023 as an embedded Linux engineer working on TI Sitara platforms. His work focuses on SPI, MTD, and DDR subsystems across Linux and U-Boot development, with contributions to upstream, platform enablement, and performance optimization... Read More →
avatar for Miquèl Raynal

Miquèl Raynal

Embedded Linux & kernel engineer, Bootlin
Miquèl Raynal joined Bootlin in 2017 as an embedded Linux engineer. He is the
maintainer of the NAND subsystem in the Linux kernel, and a co-maintainer of the
MTD subsystem. Over the past years, he has made significant contributions to the
Linux MTD subsystem, and has already sp... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

14:25 CEST

SELinux in Embedded Linux: From Basics To Best Practices - Tobias Kaufmann, BMW Car IT
Wednesday October 7, 2026 14:25 - 15:05 CEST
Modern vehicles employ a highly integrated architecture with a relatively small number of powerful Electronic Control Units (ECUs). Many of these ECUs run Linux and present a sizable attack surface. To mitigate the resulting threats, SELinux offers an enhanced mechanism for enforcing the principle of least privilege.

Despite its strengths, SELinux remains complex and is not widely adopted. This talk offers a pragmatic introduction to SELinux, with concrete guidance you can apply to your embedded Linux project.

This session will cover basic permissions and type enforcement in SELinux, including which permissions are required for an application start-up. It will introduce the reference policy and guide you through writing a first “hello-world” policy. We will also discuss SELinux in the context of Yocto. Finally, we will conclude with lessons learned from our experience in large-scale projects.
Speakers
avatar for Tobias Kaufmann

Tobias Kaufmann

Security Architect for Head-Units, BMW Car IT
Tobias holds an M.Sc. in Electrical Engineering. After several years working on smart grid projects, he joined BMW Car IT in 2018. He currently serves as the Security Architect for head units at BMW Car IT.
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

14:25 CEST

You're Measuring Memory Wrong: The Right Ways With DAMON - SeongJae (SJ) Park, Crusoe
Wednesday October 7, 2026 14:25 - 15:05 CEST
Memory efficiency problems are notoriously hard to see. DAMON was built to change that — but many users collect data incorrectly, visualize it poorly, and walk away with wrong conclusions. The tool gets blamed. The real problem goes unfixed.

This talk shows you the right ways to do it.

We cover data collection first: configuring sampling and aggregation parameters, the tradeoffs, and setup mistakes that corrupt your data before analysis begins.

We then walk through the visualization features in `damo` — heatmaps of access frequency across time and address space, working set size plots, and more. There is no single right visualization; we cover when to use each and how to read what it shows.

We also highlight mistakes that lead users astray: misreading sampling artifacts as real patterns, choosing granularities that hide behavior, observing too briefly to catch periodic patterns, and more. For each, we show what misleading output looks like and how to fix it.

By the end, you will know how to collect trustworthy DAMON data, pick the right visualization, and tell when your results are real versus when your setup is lying to you.
Speakers
avatar for SeongJae Park

SeongJae Park

Staff SW Engineer, Crusoe
SeongJae (SJ) Park is a Linux kernel programmer who maintains the data access monitoring framework of the Linux kernel called DAMON (https://damonitor.github.io/). His interests include operating system kernels, parallel computing, and memory management. He is working on Meta's kernel... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Panorama Hall (Floor 1)
  Linux

14:25 CEST

Agent Gateway: The One Decision That Eliminates AI Engineering Complexity - Lin Sun, Solo.io
Wednesday October 7, 2026 14:25 - 15:05 CEST
As AI systems move from experimentation to production, engineering teams face a growing number of infrastructure decisions. How do you secure MCP servers without modifying them? How do you seamlessly transition and fail over across multiple LLM providers? How do you enforce token rate limits and usage policies for LLMs? How do you govern agent-to-agent and agent-to-MCP communication, control context growth, enforce security policies, observe traffic, and scale operations across environments?

Rather than solving each challenge independently, organizations can adopt a single architectural pattern: the agent gateway.

Through live demos, Lin introduces the agent gateway pattern and demonstrates how it simplifies AI infrastructure by eliminating the need for teams to repeatedly solve the same cross-cutting concerns. Using agentgateway, an open-source implementation of the pattern, she will show how to secure and federate MCP servers without modifying them, route, fail over, and rate limit LLM traffic across providers, enable advanced capabilities such as code mode and progressive disclosure, and operationalize AI workloads on Kubernetes.
Speakers
avatar for Lin Sun

Lin Sun

Head of Open Source, Solo.io
Lin is the Head of Open Source at Solo.io, co-chair of KubeCon + CloudNatibeCon 2026. She actively contributes to AAIF and CNCF projects. She is the author of “Sidecar-less Istio Explained” and “AI Agents in Kubernetes”, and holds more than 200 patents.
Wednesday October 7, 2026 14:25 - 15:05 CEST
Forum Hall (Floor 2)
  Open AI & Data
  • Audience Experience Level Any

14:25 CEST

Sponsored Session: Your Dev Environment Is Probably Slowing You Down - Ben Potter, Coder
Wednesday October 7, 2026 14:25 - 15:05 CEST
Every developer has felt it: a fresh clone that takes hours to get running, a build that only works on one machine, or a setup that's impossible for a teammate - or an AI agent - to reproduce.

As projects grow, developer environments become infrastructure in their own right. Get them wrong, and onboarding slows, builds become fragile, and "works on my machine" never really goes away.

This talk explores the patterns behind development environments that scale - from solo open source projects to large mono and multirepos. We'll look at reproducible environment definitions, dependency caching, ephemeral versus persistent environments, and where tooling should replace documentation.

You'll also learn how high-performing teams measure developer experience with metrics like time-to-first-commit and onboarding time, rather than intuition, and why the best developer platforms succeed by making the right path the easiest one.

AI agents are now consumers of your development environment too. If a new contributor can't get started quickly, neither can an agent.

Whether you maintain an open source project or build software at enterprise scale, you'll leave with practical ideas for creating faster, more reproducible development workflows that developers actually want to use.

Speakers
avatar for Ben Potter

Ben Potter

Head of Dev Rel and Open Source, Coder
Ben helps engineering teams build secure cloud development environments for both developers and AI agents. A Linux tinkerer who has been building on remote machines since his teens, Ben is passionate about improving developer experience and making cloud-based development the new... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 2 A (Floor 2)

14:25 CEST

Derivative Work and Modification(s): Where Copyright and Open Source Software Collide - Yet Again - Eleftheria Stefanaki, Nokia Technologies & Jimmy Ahlberg, Ericsson
Wednesday October 7, 2026 14:25 - 15:05 CEST
Talking points:

• Copyright law as a (wrong) playing field for open source software
• Working with what we have – the curious case of modifications
• Modification of software – what does this mean practically (e.g., bug fix, alteration of existing code, new code)
• Derivative work and modification in FOSS licensing
• Practical cases and “risks”
o Products
o M&As


Abstract:
There are many legal concepts that create havoc in the open source world, but only a few are as “scary” as the concept of modification and derivative work. Copyright law concept are challenging to adopt in the software context. The ambiguity of the legislation as well as the case law in many jurisdictions, such as the US and many EU countries and institutes, is proof enough that this is a convoluted topic, and not just in theory. The practical impact of derivative works and modifications runs through the entirety of the open source compliance process. In this session, we will attempt to demystify the aforementioned concepts and possibly open up more questions for discussion.
Speakers
avatar for Eleftheria Stefanaki

Eleftheria Stefanaki

FOSS Legal Counsel, Nokia Technologies
I am a lawyer from Greece, specialized in technology and passionate about open source. I have started my 'open source journey' in Ericsson, assisting and participating in the activities and day-to-day of the OSPO since 2022. Currently, I am the FOSS Legal Counsel for Nokia Technologies... Read More →
avatar for Jimmy Ahlberg

Jimmy Ahlberg

Expert & Senior Legal Counsel, Ericsson
Currently Mr Ahlberg is the Director of Open Source Policy with the Ericsson OSPO. Prior to the inception of the Ericsson OSPO he worked in different roles with various aspects of Open Source in the Ericsson organization, This included consumption of and contribution to Open Source... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Terrace 2A (Floor 2)
  Open Source 101

14:25 CEST

Panel: Having an SBOM Is Not Enough. Introducing the OpenChain SBOM Document Quality Guide - Yoshiyuki Ito & Tsukasa Yobo, Renesas Electronics; Kiyoshi Owada, Socionext Inc.; Yumi Tomita, Cybertrust Japan Co., Ltd.; Takashi Ninjouji, Honda Motor Co., Ltd.
Wednesday October 7, 2026 14:25 - 15:05 CEST
SBOM adoption is growing, driven by global regulation such as the EU Cyber Resilience Act(CRA). Today’s software supply chains are complex and global, involving many organizations, tools, and layers of dependencies. In this environment, SBOMs need to accurately share software component information without confusion.

A high‑quality SBOM enables precise, unambiguous information exchange between organizations, minimizing gaps and misinterpretation.

To achieve this, the OpenChain SBOM Working Group released a draft SBOM Document Quality Guide in April 2026 on the foundation of the Telco SBOM Guide. Global public comments have been incorporated into the official version released at this session. It defines what should be contained, how to evaluate, and how to exchange between organizations. 

In this panel, we will discuss:
- why each of us engaged in this work
- the distinct SBOM quality challenges from our own vantage points
- how we actively utilize the guide to address industry-specific quality hurdles
We hope this sparks dialogue with many addressing Cyber Resilience Act and other security regulations 
Speakers
avatar for Takashi Ninjouji

Takashi Ninjouji

Chief Engineer, Honda R&D Co., Ltd.
Takashi Ninjouji is a Chief Engineer at Honda Motor Co., Ltd., with a focus on Software-Defined Vehicles (SDV). He is a manager of the Open Source Program Office (OSPO). His interests also include AI-assisted engineering automation.
avatar for Yoshiyuki Ito

Yoshiyuki Ito

Principal Specialist, Renesas Electronics
Working on Linux and open-source software technology for various presales efforts. Currently serving as Deputy Co-Chair of the SBOM Sub-Working Group of the Community “Open Chain Project” on behalf of Renesas. Worked as a software engineer for NEC since 1993 and with Renesas on... Read More →
avatar for Kiyoshi Owada

Kiyoshi Owada

Manager (Software Management Promotion), Socionext Inc.
- Joined Matsushita Electric Industrial Co., Ltd. (Currently Panasonic) in 1988 and moved to Socionext Inc. in 2015.
- Participated in the development of digital home appliances as uITRON and Linux Engineer
- Worked on establishing the CE Linux Forum
- OpenChain JapanWG Planning... Read More →
avatar for Tsukasa Yobo

Tsukasa Yobo

senior software engineer, Renesas electronics corp.

avatar for Yumi Tomita

Yumi Tomita

Field marketer, Cybertrust Japan Co., Ltd.
Yumi Tomita is a Marketer in Cybertrust Japan. She works to utilize SBOM for vulnerability management. She is a member of the OpenChain Project Japan Working Group.
Wednesday October 7, 2026 14:25 - 15:05 CEST
Chamber Hall (Floor 3)

14:25 CEST

Practical End-to-End Traceability for Zephyr’s Path To Safety Certification - Tobias Kästner & Andreas Kurz, inovex GmbH
Wednesday October 7, 2026 14:25 - 15:05 CEST
As part of the ongoing effort to achieve IEC 61508 certification, Zephyr's requirements capture process is underway. Yet there is still no clear picture of how these requirements trace to the tests that verify them or the code that implements them. Safety evidence is largely documented evidence, so the primary concern is generating auditable documents: requirement and test specifications, test reports, and traceability matrices.
The challenge is collecting this evidence in a community-compatible way — low-friction processes and tooling that developers and maintainers will accept.

This talk proposes a pipeline built on Zephyr's existing documentation tools (Doxygen/Sphinx) to extract the needed information from annotated source and tests, then trace it back against requirements into an end-to-end chain.
Two demos are shown: a minimal working example against Zephyr itself, and a self-contained pipeline for a Zephyr module the authors maintain. Required process adaptations and guidelines are explained. The work is an open proposal for discussion; once agreed, it gives the community a scalable foundation to advance safety efforts, with concrete tasks contributors can pick up.
Speakers
avatar for Tobias Kästner

Tobias Kästner

Safety Architect, Zephyr Project, inovex GmbH
A physicist by training, Tobias Kaestner has long been fascinated by where the physical and digital worlds meet. He began as a software team lead in a medical device start-up and has since spent 15+ years in the industry. As a solution architect for Medical IoT at inovex GmbH he helps... Read More →
avatar for Andreas Kurz

Andreas Kurz

Senior Embedded Software Engineer, inovex GmbH
Senior Embedded Software Engineer doing safety critical software for e.g., medical.
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

14:45 CEST

Strategic Approach To Demonstrating the Value of OSS Efforts - Dawn Foster, Fast Wonder
Wednesday October 7, 2026 14:45 - 15:05 CEST
We’ve probably all had leadership question the value of our OSS efforts. It can be difficult to frame the value in ways that resonate with stakeholders and clearly articulate the benefits gained through continued OSS contributions. Taking a strategic approach that connects the OSS work with the broader goals and objectives of the organization can demonstrate the value of this work so that the organization can continue to allocate resources to the OSPO or other OSS teams.

Using examples from my decades of experience in OSS, this talk will provide details about how to demonstrate value by focusing on how your OSS work helps the organization achieve their strategies and goals. Every organization has unique needs and goals based on what they are trying to achieve, so there is no “one size fits all” way of demonstrating value, but aligning your OSS strategy with your organization’s goals and focusing on the most strategic projects can help show the value of your efforts. This talk will help you reason about how OSS efforts allow your organization to achieve its goals along with framing and communicating that value in ways that resonate with leadership, funders, and stakeholders.
Speakers
avatar for Dawn Foster

Dawn Foster

Open Source Strategy Consultant, Fast Wonder
Dr. Dawn Foster is an OSS strategy consultant. She is also on the board of CHAOSS, OpenUK, and the Software Stewardship Lab. She was previously a co-chair of the CNCF Contributor Strategy TAG. She has 20+ years of experience at companies like VMware and Intel with expertise in strategy... Read More →
Wednesday October 7, 2026 14:45 - 15:05 CEST
Conference Hall (Floor 4)

15:05 CEST

Ask the Expert Sessions
Wednesday October 7, 2026 15:05 - 15:35 CEST
Come sit down with some open source experts to gain knowledge 1:1 and ask all your pressing questions! No sign-up necessary. More information to come!
Wednesday October 7, 2026 15:05 - 15:35 CEST
Congress Hall Foyer 4B

15:05 CEST

Coffee Break
Wednesday October 7, 2026 15:05 - 15:35 CEST

Wednesday October 7, 2026 15:05 - 15:35 CEST
TBA

15:35 CEST

Embracing Service-Oriented Connectivity Across OpenStack and Kubernetes - Mitsuhiro Tanino & Rei Shimizu, LY Corporation
Wednesday October 7, 2026 15:35 - 16:15 CEST
Modern infrastructure platforms increasingly combine OpenStack VMs, Kubernetes Pods, managed platforms, and external services, yet connectivity models often remain fragmented across runtime boundaries and tied to infrastructure-specific constructs such as IP-based ACLs.

This session presents how LY Corporation introduced a service-oriented connectivity model across OpenStack and Kubernetes environments. Rather than extending Kubernetes-native service mesh concepts to VM workloads, we introduced a runtime-independent service abstraction where connectivity and policy are defined consistently across VMs, Pods, PaaS instances, and external resources.

Under this model, services become the primary unit for service discovery, authentication and authorization, ACL management, and traffic control, independent of the underlying runtime or network topology. A sidecar proxy enforces service-to-service policy consistently across both OpenStack-managed VMs and Kubernetes workloads.

We cover the architectural design, OpenStack and Kubernetes integration for service registration and identity propagation, and lessons from migrating production workloads at scale.
Speakers
avatar for Mitsuhiro Tanino

Mitsuhiro Tanino

Senior Software Engineer, LY Corporation
Mitsuhiro Tanino is a senior software engineer who has been working for LY Corporation since 2019. He has experience to contribute OpenStack Cinder project for several years and also contributed Kubernetes sig-storage for several years. His current working area is operating hyper-scale... Read More →
avatar for Rei Shimizu

Rei Shimizu

Senior Software Engineer, LY Corporation
Rei Shimizu is working as Software Engineer for Private Cloud in LY Corporation.
Wednesday October 7, 2026 15:35 - 16:15 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

15:35 CEST

Sponsored Session: Kubernetes Is the AI OS. Here's the Open Source Stack Running on Top of It - Jonathan Bryce, The Linux Foundation & Daniel Krook, CNCF
Wednesday October 7, 2026 15:35 - 16:15 CEST
Kubernetes has become the AI operating system (82% of container users run it in production and 66% use it for AI inference) but the real challenge is scaling inference, not training. Every prompt and every agent call runs inference, and standard Kubernetes routing is blind to the KV cache state and token dynamics that determine whether you hit your SLOs. This session covers the open stack the CNCF community is coalescing around to fix that: HAMi (now Incubating) for fractional GPU virtualization and hard accelerator isolation, Inference Gateway (GA) for model-aware traffic routing, llm-d (new CNCF Sandbox project) for cache and load-aware distributed inference, KServe (Incubating) for multi-model serving, and the KAR (Kubernetes AI Conformance Requirements) program now spanning 31 certified platforms. We’ll also cover four trends shaping the next 12 months of cloud native AI.
Speakers
avatar for Daniel Krook

Daniel Krook

Senior Director of Developer Experience, CNCF
Daniel Krook is the Senior Director of Developer Experience at the Cloud Native Computing Foundation (part of the Linux Foundation), where he and his team support the maintainers, contributors, and users across 225+ hosted open source projects. Previously a Principal Cloud Architect... Read More →
avatar for Jonathan Bryce

Jonathan Bryce

Executive Director, Cloud and Infrastructure, The Linux Foundation
Jonathan Bryce is the Executive Director of Cloud & Infrastructure at the Linux Foundation, where he leads both the Cloud Native Computing Foundation (CNCF) and the OpenInfra Foundation—two of the largest and most influential open source communities in the world. With over... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 2 A (Floor 2)

15:35 CEST

A Clockwork Frequency: Bringing Spread Spectrum To the Linux Clock Subsystem - Dario Binacchi, Amarula Solutions
Wednesday October 7, 2026 15:35 - 16:15 CEST
Reducing electromagnetic interference (EMI) is often a key requirement for embedded products seeking EMC certification. Spread Spectrum Clocking (SSC) is a common hardware technique used to lower peak emissions by slightly modulating clock frequencies.

This talk describes the journey of bringing SSC support to the Linux Clock Subsystem on platforms such as TI Sitara, STM32 and i.MX8M. The work started from customer requirements and platform-specific solutions, then evolved into a more generic approach integrated with the Linux clock framework and Device Tree.

After a brief introduction to SSC and the real-world use cases behind this work, the talk explores the challenges of exposing SSC configuration through Linux abstractions. We will cover the design of new Device Tree bindings, the implementation of SSC support within the Linux clock framework, and the upstream review process that helped shape a reusable solution across different SoCs, highlighting how Linux can turn existing silicon capabilities into practical product solutions.
Speakers
avatar for Dario Binacchi

Dario Binacchi

Embedded Linux and kernel engineer, Amarula Solutions
With a thesis on DSP I graduated in Software Engineering in 2000, but above all I started my career in the embedded world, first on bare-metal systems and then on architectures with Linux operating systems.

Joining Amarula aroused in me the desire to actively contribute to proje... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:35 CEST

OP-TEE Footguns: Lessons From the Integration Trenches - Richard Weinberger, sigma star gmbh
Wednesday October 7, 2026 15:35 - 16:15 CEST
OP-TEE is a widely adopted Trusted Execution Environment (TEE) commonly used on ARM-based SoCs. While it is highly portable and often features strong vendor support, achieving a functionally working setup is only half the battle. There are surprisingly many pitfalls where a developer can successfully integrate OP-TEE, only to introduce subtle security misconfigurations that silently undermine the entire system's threat model.

In this talk, Richard will outline the hidden security traps and integration challenges he has encountered over the past few years on custom hardware. Attendees will learn which footguns to watch out for, ultimately saving them the countless hours Richard spent debugging these exact issues.
Speakers
avatar for Richard Weinberger

Richard Weinberger

CTO, sigma star gmbh
Richard Weinberger is co-founder of sigma star gmbh where he offers consulting services around Linux and IT security. Upstream he maintains various subsystems of the Linux kernel such as UserModeLinux and UBIFS. Beside of low level and security aspects of computers he enjoys growing... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

15:35 CEST

The Engineer's Guide To the Embedded Linux Galaxy: Navigating Failures and Bricked Devices - Leon Anavi, Konsulko Group & Piotr Buliński, Qbee
Wednesday October 7, 2026 15:35 - 16:15 CEST
Everyone can build a prototype, but shipping products is where the chaos begins. In this session, we explore embedded systems by discussing failures we have experienced as engineers, consumers, and industry observers. Navigating the vast open-source ecosystem of the embedded Linux galaxy and selecting the right tools for the job is a challenge.

Instead of idealized architectural theory, we will share war stories and costly mistakes, facing the grim reality of bricked devices, maintenance costs and e-waste generation. We will be talking about a coffee machine that needs a technician to cross the galaxy to replace a PCB, an OTA update strategy that lacks the ability to upgrade offline devices with a USB stick, a smart home turned into a wreck when a bankruptcy leaves the IoT fleet permanently bricked and a final story on what happens when immovable object like legacy incident management meets unstoppable force like AI and CRA.

This talk is for anyone working on an embedded Linux product, from junior developers to experienced engineers and managers. Since it is always better to learn from others' mistakes, you will walk away with insights that will help you improve your products.
Speakers
avatar for Leon Anavi

Leon Anavi

Software Engineer, Konsulko Group
Leon Anavi is an open source enthusiast and a senior software engineer at Konsulko Group. He is an active contributor to various Yocto/OpenEmbedded meta layers and many other open source projects. His professional experience includes maintaining embedded Linux distributions to Raspberry... Read More →
avatar for Piotr Buliński

Piotr Buliński

Chief Technologist, Qbee
Piotr is the Chief Technologist of Qbee, where he drives the technological vision for secure, automated IoT fleet management. Over a 20+ year career across the tech stack, Piotr has specialized in low-level system internals, large-scale cloud-native architectures, and global data... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:35 CEST

FreeBSD as a Linux Platform: LinuxKPI, Linuxulator, and the Case for Convergence - Moin Rahman, The FreeBSD Project
Wednesday October 7, 2026 15:35 - 16:15 CEST
Linux dominates modern infrastructure, yet its monopoly on hardware support and application ecosystems creates a false premise, that Linux is the only viable platform. FreeBSD has quietly built two production grade compatibility layers that challenge this assumption.
LinuxKPI implements Linux kernel APIs directly inside the FreeBSD kernel, enabling unmodified GPU, wireless, and RDMA drivers including but not limited to amdgpu, iwlwifi, and Mellanox OFED to compile and run natively. Contrary too emulation this is source-level API compatibility with negligible runtime overhead.
The Linuxulator complements this at the userland boundary which is a high-performance syscall translation layer that executes unmodified Linux ELF binaries on the FreeBSD kernel, with measured overhead consistently under 2% for I/O-bound workloads.
Combined with FreeBSD Jails and VNET, operators gain isolated Linux environments with native ZFS storage, DTrace observability, and a hardened network stack without a hypervisor.
This talk examines the architecture of both layers, their production deployment patterns, and the upstream contribution model that keeps them current with Linux kernel releases.
Speakers
avatar for Moin Rahman

Moin Rahman

Contributor, The FreeBSD Project
Long-time contributor to The FreeBSD project, he works on release engineering, reproducible build infrastructure, automated CI/CD pipelines, and distributed cluster administration. He also leads Cybermancer Infosec, a consultancy focused on Zero Trust OS pipelines, artifact verification... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
Panorama Hall (Floor 1)
  Linux

15:35 CEST

Iceberg for Agents - Turning Lakehouse Data Into AI-Ready Context - Andrew Madson, Fivetran
Wednesday October 7, 2026 15:35 - 16:15 CEST
AI agents fail in production because they're overwhelmed with data but starved for context. LLM models aren’t the problem. The bottleneck is the data stack: fragmented silos, inconsistent definitions, and logic hidden in tribal knowledge. Agents need structured, reliable, and interpretable context—not just data access.

In this session, we'll show how Apache Iceberg becomes the backbone of AI-ready pipelines. You’ll learn how to elevate your Iceberg implementation from a storage format to a live context layer that powers structured retrieval-augmented generation (RAG), schema-aware agents, and autonomous reasoning grounded in truth.

What we’ll cover:
1. Iceberg Foundations for AI - from ACID to Time Travel
2. From Rows to Relationships - The role of the semantic layer
3. Structured RAG in Practice - Fully open source

The session includes a live demo of a fully open-source Structured RAG stack built on Apache Iceberg, featuring semantic query translation, hybrid retrieval, and governed agent reasoning. Expect architecture diagrams, real code, and practical guidance.
Speakers
avatar for Andrew Madson

Andrew Madson

Head of Developer Relations, Fivetran
Andrew Madson is Head of Developer Relations at Fivetran, where he builds global programs that help developers and data teams adopt modern data and AI tooling. He previously led DevRel and evangelism at Tobiko Data (creators of SQLMesh) and Dremio, is author of the O'Reilly Definitive... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
Forum Hall (Floor 2)
  Open AI & Data

15:35 CEST

Your Backup Data Doesn't Belong To You - Julien Castets, Plaklar
Wednesday October 7, 2026 15:35 - 16:15 CEST
You can rebuild your infrastructure from a git repo and migrate workloads across clouds. Your backup data is locked in a proprietary format, on vendor hardware, encrypted with keys you don't fully control. This talk applies the open-source portability argument to resilience, and examines what genuine backup ownership actually requires: open formats, storage-backend independence, and key custody that stays with the data owner.
Speakers
avatar for Julien Castets

Julien Castets

Software Engineer, Plaklar
Julien Castets is a French software engineer based in Prague, Czech Republic. Passionate about infrastructure, he previously worked at cloud providers Scaleway and Koyeb as a DevOps and backend engineer, and now works at Plakar, an open-source backup platform, where he focuses on... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
Terrace 2A (Floor 2)
  Open Source 101

15:35 CEST

BoF: Open by Default or Intent: Inflection Points for Public Sector Open Source Decisions - Clare Dillon, CURIOSS; Remy DeCausemaker, CMS.gov; Johan Linåker, RISE Research Institutes of Sweden; Karel Rietveld, Netherlands Tax Administration
Wednesday October 7, 2026 15:35 - 16:15 CEST
Many organizations have bought into the value of open source, but don't choose to open source everything. This Bird of a Feather session focuses on the inflection points for public sector organizations: what actually causes an organization to move projects from closed source to Open Source, or — just as importantly — to make a deliberate call that something should stay closed. The triggers are rarely just technical. Public Sector organizations may consider the ROI on open sourcing; whether the codebase, the team, and the organization are actually in a position to do this well; if there are regulatory obligations or policy considerations that push you towards being more open or closed. Sometimes the honest answer is that the perceived collaboration overhead (e.g. documentation, governance) may not be worth it for code that's considered throwaway or not ready for public consumption. Session participants will include researchers, representatives from InnerSource Commons and OSPOs in public sector organizations who have experience navigating these decisions.
Speakers
avatar for Clare Dillon

Clare Dillon

Community Lead, CURIOSS
Clare Dillon is community lead for CURIOSS, a community for university and research institution OSPOs. Clare is also a PhD researcher with Lero, the Science Foundation Ireland Research Centre for Software and a member of Lero's OSPO team. Clare was the inaugural Executive Director... Read More →
avatar for Remy DeCausemaker

Remy DeCausemaker

Acting Director, OSPO, CMS.gov
Remy DeCausemaker is the Acting Director of the Open Source Program Office at the Centers for Medicare & Medicaid Services (CMS.) Remy helps developers, designers, and other contributors work with dedicated civil servants to create open accessible health technology projects, programs... Read More →
avatar for Johan Linaker

Johan Linaker

Senior Researcher at RISE Research Institutes of Sweden and an Adjunct Assistant Professor at Lund University, RISE Research Institutes of Sweden
Johan Linåker is a Senior Researcher at RISE Research Institutes of Sweden and an Adjunct Assistant Professor at Lund University, working at the intersection of empirical software engineering, open technologies, and digital sovereignty. His work focuses on how public and private... Read More →
avatar for Karel Rietveld

Karel Rietveld

Open Source Program Office lead, Netherlands Tax Administration
Working within the Chief Technology Office in building an Open Source Program Office for the Netherlands Tax administration, Customs and Benefits
Wednesday October 7, 2026 15:35 - 16:15 CEST
Conference Hall (Floor 4)

15:35 CEST

The EU Cyber Resilience Act and Open Source: What Product Vendors Must Do - Timo Perala & Gergely Csatari, Nokia
Wednesday October 7, 2026 15:35 - 16:15 CEST

The EU Cyber Resilience Act (CRA) is fundamentally changing how companies develop, secure, and bring products to market in the European Union. It introduces comprehensive security requirements across the entire software development lifecycle—including how open source components are selected, integrated, and maintained.
Timo and Gergely provide a practitioner-focused view of what CRA means in practice, with a particular emphasis on open source.

In their talk, they examine the CRA from a product vendor perspective, with focus on open source. They will break down the practical implications of the regulation across three key areas: open source consumption, vulnerability management, and open source stewardship. They will also highlight where the regulation leaves room for interpretation and share insights from ongoing industry discussions that are shaping emerging best practices.
Speakers
avatar for Timo Perala

Timo Perala

Head of Open Source Service & Network Automation, Nokia
Timo has over 25 years of experience in network systems, systems architecture research, new business incubation, to mobile network and operations systems standardization. In his current role Timo is with Nokia OSPO, responisble for Automation related open source projects and Regulatory... Read More →
avatar for Gergely Csatari

Gergely Csatari

Senior Open Source Specialist, Nokia
Working in the telecom industry in the last two decades it was possible for Gergely to see the evolution from vendor specific hardware to virtualisation and cloud and a to cloud native. Currently Gergely is part of the OSPO team of Nokia CTO which is reponsible for open source. In... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
Chamber Hall (Floor 3)

15:35 CEST

AI in Zephyr PSIRT: Lessons From the Front Line - Flavio Vinicius Alvares Ceolin, Hubble Network & David Brown, Linaro
Wednesday October 7, 2026 15:35 - 16:15 CEST
Zephyr’s security response is run by a small, mostly volunteer team handling a large and growing workload. Every vulnerability report must be triaged against a million-line codebase, confirmed in source, scored, mapped to a CWE, written up as a CVE record, documented for disclosure, and tracked across multiple release branches — often under embargo deadlines that don’t move. It’s repetitive, high-stakes work, and it’s exactly the kind of burden that burns maintainers out.

This talk is a candid look at how we started using AI to help: grounding analysis in the source tree with file:line citations, drafting CVE records against a strict schema to prevent fabricated fields, and reducing release vulnerability accounting from hours to minutes. It covers what worked, what failed, and the guardrails we built to keep a human in the loop. You’ll leave with a practical blueprint and checklist for using AI in security response — and an honest view of where it helps and where it’s still a liability.
Speakers
avatar for Flavio Vinicius Alvares Ceolin

Flavio Vinicius Alvares Ceolin

Principal engineer, Hubble Network
Flavio Ceolin is a Principal Engineer at Hubble Network, where he works on embedded SDKs, device firmware, and communication protocols that use Zephyr and Bluetooth chips to connect devices to satellites. He is also a long-time Zephyr RTOS contributor, Zephyr’s Security Architect... Read More →
avatar for David Brown

David Brown

Tech Lead, Linaro
David Brown has worked on the Linux kernel, with a focus on security for a number of years. Recently, he has been focusing on security as it relates to IoT and embedded devices, including focusing on secure booting, and secure network communications. He is currently the Security Chair... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

16:30 CEST

Demystifying Board Farms: Build a Mini Desktop Board Farm With Standard Tools and Hardware - Francesco Cervigni, Neoncomputing
Wednesday October 7, 2026 16:30 - 16:50 CEST
Large companies have built board farms for decades, providing both solid automated QA capabilities and short developer feedback loops.
LAVA and Labgrid have emerged as standard tools.

Although, today most small companies have not adopted those tools and practices, and too many developers spend time, constantly, on hardware set-up.
Either standard tools are unknown, or two myths circulate: that LAVA is just for large-scale scenarios, and Labgrid is complex to set up.
While at this, many create, instead, new in-house tools (wheel reinvention).

This talk aims to reverse this, by showing two portable mini board farms: one using LAVA, and one using Labgrid.
These two examples will act as comparison and demystification of these standard open-source tools, while showing common concepts.
Both examples share a common open-source CI/CD (GitLab), and the physical layout: a portable 10-inch rack, which can sit on a desk (introduced only in recent years).
Network, serial, power and cable management is done assembling off-the-shelf hardware.

Board farm adoption, at any scale, can help teams to increase ergonomics, comfort, and determinism, for stress-free development, CI, and test workflows.
Speakers
avatar for Francesco Cervigni

Francesco Cervigni

Independent Embedded CI/CD & Test Automation Specialist, Neoncomputing
Francesco Cervigni is an embedded software consultant with 14 years in Embedded Systems and Industrial IoT.
He helps companies from different sectors improve development experience focusing on reproducible build systems, CI/CD, automated testing on emulated and real hardware, met... Read More →
Wednesday October 7, 2026 16:30 - 16:50 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

16:30 CEST

Challenges Using an IEC Standard in Open Source - Nico Rikken, Alliander
Wednesday October 7, 2026 16:30 - 16:50 CEST
The electrical energy sector can largely be defined by the IEC standards that ensure compatibility and conformity. In this way IEC standards serve our industry very well, both in the physical and digital realm. Although the open source projects and IEC share a similar goal of compatibility and innovation, in practice they conflict with one another. This has to do with the way in which IEC standards are created, licensed and distributed.

In this presentation Nico will share his experiences in dealing with IEC licenses from the perspective of an OSPO supporting open source development. This will highlight various issues, big and small, that hinder open source development. The presentation will also gather insights from the standards group in the LF Energy community group. By presenting this constructive assessment Nico hopes to foster discussion and encourage improvement of the situation. Much of the content will carry over to other closed standards.
Speakers
avatar for Nico Rikken

Nico Rikken

Solution Architect, OSPO member, Alliander
Nico Rikken has a track record in maximizing the potential of Free and Open Source Software in the energy sector and in the Netherlands. As Open Source Ambassador at grid operator Alliander he helps make open source project participation successful and ensure control over the company... Read More →
Wednesday October 7, 2026 16:30 - 16:50 CEST
Chamber Hall (Floor 3)

16:30 CEST

MCP and AI Protocols: Questions for Open Source Managers - Ana Jiménez Santamaría, Linux Foundation
Wednesday October 7, 2026 16:30 - 16:50 CEST
Open protocols are creating a new layer of infrastructure for how AI agents connect to tools, data, and each other. For OSPOs and open source managers, this also creates a new governance surface: How should open source repositories document instructions for AI agents?; What policies are needed for AI-assisted contributions?; How can OSPOs help bring an open source perspective into agentic AI policies and processes while working with the teams responsible for security, legal and platform engineering?

This talk will introduce the basic concepts behind the open agent protocol landscape, with a special focus on the Model Context Protocol (MCP), and explore how OSPOs can apply this knowledge to open source policies, developer experience, contribution workflows, and reporting

The session will close with a few open questions and practical considerations for open source managers starting to explore this space, including how collaborative efforts such as TODO Group’s Agentic AI to Empower OSPOs initiative can help the community build in collaboration
Speakers
avatar for Ana Jiménez Santamaría

Ana Jiménez Santamaría

Senior Project Manager, Linux Foundation
Ana Jiménez Santamaría is an open source community leader and data scientist with 5+ years of experience at the Linux Foundation, working as Sr. project manager supporting global, multi-stakeholder IT ecosystems. She is also an Agentic AI Foundation Ambassador, helping developers... Read More →
Wednesday October 7, 2026 16:30 - 16:50 CEST
Conference Hall (Floor 4)

16:30 CEST

Life Finds a Way , Sandboxed Agents, Observable Verdicts - Henrik Rexed, Dynatrace
Wednesday October 7, 2026 16:30 - 17:10 CEST
"Life, uh, finds a way." So do AI agents. Give one a tool, and a prompt-injected README will teach it to spawn a shell. CVE-2025-59528 (CVSS 10.0) and Google's Antigravity sandbox escape proved the same thing twice in 2025: the agent didn't break the sandbox , either the sandbox was missing, or the electric fence was in the wrong place.
This talk is a tour of Jurassic Park, rebuilt on Kubernetes. The paddock walls are containers. The electric fence is kubernetes-sigs/agent-sandbox, swapping gVisor for Kata Containers under the same CRD. The control room is OpenTelemetry where invoke_agent, execute_tool, and tool.policy_check spans turn every isolation verdict into queryable telemetry.
We will deploy OpenClaw ,an open-source AI agent gateway inside a Sandbox resource on Cluster API, watch the agent attempt three different escapes, and ship policy decisions as first-class spans. Help shape OpenTelemetry semconv #3583 before the park opens.
Speakers
avatar for Henrik Rexed

Henrik Rexed

Cloud Native Advocate, Dynatrace
Henrik is a Cloud Native Advocate at Dynatrace, the leading Observability platform. Prior to Dynatrace, Henrik has worked more than 15 years, as Performance Engineer. Henrik Rexed Is Also one of the Organizer of the conferences named WOPR, KCD Austria and the owner of the Youtube... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

16:30 CEST

Fully Describe Your Regulators and Supplies - Chen-Yu Tsai, Google LLC
Wednesday October 7, 2026 16:30 - 17:10 CEST
All active components require power. The device tree should properly describe these supplies so that the software can control power to the devices. On the other side of things, regulators also have their power inputs, and constraints on their power outputs. The device tree should also describe this. Nothing should be left to default.

This session will present how to fully describe the regulator tree of a system, how to identify missing bits, and how to properly describe regulator constraints.
Speakers
avatar for Chen-Yu Tsai

Chen-Yu Tsai

Staff Software Engineer, Google LLC
Software engineer at Google working on MediaTek based Chromebooks.
Wednesday October 7, 2026 16:30 - 17:10 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

16:30 CEST

Securing Embedded Linux Buildsystems Against Supply Chain Attacks - Alejandro Enedino Hernandez Samaniego, Microsoft Corporation
Wednesday October 7, 2026 16:30 - 17:10 CEST
Embedded Linux build systems such as The Yocto Project and Buildroot rely on reused build artifacts and external inputs, while these represent an improvement in build time for subsequent builds, also create opportunities for supply chain attacks that are difficult to detect.

This talk demonstrates practical attack vectors, showing how intermediate object files produced by make in Buildroot can be modified during the build to introduce malicious behavior without changing source code, and also demonstrate its possible to poison Yocto Project shared state (sstate) cache artifacts to propagate compromised binaries.
These attacks are validated end-to-end by executing poisoned binaries in the final Linux image under QEMU.

I will then present mitigation strategies, focusing on signing and verification of the sstate artifacts and improved control over build inputs. The discussion covers integration approaches and tradeoffs between security, performance, and developer workflows.

Attendees will gain practical insight into real-world risks when creating customized Linux distributions and concrete steps to improve their build system's security.
Speakers
avatar for Alejandro Enedino Hernandez Samaniego

Alejandro Enedino Hernandez Samaniego

Principal Software Engineer, Microsoft Corporation
Alejandro is an Principal Software Engineer at Microsoft, he works as a Yocto Project developer in the Linux Systems Group, designing software to improve system's developers experience when building customized embedded Linux distributions and applications, currently maintains the... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

16:30 CEST

Modernizing Vmalloc With Maple Tree: Design, Challenges, and Trade Offs - Pranjal Arya, Qualcomm
Wednesday October 7, 2026 16:30 - 17:10 CEST
Linux has steadily evolved toward Maple Tree as the preferred infrastructure for range-based indexing. While Maple Tree transformed process address-space management, several core memory-management subsystems still rely on legacy rb-tree-based designs.

This session uses the my vmalloc Maple Tree migration patch series as a case study to explore a broader question: what does it take to modernize a mature memory-management subsystem at the heart of the Linux kernel?

Unlike VMAs, vmalloc combines range allocation, gap tracking, coalescing, and lazy reclamation used by drivers, architectures, modules, and core kernel services. More than a data-structure replacement, it demonstrates how foundational kernel infrastructure can evolve while preserving correctness and long-standing semantics.

The talk covers the design motivations behind the transition, key trade-offs between augmented rb-trees and Maple Tree, scalability and metadata-efficiency improvements, and lessons learned from modernizing a core allocator. Attendees will gain insight into vmalloc internals, Maple Tree adoption beyond VMAs, and practical approaches for evolving Linux memory management infrastructure.
Speakers
avatar for Pranjal Arya

Pranjal Arya

Senior Software Engineer, Qualcomm
Pranjal Arya is a Linux kernel & system engineer at Qualcomm, working on GPU and data center SoCs. His 6 years of experience spans PCIe & GPU drivers, memory management, Vulkan, DRM, and graphics software across kernel and user space. His contributions include PCIe, VFIO, QEMU, and... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
Panorama Hall (Floor 1)
  Linux
  • Audience Experience Level Any

16:30 CEST

From Single Agent To Production Swarm: Patterns for Building Reliable Multi-Agent Systems - Betty Zheng, AWS & Trista Pan, Tetrate
Wednesday October 7, 2026 16:30 - 17:10 CEST
AI agents are evolving from simple chatbots to coordinated systems that plan, collaborate, and execute real-world tasks. But moving from a working prototype to a production-grade multi-agent system is where most teams struggle.

In this session, two practitioners share battle-tested patterns from deploying agent swarms in industrial environments. We cover:
The architectural shift from single-agent to multi-agent: when and why you need a swarm
Comparing open source frameworks (LangChain, AutoGen, Strands Agents SDK) — strengths, trade-offs, and selection criteria
Practical orchestration patterns: task delegation, shared memory, tool coordination via MCP (Model Context Protocol)
Live demo: building a multi-agent system that collaborates to solve a real task
Safety-first design: guardrails, execution boundaries, and observability for production
Attendees will leave with a reusable architectural blueprint applicable to any open source agent framework.
Speakers
avatar for zheng yubin

zheng yubin

Senior developer advocate, AWS
Yubin Zheng is a seasoned engineer with over 20 years of experience in ICT and digital transformation. She focuses on building real-world AI systems, including agent runtime design, multi-agent coordination, and production deployment. She is an active contributor to developer and... Read More →
avatar for Trista Pan

Trista Pan

AI Engineer, Tetrate
AI Engineer at Tetrate, Ex AI Product Director at Bytedance, Former Co-founder of SphereEx, Apache Member and Incubator Mentor, and AWS Data Hero

Her expertise is in big data and AI. She was elected an OSCAR Top Open Source Pioneer. In 2022, her paper “Apache ShardingSphere: A Holistic and Pluggable Platform for Data Sharding” was published on ICDE. As the first author, she wrote a book titled A Definitive Guide to Apache S... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
Forum Hall (Floor 2)
  Open AI & Data

16:30 CEST

A Day in the Life of a CVE Remediator - Shubham Kalloli & Cameron Scholes, Ericsson Software Technology
Wednesday October 7, 2026 16:30 - 17:10 CEST
This talk will focus on a day in the life of CVE remediators. It will go through the full process of identifying, resolving, upstreaming and following up CVEs in various dependencies. It will also go through the various Open Source tools that we use throughout the full process, touch on our experiences working upstream and go through how we are sharing this knowledge and experience internally.
Speakers
avatar for Shubham Kalloli

Shubham Kalloli

Senior Software Engineer, Ericsson Software Technology
Senior Software Engineer at Ericsson Software Technology working in the Open Source Community
avatar for Cameron Scholes

Cameron Scholes

Software Engineer, Ericsson Software Technology
Cameron is a software engineer working for Ericsson Software Technology in Ireland for over 3 years. He has been working in many different open-source projects and communities with a focus on the security supply chain and CVE remediation upstream. He has experience with many different... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
Terrace 2A (Floor 2)
  Open Source 101

16:30 CEST

CRA Readiness With SPDX 3 SBOMs in Zephyr - Benjamin Cabé, The Linux Foundation
Wednesday October 7, 2026 16:30 - 17:10 CEST
SBOMs for embedded firmware are harder than simple dependency lists. A Zephyr-based product typically combines upstream Zephyr code, vendor HALs, out-of-tree modules, binary blobs, generated files, Kconfig and devicetree configuration, and of course user/application code. Some of these pieces end up in the final firmware image, some do not, and yet it is important to have a clear picture of what was used, what was changed, and what actually shipped. This is what helps teams avoid chasing false positives, while still knowing when a new CVE might really affect them.

In this talk, we will look at Zephyr’s SPDX-based SBOM generation, including its recently added support for SPDX 3.0. We will show why it is useful to describe not only _which_ components are present, but also _why_ they were pulled into the build and how they relate to each other.

We will also discuss how build-aware SBOMs can directly support vulnerability management and help prepare for regulations such as the Cyber Resilience Act.
Speakers
avatar for Benjamin Cabé

Benjamin Cabé

Developer Advocate, The Zephyr Project, Linux Foundation
Benjamin Cabé is a technology enthusiast with a passion for empowering developers to build innovative solutions.

He has invented an award-winning open source and open hardware artificial nose that he likes to use as an educational platform for people interested in diving into t... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

16:50 CEST

Cukinia: A Lightweight Test Framework for Embedded Linux Systems - Kévin L'hôpital, Savoir-Faire Linux
Wednesday October 7, 2026 16:50 - 17:10 CEST
Embedded Linux projects already have powerful testing frameworks, but they often come with requirements about infrastructure, dependencies, or target environments. In many firmware projects, developers need something simpler: a lightweight way to run system-level validation directly on the device, with minimal setup and no additional runtime requirements.

Cukinia is an open-source test framework designed to make embedded Linux validation simple and accessible. Requiring only a POSIX shell, Cukinia can run directly on target devices even in production and integrates quickly into existing CI/CD workflows. With a collection of predefined test statements, developers can quickly create tests for system configuration, hardware interfaces, services, networking, storage, and more.
Speakers
avatar for kévin L'hôpital

kévin L'hôpital

Embedded engineer, Savoir-faire Linux
Kevin is an embedded engineer working in Savoir-faire Linux in Rennes. He is mainly working on creating Yocto based distribution, kernel debugging, secure-boot implementation and creating media applications. He is the main contributor of the GEISA conformance test application.
Wednesday October 7, 2026 16:50 - 17:10 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

16:50 CEST

AI Everywhere, Trust Nowhere: Navigating Open Source Security, "AI Slop," and the New Attack Surface - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
Wednesday October 7, 2026 16:50 - 17:10 CEST
Artificial Intelligence is fundamentally changing the open-source ecosystem, promising unparalleled development velocity. However, this speed scales risk simultaneously. Open-source software (OSS) maintainers—already heavily resource-constrained and unevenly funded—are finding themselves caught in a crossfire of AI-driven complications.

This session, led by the Open Source Security Foundation (OpenSSF), breaks down the three critical security paradigm shifts introduced by AI:

Securely Using AI to Build Software: How insecure-by-default code suggestions, copied risks, and hallucinated packages compromise codebase integrity.

Using AI to Secure Software: The reality of how upstream maintainers are overwhelmed by a massive influx of automated vulnerability reports generated by AI bug hunters.
AI as an Attack Surface: Moving past traditional DevSecOps to address MLSecOps pipeline vulnerabilities, including data poisoning, model theft, and container security across the machine learning lifecycle.

Attendees will walk away with an understanding of OpenSSF’s recommended approach designed to shift the focus from cheap "findings" to valuable, validated "fixes".
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Security Lorax, Openssf
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Adrianne Marcum

Adrianne Marcum

OpenSSF Chief of Staff, Linux Foundation
Adrianne Marcum brings extensive experience in engineering, product, project, and program management to her role as Chief of Staff at OpenSSF. With a career that began in mechanical engineering, she has since worked across a multitude of industries, including defense, heavy machinery... Read More →
Wednesday October 7, 2026 16:50 - 17:10 CEST
Conference Hall (Floor 4)

16:50 CEST

Rebuilding Mini-Grid Metering as Open Infrastructure - Joscha Winzer & Vivien Barnier, EnAccess Foundation
Wednesday October 7, 2026 16:50 - 17:10 CEST
In the past 9 months, the two largest smart-metering providers serving rural mini-grids entered insolvency or severe distress, putting ~250,000 meters in 30+ countries at risk of losing billing, payment, and remote management, and threatening to leave over a million people, plus clinics and schools, in the dark. The cause was structural and familiar to anyone in open source: vertically integrated proprietary stacks, cloud lock-in, and no "supplier of last resort" for critical infrastructure.

This talk is a field report on the open-source response: an alliance of competitors, NGOs, and operators building an unbundled, multi-vendor platform on Digital Public Good principles. We cover the architecture (open APIs, multi-OEM interoperability, code and key release tied to bridge funding), the governance model for an asset that must outlive any single contributor, and how critical open infrastructure can be funded sustainably.

We close with concrete contribution paths: protocol work, hardware integrations (DLMS/COSEM, MQTT, STS), security review, and governance participation.
Speakers
avatar for Vivien Barnier

Vivien Barnier

Managing Direktor, EnAccess Foundation
Vivien has 9+ years of experience in the renewable energy sector. His expertise lies in technologies, business model development, operation, and regulation for Distributed Energy Systems in underserved areas. He has advised development banks, governments, and investors on setting... Read More →
avatar for Joscha Winzer

Joscha Winzer

Head of Technology, EnAccess Foundation
Joscha Winzer is a battery and energy systems engineer with 10+ years' experience designing, certifying, and industrializing electrical energy systems, including the world's first second-life EV battery storage products. And co-founded SunZilla, an early open-source renewable battery... Read More →
Wednesday October 7, 2026 16:50 - 17:10 CEST
Chamber Hall (Floor 3)

17:25 CEST

Rethinking Wireless Networking With Synchronous Transmissions: The OpenSTX Standard - Davide Vecchia, University of Trento
Wednesday October 7, 2026 17:25 - 17:45 CEST
Synchronous Transmission (STX) techniques have matured over a decade of research, enabling a new approach to low-power wireless networking. STX protocols exploit floods that, unlike traditional methods, purposefully embrace on-air collisions via tightly synchronized transmissions. Research repeatedly shows order-of-magnitude gains in reliability, and reduced latency and energy use over conventional approaches.

Standardization is now needed to make STX industry-ready. The OpenSTX Foundation aims to define an open standard from radio interface to application layer, targeting IEEE 802.15.4, Bluetooth, and UWB.

OpenSTX excels where routing-based protocols fall short: network-wide flooding completes in milliseconds with bounded latency; end-to-end reliability is above 99.9% in dense, interference-prone settings; and the absence of routing tables and topology maintenance makes networks inherently tolerant to failure and mobility. Radio duty cycling extends battery life, and network-wide time synchronization is a free by-product.

This session overviews STX techniques, showcases OpenSTX primitives across a layered architecture, presents the roadmap, and describes how to get involved.
Speakers
avatar for Davide Vecchia

Davide Vecchia

Technical Chair, OpenSTX Foundation, University of Trento
Davide Vecchia is a Post-Doctoral Researcher at the University of Trento, where he earned his M.Sc. (2018) and Ph.D. (2022). His research focuses on ultra-wideband (UWB) communication and localization in large-scale multihop networks. Within the OpenSTX Foundation, a Linux Foundation... Read More →
Wednesday October 7, 2026 17:25 - 17:45 CEST
Chamber Hall (Floor 3)

17:25 CEST

Teaching BIND9 New Tricks: A Rust Operator for Declarative DNS on Kubernetes - Erick Bourgeois, RBC Capital Markets
Wednesday October 7, 2026 17:25 - 18:05 CEST
Authoritative DNS is one of the last holdouts against declarative, GitOps-style management. BIND9 still serves a huge share of the world's zone data, but it's driven imperatively: hand-edited zone files, rndc reload, and brittle automation glued on top. bindy is an open-source Kubernetes operator, written in Rust on kube-rs, that closes the gap. It models zones and records as custom resources and continuously reconciles a running BIND9 against them, leaving no orphaned zone file behind.
This talk walks through the architecture of bindy and its sibling projects, bindcar, a sidecar that exposes RNDC operations over a typed API, and hornet, a Rust zone-file parser, then digs into the operator-engineering lessons that transfer to anyone writing controllers in Rust. We'll cover splitting selection from synchronization to avoid reconcile loops, using the reflector and store, modeling ownership and status conditions, and where Rust and kube-rs paid off versus Go's controller-runtime.
Attendees leave with a concrete, reusable pattern for wrapping any stateful, non-cloud-native daemon in a declarative Kubernetes API, and three open-source projects they can adopt, fork, or contribute to.
Speakers
avatar for Erick Bourgeois

Erick Bourgeois

Head of Kubernetes Platform Engineering, Director, RBC Capital Markets
Erick Bourgeois is a platform engineering specialist focused on Kubernetes operators and infrastructure automation for regulated industries. Creator of Bindy, an open-source DNS controller built in Rust, Erick brings expertise in cloud-native architecture, compliance frameworks (SOX... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

17:25 CEST

Your Network Is Already a Compute Platform. Time To Treat It Like One - Eleni Grosdouli & Josh Halley, Cisco
Wednesday October 7, 2026 17:25 - 18:05 CEST
Network switches and routers are no longer passive packet forwarders. They have been running containers for some time already. But managing them still requires separate tools, CLIs, and workflows, and that creates real operational friction.

Virtual Kubelet eliminates this. Network devices become Kubernetes nodes. Workloads are provisioned with standard kubectl commands. Device configuration is declared as Kubernetes resources with continuous drift detection. Telemetry flows through OpenTelemetry to any OTLP-compatible backend.

This session demonstrates how to converge network and platform operations into a single control plane. We will demonstrate live provisioning of network devices and show how the CNCF ecosystem enables observability, security, and policy enforcement for edge deployments.
Speakers
avatar for Eleni Grosdouli

Eleni Grosdouli

DevOps Consulting Engineer, Cisco Systems
Eleni is your go-to DevOps and GitOps expert, passionate about networking, security, and endpoint management. As a DevOps Consulting Engineer at Cisco Systems, she brings hands-on experience across diverse technical domains. A lifelong learner, Eleni loves experimenting with cutting-edge... Read More →
avatar for Josh Halley

Josh Halley

Principal Architect, Cisco
Josh Halley, is a Principal Architect and published technical author, in the office of the CTO at Cisco,
focused on next generation technologies and technical transformation for some
of Cisco’s largest global customers. His main focus today is in the domains of AI Operations, leading and supporting multiple teams in their generation of Agentic AI systems to support todays and tomorrows future technologies use cases... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 2 A (Floor 2)
  Cloud & Orchestration
  • Audience Experience Level Any

17:25 CEST

Labgrid & Board Farming BOF - Rouven Czerwinski, Linaro
Wednesday October 7, 2026 17:25 - 18:05 CEST
Labgrid is a tool for both board farming and embedded systems testing. This session will include an overview of current developments and also provides a gathering for people interested or already using Labgrid.
Speakers
avatar for Rouven Czerwinski

Rouven Czerwinski

Software Engineer, Linaro
At first building the labgrid hardware access layer, rouven nowadays works on security and multimedia solutions for embedded devices.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

17:25 CEST

Secure by Default: Building Locked-Down Embedded Linux Devices With Systemd - Mohammad Abdoli, Segula Technologies
Wednesday October 7, 2026 17:25 - 18:05 CEST
Modern embedded Linux devices must balance security, maintainability, and operational flexibility. While the Linux kernel provides powerful security primitives such as namespaces, cgroups, eBPF, and dm-verity, integrating them consistently across products remains a challenge.

This session explores how systemd has evolved beyond a traditional init system into a security and lifecycle management framework for embedded Linux platforms.

Using practical examples, we will examine how systemd Portable Services enable immutable application deployment, how dm-verity protects software integrity from storage to execution, how systemd leverages eBPF for kernel-enforced sandboxing and policy enforcement, and how cgroup-based resource management can contain both faults and attacks.

Attendees will learn how these mechanisms interact, how they can be integrated into Yocto-based systems, and how systemd can act as the orchestration layer between applications and modern Linux kernel security features.

Rather than presenting isolated hardening techniques, this session introduces a practical architecture for designing maintainable, resilient, and secure-by-default embedded Linux products.
Speakers
avatar for Mohammad Abdoli

Mohammad Abdoli

Senior Embedded systems consultant, Segula technologies
Mohammad Abdoli (mominux) is an Embedded Systems Engineer specializing in the safety and security of embedded platforms, Linux system architecture, and open-source technologies. His interests include Linux security, systemd, virtualization, and secure-by-design embedded systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

17:25 CEST

ZBus for Linux - Peter Fecher, PHYTEC Messtechnik GmbH
Wednesday October 7, 2026 17:25 - 18:05 CEST
ZBus (Zephyr Bus) is a thread-to-thread message and data exchange protocol based on a bus topology. Since Zephyr v4.4.0, it also supports IPC between multiple Zephyr domains running on different CPU cores.

While this fits well for homogeneous multicore systems, heterogeneous SoCs typically run different operating systems on different cores. A common ARM-based setup uses Linux on a Cortex-A core for high-level tasks and Zephyr on a Cortex-M core for real-time workloads.

Communication between these environments requires data exchange across both cores and operating systems. Currently, the practical approach is to transfer raw bytes through RPMsg channels, requiring developers to implement custom protocols on both sides.

ZBus for Linux bridges this gap by connecting Linux applications to a remote ZBus instance, enabling structured communication across heterogeneous systems.

This talk presents the implementation of an early prototype, the challenges encountered, and the overall architecture of ZBus for Linux.
Speakers
avatar for Peter Fecher

Peter Fecher

Embedded Engineer, PHYTEC Messtechnik GmbH
Peter Fecher just finished his bachelors degree in Computer Engineering. He has been working at PHYTEC for 3 years now, specialising on microcontrollers and IoT systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

17:25 CEST

Sandlock: Rootless and Containerless Confinement for AI Agents - Cong Wang, Multikernel Technologies
Wednesday October 7, 2026 17:25 - 18:05 CEST
Your AI agent just wrote some code and wants to run it on your machine. It can read your SSH keys, exfiltrate data to any host, and overwrite your project. How do you give it just enough freedom to be useful, and nothing more?

This talk presents Sandlock, an AI agent sandbox for Linux that locks a process down in about 5 milliseconds using nothing but the kernel. No root. No cgroups. No containers. Spinning up a container or microVM per agent action means image builds, privileged setup, and a ~100 ms tax on every launch. Sandlock makes confinement cheap enough to wrap every command an agent runs.

We will show how it composes three kernel features: Landlock for filesystem, network, and IPC scoping; seccomp-bpf for syscall filtering; and seccomp user notification, where a supervisor enforces memory limits, an IP and port allowlist, HTTP-level ACLs with zero-config HTTPS inspection, and a copy-on-write working directory.

Live demos: pin an agent's egress to a single API, give it data access but no network, preview every file it would change before committing, and see real numbers (44x faster startup than Docker).
Speakers
avatar for Cong Wang

Cong Wang

Founder and CEO, Multikernel Technologies
Cong Wang is a professional Linux kernel developer mainly focuses on AI agent infrastructure, he founded Multikernel Technologies and Agentry. He has contributed over 1000 patches to the Linux kernel project and many other open source projects.
Wednesday October 7, 2026 17:25 - 18:05 CEST
Panorama Hall (Floor 1)
  Linux

17:25 CEST

Nine Seconds To Production: Security Governance for AI Agents - Jasdeep Singh Bhalla, GoDaddy
Wednesday October 7, 2026 17:25 - 18:05 CEST
On April 24, 2026, an AI coding agent deleted a company's entire production database in nine seconds. Every customer record, every reservation, and every backup vanished. The system prompt explicitly told the agent never to execute destructive commands. It did it anyway.

It was a chain of architectural failures: an agent improvising instead of stopping, overprivileged credentials, no human approval for high-risk actions, and backups inside the same blast radius.

This session recreates the incident and rebuilds the security architecture live. You'll see how OPA enforces policy before tools execute, Falco detects suspicious runtime behavior, and OpenTelemetry captures structured reasoning traces for compliance-grade audit logs.

We'll implement six defensive layers: pre-execution policy enforcement, runtime behavioral monitoring, structured audit logging, least-privilege execution roles, infrastructure deletion protection, and recovery systems isolated outside the agent trust boundary.

Prompts are guidance. Infrastructure is enforcement. You'll leave with a vendor-neutral security architecture for deploying AI agents safely across any framework or LLM provider.
Speakers
avatar for Jasdeep Singh Bhalla

Jasdeep Singh Bhalla

Senior Software Engineer, GoDaddy
Jasdeep Singh Bhalla is a Senior Software Engineer at GoDaddy, specializing in AI security governance, cloud native infrastructure, and distributed systems. With over a decade of experience across GoDaddy, Electronic Arts, Dialpad, and Yahoo, he has architected production platforms... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Forum Hall (Floor 2)
  Open AI & Data

17:25 CEST

5 Practical Tips To Improve Your Log File Analysis Efficiently - Syed Usman Ahmad, Grafana Labs
Wednesday October 7, 2026 17:25 - 18:05 CEST
Linux now stands as the most widely used operating system for production and development environments, as it provides a lot of services (daemons) and tools for debugging.

One core part are the log files which is widely used. You can use built-in commands such as less, grep, awk/sed or tail for log analysis, but there are times when you need some more advanced commands or tools that can help to investigate large log files efficiently.

In this talk, you will learn five practical tips to view your log files for analysis. You will learn about Open Source tools that can make your job easier for your daily tasks.

Join us to learn more about Linux, log analysis, aggregation tools, and the value of Open Source Community.
Speakers
avatar for Syed Usman Ahmad

Syed Usman Ahmad

Staff Developer Advocate, Grafana Labs
Usman is a Staff Developer Advocate at Grafana Labs from Nuremberg, Germany and works with the Open Source community on the community forum, GitHub and Slack.

He has over 15 years of experience in IT and Cloud Support where he served multiple customers all over EU, US and Japan.
... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Terrace 2A (Floor 2)
  Open Source 101
  • Audience Experience Level Any

17:25 CEST

Panel Discussion: Open Source in Software-Defined World - Sven Jeroschewski, Robert Bosch GmbH; Ana Jiménez Santamaría, Linux Foundation; Cornelius Schumacher, DB Systel GmbH; Agustin Benito Bethencourt, Independent
Wednesday October 7, 2026 17:25 - 18:05 CEST
Many initially hardware-driven industries, undergo a profound transformation and become more defined by software like it is the case in the automotive industry. Driven by increasing software complexity, this shift demands unprecedented levels of collaboration and joint integration. As many organizations whose core business was not selling software accelerate towards a more software-defined world, a critical question is how to consume, grow, run and consume the involved Open Source projects to deliver lasting value.

While many of the effects of open collaboration are not unique to a particular domain, the lessons learned from already more "software-defined" industries unlock invaluable insights that are collected in the TODO Group Business Guide.

Taking the learnings from that guide, this panel will delve into how Open Source activities effectively contribute to reaching business goals.

Join us to uncover enablers of sustainable Open Source development, learn from cross-industry successes, and equip your teams with the necessary competencies to thrive in the rapidly evolving software-defined world.
Speakers
avatar for Sven Erik Jeroschewski

Sven Erik Jeroschewski

OSPO Member, Robert Bosch GmbH
Sven Erik Jeroschewski is a Software Engineer with the OSPO of the Robert Bosch GmbH. He combines Open Source strategy with software engineering and actively works within the automotive open-source ecosystem by acting as a committer for Eclipse Kuksa. Sven studied Computer Engineering... Read More →
avatar for Ana Jiménez Santamaría

Ana Jiménez Santamaría

Senior Project Manager, Linux Foundation
Ana Jiménez Santamaría is an open source community leader and data scientist with 5+ years of experience at the Linux Foundation, working as Sr. project manager supporting global, multi-stakeholder IT ecosystems. She is also an Agentic AI Foundation Ambassador, helping developers... Read More →
avatar for Cornelius Schumacher

Cornelius Schumacher

Open Source Steward, DB Systel GmbH
Cornelius helps teams at Deutsche Bahn, the German railway company, to use and contribute to open source software. He has a background from more than two decades in the open source community and industry. Originally a software developer he now focus on management of open source.
avatar for Agustin Benito Bethencourt

Agustin Benito Bethencourt

Consultant, self-employed
Independent consultant, focused on increasing organizational performance in two ways:
1.- Through Tagoross, the forum for professionals at the crossroad of open source as strategy and business
2.- By supporting their journey towards becoming good open source citizens, including AI... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Conference Hall (Floor 4)

17:25 CEST

Where Zephyr Fits in Space Computer Architecture - Yasushi Shoji, Space Cubics Inc.
Wednesday October 7, 2026 17:25 - 18:05 CEST
Using Zephyr in space is not only a question of choosing an RTOS. A space computer is a system architecture: boot firmware, supervisor logic, watchdogs, safe mode, recovery paths, update policy, hardware monitoring, FPGA or SoC configuration, and the boundary between platform software and mission-specific applications all matter.

This talk looks at Zephyr from that system-architecture point of view. Based on Space Cubics’ OBC development experience and recent Space Grade Linux discussions, it explores where Zephyr can fit in future space systems: mission RTOS, payload-controller OS, supervisor/control-plane OS, or companion to Linux. Space already has credible RTOS options, but Zephyr can bring value if the ecosystem develops a clear architectural story around boot, recovery, observability, hardware control, and responsibility boundaries.

Attendees will leave with a practical checklist for evaluating Zephyr’s role in a space computer: what Zephyr should control, what should remain outside it, what must be recoverable after launch, and how to structure boot, update, monitoring, isolation, and fault-handling responsibilities.
Speakers
avatar for Yasushi SHOJI

Yasushi SHOJI

Co-Founder and CEO, Space Cubics Inc.
Yasushi SHOJI is a Linux kernel and embedded systems developer with over 20 years of experience. Founder of Space Cubics, he develops spacecraft using Zephyr RTOS and contributes to open source projects for high-reliability systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

17:45 CEST

Open Quantum Safe: Post-Quantum Software Research in the Era of the First PQC Standards - Rodrigo Martín, Indra
Wednesday October 7, 2026 17:45 - 18:05 CEST
The Open Quantum Safe (OQS) project was founded with the mission of supporting the transition to Post-Quantum Cryptography. On its way, it became one of the most important open-source post-quantum cryptographic organizations. The subsequent publication and adoption of the first PQ standards by major cryptographic projects helps the cryptographic community in the adoption of this required type of cryptography. The mission of the OQS organization remains being at the forefront of PQC research. This talk provides an update of what these efforts look like in the era of the first PQ standards. It will include lessons learned along the way, challenges encountered when handling a PQ Open Source project and future directions, such as: 

1) Addition of new PQ schemes being considered for standardization or relevant to the PQ cryptographic community (e.g. NIST on-ramp signature schemes)

2) Inclusion of new functionalities like: new hybrids or constant-time analysis.
Speakers
avatar for Rodrigo Martín

Rodrigo Martín

Senior Cryptography Researcher, Indra
Rodrigo is a Senior Cryptography Researcher at Indra. He is also an Industrial PhD candidate, focused on the algebraic aspects of PQC, as well as PQC migrations. His work experience is the research, development and secure deployment of cryptography in real applications and protocols... Read More →
Wednesday October 7, 2026 17:45 - 18:05 CEST
Chamber Hall (Floor 3)

18:30 CEST

Attendee Reception
Wednesday October 7, 2026 18:30 - 21:30 CEST
Time: 18:30 – 21:30
Location: Žofín Palace, Slovanský ostrov 226, 110 00 Praha 1, Czechia

Join us at Žofín Palace to continue the conversations beyond the conference venue – the perfect setting for an evening dedicated to connection. After a heavy day of technical tracks, cross the bridge over the Vltava River and enter a grand Neo-Renaissance palace filled with your open source peers. This is your space to step away from the screens, grab a drink, and truly connect.

Whether you’re looking to meet a key maintainer, swap notes on the day’s breakthrough sessions, or find your next collaborator, the palace’s grand ballrooms offer the space to make it happen. Come hungry for local Czech cuisine and ready to kick off an incredible conference with the open source community.
Wednesday October 7, 2026 18:30 - 21:30 CEST
Žofín Palace
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -