Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Company: Intermediate clear filter
arrow_back View All Dates
Wednesday, October 7
 

09:05 CEST

Marrying Device Tree and SCMI - Geert Uytterhoeven, GLIDER bv
Wednesday October 7, 2026 09:05 - 09:45 CEST
Traditionally, Linux has been fully responsible for and in full control of all hardware components in an embedded system, as described by its Device Tree (DT). With the advent of heterogeneous System-on-Chips (SoCs) with multiple CPU cores (Application and Real-Time) and security technologies (Secure Boot, Trusted Environments, Virtualization), this is no longer the case. To avoid compromising system integrity, Linux must now be prevented from controlling system resources used by other CPU cores, and cannot be tasked with control of shared system resources, while Linux still needs to access these resources.

The Arm System Control and Management Interface (SCMI) is intended to solve this, by providing a firmware interface to handle access to system resources like clocks and power domains.

In this presentation, targeting Embedded Linux Developers and System Architects, Geert will give an overview of SCMI, and its impact on DT hardware description. He will discuss the challenges of supporting multiple evolving firmware versions and lineages, and possible solutions, based on experience gained while upstreaming Linux support for R-Car X5H, Renesas' fifth-generation automotive SoC.
Speakers
avatar for Geert Uytterhoeven

Geert Uytterhoeven

Embedded Linux Kernel Hacker, GLIDER bv
Geert Uytterhoeven became involved with Linux 30 years ago, when he started hacking the Linux kernel to make it work better on his Amiga. This paved the way for a long string of contributions to Linux.
In 2013, Geert founded Glider bv (http://glider.be/), to build upon the (embed... Read More →
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

09:05 CEST

Triaging CVEs for the Linux Kernel - Christoph Steiger & Negar Masoudifar, Siemens AG
Wednesday October 7, 2026 09:05 - 09:45 CEST
The Linux kernel currently sees around 60 CVEs per week. With the EU Cyber Resilience Act (CRA) rapidly approaching this creates a serious challenge for anyone shipping commercial products based on it: a lot of additional vulnerability management and compliance work.

In this talk, we will introduce kernel-cve-triage, a tool developed under the umbrella of the Civil Infrastructure Platform (CIP). It addresses these compliance challenges with a unique approach, using the kernel’s Kconfig build configuration to determine which reported CVEs actually apply. With this method, we base our assessment only on the kernel source tree and its configuration and are build-system independent. This reduces false-positive CVEs by up to 95%, depending on the exact configuration and the set of vulnerabilities considered.

We will also cover the key differences compared to another major kernel CVE automation tool: the Yocto Project and its cve-check. Finally, we will give an outlook and suggestions on how to improve the current situation for the Linux kernel's users.
Speakers
avatar for Christoph Steiger

Christoph Steiger

Embedded Linux Engineer, Siemens AG
Open Source enthusiast who is working on embedded Linux systems. He focuses on all things Linux Kernel: from driver implementation to real-time applications and supply chain security.
avatar for Negar Masoudifar

Negar Masoudifar

Working Student – Embedded Linux, Siemens AG
Negar Masoudifar is a working student at Siemens focused on Linux kernel development and embedded systems. She works on the CIP kernel CVE triage project, building tools to help figure out which vulnerabilities actually matter for a given kernel setup.
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:05 CEST

Zephyr at 10: Scaling an Open Source RTOS for the Next Decade - Anas Nashif, Intel
Wednesday October 7, 2026 09:05 - 09:45 CEST
Over the last decade, Zephyr has grown from a focused open source RTOS into one of the most widely adopted platforms for connected, secure, and portable embedded systems. That success brings new challenges: more architectures, more boards, more vendors, more contributors, more downstream users, and higher expectations around quality, security, safety, documentation, testing, and long-term maintenance.

This talk looks at Zephyr’s evolution through the lens of project sustainability. It will highlight where the current model is working, where scaling pressure is becoming visible, and what the community needs to address to keep Zephyr healthy for the next 10 years. Topics include maintainer bandwidth, review latency, infrastructure load, test and sample growth, vendor enablement, downstream compatibility, long-term support, security updates, dependency management, and the tension between a unified upstream and the need for product- and platform-specific innovation.
Speakers
avatar for Anas Nashif

Anas Nashif

Senior Prinicipal Engineer, Intel
Senior Principal Software Engineer at Intel and TSC chair of the Zephyr project.
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

09:50 CEST

An Approach To Managing CVEs With Vendor Kernels - Jan Pfiffner, Grossenbacher Systeme AG
Wednesday October 7, 2026 09:50 - 10:30 CEST
Managing vulnerabilities in the kernel has gotten more attention but also needs more effort due to the exploding number of CVEs. With the kernel now being a CNA since 2024, options have evolved, and most recently, since 596ad6c on openembedded-core/master, it has gotten "easy".

But this is not working for vendor kernels, as they lag mainline and a rebase is impractical, if not impossible, due to the vendor delta.
As vendor kernels are heavily used in the industry and a switch to linux-yocto is often not possible due to budget, timeline or vendor lock-in, a solution is needed.

I've built a solution that locates the fix for each detected CVE on the matching stable branch, emits a candidate backport patch, verifies it applies cleanly, checks (via koverage, at line granularity) whether the affected code is compiled, and classifies results into actionable buckets.
Output is a list of unaffected CVEs and a collection of patches for review. In my opinion, this is verified and evidence-backed patching rather than just a cherry-picked list.

I'd like to present a solution (layer) which includes this workflow and start a broader discussion about the issue with vendor kernels.
Speakers
avatar for Jan Pfiffner

Jan Pfiffner

Head of Software Engineering, Grossenbacher Systeme AG
I'm Head of Software Engineering at Grossenbacher Systeme AG (GESYS), a Swiss embedded systems manufacturer. After several years in PLC and machine vision software development, I moved into embedded and have spent the last four years working with Yocto, building, producing and maintaining... Read More →
Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:50 CEST

Reproducible Embedded Linux Testing From Laptop To CI To Scale - Anders Roxell, Linaro
Wednesday October 7, 2026 09:50 - 10:30 CEST
Kernel and embedded Linux engineers often need to reproduce a build or test from someone else. In practice this is still harder than it should be.

A kernel may be built with one toolchain. The rootfs may come from a local build. Firmware may have changed. A model may need specific variables. Continuous Integration (CI) and lab runs may hide setup steps in scripts or jobs.

Then someone asks:

Can I reproduce this?

Too often the answer is: not easily.

This talk shows a practical way to make this better with modern open source tooling, and to show useful workflows that kernel and embedded engineers may not know about yet.

We show how to build the kernel in a repeatable way, provide a known rootfs, boot the target, run tests, and collect logs.

Then we use two Arm examples. One is an OP-TEE flow, where TF-A, U-Boot, and OP-TEE are part of the setup. The other is a CCA flow on QEMU-arm64 and FVP-aemva, where the model setup and software stack also matter.

We use open source tools from the TuxSuite ecosystem, but the focus is the workflow. The same workflow can run on a laptop, in CI, in lab infrastructure, or at scale.
Speakers
avatar for Anders Roxell

Anders Roxell

Senior Engineer, Linaro
Anders Roxell is a Linux kernel engineer at Linaro, focused on testing and platform validation. He's a KernelCI and TuxSuite contributor, and works currently on the Linux kernel builds and tests workflows.
Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

11:20 CEST

Open Source Security as the Foundation of European Sovereignty - Madalin Neag & Mirko Boehm, The Linux Foundation
Wednesday October 7, 2026 11:20 - 11:40 CEST
European digital policy is often discussed through frameworks such as NIS2, the CRA, DORA, the CSA, and the broader Tech Sovereignty agenda. Yet these initiatives share a common objective: securing the software supply chains underpinning Europe’s critical digital infrastructure.

OSS is the foundation of modern technology stacks, from cloud services and critical infrastructure to financial systems and AI. It is also inherently global, developed and maintained by a distributed ecosystem across borders. As reliance on OSS grows, the challenge is no longer whether it is used, but how it is integrated, governed, and secured throughout its lifecycle within this global dependency network.

This session explores software supply chain security as the common thread across Europe’s cyber and digital policy landscape. It examines how regulations converge on transparency, dependency management, vulnerability handling, provenance, and secure development practices.

Finally, it connects these developments to EU Tech Sovereignty goals, arguing that secure and standardized consumption of globally developed open source is key to Europe’s resilience, competitiveness, and technological sovereignty.
Speakers
avatar for Mirko Boehm

Mirko Boehm

Community Development, Linux Foundation Europe

avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, OpenSSF/The Linux Foundation
Madalin is the EU Policy Advisor at OpenSSF, working at the intersection of cybersecurity, open source software, and European technology policy. He helps connect open source technical communities and policymakers, supporting the development of practical regulatory frameworks, aligning... Read More →
Wednesday October 7, 2026 11:20 - 11:40 CEST
Chamber Hall (Floor 3)

11:20 CEST

Evolving the YAML Family (without Breaking the World) - Ingy döt Net, YAML LLC
Wednesday October 7, 2026 11:20 - 12:00 CEST
YAML turned 25 this year.
It is essential to Kubernetes, Docker, Ansible, CI pipelines, and config files for everything in between.
That ubiquity is both a gift and a curse: every change risks breaking something, somewhere, silently.
So how do you grow a data language that a billion files depend on without risk of catastrophe?

Ingy döt Net helped invent YAML and he now maintains the YAML Specification and The YAML Family (libyaml, go-yaml, PyYAML, YAMLStar, YAMLScript etc).
In this talk he'll show how he plans to grow YAML by extension: a plugin system that can deeply affect YAML behavior in completely configurable ways.
Plugin APIs include schema association, tab indent, standard functions, comment support include i18n.
This is being delivered first to go-yaml with the rest of the Family to follow.
The work and its real world feedback will guide future changes to the specification.
Speakers
avatar for Ingy dot Net

Ingy dot Net

Invented YAML, YAML LLC
Ingy döt Net is one of the original inventors of the YAML data language, and its primary maintainer. He is also the active maintainer of go-yaml, the YAML framework trusted by Kubernetes and much of its ecosystem,
Wednesday October 7, 2026 11:20 - 12:00 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:20 CEST

FIT Happens: How Secure Boot Wasn't - Ahmad Fatoum, Pengutronix e.K.
Wednesday October 7, 2026 11:20 - 12:00 CEST
Flat Image Tree (FIT) is Das U-Boot’s preferred boot image format and underpins billions of embedded Linux boot flows, with adoption extending into other bootloaders such as barebox.

Its core idea of using the flattened device tree format for flexibility and code reuse, enabled widespread adoption, but also became a fertile source of subtle security flaws.

This talk traces FIT’s evolution from a pragmatic design choice to a widely trusted format, highlighting how its structure led to recurring weaknesses, culminating in CVE-2026-33243, a decade-old vulnerability whose exploitation bypassed verified boot for millions of devices.

Finally, Ahmad presents a proposal to improve FIT: a backwards-compatible scheme for whole-image signing that requires limited parsing, aiming to deliver stronger security guarantees without the format’s historical pitfalls.
Speakers
avatar for Ahmad Fatoum

Ahmad Fatoum

Kerningenieur, Pengutronix e.K.
Ahmad joined the kernel team at Pengutronix in 2018 to work full-time on furthering Linux world domination. He does so by helping automotive and industrial customers build embedded Linux systems based on the mainline Linux kernel.
Having a knack for digging in low-level guts, his... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

11:20 CEST

What Is Linux Doing With My RAM? - Vlastimil Babka, SUSE Labs
Wednesday October 7, 2026 11:20 - 12:00 CEST
This talk will cover several memory management concepts and underlying principles to give the audience a better understanding about what happens to the RAM on a Linux system, and how to determine that on their own system, namely:

- how much memory is used by userspace processes, the page cache, and the kernel itself
- how to determine accurately how much memory is used by individual processes
- why free memory is always eventually exhausted and what happens then
- how to observe what the kernel is doing to make memory available for allocations, and recognize when it's struggling
- what is the role of swap and why not fear swapping

This includes explaining some key parts of files like /proc/meminfo and /proc/vmstat.
Speakers
avatar for Vlastimil Babka

Vlastimil Babka

Linux Kernel Developer, SUSE Labs
Vlastimil works as a kernel developer at SUSE Labs since 2013, focusing on the memory management subsystem. He currently co-maintains the slab and page allocators, and is a reviewed for several other parts of mm. He is also interesting in performance improvements, debugging features... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
Panorama Hall (Floor 1)
  Linux

11:20 CEST

Containers as an Illusion - Michael Kerrisk, man7.org Training and Consulting
Wednesday October 7, 2026 11:20 - 12:00 CEST
One goal of containers is to provide an illusion: that a group of
processes are in a world of their own, and that there are no other processes on the system. In this session1, we'll look at the nature of that illusion and–through a series of experiments and live demonstrations–examine the various Linux mechanisms–namespaces, capabilities, cgroups (control groups), and seccomp–are used to support the creation of that illusion. (Bring a laptop with a recent Linux distro installed!)
Speakers
avatar for Michael Kerrisk

Michael Kerrisk

Trainer/author/programmer, man7.org Training and Consulting
Michael Kerrisk is a trainer, programmer, and author of "The Linux Programming Interface", a widely acclaimed book on Linux (and UNIX) system programming. From 2004 to 2021, he maintained the Linux "man-pages" project, which provides the primary documentation for Linux system calls... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
Terrace 2A (Floor 2)
  Open Source 101

11:20 CEST

Ten Years of Zephyr: Replace Linux, or Work With It? - Iuliana Prodan, NXP Semiconductors
Wednesday October 7, 2026 11:20 - 12:00 CEST
A decade after its launch, Zephyr has grown from a small RTOS into a capable, MMU-aware, userspace-supporting system running on application-class cores. So people keep asking: can it replace Linux? A better question is how the two can work together - and Zephyr already has what it needs to do that.

This talk shows how Linux and Zephyr run side by side on the same SoC, using parts Zephyr ships today: the IPC service layer, OpenAMP and RPMsg for messaging between the two cores, mailbox and shared-memory backends, and the mechanisms that let Linux start and stop Zephyr firmware. Based on real work on NXP i.MX and i.MX RT platforms, I'll show how these pieces fit, and where the hard parts are - memory layout, buffer sizes, address translation, and shutdown order.

The takeaway: after ten years, the interesting frontier isn't replacement. It's connecting the two so each kernel does what it's best at on the same chip.
Speakers
avatar for Iuliana Prodan

Iuliana Prodan

Software Engineer, NXP Semiconductors
Software Engineer at NXP and the company's Zephyr Technical Ambassador. With a background in Linux, particularly the audio subsystem and Sound Open Firmware, though main focus is now Zephyr. Maintains Zephyr's IPC subsystem, OpenAMP, and libmetal, and works on asymmetric multipro... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

13:30 CEST

How Git Clone Took Down Our CI for 20 Days - Yathartha Goenka, Mercari, Inc.
Wednesday October 7, 2026 13:30 - 14:10 CEST
One morning, CI across ~1,800 repos ground to a near-total halt. HTTP 401 from github.com, everywhere. Deterministic, not flaky. Valid tokens, healthy rate limits. GitHub support said "anti-abuse." We said "which abuse?"

Twenty days and 17,863,537 log records later, we'd gone deeper into git's open source plumbing than we ever intended: how git negotiates HTTP auth, what it leaks in user-agents, which config knobs actually matter under load, and how its defaults — sensible on a laptop — behave pathologically behind Kubernetes NAT at 50,000 CI runs a day.

This talk is a forensic walkthrough of git's HTTP transport, told through an outage: the red herrings, the tcpdumps, the fixes that didn't work, the fix that did. You'll leave knowing what git clone really does when you're not looking — and how to configure it so it never makes you look guilty.

Bring popcorn.
Speakers
avatar for Yathartha Goenka

Yathartha Goenka

Platform Engineer, Mercari, Inc.
A platform engineer at Mercari Japan, leading projects around DX, distributed systems and AI. Been working with backend development using Golang, CI/CD, cloud infrastructure, and scalable system design. Been learning more about the quiet ways a platform can fall over than I ever meant... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

13:30 CEST

20 Years of Quality Assurance for Embedded Linux Systems - The Good, the Bad, the Unexpected - Jan Altenberg, Open Source Automation Development Lab (OSADL) eG
Wednesday October 7, 2026 13:30 - 14:10 CEST
More than 20 years ago the idea of transforming Linux into a real-time operating system resulted in the birth of the PREEMPT_RT development. But how could the real-time properties of such a complex system be tested? Due to the complexity of modern operating systems, such as Linux, and due to the fact that modern processors operate in a performant but non-deterministic way, appropriate methods for evaluating the real-time behaviour of a given system had to be established: That's why the OSADL QA Farm was born. While the initial focus of the QA Farm was (and still is) the long-term evaluation of the real-time properties of Embedded Linux systems, 20 years of operation with more than 100 systems have also brought many other insights to light - expected and unexpected. This presentation provides an overview of the quality assurance methods used at the OSADL QA Farm, the insights gained from numerous long-term measurements and latest developments, such as the integration of Zephyr systems.
Speakers
avatar for Jan Altenberg

Jan Altenberg

Director R&D, Open Source Automation Development Lab (OSADL) eG
Jan Altenberg has more than 20 years of experience in developing and maintaining Embedded Linux systems. Since October 2021 Jan works as Senior Open Source Consultant and Embedded Systems Integrator at the Open Source Automation Development Lab (OSADL) eG and since 2024, he also serves... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

13:30 CEST

Journey of a Massive Internal Kernel Rework - Luca Ceresoli, Bootlin
Wednesday October 7, 2026 13:30 - 14:10 CEST
While changes to the internal kernel APIs and design are possible, that doesn't mean they are easy.

In preparation for a larger work to make the DRM subsystem support video output pipelines with hot-pluggable components, we have been working for the past two years to change the lifetime of `struct drm_bridge` in the DRM subsystem. This required changing the semantics of a dozen internal APIs and adaptations to more than 50 drivers.

This talk is not about the content of the changes but rather about the process to achieve it: the initial steps to find the best strategy, the continuation to convert all APIs, bugs introduced and reacting to them, working on lots of drivers without the chance to test them, dead ends encountered, tools used, the time required for the whole process, and the community interactions in the whole time span.

The focus will be on lessons learnt and which strategies worked better, and ultimately how to make a similar kind of massive conversion in the most efficient (and least frustrating!) way.
Speakers
avatar for Luca Ceresoli

Luca Ceresoli

Embedded Linux and Kernel engineer, Bootlin
Luca is an embedded Linux and kernel engineer at Bootlin, primarily working on device drivers and recently active mostly on DRM bridges to support hotplugging of non-discoverable devices.

He contributed several improvements the Linux kernel and other open source projects.

Luca... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

13:30 CEST

Off the Laptop, Into Production: An Open Source Stack for AI Agents on Kubernetes - Brian Hammons & Nirmal Mehta, Amazon Web Services
Wednesday October 7, 2026 13:30 - 14:10 CEST
AI agents are fast becoming how modern software gets built. But taking one from prototype to safe, production-grade operation is still genuinely challenging, and how they behave at scale remains largely uncharted. Agents are stochastic, so testing becomes continuous evaluation. They run code nobody wrote, so a shared kernel stops being a boundary you can trust. They decide their own network calls at runtime, so egress is no longer predictable. And they still need what any service needs: source control, CI/CD, observability, memory, and tool access.

This session walks the full lifecycle of running agents on Kubernetes, open source the whole way. The "outer loop" (build, deploy, trace, evaluate) runs on tools like GitLab, Argo, Langfuse, Milvus, and MCP gateways. The "inner loop" (isolated execution) runs on the kubernetes-sigs Agent Sandbox CRD, gVisor, and FQDN-aware egress via Cilium. We'll show what maps cleanly from the platform you run, what changes for agents, and the production gotchas no quickstart warns you about, drawn from building these in the open with teams running from a handful of developer sandboxes to the hundreds of thousands that frontier-scale RL spins up.
Speakers
avatar for Brian Hammons

Brian Hammons

Principal Solutions Architect, AWS
Brian Hammons is a Principal Architect at AWS, focused on Kubernetes-native AI agent development and platform engineering. He led the first AWS-backed contribution of the kubernetes-sigs Agent Sandbox CRD into the open source awslabs/ai-on-eks project. An Amazon EKS launch-team member... Read More →
avatar for Nirmal Mehta

Nirmal Mehta

World Wide Tech Leader - Containers, Amazon Web Services
Nirmal Mehta is the World Wide Tech Leader for Containers at AWS and a Principal Specialist SA in the Worldwide Application Modernization team. He is experienced in open source platform engineering, kubernetes, MLOps, agentic devops and executive org strategy. He has presented at... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
Forum Hall (Floor 2)
  Open AI & Data

14:25 CEST

Kata at Scale: The Hidden Cost of Running VMs Behind Every Container - Kavitha Daula & Ann Wallace, Edera
Wednesday October 7, 2026 14:25 - 15:05 CEST
There is a big difference between getting Kata Containers running in a proof of concept and operating a large multi-tenant Kata environment for years.

This talk is a practical, vendor-neutral look at what becomes hard after the demo works. Once every pod carries a lightweight VM lifecycle behind it, platform teams are no longer operating only Kubernetes. They are also operating guest kernels, guest images, VMMs, hypervisor behavior, virtio devices, runtime and agent version skew, and a second debugging surface under the container platform.

We will walk through production issues that show up at scale: guest kernel CVEs and regressions, host/guest kernel drift, CNI and tap-device networking, virtio-fs and storage durability semantics, fragmented observability, boot storms, vCPU oversubscription, memory accounting drift, NUMA behavior, GPU passthrough, VFIO/IOMMU lifecycle, upgrade matrices, and incident ownership.

This is not a criticism of Kata. Kata solves a real open source isolation problem. The goal is to help operators understand the operational work required to run VM-isolated containers safely and sustainably in production.
Speakers
avatar for Kavitha Daula

Kavitha Daula

VP of Engineering, Edera
Kavitha Daula is the VP of Engineering at Edera, where she leads the development of secure, high-performance container runtime technologies. Previously, she was Senior Director at GEICO, driving innovations in OS, containers, and language runtimes, including a custom Linux distro... Read More →
avatar for Ann Wallace

Ann Wallace

VP of Customer Experience, Edera
Ann Wallace is the VP of Customer Experience at Edera. Before Edera, she held leadership and architecture roles in security and cloud at Okta, Shopify, Google, and Nike. Ann speaks regularly at conferences on topics like compliance, container security, and using storytelling to make... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

14:25 CEST

Debugging Heisenbugs: The Nightmare of Every Embedded Engineer - Beleswar Prasad Padhi, Texas Instruments
Wednesday October 7, 2026 14:25 - 15:05 CEST
Defined as bugs which disappear or change behavior when observed, every embedded engineer has come across one at some point. Some classic examples include bugs that stop reproducing after adding printk() statements, introducing new variables, connecting a debugger or even simply recompiling the same source code. The root causes of Heisenbugs range all the way from race conditions, memory corruption, alignment issues, cache incoherency, incorrect linker configurations to even hardware bugs.

This talk walks through the debugging techniques which could be applied for debugging these Heisenbugs like static code analysis, memory analysis, diagnostic data collection, tracing and instrumentation, selective elimination of unrelated code paths, modifying assembly instructions at runtime; all without probing the observer’s effect. Beyond techniques, the talk aims to develop the intuition and thought process needed when confronting these bugs. The talk discusses how to distinguish between mere workarounds that mask the underlying issue vs actual fixes. Practical experiences in debugging real Heisenbugs will be shared along with their root causes, investigation approaches and the fixes.
Speakers
avatar for Beleswar Prasad Padhi

Beleswar Prasad Padhi

Senior Software Engineer at Texas Instruments, Texas Instruments
Beleswar is a Senior Software Engineer at Texas Instruments, actively working on Upstream Linux Kernel and U-Boot. His work mainly focuses on Remoteproc, RPMsg, Mailbox, Virtio subsystems, as well as boot-time optimizations. He was listed among the top contributors for Linux 6.18... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

14:25 CEST

SELinux in Embedded Linux: From Basics To Best Practices - Tobias Kaufmann, BMW Car IT
Wednesday October 7, 2026 14:25 - 15:05 CEST
Modern vehicles employ a highly integrated architecture with a relatively small number of powerful Electronic Control Units (ECUs). Many of these ECUs run Linux and present a sizable attack surface. To mitigate the resulting threats, SELinux offers an enhanced mechanism for enforcing the principle of least privilege.

Despite its strengths, SELinux remains complex and is not widely adopted. This talk offers a pragmatic introduction to SELinux, with concrete guidance you can apply to your embedded Linux project.

This session will cover basic permissions and type enforcement in SELinux, including which permissions are required for an application start-up. It will introduce the reference policy and guide you through writing a first “hello-world” policy. We will also discuss SELinux in the context of Yocto. Finally, we will conclude with lessons learned from our experience in large-scale projects.
Speakers
avatar for Tobias Kaufmann

Tobias Kaufmann

Security Architect for Head-Units, BMW Car IT
Tobias holds an M.Sc. in Electrical Engineering. After several years working on smart grid projects, he joined BMW Car IT in 2018. He currently serves as the Security Architect for head units at BMW Car IT.
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

14:25 CEST

You're Measuring Memory Wrong: The Right Ways With DAMON - SeongJae (SJ) Park, Crusoe
Wednesday October 7, 2026 14:25 - 15:05 CEST
Memory efficiency problems are notoriously hard to see. DAMON was built to change that — but many users collect data incorrectly, visualize it poorly, and walk away with wrong conclusions. The tool gets blamed. The real problem goes unfixed.

This talk shows you the right ways to do it.

We cover data collection first: configuring sampling and aggregation parameters, the tradeoffs, and setup mistakes that corrupt your data before analysis begins.

We then walk through the visualization features in `damo` — heatmaps of access frequency across time and address space, working set size plots, and more. There is no single right visualization; we cover when to use each and how to read what it shows.

We also highlight mistakes that lead users astray: misreading sampling artifacts as real patterns, choosing granularities that hide behavior, observing too briefly to catch periodic patterns, and more. For each, we show what misleading output looks like and how to fix it.

By the end, you will know how to collect trustworthy DAMON data, pick the right visualization, and tell when your results are real versus when your setup is lying to you.
Speakers
avatar for SeongJae Park

SeongJae Park

Staff SW Engineer, Crusoe
SeongJae (SJ) Park is a Linux kernel programmer who maintains the data access monitoring framework of the Linux kernel called DAMON (https://damonitor.github.io/). His interests include operating system kernels, parallel computing, and memory management. He is working on Meta's kernel... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Panorama Hall (Floor 1)
  Linux

14:25 CEST

Derivative Work and Modification(s): Where Copyright and Open Source Software Collide - Yet Again - Eleftheria Stefanaki, Nokia Technologies & Jimmy Ahlberg, Ericsson
Wednesday October 7, 2026 14:25 - 15:05 CEST
Talking points:

• Copyright law as a (wrong) playing field for open source software
• Working with what we have – the curious case of modifications
• Modification of software – what does this mean practically (e.g., bug fix, alteration of existing code, new code)
• Derivative work and modification in FOSS licensing
• Practical cases and “risks”
o Products
o M&As


Abstract:
There are many legal concepts that create havoc in the open source world, but only a few are as “scary” as the concept of modification and derivative work. Copyright law concept are challenging to adopt in the software context. The ambiguity of the legislation as well as the case law in many jurisdictions, such as the US and many EU countries and institutes, is proof enough that this is a convoluted topic, and not just in theory. The practical impact of derivative works and modifications runs through the entirety of the open source compliance process. In this session, we will attempt to demystify the aforementioned concepts and possibly open up more questions for discussion.
Speakers
avatar for Eleftheria Stefanaki

Eleftheria Stefanaki

FOSS Legal Counsel, Nokia Technologies
I am a lawyer from Greece, specialized in technology and passionate about open source. I have started my 'open source journey' in Ericsson, assisting and participating in the activities and day-to-day of the OSPO since 2022. Currently, I am the FOSS Legal Counsel for Nokia Technologies... Read More →
avatar for Jimmy Ahlberg

Jimmy Ahlberg

Expert & Senior Legal Counsel, Ericsson
Currently Mr Ahlberg is the Director of Open Source Policy with the Ericsson OSPO. Prior to the inception of the Ericsson OSPO he worked in different roles with various aspects of Open Source in the Ericsson organization, This included consumption of and contribution to Open Source... Read More →
Wednesday October 7, 2026 14:25 - 15:05 CEST
Terrace 2A (Floor 2)
  Open Source 101

14:25 CEST

Practical End-to-End Traceability for Zephyr’s Path To Safety Certification - Tobias Kästner & Andreas Kurz, inovex GmbH
Wednesday October 7, 2026 14:25 - 15:05 CEST
As part of the ongoing effort to achieve IEC 61508 certification, Zephyr's requirements capture process is underway. Yet there is still no clear picture of how these requirements trace to the tests that verify them or the code that implements them. Safety evidence is largely documented evidence, so the primary concern is generating auditable documents: requirement and test specifications, test reports, and traceability matrices.
The challenge is collecting this evidence in a community-compatible way — low-friction processes and tooling that developers and maintainers will accept.

This talk proposes a pipeline built on Zephyr's existing documentation tools (Doxygen/Sphinx) to extract the needed information from annotated source and tests, then trace it back against requirements into an end-to-end chain.
Two demos are shown: a minimal working example against Zephyr itself, and a self-contained pipeline for a Zephyr module the authors maintain. Required process adaptations and guidelines are explained. The work is an open proposal for discussion; once agreed, it gives the community a scalable foundation to advance safety efforts, with concrete tasks contributors can pick up.
Speakers
avatar for Tobias Kästner

Tobias Kästner

Safety Architect, Zephyr Project, inovex GmbH
A physicist by training, Tobias Kaestner has long been fascinated by where the physical and digital worlds meet. He began as a software team lead in a medical device start-up and has since spent 15+ years in the industry. As a solution architect for Medical IoT at inovex GmbH he helps... Read More →
avatar for Andreas Kurz

Andreas Kurz

Senior Embedded Software Engineer, inovex GmbH
Senior Embedded Software Engineer doing safety critical software for e.g., medical.
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

14:45 CEST

Strategic Approach To Demonstrating the Value of OSS Efforts - Dawn Foster, Fast Wonder
Wednesday October 7, 2026 14:45 - 15:05 CEST
We’ve probably all had leadership question the value of our OSS efforts. It can be difficult to frame the value in ways that resonate with stakeholders and clearly articulate the benefits gained through continued OSS contributions. Taking a strategic approach that connects the OSS work with the broader goals and objectives of the organization can demonstrate the value of this work so that the organization can continue to allocate resources to the OSPO or other OSS teams.

Using examples from my decades of experience in OSS, this talk will provide details about how to demonstrate value by focusing on how your OSS work helps the organization achieve their strategies and goals. Every organization has unique needs and goals based on what they are trying to achieve, so there is no “one size fits all” way of demonstrating value, but aligning your OSS strategy with your organization’s goals and focusing on the most strategic projects can help show the value of your efforts. This talk will help you reason about how OSS efforts allow your organization to achieve its goals along with framing and communicating that value in ways that resonate with leadership, funders, and stakeholders.
Speakers
avatar for Dawn Foster

Dawn Foster

Open Source Strategy Consultant, Fast Wonder
Dr. Dawn Foster is an OSS strategy consultant. She is also on the board of CHAOSS, OpenUK, and the Software Stewardship Lab. She was previously a co-chair of the CNCF Contributor Strategy TAG. She has 20+ years of experience at companies like VMware and Intel with expertise in strategy... Read More →
Wednesday October 7, 2026 14:45 - 15:05 CEST
Conference Hall (Floor 4)

15:35 CEST

Embracing Service-Oriented Connectivity Across OpenStack and Kubernetes - Mitsuhiro Tanino & Rei Shimizu, LY Corporation
Wednesday October 7, 2026 15:35 - 16:15 CEST
Modern infrastructure platforms increasingly combine OpenStack VMs, Kubernetes Pods, managed platforms, and external services, yet connectivity models often remain fragmented across runtime boundaries and tied to infrastructure-specific constructs such as IP-based ACLs.

This session presents how LY Corporation introduced a service-oriented connectivity model across OpenStack and Kubernetes environments. Rather than extending Kubernetes-native service mesh concepts to VM workloads, we introduced a runtime-independent service abstraction where connectivity and policy are defined consistently across VMs, Pods, PaaS instances, and external resources.

Under this model, services become the primary unit for service discovery, authentication and authorization, ACL management, and traffic control, independent of the underlying runtime or network topology. A sidecar proxy enforces service-to-service policy consistently across both OpenStack-managed VMs and Kubernetes workloads.

We cover the architectural design, OpenStack and Kubernetes integration for service registration and identity propagation, and lessons from migrating production workloads at scale.
Speakers
avatar for Mitsuhiro Tanino

Mitsuhiro Tanino

Senior Software Engineer, LY Corporation
Mitsuhiro Tanino is a senior software engineer who has been working for LY Corporation since 2019. He has experience to contribute OpenStack Cinder project for several years and also contributed Kubernetes sig-storage for several years. His current working area is operating hyper-scale... Read More →
avatar for Rei Shimizu

Rei Shimizu

Senior Software Engineer, LY Corporation
Rei Shimizu is working as Software Engineer for Private Cloud in LY Corporation.
Wednesday October 7, 2026 15:35 - 16:15 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

15:35 CEST

OP-TEE Footguns: Lessons From the Integration Trenches - Richard Weinberger, sigma star gmbh
Wednesday October 7, 2026 15:35 - 16:15 CEST
OP-TEE is a widely adopted Trusted Execution Environment (TEE) commonly used on ARM-based SoCs. While it is highly portable and often features strong vendor support, achieving a functionally working setup is only half the battle. There are surprisingly many pitfalls where a developer can successfully integrate OP-TEE, only to introduce subtle security misconfigurations that silently undermine the entire system's threat model.

In this talk, Richard will outline the hidden security traps and integration challenges he has encountered over the past few years on custom hardware. Attendees will learn which footguns to watch out for, ultimately saving them the countless hours Richard spent debugging these exact issues.
Speakers
avatar for Richard Weinberger

Richard Weinberger

CTO, sigma star gmbh
Richard Weinberger is co-founder of sigma star gmbh where he offers consulting services around Linux and IT security. Upstream he maintains various subsystems of the Linux kernel such as UserModeLinux and UBIFS. Beside of low level and security aspects of computers he enjoys growing... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

16:30 CEST

Demystifying Board Farms: Build a Mini Desktop Board Farm With Standard Tools and Hardware - Francesco Cervigni, Neoncomputing
Wednesday October 7, 2026 16:30 - 16:50 CEST
Large companies have built board farms for decades, providing both solid automated QA capabilities and short developer feedback loops.
LAVA and Labgrid have emerged as standard tools.

Although, today most small companies have not adopted those tools and practices, and too many developers spend time, constantly, on hardware set-up.
Either standard tools are unknown, or two myths circulate: that LAVA is just for large-scale scenarios, and Labgrid is complex to set up.
While at this, many create, instead, new in-house tools (wheel reinvention).

This talk aims to reverse this, by showing two portable mini board farms: one using LAVA, and one using Labgrid.
These two examples will act as comparison and demystification of these standard open-source tools, while showing common concepts.
Both examples share a common open-source CI/CD (GitLab), and the physical layout: a portable 10-inch rack, which can sit on a desk (introduced only in recent years).
Network, serial, power and cable management is done assembling off-the-shelf hardware.

Board farm adoption, at any scale, can help teams to increase ergonomics, comfort, and determinism, for stress-free development, CI, and test workflows.
Speakers
avatar for Francesco Cervigni

Francesco Cervigni

Independent Embedded CI/CD & Test Automation Specialist, Neoncomputing
Francesco Cervigni is an embedded software consultant with 14 years in Embedded Systems and Industrial IoT.
He helps companies from different sectors improve development experience focusing on reproducible build systems, CI/CD, automated testing on emulated and real hardware, met... Read More →
Wednesday October 7, 2026 16:30 - 16:50 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

16:30 CEST

Challenges Using an IEC Standard in Open Source - Nico Rikken, Alliander
Wednesday October 7, 2026 16:30 - 16:50 CEST
The electrical energy sector can largely be defined by the IEC standards that ensure compatibility and conformity. In this way IEC standards serve our industry very well, both in the physical and digital realm. Although the open source projects and IEC share a similar goal of compatibility and innovation, in practice they conflict with one another. This has to do with the way in which IEC standards are created, licensed and distributed.

In this presentation Nico will share his experiences in dealing with IEC licenses from the perspective of an OSPO supporting open source development. This will highlight various issues, big and small, that hinder open source development. The presentation will also gather insights from the standards group in the LF Energy community group. By presenting this constructive assessment Nico hopes to foster discussion and encourage improvement of the situation. Much of the content will carry over to other closed standards.
Speakers
avatar for Nico Rikken

Nico Rikken

Solution Architect, OSPO member, Alliander
Nico Rikken has a track record in maximizing the potential of Free and Open Source Software in the energy sector and in the Netherlands. As Open Source Ambassador at grid operator Alliander he helps make open source project participation successful and ensure control over the company... Read More →
Wednesday October 7, 2026 16:30 - 16:50 CEST
Chamber Hall (Floor 3)

16:30 CEST

Life Finds a Way , Sandboxed Agents, Observable Verdicts - Henrik Rexed, Dynatrace
Wednesday October 7, 2026 16:30 - 17:10 CEST
"Life, uh, finds a way." So do AI agents. Give one a tool, and a prompt-injected README will teach it to spawn a shell. CVE-2025-59528 (CVSS 10.0) and Google's Antigravity sandbox escape proved the same thing twice in 2025: the agent didn't break the sandbox , either the sandbox was missing, or the electric fence was in the wrong place.
This talk is a tour of Jurassic Park, rebuilt on Kubernetes. The paddock walls are containers. The electric fence is kubernetes-sigs/agent-sandbox, swapping gVisor for Kata Containers under the same CRD. The control room is OpenTelemetry where invoke_agent, execute_tool, and tool.policy_check spans turn every isolation verdict into queryable telemetry.
We will deploy OpenClaw ,an open-source AI agent gateway inside a Sandbox resource on Cluster API, watch the agent attempt three different escapes, and ship policy decisions as first-class spans. Help shape OpenTelemetry semconv #3583 before the park opens.
Speakers
avatar for Henrik Rexed

Henrik Rexed

Cloud Native Advocate, Dynatrace
Henrik is a Cloud Native Advocate at Dynatrace, the leading Observability platform. Prior to Dynatrace, Henrik has worked more than 15 years, as Performance Engineer. Henrik Rexed Is Also one of the Organizer of the conferences named WOPR, KCD Austria and the owner of the Youtube... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

16:30 CEST

Securing Embedded Linux Buildsystems Against Supply Chain Attacks - Alejandro Enedino Hernandez Samaniego, Microsoft Corporation
Wednesday October 7, 2026 16:30 - 17:10 CEST
Embedded Linux build systems such as The Yocto Project and Buildroot rely on reused build artifacts and external inputs, while these represent an improvement in build time for subsequent builds, also create opportunities for supply chain attacks that are difficult to detect.

This talk demonstrates practical attack vectors, showing how intermediate object files produced by make in Buildroot can be modified during the build to introduce malicious behavior without changing source code, and also demonstrate its possible to poison Yocto Project shared state (sstate) cache artifacts to propagate compromised binaries.
These attacks are validated end-to-end by executing poisoned binaries in the final Linux image under QEMU.

I will then present mitigation strategies, focusing on signing and verification of the sstate artifacts and improved control over build inputs. The discussion covers integration approaches and tradeoffs between security, performance, and developer workflows.

Attendees will gain practical insight into real-world risks when creating customized Linux distributions and concrete steps to improve their build system's security.
Speakers
avatar for Alejandro Enedino Hernandez Samaniego

Alejandro Enedino Hernandez Samaniego

Principal Software Engineer, Microsoft Corporation
Alejandro is an Principal Software Engineer at Microsoft, he works as a Yocto Project developer in the Linux Systems Group, designing software to improve system's developers experience when building customized embedded Linux distributions and applications, currently maintains the... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

16:50 CEST

Cukinia: A Lightweight Test Framework for Embedded Linux Systems - Kévin L'hôpital, Savoir-Faire Linux
Wednesday October 7, 2026 16:50 - 17:10 CEST
Embedded Linux projects already have powerful testing frameworks, but they often come with requirements about infrastructure, dependencies, or target environments. In many firmware projects, developers need something simpler: a lightweight way to run system-level validation directly on the device, with minimal setup and no additional runtime requirements.

Cukinia is an open-source test framework designed to make embedded Linux validation simple and accessible. Requiring only a POSIX shell, Cukinia can run directly on target devices even in production and integrates quickly into existing CI/CD workflows. With a collection of predefined test statements, developers can quickly create tests for system configuration, hardware interfaces, services, networking, storage, and more.
Speakers
avatar for kévin L'hôpital

kévin L'hôpital

Embedded engineer, Savoir-faire Linux
Kevin is an embedded engineer working in Savoir-faire Linux in Rennes. He is mainly working on creating Yocto based distribution, kernel debugging, secure-boot implementation and creating media applications. He is the main contributor of the GEISA conformance test application.
Wednesday October 7, 2026 16:50 - 17:10 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

16:50 CEST

AI Everywhere, Trust Nowhere: Navigating Open Source Security, "AI Slop," and the New Attack Surface - Adrianne Marcum, Linux Foundation & Christopher Robinson, OpenSSF
Wednesday October 7, 2026 16:50 - 17:10 CEST
Artificial Intelligence is fundamentally changing the open-source ecosystem, promising unparalleled development velocity. However, this speed scales risk simultaneously. Open-source software (OSS) maintainers—already heavily resource-constrained and unevenly funded—are finding themselves caught in a crossfire of AI-driven complications.

This session, led by the Open Source Security Foundation (OpenSSF), breaks down the three critical security paradigm shifts introduced by AI:

Securely Using AI to Build Software: How insecure-by-default code suggestions, copied risks, and hallucinated packages compromise codebase integrity.

Using AI to Secure Software: The reality of how upstream maintainers are overwhelmed by a massive influx of automated vulnerability reports generated by AI bug hunters.
AI as an Attack Surface: Moving past traditional DevSecOps to address MLSecOps pipeline vulnerabilities, including data poisoning, model theft, and container security across the machine learning lifecycle.

Attendees will walk away with an understanding of OpenSSF’s recommended approach designed to shift the focus from cheap "findings" to valuable, validated "fixes".
Speakers
avatar for Christopher

Christopher "CRob" Robinson

Security Lorax, Openssf
Christopher Robinson (aka CRob) is the Chief Security Architect for the Open Source Security Foundation. With over 25 years of Enterprise-class engineering, architectural, operational and leadership experience, CRob has worked at several Fortune 500 companies with experience in the... Read More →
avatar for Adrianne Marcum

Adrianne Marcum

OpenSSF Chief of Staff, Linux Foundation
Adrianne Marcum brings extensive experience in engineering, product, project, and program management to her role as Chief of Staff at OpenSSF. With a career that began in mechanical engineering, she has since worked across a multitude of industries, including defense, heavy machinery... Read More →
Wednesday October 7, 2026 16:50 - 17:10 CEST
Conference Hall (Floor 4)

17:25 CEST

Teaching BIND9 New Tricks: A Rust Operator for Declarative DNS on Kubernetes - Erick Bourgeois, RBC Capital Markets
Wednesday October 7, 2026 17:25 - 18:05 CEST
Authoritative DNS is one of the last holdouts against declarative, GitOps-style management. BIND9 still serves a huge share of the world's zone data, but it's driven imperatively: hand-edited zone files, rndc reload, and brittle automation glued on top. bindy is an open-source Kubernetes operator, written in Rust on kube-rs, that closes the gap. It models zones and records as custom resources and continuously reconciles a running BIND9 against them, leaving no orphaned zone file behind.
This talk walks through the architecture of bindy and its sibling projects, bindcar, a sidecar that exposes RNDC operations over a typed API, and hornet, a Rust zone-file parser, then digs into the operator-engineering lessons that transfer to anyone writing controllers in Rust. We'll cover splitting selection from synchronization to avoid reconcile loops, using the reflector and store, modeling ownership and status conditions, and where Rust and kube-rs paid off versus Go's controller-runtime.
Attendees leave with a concrete, reusable pattern for wrapping any stateful, non-cloud-native daemon in a declarative Kubernetes API, and three open-source projects they can adopt, fork, or contribute to.
Speakers
avatar for Erick Bourgeois

Erick Bourgeois

Head of Kubernetes Platform Engineering, Director, RBC Capital Markets
Erick Bourgeois is a platform engineering specialist focused on Kubernetes operators and infrastructure automation for regulated industries. Creator of Bindy, an open-source DNS controller built in Rust, Erick brings expertise in cloud-native architecture, compliance frameworks (SOX... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

17:25 CEST

Labgrid & Board Farming BOF - Rouven Czerwinski, Linaro
Wednesday October 7, 2026 17:25 - 18:05 CEST
Labgrid is a tool for both board farming and embedded systems testing. This session will include an overview of current developments and also provides a gathering for people interested or already using Labgrid.
Speakers
avatar for Rouven Czerwinski

Rouven Czerwinski

Software Engineer, Linaro
At first building the labgrid hardware access layer, rouven nowadays works on security and multimedia solutions for embedded devices.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

17:25 CEST

Secure by Default: Building Locked-Down Embedded Linux Devices With Systemd - Mohammad Abdoli, Segula Technologies
Wednesday October 7, 2026 17:25 - 18:05 CEST
Modern embedded Linux devices must balance security, maintainability, and operational flexibility. While the Linux kernel provides powerful security primitives such as namespaces, cgroups, eBPF, and dm-verity, integrating them consistently across products remains a challenge.

This session explores how systemd has evolved beyond a traditional init system into a security and lifecycle management framework for embedded Linux platforms.

Using practical examples, we will examine how systemd Portable Services enable immutable application deployment, how dm-verity protects software integrity from storage to execution, how systemd leverages eBPF for kernel-enforced sandboxing and policy enforcement, and how cgroup-based resource management can contain both faults and attacks.

Attendees will learn how these mechanisms interact, how they can be integrated into Yocto-based systems, and how systemd can act as the orchestration layer between applications and modern Linux kernel security features.

Rather than presenting isolated hardening techniques, this session introduces a practical architecture for designing maintainable, resilient, and secure-by-default embedded Linux products.
Speakers
avatar for Mohammad Abdoli

Mohammad Abdoli

Senior Embedded systems consultant, Segula technologies
Mohammad Abdoli (mominux) is an Embedded Systems Engineer specializing in the safety and security of embedded platforms, Linux system architecture, and open-source technologies. His interests include Linux security, systemd, virtualization, and secure-by-design embedded systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

17:25 CEST

ZBus for Linux - Peter Fecher, PHYTEC Messtechnik GmbH
Wednesday October 7, 2026 17:25 - 18:05 CEST
ZBus (Zephyr Bus) is a thread-to-thread message and data exchange protocol based on a bus topology. Since Zephyr v4.4.0, it also supports IPC between multiple Zephyr domains running on different CPU cores.

While this fits well for homogeneous multicore systems, heterogeneous SoCs typically run different operating systems on different cores. A common ARM-based setup uses Linux on a Cortex-A core for high-level tasks and Zephyr on a Cortex-M core for real-time workloads.

Communication between these environments requires data exchange across both cores and operating systems. Currently, the practical approach is to transfer raw bytes through RPMsg channels, requiring developers to implement custom protocols on both sides.

ZBus for Linux bridges this gap by connecting Linux applications to a remote ZBus instance, enabling structured communication across heterogeneous systems.

This talk presents the implementation of an early prototype, the challenges encountered, and the overall architecture of ZBus for Linux.
Speakers
avatar for Peter Fecher

Peter Fecher

Embedded Engineer, PHYTEC Messtechnik GmbH
Peter Fecher just finished his bachelors degree in Computer Engineering. He has been working at PHYTEC for 3 years now, specialising on microcontrollers and IoT systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

17:25 CEST

Nine Seconds To Production: Security Governance for AI Agents - Jasdeep Singh Bhalla, GoDaddy
Wednesday October 7, 2026 17:25 - 18:05 CEST
On April 24, 2026, an AI coding agent deleted a company's entire production database in nine seconds. Every customer record, every reservation, and every backup vanished. The system prompt explicitly told the agent never to execute destructive commands. It did it anyway.

It was a chain of architectural failures: an agent improvising instead of stopping, overprivileged credentials, no human approval for high-risk actions, and backups inside the same blast radius.

This session recreates the incident and rebuilds the security architecture live. You'll see how OPA enforces policy before tools execute, Falco detects suspicious runtime behavior, and OpenTelemetry captures structured reasoning traces for compliance-grade audit logs.

We'll implement six defensive layers: pre-execution policy enforcement, runtime behavioral monitoring, structured audit logging, least-privilege execution roles, infrastructure deletion protection, and recovery systems isolated outside the agent trust boundary.

Prompts are guidance. Infrastructure is enforcement. You'll leave with a vendor-neutral security architecture for deploying AI agents safely across any framework or LLM provider.
Speakers
avatar for Jasdeep Singh Bhalla

Jasdeep Singh Bhalla

Senior Software Engineer, GoDaddy
Jasdeep Singh Bhalla is a Senior Software Engineer at GoDaddy, specializing in AI security governance, cloud native infrastructure, and distributed systems. With over a decade of experience across GoDaddy, Electronic Arts, Dialpad, and Yahoo, he has architected production platforms... Read More →
Wednesday October 7, 2026 17:25 - 18:05 CEST
Forum Hall (Floor 2)
  Open AI & Data

17:25 CEST

Where Zephyr Fits in Space Computer Architecture - Yasushi Shoji, Space Cubics Inc.
Wednesday October 7, 2026 17:25 - 18:05 CEST
Using Zephyr in space is not only a question of choosing an RTOS. A space computer is a system architecture: boot firmware, supervisor logic, watchdogs, safe mode, recovery paths, update policy, hardware monitoring, FPGA or SoC configuration, and the boundary between platform software and mission-specific applications all matter.

This talk looks at Zephyr from that system-architecture point of view. Based on Space Cubics’ OBC development experience and recent Space Grade Linux discussions, it explores where Zephyr can fit in future space systems: mission RTOS, payload-controller OS, supervisor/control-plane OS, or companion to Linux. Space already has credible RTOS options, but Zephyr can bring value if the ecosystem develops a clear architectural story around boot, recovery, observability, hardware control, and responsibility boundaries.

Attendees will leave with a practical checklist for evaluating Zephyr’s role in a space computer: what Zephyr should control, what should remain outside it, what must be recoverable after launch, and how to structure boot, update, monitoring, isolation, and fault-handling responsibilities.
Speakers
avatar for Yasushi SHOJI

Yasushi SHOJI

Co-Founder and CEO, Space Cubics Inc.
Yasushi SHOJI is a Linux kernel and embedded systems developer with over 20 years of experience. Founder of Space Cubics, he develops spacecraft using Zephyr RTOS and contributes to open source projects for high-reliability systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

17:45 CEST

Open Quantum Safe: Post-Quantum Software Research in the Era of the First PQC Standards - Rodrigo Martín, Indra
Wednesday October 7, 2026 17:45 - 18:05 CEST
The Open Quantum Safe (OQS) project was founded with the mission of supporting the transition to Post-Quantum Cryptography. On its way, it became one of the most important open-source post-quantum cryptographic organizations. The subsequent publication and adoption of the first PQ standards by major cryptographic projects helps the cryptographic community in the adoption of this required type of cryptography. The mission of the OQS organization remains being at the forefront of PQC research. This talk provides an update of what these efforts look like in the era of the first PQ standards. It will include lessons learned along the way, challenges encountered when handling a PQ Open Source project and future directions, such as: 

1) Addition of new PQ schemes being considered for standardization or relevant to the PQ cryptographic community (e.g. NIST on-ramp signature schemes)

2) Inclusion of new functionalities like: new hybrids or constant-time analysis.
Speakers
avatar for Rodrigo Martín

Rodrigo Martín

Senior Cryptography Researcher, Indra
Rodrigo is a Senior Cryptography Researcher at Indra. He is also an Industrial PhD candidate, focused on the algebraic aspects of PQC, as well as PQC migrations. His work experience is the research, development and secure deployment of cryptography in real applications and protocols... Read More →
Wednesday October 7, 2026 17:45 - 18:05 CEST
Chamber Hall (Floor 3)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -