Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



arrow_back View All Dates
Friday, October 9
 

08:00 CEST

Hacker Space
Friday October 9, 2026 08:00 - 16:50 CEST
Discover a space, where you can collaborate, create, and explore new ideas with fellow attendees. Whether you’re here to learn or build, our space is open for everyone to enjoy throughout the conference!


Friday October 9, 2026 08:00 - 16:50 CEST
Terrace 2B (Floor 2)

08:00 CEST

08:00 CEST

Zen Zone
Friday October 9, 2026 08:00 - 16:50 CEST
All attendees may feel free to use the Zen Zone as needed. This is a quiet space for sensory relaxation, meditation, and worship. It is not to be used for conversations or as a workspace.

Friday October 9, 2026 08:00 - 16:50 CEST
TBA

08:00 CEST

Solutions Showcase
Friday October 9, 2026 08:00 - 17:20 CEST
The Solutions Showcase is your hub to network, explore sponsor exhibits, and learn how these organizations are shaping the future of the ecosystem.

**In order to facilitate networking and business relationships at the event, you may choose to visit a third party’s booth or access sponsored content. You are never required to visit third party booths or to access sponsored content. When visiting a booth or participating in sponsored activities, the third party will receive some of your registration data. This data includes your first name, last name, title, company, address, email, standard demographics questions (i.e. job function, industry), and details about the sponsored content or resources you interacted with. If you choose to interact with a booth or access sponsored content, you are explicitly consenting to receipt and use of such data by the third-party recipients, which will be subject to their own privacy policies.**
Friday October 9, 2026 08:00 - 17:20 CEST
Solutions Showcase, Floor 2 & 3 Foyers

09:00 CEST

Welcome Back - Thierry Carrez, General Manager, OIF & LF Europe
Friday October 9, 2026 09:00 - 09:05 CEST

Speakers
avatar for Thierry Carrez

Thierry Carrez

General Manager, OIF & LF Europe

Friday October 9, 2026 09:00 - 09:05 CEST
Congress Hall (Floor 2)

09:05 CEST

Keynote to be Announced
Friday October 9, 2026 09:05 - 09:15 CEST

Friday October 9, 2026 09:05 - 09:15 CEST

09:05 CEST

Buildroot LTS in the CRA Era: 18 Months of Keeping a 3-Year Branch Secure - Thomas Perale & Titouan Christophe, Mind OSS NV
Friday October 9, 2026 09:05 - 09:45 CEST
The Buildroot Long-Term Support (LTS) sponsorship initiative was launched in March 2025. Its goal is to help Buildroot users maintain stable and secure products over longer periods, particularly in light of upcoming security regulations such as the Cyber Resilience Act (CRA).

We transitioned from a day-to-day maintenance workflow to a more systematic, weekly peer-reviewed approach. After more than a year and a half of maintaining the Buildroot LTS branch, we have encountered both successes and unforeseen challenges. We had to develop custom tooling to deal with a growing number of vulnerability reports, all while preserving stability for the releases.

This talk covers:

* How we tackle the maintenance task as a distributed team.
* Maintenance challenges with the constant flow of CVEs.
* Keeping the package metadata up-to-date and improving the vulnerability
monitoring across branches.
* What worked and what didn't.
* How we plan to evolve and improve for the future.
Speakers
avatar for Thomas Perale

Thomas Perale

Embedded Software Engineer, Mind OSS NV
Thomas Perale is a Belgian embedded software engineer working for Mind with a strong passion for free software development and embedded systems.

He is involved in maintaining Buildroot stable and LTS releases.
avatar for Titouan Christophe

Titouan Christophe

Embedded Software Engineer, Mind OSS NV
Titouan is an embedded and backend developer. He has worked in remote railway vehicle monitoring and automated visual quality control for the manufacturing industry.

Titouan is now working at Mind OSS, helping customers with Zephyr, embedded Linux and open source in general. He is the author of Zephyr's USB-MIDI and Network MIDI 2.0 stacks, and co-steward of the Buildroot LTS initiative... Read More →
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

09:05 CEST

The Upstream Way: Current State of I.MX SoCs in the Linux Kernel - Daniel Baluta, NXP Semiconductors
Friday October 9, 2026 09:05 - 09:45 CEST
NXP has historically maintained a large number of i.MX-specific patches in downstream Linux trees, increasing maintenance effort and limiting community adoption.

This talk presents NXP's updated upstreaming strategy and the progress made across i.MX SoCs. We will review the current upstream status of key drivers, lessons learned from recent upstreaming efforts and the processes introduced to improve patch quality and acceptance rates.

We will also cover NXP's efforts to strengthen community engagement, work on testing infrastructure and plans for the remaining internal patches.
Speakers
avatar for Daniel Baluta

Daniel Baluta

Software Engineer, NXP Semiconductors
Daniel works at NXP in Romania hacking on Linux kernel audio drivers for i.MX boards. He is a teaching assistant for Operating System Internals class at University POLITEHNICA in Bucharest and very passionate about helping newcomers to the Linux kernel world while being a mentor for... Read More →
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

09:05 CEST

XDP & XSK Support From a Linux Driver Standpoint - Théo Lebrun, Bootlin
Friday October 9, 2026 09:05 - 09:45 CEST
XDP (eXpress Data Path) is about running eBPF programs on network packets as early as possible. The goal of such an approach is performance: we minimise operating system networking stack overhead by letting the user decide which packets should reach it.

XSK is an extension to XDP allowing zero-copy redirect from the Ethernet driver directly to userspace processes. This approach approximates kernel-bypass solutions while remaining well integrated into the Linux networking stack for less critical traffic.

Both bring benefits but require adaptations on an Ethernet MAC driver standpoint; we'll dig into those. Quite some ground will be covered:
- allocators, their allocation patterns and memory layout,
- networking subsystem callbacks to be implemented,
- scheduling logic at runtime,
- performance numbers,
- etc.

Experience has been acquired through the upstreaming process of XDP & XSK support to the MACB/GEM controller driver, after having added Mobileye EyeQ5 support to the same driver.

References:
https://en.wikipedia.org/wiki/Express_Data_Path
https://ebpf.io/
https://www.kernel.org/doc/html/latest/networking/af_xdp.html
Speakers
avatar for Théo Lebrun

Théo Lebrun

Embedded Linux engineer & trainer at Bootlin, Bootlin
Théo joined Bootlin in 2022, studying the potential applications for the PipeWire ecosystem to embedded topics. He then went onto Linux kernel work: deep suspend-to-RAM support for a TI automotive SoC, upstreaming of base platform and Ethernet controller support for Mobileye hardware... Read More →
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

09:05 CEST

Clocks in Zephyr: A Practical Guide for BSP Developers (Lesson Learned From a Real Porting) - Martin Hoff, Silicon Laboratories
Friday October 9, 2026 09:05 - 09:45 CEST
Clocks are easy to ignore until your first Zephyr BSP port — when UART, SPI, or DMA suddenly depend on device tree properties you have never touched.
This beginner-friendly talk explains how clocks work in Zephyr today: clocks as phandle-arrays (like pwms and gpios), the meaning of #clock-cells, and how DT macros connect DTS to driver code. We separate three everyday questions: enabling a clock, selecting its source, and reading its rate — mapped to clock_control_on(), clock_control_configure(), and get_rate().
We then cover practical porting decisions any SoC author faces: what to describe in device tree at boot, what to leave to runtime (for example power management), and common mistakes — wrong cells, gates versus muxes and over-modelling hardware in DT.
Finally, we look at where Zephyr is heading: RFCs for a Clock Management Subsystem propose richer clock trees and predefined clock states, closer to how silicon is wired. You will leave with a reusable mental model for today’s APIs and a map of tomorrow’s direction.
Audience: developers new to Zephyr, BSP porters, and device tree authors. No prior clock-driver experience required.
Speakers
avatar for Martin Hoff

Martin Hoff

Software System Engineer, Silicon Laboratories
Four years of Zephyr experience, including two at Silicon Laboratories co-maintaining upstream support for SiWx91x and EFR32 SoCs. My work spans BSP porting, device tree, and driver development across Silicon Labs platforms.
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

09:05 CEST

From Zero Hardware To Production: High-Performance Sensors With Zephyr - Jan Germer, Fluke Deutschland GmbH
Friday October 9, 2026 09:05 - 09:45 CEST
This talk shares practical lessons learned from building multi-platform sensor firmware on Zephyr RTOS for industrial alignment tools. Zephyr enabled our team to deliver a high-quality solution despite an extremely tight project schedule. Early prototyping along with Zephyr’s native simulator (native_sim) enables firmware development and testing long before first PCBs are available. A modular architecture based on message queues and the Kconfig system allows for independent, testable components.
Finally, we dive into the hardware-facing challenges we encountered and solved: deterministic event handling under tight timing constraints and zero-CPU data acquisition using DMA-driven ADC pipelines.
Attendees will gain insights into structuring scalable Zephyr firmware, accelerating development without hardware, and building high-performance embedded systems with confidence.
Speakers
avatar for Jan Germer

Jan Germer

Senior Development Engineer, Fluke Deutschland GmbH
Jan Germer is a Senior Development Engineer at Fluke Deutschland GmbH, working on solutions for industrial sensing applications. After completing his PhD in Physics, he moved into industry, where he has worked across R&D, software, and firmware development. His focus areas include... Read More →
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

09:15 CEST

Keynote: Open Source in the Era of Agents - Ryan Waite, Director, Open Source Ecosystems and Incubations, Microsoft
Friday October 9, 2026 09:15 - 09:25 CEST
The era of agentic AI is here, and open source is building the infrastructure to make these innovations possible. We'll highlight how cross-industry collaboration on today's AI-native stack makes it possible to create, secure, and understand today's infrastructure. From hardware-aware scheduling to geo-specific workload isolation, learn how open source preserves local choices while opening up global opportunities

Speakers
avatar for Ryan Waite

Ryan Waite

Director, Open Source Ecosystems and Incubations, Microsoft
Ryan Waite leads open-source strategy for Microsoft as well as the Azure Open-Source Incubations team. He’s run engineering teams focused on high-performance computing, big data analytics, fraud detection, and mobile computing at Microsoft, Amazon Web Services, and Cray, the Supercomputing... Read More →
Friday October 9, 2026 09:15 - 09:25 CEST
Congress Hall (Floor 2)

09:25 CEST

Keynotes to be Announced
Friday October 9, 2026 09:25 - 09:50 CEST

Friday October 9, 2026 09:25 - 09:50 CEST
Congress Hall (Floor 2)

09:50 CEST

How We Shipped Power & Perf Optimized Snapdragon Based Product on Upstream - Neil Armstrong & Rui Silva, Linaro
Friday October 9, 2026 09:50 - 10:20 CEST
Booting mainline Linux on a Snapdragon SoC is a great step, but it is very different from shipping a product. In standard vendor BSPs, power and performance tuning is often hidden behind blobs and downstream hacks. When you build a commercial device entirely on upstream Linux and U-Boot, you lose those vendor shortcuts. You have to understand the hardware deeply to balance battery life and processing power.

In this talk, we will share our war story of shipping a real-world consumer product based on Snapdragon SoC using mainline Linux & U-Boot. We will guide you through our optimization journey, starting from the initial dev kit. We will see how we used the Linaro DebugBoard to profile and tune power consumption across different sleep states and active workloads. We will talk about leveraging standard kernel power management frameworks instead of relying on downstream workarounds, which helps keep the system easily maintainable.

We will explain how we identified power regressions and traced performance bottlenecks using upstream tools. Finally, we will look at the practical trade-offs we had to make to deliver a highly responsive, low-power device while staying close to mainline
Speakers
avatar for Rui Miguel Silva

Rui Miguel Silva

Senior Linux Engineer, Linaro
Working on Linux systems for long time...
avatar for Neil Armstrong

Neil Armstrong

Senior Linux Engineer, Linaro
Neil joined Linaro in September 2022 to work full-time on Qualcomm Upstreaming of their high-end SoC platforms.
Neil has been hacking on embedded platforms since he was 16 years old, from Casio Calculators to Phones platforms in the last months.
He maintains the Amlogic Linux & U-Boot baseport, Linux DRM Bridge & Panel codebase. In addition to Qualcomm, Neil regularly contributes to the Linux Kernel and U-Boot supporting the Amlogic SoCs support and DRM codebase... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

09:50 CEST

Seeing Inside the NPU: Open-Source Hardware Counter Profiling for Ethos-U on Linux and Zephyr - Vibhore Vardhan, BayLibre
Friday October 9, 2026 09:50 - 10:20 CEST
Edge AI runs on dozens of NPUs — Ethos-U, Hexagon, APUs, DSPs — each with its own closed toolchain and proprietary profiling tools. Application developers have no standard way to answer the basic question: what is my NPU actually doing?

This talk walks through the edge AI software stack — frameworks, delegates, drivers, hardware counters — and shows what it takes to make performance visible. Building on Tomeu Vizoso's Ethos-U PMU kernel work (upstream), we are instrumenting ONNX Runtime and TFLite operators with per-operator CPU PMU data (cycles, cache miss, bandwidth), surfaced via open trace formats, and wiring NPU hardware counter values into ExecuTorch ETDump traces on Zephyr.

The goal: per-operator timing, CPU cache and bandwidth data, and NPU cycle counts in a single open trace — without a proprietary tool.

Contributing to the Linux perf subsystem, this work lays the groundwork for open profiling support on other NPU targets.
Speakers
avatar for Vibhore Vardhan

Vibhore Vardhan

Senior Software Engineer, BayLibre
Vibhore Vardhan is a senior embedded systems engineer and researcher at BayLibre, leading R&D with a current focus on Edge AI. He brings a background in system-level power management on TI SoCs, now applied to NPU toolchain observability and profiling across the Edge AI software... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

09:50 CEST

Yocto BSP Layers: Breaking Free From Complexity - Mathieu Dubois-Briand & Köry Maincent, Bootlin
Friday October 9, 2026 09:50 - 10:20 CEST
Many Yocto layers provided by silicon vendors prioritize vendor-specific tooling, demos, and opinionated decisions often at the expense of simplicity, flexibility and maintainability. This makes
them challenging to integrate for custom boards or to adapt to specific customer needs.

Additionally, some of those vendor-provided layers create a maintenance burden: when you need to update, you become dependent on the vendor's choices and changes, which are often hard to understand and follow.

In this talk, we'll examine common issues found in vendor-provided Yocto layers and show how they introduce unnecessary complexity into embedded Linux projects. Much of what new users perceive as “Yocto complexity” actually comes from the design and maintenance practices used in vendor layers.

We'll then introduce yocto-kiss as an example of a simpler and more maintainable approach to vendor support layers. The talk will cover practical best practices for layer design, common pitfalls to avoid, and strategies for building vendor layers that are clean, flexible, and pleasant to maintain.
Speakers
avatar for Mathieu Dubois-Briand

Mathieu Dubois-Briand

Embedded Linux engineer, Bootlin
Mathieu Dubois-Briand is an Embedded Linux engineer at Bootlin since 2024, specializing in Yocto integration, kernel development, device drivers and bootloaders.
He is part of the Yocto Build Failure "SWAT" team, in charge of testing patches submitted to OpenEmbedded core layer and Bitbake master branches... Read More →
avatar for Köry Maincent

Köry Maincent

Embedded Linux engineer, Bootlin
Köry Maincent is an Embedded Linux engineer at [Bootlin](https://bootlin.com/) since 2020, working on kernel, device drivers, bootloaders and build system integration, and on upstreaming on all the above.
He is the maintainer of the [ST Buildroot External](https://github.com/boo... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:50 CEST

Apps, Not Firmware: A Service-Oriented Application Layer for Zephyr - Sylvio Alves, Espressif Systems
Friday October 9, 2026 09:50 - 10:20 CEST
Microcontroller firmware is monolithic: one image, one failure domain, where a bug anywhere can crash everything. Yet modern MCUs ship with memory protection (MPU, MMU, or PMP), and Zephyr already has the isolation pieces - userspace, memory domains, kernel-object capabilities, watchdogs, zbus - never assembled into an application model.

This talk presents a service-oriented application layer for Zephyr: multiple memory-isolated apps running as managed units, each reaching hardware and the network only through a capability-gated service broker, so a misbehaving app cannot corrupt, starve, or crash its neighbors.

We build the missing keystone - an app-group lifecycle and a service broker - on top of existing Zephyr, and demonstrate it live: two isolated apps share one Wi-Fi stack, each making independent network requests; one hangs and another faults, both are killed and reclaimed, while the healthy app runs on. We close with hardware lessons and upstreamable RFC targets.
Speakers
avatar for Sylvio Alves

Sylvio Alves

Software Engineer, Espressif Systems
Sylvio Alves is an Embedded Software Engineer at Espressif Systems, driving ESP32-family support in Zephyr RTOS. Over 15+ years in embedded - as both a hardware and firmware developer - he has worked across many chip families and frameworks, and today focuses on low-level bring-up... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

09:50 CEST

Playing Audio on a SoC DAC Output With Zephyr - Eve Redero, Redero Tech
Friday October 9, 2026 09:50 - 10:20 CEST
Some SoCs have an embedded DAC peripheral, which allow to play low or medium resolution audio with minimal electronics, no advanced I2S external codec required.

In this talk, I present a list of ingredients required to make an acceptable audio output:
- The DAC: what it is, how it is different from PWM audio output or I2S peripherals
- DMA, your DAC’s best friend, to run continuously and without drops
- Debug something fast and real-time thanks to tracing

Then I will discuss implementation, with the codec subsystem. Example platform will be ST STM32F7 and Atmel ATSAM3X8E.

Finally, if nothing crashes or burn in the meantime, I will give a demonstration.
Speakers
avatar for Eve Redero

Eve Redero

Senior Electronics Engineer, Redero Tech
I have worked as an electronics and embedded systems engineer for about 10 years, mostly in consumer electronics companies. My skills set includes board design, low-level firmware development, and a bit of knowledge about board production and testing. I usually work for tech companies... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

09:55 CEST

Keynote: Keynote: Linus Torvalds, Creator of Linux & Git, in Conversation with Dirk Hohndel, Head of Ericsson Software Technology
Friday October 9, 2026 09:55 - 10:25 CEST

Speakers
avatar for Dirk Hohndel

Dirk Hohndel

Head of Ericsson Software Technology
Dirk is the Head of Ericsson Software Technology, leading a team of engineers working on upstream open source contributions. He brings nearly four decades of software and open source leadership, most recently as head of Verizon's Open Source Office, focused on open source governance... Read More →
avatar for Linus Torvalds

Linus Torvalds

Creator, Linux & Git
Linus was born on December 28, 1969, in Helsinki, Finland. He enrolled at the University of Helsinki in 1988, graduating with a master’s degree in computer science. His M.Sc. thesis was titled “Linux: A Portable Operating System” and was the genesis for what would become the... Read More →
Friday October 9, 2026 09:55 - 10:25 CEST
Congress Hall (Floor 2)

10:35 CEST

Ask the Expert Sessions
Friday October 9, 2026 10:35 - 11:05 CEST
Come sit down with some open source experts to gain knowledge 1:1 and ask all your pressing questions! No sign-up necessary. More information to come!
Friday October 9, 2026 10:35 - 11:05 CEST
Congress Hall Foyer 4B

10:35 CEST

Coffee Break
Friday October 9, 2026 10:35 - 11:05 CEST

Friday October 9, 2026 10:35 - 11:05 CEST
TBA

11:05 CEST

Lightning Talk: Declarative Systems Still Have Hidden State - Kim Schaefer, Game Plan Tech
Friday October 9, 2026 11:05 - 11:15 CEST
Declarative infrastructure promises reproducibility: desired state is defined, controllers reconcile drift, and redeployments should behave predictably.

Except they often don’t.

This talk explores the hidden operational state declarative systems quietly depend on: webhook certificates cached in cluster resources, infrastructure dependencies that survive deletion, controller ordering assumptions, persistent node state, and lifecycle coupling reconciliation engines cannot see.

These problems become especially visible when infrastructure spans multiple systems or workloads take minutes rather than seconds to initialize.

Using real operational examples from Kubernetes and GitOps environments, this lightning talk examines why “delete and redeploy” frequently fails to produce clean state and why many reliability problems are actually hidden state-management problems.

The core lesson: declarative systems still depend on operational history, even when the infrastructure appears fully declarative.
Speakers
avatar for Kim Schaefer

Kim Schaefer

Senior DevOps Engineer, Game Plan Tech
Kim Schaefer is a Senior DevOps and Cloud Engineer focused on Kubernetes, GitOps, and secure platform engineering. She designs and operates production Kubernetes platforms with a focus on deployment reliability and automation in constrained environments.

Kim's work centers on bu... Read More →
Friday October 9, 2026 11:05 - 11:15 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:05 CEST

Pairing PX4 and ROS 2 Through Micro XRCE-DDS and Zenoh-pico, a Comparison - Beniamino Pozzan, Archangel Autonomy
Friday October 9, 2026 11:05 - 11:25 CEST
Since Micro XRCE-DDS replaced Fast-RTPS in PX4 version 1.14 the support for direct communication between ROS 2 and PX4 never stopped improving.
With PX4 stable version 1.17 recently released and version 1.18 close to enter its beta testing phase this presentation aims to cover the latest changes, imporvents and limitations of the Micro XRCE-DDS and Zenoh-pico interfaces.
The presentation will also compare the two communication methods to give the audience all the information necessary to choose the best approach given their requirements and application contraints.
Speakers
avatar for Beniamino Pozzan

Beniamino Pozzan

Senior Robotics Engineer, Archangel Autonomy
B. Pozzan is a PX4 Maintainer and Senior Robotics Engineer at Archangel Autonomy. He has extensive experience integrating autopilots with ROS 2 for UAV control and GNSS-denied navigation. With a Ph.D. in Automation Engineering from the University of Padova, he has extensive experience... Read More →
Friday October 9, 2026 11:05 - 11:25 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

11:05 CEST

Proofs of Personhood: Managing Identity in the Age of AI - Hart Montgomery, The Linux Foundation; Drummond Reed, First Person Cooperative; Glenn Gore, Affinidi
Friday October 9, 2026 11:05 - 11:45 CEST
“On the internet, nobody knows you’re a dog,” the famous New Yorker comic goes, and that aphorism couldn’t ring truer today. In a world of AI agents, how can we be sure that we (or our agents) are interacting with other trusted, reputable systems and agents rather than impersonators or scammers? As open source maintainers, how can we be sure that new contributors are responsible, trustworthy individuals rather than adversarial state actors, helping to thwart compromises like the XZUtils attack? More generally, how do we deal with digital identity in the age of AI?

Our proposal is to use cryptographic proofs of personhood. These can be built from a decentralized, privacy-preserving reputation system, which we can build with tools and standards we have developed in several projects in LFDT. The session will cover some background on how proofs of personhood work, including privacy guarantees from cryptography (at a beginner level). Then, we will explain some applications in agentic AI and open source software maintenance. Finally, we will give an end-to-end demo of how our systems work in practice which will include audience participation in a “verifiable trust graph”.
Speakers
avatar for Drummond Reed

Drummond Reed

Director, First Person Cooperative
30+ years working on Internet identity, security, privacy & trust
Co-Editor, W3C Decentralized Identifiers (DID) Specification
Steering Member, Trust Over IP (ToIP) Foundation
Co-Author, Self-Sovereign Identity (Manning, 2021)
avatar for Hart Montgomery

Hart Montgomery

CTO, LFDT, Linux Foundation
Hart Montgomery serves as the CTO of LFDT and the ED of the PQCA. Hart previously worked in blockchain and cryptography research at Fujitsu Research where he helped lead Fujitsu’s contributions to Hyperledger. Prior to Fujitsu, Hart received a Ph.D. in cryptography at Stanford under... Read More →
avatar for Glenn Gore

Glenn Gore

CEO, Affinidi
30+ year Veteran of building Internet-scale infrastructure (OzEmail, UUNet, AWS, Affinidi). CEO of Affinidi, board member to tech startups. Glenn is still a hands-on developer, building next-generation security and privacy services that are open by design and open-source in devel... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club H (Floor 1)
  Digital Trust
  • Audience Experience Level Any

11:05 CEST

A Language Model in 256 MB: Running SLMs on a $10 RISC-V Linux Board Without a GPU - Akshat Khanna, Angel One
Friday October 9, 2026 11:05 - 11:45 CEST
Running a language model used to mean a datacenter GPU. This talk shows a 1-billion-parameter model generating tokens on a roughly $10 RISC-V board (the SOPHGO SG2002, as on the Sipeed LicheeRV Nano) with 256 MB of RAM no GPU, no Python, no cloud. The speaker walks the full embedded stack: a minimal C transformer inference engine running quantized GGUF weights, cross-compiled for RISC-V on embedded Linux, plus the quantization (4-bit GGUF), memory-mapping, and KV-cache choices that make it fit. The session is honest about the trade-offs, tokens-per-second, accuracy loss from aggressive quantization, and where an NPU or a microcontroller-class TinyML model is the better call. Attendees leave with a reproducible recipe for putting useful local inference on cheap, disconnected, privacy-sensitive hardware, and a clear-eyed sense of what 256 MB can and cannot do.
Speakers
avatar for Akshat Khanna

Akshat Khanna

Machine Learning Engineer, Angel One
Akshat Khanna is a Machine Learning Engineer at Angel One, where he builds GenAI-powered bots and leverages agentic AI for high-performance trading platforms. Previously, he worked as MTS at VMware Tanzu, focusing on Kubernetes solutions for the edge. He is an active open-source contributor... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

11:05 CEST

From Vendor Bring-up To Community Upstreaming: What We Learned From SpacemiT K3 - Troy Mitchell, SpacemiT
Friday October 9, 2026 11:05 - 11:45 CEST
Upstreaming initial support for a new RISC-V SoC is becoming more common, but keeping that support useful, reviewable, and maintainable is still difficult. As more application-class SoCs land, a one-vendor model stops scaling.

This talk uses SpacemiT K3, the first mass-produced RVA23-compatible SoC, as a case study. It's not about what we support, but about the upstream work we did, what tripped me up, and how we got past it.

We'll walk through in-house K3 enablement work on DMA, audio I2S, bindings, and DTS. The interesting patches aren't the ones that applied cleanly; they're the ones that didn't. We'll look at where to split bindings, drivers, and DTS; how K3 hardware constraints had to be modeled in upstream terms; and how review rounds reshaped the design.

The second part focuses on working with community developers outside SpacemiT: making boards available, keeping test images reproducible, pre-reviewing patches, turning regression around quickly, and keeping the internal tree close to mainline.

We’ll share lessons practical for making new RISC-V platforms not only upstreamed once, but easier for vendors and community contributors to review, test, debug, and maintain.
Speakers
avatar for Troy Mitchell

Troy Mitchell

Software Design Engineer, SpacemiT
I'm Troy Mitchell, a software design engineer at SpacemiT and a contributor to the upstream Linux kernel and OpenSBI, working on low-level system software and kernel enablement for RISC-V SoCs. I maintain the SpacemiT K1 I2C/I2S driver upstream, and day to day I work on kernel drivers... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

11:05 CEST

Is It Time To Retire Kas? - Jan Kiszka & Felix Mößbauer, Siemens
Friday October 9, 2026 11:05 - 11:45 CEST
You are using kas, the user-friendly orchestration tool for bitbake projects, and you just got nervous? Sorry for that.

With your full attention now, this talk shall bring you up to date with latest developments in kas. Among them are the diff plugin, buildtools support, build attestations, improved lock file handling, unprivileged containers, commit signature validation, easier CI builds, and more.

But we would also like to hear from you what could be further improved. Are there use cases or workflows that should be added to kas or could be better handled than so far. Be prepared for an interactive part.

Last but not least, we will relieve you from worries that kas might be retired by explaining our motivations and plans to drive this project also in the foreseeable future.
Speakers
avatar for Jan Kiszka

Jan Kiszka

Principal Key Expert, Siemens
Jan Kiszka is working as consultant, open source evangelist and Principal Key Expert Engineer in the Linux Expert Center at Siemens Technology. He is supporting Siemens businesses with adapting, enhancing or strategically driving open source as platform for their product demands... Read More →
avatar for Felix Mößbauer

Felix Mößbauer

Senior Embedded Developer, Siemens AG
Having a strong background in High Performance Computing, Felix is currently focusing on embedded Linux platforms for realtime applications. Hereby, he works across country and company boundaries to unify patterns that are recurring and mandatory for embedded products (like secure... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:05 CEST

An Native API for Linux Systems With Systemd + Varlink - Lennart Poettering, Amutable
Friday October 9, 2026 11:05 - 11:45 CEST
Modern Linux based distributed systems generally rely on bespoke "agent" services on each node for introspecting their state or issuing operations.

In this talk I'd like to explain systemd's vision of improving and cleaning up this logic, with the ultimate goal of avoiding any local agents but nonetheless making the system nicely introspectable and accessible, with modern technologies.

For this, we'll talk about the Varlink IPC system, and the numerous Varlink APIs systemd provides these days. We'll also cover the HTTP Varlink proxy, which opens up these APIs in a web-native way, with modern authorization mechanisms. We'll also discuss systemd's metrics collection/report generation subsystem, it's cryptographic properties and remote access to it.
Speakers
avatar for Lennart Poettering

Lennart Poettering

Chief Engineer, Amutable
Lennart is a systemd creator & maintainer. He's also the Chief Engineer @ Amutable.
Friday October 9, 2026 11:05 - 11:45 CEST
Panorama Hall (Floor 1)
  Linux

11:05 CEST

Scaling OSS Code Quality With Multi-Agent Swarms - Vikram Vaswani, Independent
Friday October 9, 2026 11:05 - 11:45 CEST
Development teams are seeing a rapid increase in code contributions, many of them from AI tools and pair-programming copilots. As AI-generated code increases, human reviewers can quickly get overwhelmed.

The instinct to throw "an AI reviewer" at the problem mostly doesn't work. A single agent produces shallow comments, misses context, and either over-flags or under-flags depending on how it's prompted.

This talk presents a pattern that works better, built and demonstrated from scratch: three specialized reviewing agents in parallel, followed by a developer agent that applies the fixes. One reviewer focuses on architecture, one on security, one on test coverage. When all three finish, a fourth agent rewrites the code to address each issue and opens a new PR for human sign-off.

The architecture is adaptable: teams with data sovereignty requirements can swap the hosted model for a self-hosted open-weight alternative (Llama 3, Mistral) served via vLLM or Ollama.

Attendees leave with a concrete, working pattern they can adapt to their own projects, and a clearer picture of where AI can genuinely reduce review bottlenecks.

Includes live demo.
Speakers
avatar for Vikram Vaswani

Vikram Vaswani

Developer Advocate

Friday October 9, 2026 11:05 - 11:45 CEST
Forum Hall (Floor 2)
  Open AI & Data
  • Audience Experience Level Any

11:05 CEST

Small Language Models 101: Why Bigger Isn't Always Better - Mohit Gaur, Microsoft
Friday October 9, 2026 11:05 - 11:45 CEST
Large Language Models often dominate headlines, but many real world AI applications don't need billions of parameters to be effective. Tasks such as classification, information extraction, intent detection, summarization and domain specific assistants can often be served effectively by smaller open source models with lower latency, reduced infrastructure requirements and improved privacy.

This session introduces Small Language Models (SLMs), explores the trade-offs between model size, accuracy, cost and performance and discusses techniques such as quantization, distillation and domain adaptation that make these models practical for deployment on laptops and edge devices.

Attendees will leave with a framework for selecting the right model for a given use case, understanding why bigger is not always better and how open-source SLMs are making AI more accessible to developers and organizations with limited compute resources.
Speakers
avatar for Mohit Gaur

Mohit Gaur

Software Engineer 2, Microsoft
Mohit Gaur is a software engineer at Microsoft with a passion for exploring new tools and sharing insights that help others harness the full potential of technology. He thrives on collaboration and mutual success and is guided by the belief that every challenge holds the potential... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Terrace 2A (Floor 2)
  Open Source 101

11:05 CEST

From Using To Leading: How a Grid Operator Leverages Open Source Strategically - Jonas van den Bogaard, Alliander
Friday October 9, 2026 11:05 - 11:45 CEST
As the energy system transitions into a highly digital, data-driven ecosystem, grid operators face mounting complexity, rising costs, and increasing pressure to deliver scalable and future-proof solutions. In this context, open source is no longer a technical preference. It is becoming a strategic necessity.

In this session, Alliander shares how it has repositioned open source as a key enabler of its digital strategy. We show how a clear vision helps maximize public value, accelerate innovation, strengthen digital sovereignty, and improve transparency, while maintaining control over long-term costs.

We introduce three guiding principles: Open Source First, Building Together, and Confidence in Openness. We also highlight practical implications, from embedding open source in procurement to actively contributing and opening internal solutions.

This session offers a concrete example for executives on how to move from ad hoc use of open source to a coherent, organization-wide strategy. Reducing duplication, optimizing investments, and strengthening collaboration across the energy ecosystem, including within LF Energy.
Speakers
avatar for Jonas van den Bogaard

Jonas van den Bogaard

Open Source Office Lead, Alliander N.V.
Jonas van den Bogaard is a Digital Strategy Lead at Alliander, a distribution system operator (DSO) in the Netherlands. Alliander provides reliable, affordable, and accessible energy transport and distribution to a large part of the Netherlands. Open source has proved to be an enabler... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 1 A (Floor 1)

11:05 CEST

This Talk Is Already Out of Date: Planning for the Long Term in a Short Term World - Rebecca Rumbul, Rust Foundation
Friday October 9, 2026 11:05 - 11:45 CEST
Successful Open Source projects have always had to balance the need to work towards long term sustainability and growth with meeting shorter term issues such as immediate funding and human resourcing needs. Projects would generally work to an annual rhythm to align with budgeting and funding decisions made by corporate supporters, and annual planning cycles were in many places well established. However, this rhythm has been hugely impacted by the new age of AI and the pivots in focus of the commercial tech industry. Long term planning feels impossible, and funding work sustainably feels increasingly out of reach when projects are reliant on companies engaged in an AI arms race. Once-robust human processes now move too slowly to be effective, and the key individuals that still need to be a part of this new world increasingly feel like they are a day late and a dollar short for everything. This talk looks at how the human side of Open Source is being affected by these shifts, and how communities can consider how to respond to these challenges.
Speakers
avatar for Dr. Rebecca Rumbul

Dr. Rebecca Rumbul

Executive Director & CEO, Rust Foundation
Rebecca is the Executive Director and CEO of the Rust Foundation. She holds a PhD in Politics and Governance, and has worked as a consultant and researcher with governments, parliaments and development agencies all over the world, advocating for openness and transparency, and developing... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Conference Hall (Floor 4)

11:05 CEST

500,000 Containers, 5 Minutes, 10x Load: Scaling Uber’s Container Registry for Disaster Recovery - Sambhav Jain & Anton Kalpakchiev, Uber
Friday October 9, 2026 11:05 - 11:45 CEST
Kraken is Uber's open-source P2P container registry. It serves 23 petabytes of data daily with 99.9% reliability. However, during recovery from a complete regional failure, Kraken was pushed over its historical peak load by 10 times. It had to distribute over 100,000 container images every minute. The registry that "just worked" became the bottleneck blocking disaster recovery.

Adding capacity proved insufficient. So, the team reworked the caches and tuned download parallelism. But closing such a large performance gap required architectural changes. If downloads are too slow, move the data closer to the client. If you cannot serve everything at once, tier images by criticality. These optimizations eventually broke Uber’s deployment throughput record.

This talk presents a case study of evolving Kraken to deliver 10x performance under extreme load - the architectural changes, necessary trade-offs, and hard-won lessons. All optimizations are open-sourced in Kraken.

Speakers
avatar for Sambhav Jain

Sambhav Jain

Software Engineer, Uber
Sambhav Jain currently works as a Software Engineer at Uber on the container runtime team. Primarily working on container resource metrics and distributed container registry systems at Uber.
Before Uber, Sambhav worked at Cockroach Labs in the Database Performance team and at Confluent in the Kafka Connect team... Read More →
avatar for Anton Kalpakchiev

Anton Kalpakchiev

Software Engineer, Uber
Anton works as a software engineer at Uber's Compute team. He works on Kraken - Uber's P2P open-source Docker registry that distributes ~30PB of data per day. Additionally, Anton works on developer tooling used by thousands of software engineers at Uber to debug their containers live... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

11:05 CEST

Functional Safety Certification in Upstream Xen for Automotive and Avionics - Ayan Kumar Halder, AMD
Friday October 9, 2026 11:05 - 11:45 CEST
Safety-critical systems in avionics, automotive, and industrial domains increasingly rely on mixed-criticality architectures where workloads of different safety levels share hardware. This talk presents ongoing work to bring functional safety to the upstream Xen hypervisor, composed with Zephyr RTOS and Linux, to meet standards including DO-178C (avionics), ISO 26262 (automotive), and IEC 61508 (industrial).
We walk through concrete upstreamed and published contributions: MISRA C fixes, MPU support in Xen, requirements and architecture specifications, and test specifications. We describe how Xen is validated as a Safety Element out of Context using domain-based tests, fault injection, gdb-based interface testing, fuzzing, platform emulation, Ceedling unit testing, and coverage analysis (line, branch, function, MC/DC).
We also cover efforts to shrink the safety-certifiable codebase through fine-grained hardware configuration, and how Xen enforces freedom from interference between VMs via isolation. We close with opportunities to collaborate with the ELISA and Xen FuSa communities toward an open safety case for open-source systems.
Speakers
avatar for Ayan Kumar Halder

Ayan Kumar Halder

SMTS, AMD
Ayan has been working on Arm based low based software stack for the past 14 years. He has worked on variety of projects ranging from board bringup, post silicon validation to developing new features. He has contributed upstream to Xen, Linux and Zephyr.
More recently he is been actively involved within AMD on the Xen FuSa project... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

11:05 CEST

Demystifying Pinctrl: Pin Multiplexing in Zephyr - Roy Jamil, Ac6
Friday October 9, 2026 11:05 - 11:45 CEST
Pin multiplexing is always needed in embedded development. But when we start changing pins in a devicetree overlay, or when creating a custom board, things can quickly become confusing: build errors, wrong pin states, peripherals not starting, or hardware that simply does not behave as expected.

In Zephyr, the pinctrl subsystem is what connects the physical pins of the SoC with the peripherals we want to use. It defines the pin function, the electrical configuration, and the pin states used by the drivers.

In this talk, we will demystify pin multiplexing in Zephyr and explain how to use pinctrl in devicetree in simple words. We will go step by step through pin groups, pin states, common configurations, overlays, board files, and SoC-specific syntax.

We will also use practical examples for common peripherals and vendor families, and show how to debug the most frequent issues when customizing pins.
Speakers
avatar for Roy Jamil

Roy Jamil

Training Engineer, Ac6
Roy Jamil, with a PhD in the field of Asymmetric Multiprocessing (AMP) and real-time embedded systems, has over six years of experience as a Training Engineer at Ac6. He trains hundreds of engineers annually. His experience includes programming, Linux, drivers, Yocto, and various... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

11:05 CEST

Zenbedded: Bringing Ros2_control Closer To the Embedded World - Speakers to be Announced
Friday October 9, 2026 11:05 - 11:45 CEST
The Robot Operating System (ROS) is the de facto standard open-source middleware for building robot software, providing standardized messaging, tooling, and reusable components. ros2_control is a hardware-agnostic control framework focusing on the modular composition of control systems for robots, sharing of controllers as well as real-time performance.

Bringing ros2_control to embedded systems usually means bolting heavy DDS serialization and a bridge process onto microcontrollers. Zenbedded fixes this. It is a monolithic Zephyr, Zenoh, and ROS 2 framework built specifically for ros2_control. We put the transport, the RTOS client library, and the host-side hardware_interface plugin into one tight repository.
On the wire, we use a multi-tier transport that moves along a spectrum. You can choose between fully ROS-observable but slightly slower, or fully binary-encoded and fast, depending on what your control loop actually needs.
You'll leave with a pattern for running ros2_control on Zephyr-class hardware and a feel for working with ROS and ros2_control. We'll demo the stack balancing a real inverted pendulum on an ESP32, where latency is the difference between upright and toppled.
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

11:15 CEST

Lightning Talk: One Line of YAML Leaks Your Secrets: The Pwn-Request Pattern - Arpit Jain, Self Employed
Friday October 9, 2026 11:15 - 11:25 CEST
A pull_request_target trigger plus ref: ${{ github.event.pull_request.head.sha }} in a checkout step. That combination lets any external contributor run arbitrary code with your repository's secrets and write token. This is the "pwn request" pattern, and it's in production workflows across some of the most popular open-source projects on GitHub.

I'll use a real finding (a CRITICAL-severity pwn request I discovered and privately disclosed in an Apache project) to explain how the attack works: what pull_request_target does differently from pull_request, why adding permissions: read-all doesn't protect you, and why the attacker needs nothing beyond opening a pull request.

Then I'll show the three mitigations that work: splitting into unprivileged build and privileged post-processing steps, using persist-credentials: false, and gating on the head repo matching the base.
Speakers
avatar for Arpit Jain

Arpit Jain

Security Researcher, Self Employed
Supply-chain security researcher focused on CI/CD pipeline vulnerabilities. Audits GitHub Actions workflows across CNCF, sigstore/SLSA, OpenSSF, and US federal government orgs (cisagov, GSA) for exploitable patterns: pwn requests, unpinned actions, token-scope misconfigurations. Has... Read More →
Friday October 9, 2026 11:15 - 11:25 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:25 CEST

Lightning Talk: Beyond Immutable Machines: Introducing Cluster API In-Place Updates - Lennart Jern, Ericsson Software Technology
Friday October 9, 2026 11:25 - 11:35 CEST
Cluster API (CAPI) is by now a relatively mature project with many adopters using it in production already for years. Despite this, or perhaps rather thanks to it, CAPI keeps evolving, growing and adding new features. In this session, I'll present one of the most recent features: in-place updates.

In-place updates marks an important change to a fundamental assumption in CAPI. Traditionally, the Machines were considered mostly immutable. Any change required a replacement where new Machines were created and old Machines deleted. This method of operation has served CAPI well, and continues to do so, but it is not without pain points. With in-place updates, it is now finally possible to avoid replacement. This opens the door for unique use-cases and solutions, such as Talos, where each node's lifecycle can be managed through a built-in controller in the node itself.

Come learn about this new feature in CAPI, and how to make use of it!
Speakers
avatar for Lennart Jern

Lennart Jern

Senior Developer, Ericsson Software Technology
Lennart Jern is a senior developer at Ericsson with more than 6 years experience from the CNCF ecosystem. He works mainly on open source projects related to the Cluster API and is a maintainer for the Cluster API Metal3 and OpenStack infrastructure providers as well as the Baremetal... Read More →
Friday October 9, 2026 11:25 - 11:35 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

11:25 CEST

Cryptographic Flight Security: Implementing Hardware-Enforced FAA Remote ID and Trusted Identities - Ashok Kumar, gotoashok
Friday October 9, 2026 11:25 - 11:45 CEST
Global regulatory shifts—driven by strict NDAA requirements and EASA U-Space mandates—require drone manufacturers to implement verifiable supply chain security. Software-only implementations of FAA Remote ID remain vulnerable to key spoofing and firmware tampering. This session delivers a practical breakdown of how to enforce a hardware root of trust by embedding physical Secure Elements (like the OPTIGA Trust M) into open flight controllers running PX4 and NuttX.
We will bypass high-level concepts to dive straight into the embedded architecture:
Configuring the SPI/I2C bus interface between the flight MCU (PSoC C3M) and the security peripheral.
Modifying the NuttX driver layer to offload ECDSA signing keys for broadcast messages without blocking safety-critical flight loop threads.
Structuring secure boot sequences to protect downstream firmware from local physical exploits.
We will share timing benchmarks showing how to manage cryptographic latency within standard PX4 task frequencies to build compliant systems without sacrificing real-time flight performance.
Speakers
avatar for Ashok Kumar

Ashok Kumar

Ashok Kumar, gotoashok
I am a Systems Architect and Embedded Engineer with a 26-year obsession: defining what actually constitutes 'good' design in an era of over-engineering. I operate at the high-stakes intersection of Silicon and Software, translating complex hardware capabilities into mission-critical... Read More →
Friday October 9, 2026 11:25 - 11:45 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

11:35 CEST

Lightning Talk: Prove It: Is Your Kubernetes App Cloud Native? - Martin Matyáš, Tieto
Friday October 9, 2026 11:35 - 11:45 CEST
Everyone claims their app is cloud-native. But how to prove it?

CNTi Testsuite, an open-source Linux Foundation project, provides automated tests that validate cloud-native best practices such as security, scalability, and upgradability. While designed for telecom CNFs, it works for any Kubernetes application.

In this lightning talk, I’ll show how you can run CNTi Testsuite in minutes to objectively measure cloud-native maturity and uncover hidden gaps in Kubernetes workloads.
Speakers
avatar for Martin Matyáš

Martin Matyáš

Lead Cloud Engineer, Tieto
Lead cloud engineer with 20+ years of experience in application development and testing mostly in telecom industry. Worked on various aspects of Telecom software, from platforms, applications, test tools, continuous integration. Active member and maintainer of LFN's CNTi communit... Read More →
Friday October 9, 2026 11:35 - 11:45 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:55 CEST

What Hides Below 10,000+ SBOMs of a Foundation - Mario Fahlandt, Kubermatic
Friday October 9, 2026 11:55 - 12:15 CEST
It all started with the simple question: "Do we have all exceptions for license dependecies for all the projects?"

As you can imagine this is not a question most organizations can answer out of the blue.
To solve this we started not only generating SBOMS for every single project in the CNCF., but also every Subproject that has a release.
Along the way we hit every wall: inconsistent release processes, license resolution dead ends, CVE matching at scale, and the discovery that generation is maybe 20% of the problem.
We will dig into the full pipeline we built. Automated SBOM generation at scale, auto discovery of Repositories, experimenting with differnet SBOM generation tools, hitting Git limits, license enrichment via deps.dev and ClearlyDefined, vulnerability cross-referencing via OSV, and OpenVEX for suppression.
After we finished this we realized that 10,000+ SBOMs are useless if you cannot search, query, or govern them. So we built an open source toolchain for the whole thing.

You will learn how to build a toolchain for Supply Chain at a sclae that supports a foundation and you can also use in organizatiosn that is fully Open Source and Apache 2 licensed.
Speakers
avatar for Mario Fahlandt

Mario Fahlandt

Customer Delivery Architect, Kubermatic
Mario Fahlandt is a CNCF Technical Oversight Committee member, SIG ContribEx co-chair, and Kubernetes AI Conformance subproject lead. He maintains cncf/sbom, the project generating SPDX SBOMs for every CNCF release, and created SeeBOM, an open-source SBOM governance platform now applying... Read More →
Friday October 9, 2026 11:55 - 12:15 CEST
South Hall 1 A (Floor 1)

11:55 CEST

Why Switch To External Flight Modes? - Dawid Rudy, Auterion
Friday October 9, 2026 11:55 - 12:15 CEST
When it comes to controlling PX4 from a companion computer, developers are often spoiled for choice - leading to confusion about which architecture best suits their specific mission requirements. Historically, Offboard Mode has been the go-to default, but the evolution of the PX4 ecosystem has introduced powerful alternatives like External Flight Modes and the native ROS 2 Control Interface.
This session provides a technical breakdown of how PX4 handles companion computer inputs under both paradigms. We will explore how External Flight Modes register directly with PX4's internal mode manager, allowing custom autonomy apps to behave like native flight modes with built-in safety boundaries. Attendees will learn the differences between these methods, the performance benefits of moving to the ROS 2 bridge, and a practical migration path to transition legacy offboard code into robust, external ROS 2 applications.
Speakers
avatar for Dawid Rudy

Dawid Rudy

GNC Engineer, Auterion
RC hobbyist and FPV drones enthusiast, actively contributing to UAV-related open-source projects.
Friday October 9, 2026 11:55 - 12:15 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

11:55 CEST

Your Agent Did What? Forensic Observability for Systems That Don’t Leave Obvious Footprints - Adriana Villela, Dynatrace & Kasper Borg Nissen, Dash0
Friday October 9, 2026 11:55 - 12:35 CEST
The GenAI observability space is fragmented right now. OpenInference, OpenLLMetry, framework-specific conventions are all solving the same problems with incompatible attribute names. That made sense when OTel’s GenAI support was thin. It makes less sense today.

OTel is where this converges. Getting there from where most teams actually are isn’t obvious. Kasper and Adriana cover the current landscape, how the genainormalizer processor bridges the gap at the collector layer, and what a realistic path to OTel-native GenAI observability looks like.

Then the harder question: your agent just deleted a database. What does your telemetry actually tell you? Non-deterministic systems don’t leave obvious footprints, and most teams discover that at the worst possible time.
Speakers
avatar for Adriana Villela

Adriana Villela

Principal Developer Advocate, Dynatrace
Adriana Villela is a blogger, host of the Geeking Out podcast, CNCF Ambassador, OpenTelemetry Community Manager, and maintainer of the OpenTelemetry End User SIG. By day, she focuses on Observability and OpenTelemetry, as a Principal Developer Advocate at Dynatrace. By night, she... Read More →
avatar for Kasper Borg Nissen

Kasper Borg Nissen

Principal Developer Advocate, Dash0
Kasper is a CNCF Ambassador, former KubeCon+CloudNativeCon Co-Chair, Golden Kubestronaut, KCD Organizer, and CNCG Group Organizer. He co-founded Cloud Native Nordics to unite meetups across the region. At Dash0, he helps make observability easy for developers by advocating for better... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

11:55 CEST

Building Trust in the AI Era: Agent-to-Agent Communication With DIDs and VCs - Alexander Shcherbakov, DSR Corporation
Friday October 9, 2026 11:55 - 12:35 CEST
As AI moves from isolated chatbots to autonomous agent ecosystems, the "identity problem" becomes a critical security bottleneck. How does an agent verify the legitimacy of a requestor before executing a sensitive task? Traditional API keys are insufficient for dynamic, decentralized agent interactions.
This session explores a cutting-edge extension to the Linux Foundation A2A protocol that leverages Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to establish high-assurance trust and bridges the gap between Decentralized Identity standards and AI, creating a secure backbone for the next generation of agent interoperability.
We will dive into the technical design of integrating OpenID for Verifiable Presentations (OID4VP) into agent communication flows. Attendees will learn how this proposed extension moves beyond static credentials to enable granular, verifiable Authentication (AuthN) and Authorization (AuthZ) for autonomous tasks. Beyond the protocol basics, we will analyze different patterns for VC presentation—comparing interactive vs. automated flows—and evaluate diverse wallet options, ranging from cloud-based agent wallets to secure edge implementations.
Speakers
avatar for Alexander Shcherbakov

Alexander Shcherbakov

Head of Digital Trust Labs, DSR Corporation
Ph.D. in Mathematics. Master of Applied Mathematics and Computer Science.
Extensive experience in Blockchain, DLT, Self-sovereign Identity (SSI).
Significant contribution to open source. Maintainer and contributor of popular LF open-source projects (Hyperledger/OWF/Indy/Hiero).
Extensive experience speaking at international conferences: LF Open Source Summit North America 2026, LFDT Member Summit 2026, Hyperledger Global Forum 2020, Hyperledger Bootcamp 2019, Internet Identity Workshop 2021... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Club H (Floor 1)
  Digital Trust

11:55 CEST

Bitbake-setup Has Shipped in Yocto: Producing Complete Linux Systems From One File - Alexander Kanavin, Linutronix
Friday October 9, 2026 11:55 - 12:35 CEST
The Yocto project is a toolkit for creating custom Linux distributions for the embedded use cases. Historically it has not provided tools and standards for setting up and replicating build configurations in a reproducible manner, leaving that to third party projects and custom scripts.

This has changed with the latest Yocto LTS release (6.0 'wrynose'), which includes a tool called bitbake-setup. This talk will give an overview of what is available and how it can be used to write a record of how to build a complete system, and to replicate that build elsewhere with that record. I will also briefly cover possible future directions for build configuration management.
Speakers
avatar for Alexander Kanavin

Alexander Kanavin

Open Source Software Engineer, Linutronix
Alexander is an open source developer specializing in distribution engineering using vendor-neutral tooling and userspace stacks. He is one of the primary contributors to the Yocto project and has an interest in developing foundations of digital infrastructure in a sustainable ma... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:55 CEST

Edge AI on Linux -- The Software - Karim Yaghmour, Opersys inc.
Friday October 9, 2026 11:55 - 12:35 CEST
AI is inexorably puncturing into our daily lives in some way, shape or form. Up to now, cloud-based LLMs have been the most notable incarnations. And yet, our daily lives contain a slew of devices that remain, for now, of the "dumb" variant. As AI technology evolves, matures and gradually commoditizes, several underlying forces, which we'll examine, will increasingly push such functionality into edge devices. This will be especially true of Linux-grade devices that, on the surface, would seem to have the requisite capabilities to support AI-grade stacks.

This talk will examine the AI software stacks available to build edge AI devices based on Linux-grade systems, especially the seemingly infinite functionality permutations made possible by generative AI. While there have been several “open weights” models with licensing constraints, the recent introduction of the Gemma 4 family (under ASL), which includes models specifically targeted at IoT, is a game changer and likely a taste of things to come. We’ll survey available models and engines, such as llama.cpp and ollama, and how to build real systems with them while accounting for in-the-field challenges.

2nd of two companion talks.
Speakers
avatar for Karim Yaghmour

Karim Yaghmour

CEO, Opersys inc.
Karim has been an active member of the open source community since the mid-90s. He pioneered the world of Linux tracing with the Linux Trace Toolkit and introduced Adeos, one of the first nanokernels/hypervisors for Linux. He is widely known for his O'Reilly books: "Building Embedded... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

11:55 CEST

Mainline Allwinner Support Status Update - Paul Kocialkowski, sys-base
Friday October 9, 2026 11:55 - 12:35 CEST
Support for Allwinner SoC chips in mainine projects like Linux, U-Boot and TrustedFirmware-A has been thriving for over a decade, enabling a large number of use cases and applications. This ongoing effort is lead by the linux-sunxi community and supported by various companies and individuals.

This talk presents an overview of the current status of support on the boot, firmware and kernel sides, along with a comprehensive list of the supported chips with specific information for each aspect. This includes advanced topics like power management, multimedia, graphics and accelerators. The latest developments and ongoing chip support efforts is also highlighted.

Context and history regarding Allwinner and the linux-sunxi community is also presented, as well as related tools and resources.
Speakers
avatar for Paul Kocialkowski

Paul Kocialkowski

Multimedia, Graphics and Embedded Linux Expert, sys-base
Paul is a free software developer working on hardware support in mainline projects like Linux and U-Boot.

Since 2014, he has contributed hundreds of patches to the kernel, in areas that include v4l2 (decoder, capture, isp, sensor), drm (display, bridge) and platform support for... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:55 CEST

The Little-Known Mechanism for Securely Parameterizing Systemd Services - Lennart Poettering, Amutable
Friday October 9, 2026 11:55 - 12:35 CEST
In this talk I'd like to discuss the "systemd Credentials" concept, which was introduced back in systemd v250 and became a powerful mechanism for parameterizing Linux systems and services.

These credentials can be passed into systems and services, can be authenticated and encrypted by TPMs. They can be acquired from SMBIOS, via Cloud IMDS services, the UEFI System Partition, or local file systems and IPC. They have a well-defined life-cycle, and can be securely inherited down the process, container and VM hierarchy.

We'll compare them with other ways to parameterize systems and services, such as the kernel command line or environment blocks, and explain why systemd's credentials are often the much better approach.
Speakers
avatar for Lennart Poettering

Lennart Poettering

Chief Engineer, Amutable
Lennart is a systemd creator & maintainer. He's also the Chief Engineer @ Amutable.
Friday October 9, 2026 11:55 - 12:35 CEST
Panorama Hall (Floor 1)
  Linux

11:55 CEST

Look MA, No GPUs! Experiment and Develop LLMs Without GPU Support - Alexon Oliveira, Red Hat
Friday October 9, 2026 11:55 - 12:35 CEST
It's hard to experiment, let alone develop applications, for LLMs when access to GPUs is restricted. But what if you could do your development on CPUs? This session demonstrates how to deploy vLLM on a local Kubernetes cluster using Kind and Podman Desktop, running entirely on a CPU-only laptop.

The presentation covers building a minimal environment, deploying vLLM containers, and running inference against models like Gemma-3 and Qwen2.5. A live benchmark comparison between vLLM and llama.cpp reveals when each runtime excels across different model sizes and hardware profiles. The session then extends the workflow to production-grade serving with KServe, including autoscaling and model lifecycle management.

Attendees will learn how to deploy and test vLLM locally without GPUs or cloud resources, understand when to choose vLLM versus llama.cpp based on model size and hardware, and extend a local setup to production-grade serving with KServe.
Speakers
avatar for Alexon Oliveira

Alexon Oliveira

Senior Principal Technical Account Manager, Red Hat
Alexon works as a Senior Principal Technical Account Manager at Red Hat focusing on Infrastructure and Management, Integration and Automation, Cloud Computing, Storage, and AI Solutions. He also contributes to produce and enhance documentation, knowledge-base articles, blog posts... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Forum Hall (Floor 2)
  Open AI & Data

11:55 CEST

Minimal Viable AI Platform - Max Körbächer, Liquid Reply
Friday October 9, 2026 11:55 - 12:35 CEST
Creating your own AI platform sounds like a job for a funded team and a matching cloud bill. Surprisingly, it isn't. I want to show how a handful of open source tools combine into a minimal viable AI platform that runs on one machine from a single Docker Compose file.
Five layers are all needed for a valuable platform: LiteLLM as the gateway (one API for any model, with keys and cost tracking), Open WebUI as the chat interface, n8n for automation and agents that take real actions, Ollama for private local models, and Langfuse for request tracing.
Then we look at how to grow it (RAG, authentication, scaling) without adding a pile of disconnected tools. This setup can be advanced for every demand.
The setup is indeed not perfect, but it is a valid starting point for organizations of any size.
No enterprise budget needed, just you, some OSS tools and a little bit of interest.
Speakers
avatar for Max Körbächer

Max Körbächer

Chief Technology Advisor & CEO, Liquid Reply
Max Körbächer is the Founder and Chief Technology Advisor at Liquid Reply, a CNCF Ambassador and Governing Board Member, LF Europe Advisory Board member and the author of the book Platform Engineering for Architects. Max specializes in translating the crushing complexity of cloud... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Terrace 2A (Floor 2)
  Open Source 101

11:55 CEST

Burnout in Open Source: A Structural Problem We Can Fix Together - Miranda Heath, Software Stewardship Lab
Friday October 9, 2026 11:55 - 12:35 CEST
I'm a psychologist and researcher at the [Software Stewardship Lab](https://stewardshiplab.org/). Moved by the extent of burnout among Open Source developers, I have written what I believe to be the most comprehensive report to date on burnout in Open Source. This entailed a review of the academic literature, a qualitative analysis of online discussion in the OSS community, and interviews with OSS maintainers.

I present 5 factors my research identified that contribute to developer burnout: difficulty getting paid, workload and time commitment, maintenance work as unrewarding, toxic community behaviour and hyper-responsibility. I discuss 3 structural changes we can make to address developer burnout: make it easier for OSS developers to get paid, distribute maintenance responsibilities, and strengthen developer community, solidarity and capacity for advocacy. Finally, I preview the findings of a follow-up study I am currently undertaking exploring the impact of the rise of AI coding on OSS developer burnout, including where it is exacerbating existing causes of burnout, and where it might help alleviate them.
Speakers
avatar for Miranda Heath

Miranda Heath

Director and Researcher, Software Stewardship Lab
Director and researcher at the Software Stewardship Lab, an applied research non-profit dedicated to ensuring the stability of the Open Source software ecosystem. I research burnout in Open Source, investigating the structural issues that put developers at risk of burnout and how... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Conference Hall (Floor 4)

11:55 CEST

From Vulnerability Debt To Autonomous Remediation: Building a Self-Healing Container Image Pipeline - Priyanka Bettadapura, Microsoft
Friday October 9, 2026 11:55 - 12:35 CEST
Managing vulnerabilities across large fleets of container images remains a persistent challenge in cloud-native environments. In our platform, patching a single critical image often required several engineer-days of manual effort, creating remediation backlogs and compliance risk.
To address this, we built a self-healing vulnerability remediation pipeline using open source technologies across the container lifecycle. This session presents the architecture behind the system, including automated dependency updates with Dependabot, reproducible image rebuilds with DALEC, continuous OS-level patching using Project Copacetic, and deployment validation through staged rollout pipelines.
We will share the engineering decisions, trade-offs, and lessons learned while reducing remediation time from days to minutes and eliminating approximately 90% of manual patching effort. We will also discuss integrating an AI-assisted remediation agent for complex fixes and the safeguards used to validate and govern AI-generated changes in production environments.
Speakers
avatar for Priyanka Bettadapura

Priyanka Bettadapura

Senior Software Engineer, Microsoft
Priyanka Bettadapura is a Software Engineer at Microsoft focused on cloud-native security, platform engineering, and software supply chain resilience. Her work centers on automating vulnerability remediation for containerized workloads through reproducible builds, dependency management... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Club E (Floor 1)

11:55 CEST

A Safety BOM Is a Contract: Producing and Consuming the SPDX Functional Safety Profile - Tobias Kästner, inovex GmbH & Nicole Pappler, AlektoMetis
Friday October 9, 2026 11:55 - 12:35 CEST
SPDX 3.1's Functional Safety profile recently grew to model a safety case end to end: requirements and their refinement, verification, pass/fail evaluations, evidence, and assumptions of use. It standardizes how a safety case is exchanged, but not how one is produced, nor what a consumer does with one received. We demonstrate SEGkit, a prototype, open-source, project-agnostic engine that extracts a design and evidence graph from content repositories to recompute a verdict over the graph—a judgment recomputed from content, not merely recorded—and detects which evidence goes stale as code evolves; in this talk we also show how we plan to use it within Zephyr to automate safety evidence creation. This makes SEGkit interesting to projects maintaining their safety BOM as well as downstream users who want to work with one. For the latter case we argue a received BOM is best consumed as a contract—its requirements and evidence being guarantees and its assumptions the conditions the consumer must discharge against its own case. Lastly, we talk about what the profile might add for machine-checkable discharge: assumptions as checkable conditions, linked to the guarantees they constrain.
Speakers
avatar for Nicole Pappler

Nicole Pappler

Senior Safety Expert, AlektoMetis.com
Nicole has worked in different projects developing safety relevant embedded software before starting as an independent assessor.
With now more than twenty years of experience in the industry, she supported several customers to show their compliance with safety, security and quality standards. Currently she is utilizing her experience regarding the development of highly reliable software to enable open source... Read More →
avatar for Tobias Kästner

Tobias Kästner

Safety Architect, Zephyr Project, inovex GmbH
A physicist by training, Tobias Kaestner has long been fascinated by where the physical and digital worlds meet. He began as a software team lead in a medical device start-up and has since spent 15+ years in the industry. As a solution architect for Medical IoT at inovex GmbH he helps... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Club A (Floor 1)
  Safety-Critical Software

11:55 CEST

Libiio on Zephyr: A Unified API for Industrial I/O Across Linux and RTOS Targets - Maureen Helm & Pete Johanson, Analog Devices
Friday October 9, 2026 11:55 - 12:35 CEST
libiio is an open source C library developed by Analog Devices for interfacing with Industrial I/O (IIO) devices - ADCs, DACs, IMUs, RF transceivers, temperature sensors, and more. It underpins a broad ecosystem of host-side tools including Scopy, pyadi-iio, and MATLAB, all of which connect to targets over network, serial, or USB transports.

This talk walks through the architecture and practical mechanics of the port. We will cover how libiio's external backend integrates with Zephyr's device model, allowing any driver that implements the IIO device driver API to appear as a first-class IIO device. We will look at built-in bridge drivers that wrap any Zephyr ADC, DAC, or sensor device into an IIO device. We will also cover how the module integrates into the Zephyr build system using Kconfig, device tree, and snippets to enable libiio with minimal changes to an application.

We will demonstrate a Zephyr board being queried from Scopy and pyadi-iio, and close with a look at what is in progress - trigger support for deterministic sampling and streaming, and a USB transport as a complement to the existing UART and network transports.
Speakers
avatar for Maureen Helm

Maureen Helm

Distinguished Engineer, Analog Devices
Maureen Helm is a Distinguished Engineer in the Software & Digital Platforms Group at Analog Devices, focusing on embedded microcontroller software. She is an upstream maintainer in the Zephyr Project and former chair of the Technical Steering Committee.
avatar for Pete Johanson

Pete Johanson

Principal Engineer, Embedded Software, Analog Devices
Pete Johanson is an engineer with 25 years of diverse experience in healthcare IT, RESTFul APIs, and more recently embedded software with a focus on Zephyr RTOS.

His role on the Zephyr Factory team at Analog Devices allows him to focus on Zephyr RTOS, including sitting on the Zephyr TSC. In his personal time, Pete is the creator and lead of the ZMK firmware, an open source keyboard firmware built on Zephyr... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

11:55 CEST

Measuring What Matters: Introducing Hardware Performance Counters in Zephyr RTOS - Kedareswara Rao Appana, AMD
Friday October 9, 2026 11:55 - 12:35 CEST
Embedded developers optimizing Zephyr applications often rely on software timers and GPIO toggles—intrusive techniques that alter the behavior they try to measure. Modern SoCs instead provide rich hardware performance counters across the system: CPU PMUs, interconnect/NoC monitors, and memory subsystem telemetry that capture cycles, cache behavior, bandwidth, and contention with near-zero overhead. Until now, Zephyr lacked a unified way to access these metrics.

This talk introduces Zephyr’s new portable **pmu.h** API, a cross-architecture abstraction for hardware performance monitoring. We present the first backend: an ARMv8-A PMUv3 driver that probes counters at runtime, self-calibrates CPU frequency, and maintains per-CPU state using IRQ-locked sequences for SMP safety.

Using real hardware benchmarks, we show how to measure context-switch cost, IRQ latency, cache behavior, branch prediction, and memory bandwidth. Attendees will learn how to add low-overhead profiling to their applications today and how the API will extend to RISC-V HPM, Cortex-M DWT, and SoC-level monitors without changing application code.

Pull request: https://github.com/zephyrproject-rtos/zephyr/pull/107016
Speakers
avatar for Kedareswara Rao Appana

Kedareswara Rao Appana

Member of Technical Staff, AMD
Device driver developer (linux and Baremetal), Expertise on the ARM, Microblaze and Microblaze Risc-v processors, Zephyr OS and System device-tree concepts and Lopper tool, Contributed to open source Linux Up streamed CAN and Xilinx DMA drivers and contributed to axi ethernet and... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

12:15 CEST

The Hard Limits of a (de)-centralized OSPO - Sebastian Grüner, E.ON Digital Technology & Benjamin Rilz, E.ON Digital Technology GmbH
Friday October 9, 2026 12:15 - 12:35 CEST
Starting up an OSPO is not an easy task - let alone for 300+ companies. That's the scale and problem space we face in the highly federated and distributed enterprise of E.ON.

One of Europe's biggest energy utility provider has it all: critical infrastructure, regulations, services for millions of customers, purpose built hardware, SaaS businesses, an unfathomable amount of suppliers and engineers all over the place.

So before we could even start with our own ideas about the OSPO management we needed to get a hold of the status quo at E.ON for any kind of engineering and business operations. Two years after starting the OSPO we're far from done doing that yet, but we already established quite a bunch of successful initiatives.

We'll present our idea of an Hub-and-Spoke-OSPO, targeted initiatives for distinct parts of the business, curing pain points, building recurring collaborations within the enterprise and how to become more visible as 2-person-OSPO with nearly 80.000 coworkers.
Speakers
avatar for Sebastian Grüner

Sebastian Grüner

Open Source Consulting Manager, E.ON Digital Technology
Leads the OSPO initiative at the IT subsidiary of E.ON, helping transform our grid for a carbon neutral future. Before that he worked 13 years as a journalist and editor covering Open Source - technology and software as well as the sociopolitical influence of the projects and their... Read More →
avatar for Benjamin Rilz

Benjamin Rilz

Junior Tech Consultant, E.ON Digital Technology GmbH
I work in the Open Source Program Office at E.ON Digital Technology GmbH, where I focus on connecting the Open Source ecosystems with practical business needs in the energy sector. I have already attended several Linux Foundation conferences, but I haven’t given a talk yet. In this... Read More →
Friday October 9, 2026 12:15 - 12:35 CEST
South Hall 1 A (Floor 1)

12:15 CEST

A Tour of the New EKF2 - Mathieu Bresciani, Auterion
Friday October 9, 2026 12:15 - 12:35 CEST
EKF2 is the heart of PX4's navigation, and over the past few years it has quietly received a series of improvements that make it more accurate, more robust, and easier to work with. In this talk I'll walk through the most significant ones. We'll start with a short recap of the filter's architecture, then cover the move to a proper error-state formulation, along with its symbolic derivation and code generation using SymForce. We'll then see how this makes it easy to add a new state or measurement, as we did for the terrain state. From there we'll turn to round-earth navigation, paired with a position-dependent gravity model, which replaces the flat-earth assumptions to support long-range and high-latitude flight. We'll also look at how the Joseph-stabilized covariance update not only makes the filter more numerically stable, but also lets us perform partial updates, which we rely on heavily in the magnetometer and optical-flow fusion. Finally, we'll look ahead at the next changes coming to EKF2 and some of the ideas we're exploring.
Speakers
avatar for Mathieu Bresciani

Mathieu Bresciani

Staff GNC Engineer, Auterion
Mathieu Bresciani is a Flight Control Engineer specialized in Guidance, Navigation and Control (GNC). Currently working at Auterion for the last 8 years, Mathieu spends most of his time improving and developing flight control algorithms for PX4. Member of the PX4 Dev Team, Mathieu... Read More →
Friday October 9, 2026 12:15 - 12:35 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

12:35 CEST

Lunch (Provided Onsite for All Attendees)
Friday October 9, 2026 12:35 - 14:00 CEST

Friday October 9, 2026 12:35 - 14:00 CEST
TBA

14:00 CEST

Lightning Talk: 97% of MCP Tools Have Quality Defects & Here's How We Measured Them - Om Shree, Shreesozo
Friday October 9, 2026 14:00 - 14:10 CEST
Silent failures in MCP tool invocation aren't random. They trace back to a single root cause: tool descriptions that are too vague for agents to reliably select the right tool.
A SAIL Research study of 856 tools across 103 MCP servers found 97% have at least one quality defect, 56% fail to clearly state what the tool does, and 89% provide no guidance on when not to use it. A second study of 10,831 servers confirmed that well-written descriptions get selected 260% more often, improving task success rates by ~6 points.
Working with the Glama founder, I developed TDQS (Tool Definition Quality Score) : an open-source framework scoring MCP tools across six dimensions: Purpose Clarity, Usage Guidelines, Behavioral Transparency, Parameter Semantics, Conciseness, and Contextual Completeness.
This talk covers how TDQS was built, what scoring thousands of real-world servers revealed, and how the open-source community can adopt it as a quality standard for MCP tool authorship.
Speakers
avatar for Om Shree

Om Shree

Founder & MCP Infrastructure Researcher, Shreesozo
I'm the founder of Shreesozo, an AI content studio focused on MCP and agentic AI. I've written 100+ technical pieces for Glama.ai and Gentoro, covering everything from protocol internals to real-world agent deployments. I run MCP Weekly, published on YouTube (1.2K subscribers) and... Read More →
Friday October 9, 2026 14:00 - 14:10 CEST
Forum Hall (Floor 2)
  Open AI & Data

14:00 CEST

OpenChain in Central and Eastern Europe: Year One - Vladimir Slavov & Nikola Babadzhanov, Bosch
Friday October 9, 2026 14:00 - 14:20 CEST
One year ago, we created the OpenChain Meridian 22 Work Group for Central and Eastern Europe. In this year, our community has grown to include members from Poland, Hungary, Finland, Romania, Bulgaria, Greece, and other countries. We promoted OpenChain and our WG formally at open source and security events in Serbia, Slovenia, and Bulgaria, and informally in other parts of Europe and the world. We work in close collaboration with other open source communities to organize free events across Europe.

This talk is a retrospective on this past year of expanding the OpenChain community in the region. We will showcase the interesting topics we focus on in our WG, and share the lessons we learned along the way. We would like to use the talk to promote the WG locally.

The first part of the talk will focus on the journey: how we launched the OpenChain Meridian 22 WG, our promotion activities, and the topics we have tackled so far.

The second second part, about the takeaways: what makes this region special, why we received attention mostly from security communities, and other such curiosities.

The last part will be an overview of the co-located event we are organizing with the community.
Speakers
avatar for Vladimir Slavov

Vladimir Slavov

Open Source Consultant, Bosch
Vladimir is a lawyer and a programmer. He works at Bosch's Open Source Program Office, focusing on open source management and compliance. He is an AWS Certified Solutions Architect Associate, an AWS Certified AI Practitioner, and an AWS Certified Cloud Practitioner. He co-chairs the... Read More →
avatar for Nikola Babadzhanov

Nikola Babadzhanov

Open Source Management Consultant, Bosch
Nikola Babadzhanov, a Bosch Open Source Consultant since 2022 and a member of the Bosch OSPO, focusing on software and Open Source management. He expertly applies his FinTech regulatory compliance experience to the unique challenges of Open Source compliance.

Formerly the chair of a Bosch group on secure and compliant containers, Nikola is a dedicated OpenChain Ambassador, a committer on the Eclipse Apoapsis project, and an active member of the OpenChain SBOM, AI, and Tooling work groups... Read More →
Friday October 9, 2026 14:00 - 14:20 CEST
South Hall 1 A (Floor 1)

14:00 CEST

Adding ESP32/Xtensa Silicon and Custom Boards To PX4 - Henry Kotzé, AutonoSky
Friday October 9, 2026 14:00 - 14:20 CEST
This talk will introduce a new MCU architecture that PX4 only recently supported: the Xtensa ESP32. Using it as a walk-through, we'll demonstrate the software components needed to add your own custom board, contribute to or expand existing MCU architecture support, and highlight how PX4's compile process is designed to be agnostic to the underlying MCU architecture.

Some highlights will be:
How PX4 interacts with NuttX at a low level, and why that relationship is central to bringing up new hardware

The role of the High Resolution Timer (HRT) in PX4's timekeeping, and what it takes to implement it for a new architecture

The difference between Menuconfig and boardconfig, and when to use each when defining your board's peripherals and pin allocation

How PX4's build system sets up the compilation environment for NuttX, and how to configure it for your specific board

How PX4 is designed to be MCU-agnostic, and what that means in practice when working at the boundary between PX4 and NuttX
Speakers
avatar for Henry Kotzé

Henry Kotzé

Lead Engineer, AutonoSky
Henry, from South Africa, holds an MSc in augmenting classical controllers with neural networks and aims to specialise in control systems and estimation. He has implemented airship controllers in PX4 and now works at Autonosky on drone solutions for GPS-denied environments. In his... Read More →
Friday October 9, 2026 14:00 - 14:20 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

14:00 CEST

Container Metrics on Diverse Hardware: Driving Observability, Efficiency, and Real-Time Autoscaling - Sambhav Jain & Digvijay Singh Shekhawat, Uber
Friday October 9, 2026 14:00 - 14:40 CEST
Uber runs about 4 million containers on over 150,000 hosts. Our fleet includes a mix of cgroupv1 and v2 hosts, multiple cloud providers, and multiple Linux kernel versions. Tracking container performance at this massive scale is a difficult engineering challenge, including the cost of storing them. We currently process 60 million data points every second to keep everything running smoothly.

We run Cadvisor and open-source Nvidia and AMD GPU metrics exporters to reliably and affordably collect and store these metrics. This infrastructure is vital for our real-time autoscaling, which ensures our services stay online. We also use these metrics to track memory usage and keep costs low for our AI workloads. Despite maintaining all the critical use cases, we have saved around $ 4 million compared to last year by changing how we collect and store data.

We will share how we use these metrics to detect and prevent system failures before they affect users. Attendees will learn practical patterns for operating container metrics at scale. We will also discuss the hard lessons we learned while building a reliable metrics system for a complex global fleet.
Speakers
avatar for Sambhav Jain

Sambhav Jain

Software Engineer, Uber
Sambhav Jain currently works as a Software Engineer at Uber on the container runtime team. Primarily working on container resource metrics and distributed container registry systems at Uber.
Before Uber, Sambhav worked at Cockroach Labs in the Database Performance team and at Confluent in the Kafka Connect team... Read More →
avatar for Digvijay Singh Shekhawat

Digvijay Singh Shekhawat

Software Engineer, Uber
I've always loved solving problems. As a kid, that passion started with mathematics, which led me to competitive programming and eventually computer science.

At Uber, I was one of the founding engineers on the AI Solutions team, helping build Uber's new gig platform from the gr... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

14:00 CEST

Why We Fixed It Upstream: A Telco Perspective - Kashif Khan, Ericsson & Jan Melen, Ericsson Software Technology
Friday October 9, 2026 14:00 - 14:40 CEST
Working in telco infrastructure means regulatory compliance isn't optional. When a CVE drops, we can't wait a quarter. We can't backport locally. We have to fix it upstream, and we have to do it fast. This constraint forced us to ask harder questions about how we collaborate with open source projects.

At Ericsson we maintain bare metal Kubernetes using Metal3, Cluster API, and Ironic. Over the past few years, we've learned that regulatory pressure actually makes us better engineers. It forced us to build real relationships with upstream maintainers, contribute more thoughtfully, and think long term instead of short term.

This talk explores what changed in how we work with upstream projects when we couldn't carry local patches. We'll talk about the specific practices that work when your infrastructure depends on fast, reliable upstream collaboration. You'll hear about what changed in how we communicate with maintainers, how we structure our releases, and what we learned about contributing upstream that applies whether you're bound by regulation or not.
Speakers
avatar for Kashif Khan

Kashif Khan

Maintainer | Co-Chair CNCF TAG Infrastructure | Principal Open Source Architect, Ericsson
Kashif Khan is a co-chair of CNCF TAG Infrastructure and maintainer of the CNCF project Metal3.io for 6 years. He works as an open source Architect for Ericsson Software Technology, Finland. He holds a PhD in Computer Science. Kashif is a research and open source enthusiast and his... Read More →
avatar for Jan Melen

Jan Melen

General Manager, Ericsson Software Technology
Jan Melén is an expert in networking, open-source software, and cloud technologies, with a career spanning over two decades. He is a staunch advocate for Free and Open-Source Software (FOSS) adoption within Ericsson and the broader community he engages with.

Since 2019, Jan has led a team dedicated to CNCF open-source projects, contributing to Ericsson's K8s distribution, and fostering an "upstream-first" culture. He oversees Ericsson’s open-source contributions and collaboration with CNCF... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club H (Floor 1)
  Digital Trust

14:00 CEST

Buildroot at 25: A Quarter Century of Making Embedded Linux Easy - Peter Korsgaard, Barco
Friday October 9, 2026 14:00 - 14:40 CEST
Buildroot started in 2001 with the goal of having a simple and easy way to build embedded Linux systems. Now, 25 years later the size and complexity of embedded Linux systems have increased dramatically and so have the required features of the build system, but the goals are still the same.

This talk celebrates Buildroot's 25th anniversary by exploring the project evolution, the community that shaped it and the technical decisions that enabled it to remain relevant for modern projects before finishing up with some thoughts about what the future may bring.

Attendees will gain both a historical perspective, insight into how Buildroot is developed and a view to what lies ahead.
Speakers
avatar for Peter Korsgaard

Peter Korsgaard

Senior Expert Embedded Development Engineer, Barco
Peter is an embedded Linux developer and long time Buildroot maintainer with 20+ years of experience
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

14:00 CEST

Embedded in RISC-V: One Year of Android, Yocto, and Beyond - Trevor Gamblin & Guillaume La Roque, BayLibre
Friday October 9, 2026 14:00 - 14:40 CEST
The RISC-V ecosystem is maturing so rapidly that it's often hard to keep track, especially in the world of embedded systems. Now that RISC-V platforms meeting the "general-purpose" RVA23 specification - which mandates the vector and hypervisor extensions, among others - are available, this rate of change will only increase. We've been working hard on supporting RISC-V from the bottom up through Android, the Yocto Project, the Linux kernel, and we've even helped enable the Python ecosystem for AI at the edge. We want to share our experiences with our peers so that they can help contribute, avoid common pitfalls, and build great projects with our favorite new computer architecture. To do so, we'll cover everything we've done over the past year, what we're most excited about, and where we think the most challenging aspects of supporting RISC-V in embedded systems remain. We hope that this will be an inspiring roadmap for others looking to join the RISC-V community on its journey forward.
Speakers
avatar for Guillaume La Roque

Guillaume La Roque

Embedded Linux/Android Developer, BayLibre
I'm an Embedded Software Engineer at BayLibre, working on low-level systems software such as Linux, Android, and U-Boot. I focus on board bring-up and platform support, from the bootloader to the kernel, with a growing interest in RISC-V.
avatar for Trevor Gamblin

Trevor Gamblin

Senior Software Engineer, BayLibre
Trevor Gamblin is an embedded Linux developer at BayLibre. He is a contributor to many projects but is especially focused on the Yocto Project, the Linux kernel, and the RISC-V ecosystem. He has a background in wireless communication systems and physics.
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

14:00 CEST

The Journey of Adding Hardware Support To Mainline - Sven Püschel, Pengutronix
Friday October 9, 2026 14:00 - 14:40 CEST
Since v4.15 the kernel has support for the second version of the Raster Graphic Acceleration (RGA) IP core of Rockchip SoCs.
The newer RK3588 SoC additionally ships two RGA cores with version 3 and so I was tasked to extend the driver to support them.

7 months and 7 patch series versions later the driver was merged in Linux v7.2.

The talk walks through my journey to getting my first driver upstream. It shows where I had understood things the wrong way, where I've tried to do too much and where I've had to invest more work. Spiced up with some anecdotes about erroneous manuals, erratic hardware behavior and errors which only arise under load.

The talk is intended for beginners who are interested in doing mainline work. Besides showing the effort required and the frustrating moments, I want to encourage putting in the effort and showcase some of the nice solutions it has produced.
Speakers
avatar for Sven Püschel

Sven Püschel

Software Engineer, Pengutronix
Sven Püschel is an open-source developer working part-time at Pengutronix since 2024.
He supports customers to achieve their goals using popular open source software
and bringing the necessary additions for the customer use-case to upstream.
From adding Wayland protocols down to... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

14:00 CEST

Keeping Track of Resources in the Kernel - Overview and Pitfalls of Resource Management Mechanisms - Bartosz Golaszewski, Qualcomm
Friday October 9, 2026 14:00 - 14:40 CEST
While C is a spartan language by design and, as such, doesn't offer any automatic memory management, the linux kernel over the years has acquired several mechanisms that attempt to make it easier for developers to keep track of resources and control their lifetime.

These mechanisms use C compiler extensions for scope-based memory management, count object references, or rely on control flow provided by the lower-level subsystem code. They can also be an arbitrary mixture of multiple approaches.

As the C compiler by definition is unable to enforce ownership or reference counting and scope correctness, the users of these helpers must still leverage them correctly and respect the API contract.

The kernel has struggled with object lifetime issues for decades now and, while there are legitimate issues with the design of certain subsystems, some of these issues resulted from incorrect use of the kernel resource management APIs. A good example of this is scheduling devres actions for devices that will never be bound to drivers.

This talk will present different resource management mechanisms in the kernel along with examples of how to use them correctly and what mistakes to avoid.
Speakers
avatar for Bartosz Golaszewski

Bartosz Golaszewski

Linux Kernel Engineer, Qualcomm
Bartosz Golaszewski has over 16 years of engineering experience in the embedded systems domain ranging from low-level, real-time operating systems, through the linux kernel up to user-space plumbing, libraries and build systems. Bartosz has contributed hundreds of patches to a wide... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Panorama Hall (Floor 1)
  Linux

14:00 CEST

The Foundational Misnomer Hiding in Plain Sight - Powen Shiah, Sovereign Tech Agency
Friday October 9, 2026 14:00 - 14:40 CEST
"Foundation" is a word that carries weight: endowments, permanence, institutional resources. In the philanthropic world, foundations often have millions or billions in their endowments. In open source, the same word describes organizations that range from trademark holders and event hosts to genuine funders of development work.
That gap between expectation and reality matters. When developers, companies, and governments hear "foundation," many assume someone already has it covered. That assumption is one reason so many critical open source projects remain underfunded: the name signals security that often doesn't exist.
This talk unpacks the spectrum of what open source foundations actually do and don't fund, why the word creates a misleading picture of available resources, and what genuine infrastructure funding looks like in practice. Drawing on the work of the Sovereign Tech Agency, which funds critical open source projects and the ecosystem infrastructure sustaining them, this session offers a clearer picture of where the money is, where it isn't, and what that means for the long-term health of open source.
Speakers
avatar for Powen Shiah

Powen Shiah

Communications Lead, Sovereign Tech Agency
Powen handles communications at the Sovereign Tech Agency, highlighting the importance of open source digital infrastructure and the government's role in supporting it in the public interest. He’s worked in product marketing, communications, and internationalization in technology... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Terrace 2A (Floor 2)
  Open Source 101
  • Audience Experience Level Any

14:00 CEST

Sustainable Communities - Risks and Remedies - Ildiko Vancsa, OpenInfra Foundation
Friday October 9, 2026 14:00 - 14:40 CEST
Whether you care about open source projects for the success of your business or to retain your basic human right to access digital technology, it is in your interest to understand the risks these communities face and what you can do to mitigate them.

This presentation will provide you with a list of risk factors, from bad practices to mindset, that imapct the sustainability of open source communities. The talk will provide details of studies and real-life experiences to outline why certain behaviors, practices and approaches, most often without any bad intentions, are harmful to the open source ecosystem.

You will also receive tools and actionable steps to improve the sustainability of the open source projects you care about. The session will also give you ideas how to implement practices into your workflow, whether you are relying on open source software as a buiness or as an individual.
Speakers
avatar for Ildiko Vancsa

Ildiko Vancsa

Director of Community, OpenInfra Foundation
Ildikó is working for the OpenInfra Foundation as Director of Community. She is the Community Manager for the StarlingX and the Kata Containers projects, and a co-leader of the OpenInfra Edge Computing Group. Ildikó is an evangelist of open collaboration and is using her experience... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Conference Hall (Floor 4)

14:00 CEST

The PVC Must Die: How a Workflow Engine Rethought Data Sharing With Trusted Artifacts - Vincent Demeester, Red Hat
Friday October 9, 2026 14:00 - 14:40 CEST
When a CI/CD pipeline runs each step as a separate Kubernetes Pod, those Pods need a way to pass data to one another. Tekton chose the obvious Kubernetes-native answer: a shared persistent volume. Clone code in step one, build it in step two, both read from the same disk. Simple.

It wasn't. Shared volumes meant pinning Pods to the same node, which broke autoscaling. Users hit storage limits, leaked volumes after failures, and spent more time debugging infrastructure than building pipelines. Each fix created new edge cases.

Then a different question: what if steps didn't share a disk at all? What if each step uploaded what it produced, and the next downloaded and verified it, with cryptographic hashes at every handoff? That's Trusted Artifacts. The shared volume disappears, and in its place you get a verifiable chain of trust: every handoff is hashed, signed, and traceable. A storage problem became a security feature.

This talk traces that journey: the design that seemed right, the years of workarounds, and the moment the team stopped fixing the plumbing and rethought the architecture. It's for anyone who's wondered whether to keep patching a leaky abstraction or tear it out.
Speakers
avatar for Vincent Demeester

Vincent Demeester

Senior Principal Software Engineer, Red Hat
I'm a french developer 🐻, Gopher 🐹, sysadmin 🐺, factotum 🦁, free-software fan 👼 and unicode lover 🐸. I'm working at Red Hat 🎩 as a senior principal software engineer, previously at Docker 🐳 and Zenika 🐯. I am a maintainer of the docker project (moby/moby... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club E (Floor 1)

14:00 CEST

Let's Perform a Hazard Assessment! - Chuck Wolber, The Boeing Company & Pete Brink, Underwriter Laboratories (UL)
Friday October 9, 2026 14:00 - 14:40 CEST
A hazard assessment is “a process that allows the identification and evaluation of potential hazards related to [...] system function regardless of the details of its implementation” (SAE ARP4761A, section C.1). The outcome of a hazard assessment has far-reaching consequences for overall project design and the degree of engineering rigor required during development. In this session, Chuck will take the audience through a hazard assessment exercise based on a simplified model and describe the effects of the assessment on the design and development process. In addition to exposing the audience to a relatively simple but rigorous method for thinking about failure conditions during design, Chuck will also touch on gaps in non-safety-critical software engineering that can benefit from best practices developed by the safety engineering community.
Speakers
PB

Peter Brink

Functional Safety Engineering Leader, Underwriter Laboratories (UL)

avatar for Chuck Wolber

Chuck Wolber

Associate Technical Fellow, The Boeing Company
Chuck Wolber is a Boeing Associate Technical Fellow primarily focused on embedded platform engineering. He has developed multiple DO-178C certified Linux platforms currently in service on Boeing production aircraft. Chuck is co-author of the book Linux Toys, he is credited with contributions... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

14:00 CEST

Amalgamation - Tom Burdick, Infineon Technologies
Friday October 9, 2026 14:00 - 14:40 CEST
Amalgamation is a build strategy used by projects like sqlite3 that combines C sources files into a single source file for various reasons. One such reason is to give the compiler greater visibility across the program for performance gains. sqlite3 claims 5-10% net performance gains in doing so.

Does applying the technique to parts of Zephyr net us any gains? If so why and where, and what are the trade offs involved?
Speakers
avatar for Tom Burdick

Tom Burdick

Principal Software Engineer, infineon Technologies
I've been involved in the Zephyr project for close to 8 years now. I started as someone looking for a faster way to get BLE working for a product, finding Zephyr to make this trivial compared to the vendor SDK at the time. I spent the prior 5 years at Intel working to make Zephyr... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

14:00 CEST

Multiple Cores, One Zephyr: The Path To Cortex-M SMP in Zephyr - Sanjay Vallimanalan, Linumiz
Friday October 9, 2026 14:00 - 14:40 CEST
Multi-core ARM Cortex-M SoCs are becoming increasingly common in today's market. Yet Zephyr RTOS only supports Asymmetric Multiprocessing (AMP) for these devices. The problem with AMP is that it limits true resource sharing, and leaves hardware parallelism underutilized. Symmetric Multiprocessing (SMP) addresses these issues by running a single Zephyr RTOS image with a unified scheduler across all cores. Zephyr RTOS currently lacks support for Symmetric Multiprocessing on ARM Cortex-M based SoCs and hence limits multi-core Cortex-M devices to AMP configurations. This talk presents a Proof-of-Concept implementation of SMP on Dual Core Cortex-M7 cores using the Infineon Traveo T2G (CYT4DN) SoC which runs a single Zephyr image with true parallel execution across cores.

The key framework challenges are: lack of a secondary boot up path for the secondary cores and the complications of unified timekeeping with per-core SysTick timers.

The talk details what has been achieved, the limitations that remain in timeout-driven context switching and scheduling, and outlines a path toward upstream-ready Cortex-M SMP support in Zephyr.
Speakers
avatar for Sanjay Vallimanalan

Sanjay Vallimanalan

Embedded Software Engineer, Linumiz
Sanjay Vallimanalan is an embedded software engineer with experience in Embedded Linux and real-time operating systems. He is currently working with technologies such as Yocto, Zephyr RTOS, and board support package development for embedded devices.
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

14:10 CEST

Lightning Talk: Real Observability for Self-Hosted LLMs on Ubuntu - Shardul Deshpande, Canonical
Friday October 9, 2026 14:10 - 14:20 CEST
Running LLMs near devices or in constrained edge environments changes the observability problem. A small model can answer successfully while still being unusable: first token arrives too late, prompts burn scarce CPU/RAM budget, output is malformed, or gateway/model-selection errors hide behind green Linux and container metrics.

This session walks through a reproducible, CPU-first Ubuntu demo for resource-constrained self-hosted LLMs. It uses small Ollama models (llama3.2:1b and qwen3.5:2b) on the same CPU workload with MicroK8s, Juju, COS Lite, Tempo, a FastAPI OpenAI-compatible gateway, and Canonical's Charmed OpenTelemetry Collector. The gateway emits OpenTelemetry GenAI spans, metrics, and trace-correlated logs; Prometheus, Loki, Tempo, Grafana, and Alertmanager turn them into an LLM golden-signals view.

Using recorded normal, slow, expensive, error, and low-quality scenarios, attendees will see how time-to-first-token, token usage, traces, alerts, and quality signals reveal whether a local model is useful within tight compute constraints. The model comparison shows why embedded and edge AI decisions need measured latency/cost/quality trade-offs, not just 'the model runs.'
Speakers
avatar for Shardul Deshpande

Shardul Deshpande

Software Engineer, Observability Stack, Canonical
Shardul Deshpande works at Canonical on the Observability Stack (COS), building practical demos around observability, Kubernetes, and self-hosted AI infrastructure. His work connects Ubuntu, MicroK8s, Juju, OpenTelemetry, and Grafana-based operations so teams can measure whether AI... Read More →
Friday October 9, 2026 14:10 - 14:20 CEST
Forum Hall (Floor 2)
  Open AI & Data

14:20 CEST

7 MCP Servers, 50+ Tools, Zero Duplicate Code: A 5-Minute Architecture Tour - Harika Chebrolu, IBM
Friday October 9, 2026 14:20 - 14:30 CEST
We had a problem: every new integration meant writing the same code twice—once for our React dashboard, once for our AI assistant. JIRA, TestRail, Jenkins, GitHub—the duplication was unsustainable.

MCP changed everything. In this lightning talk, I'll show how we built 7 MCP servers that now power both our dashboard AND our AI agents from a single source of truth. 50+ tools, used daily by Dev, QE, and Management teams.

In 5 minutes, you'll see:

- The architecture: FastAPI as a unified backend → MCP Servers → External APIs (JIRA, TestRail, Jenkins, GitHub, GSheets, Release Calendar, Risk Predictor)
- The pattern: Thin MCP tools that call centralized APIs—one integration, two consumers
- Real metrics: 10+ hours/week saved per engineer; release tracking, regression monitoring, and production health checks unified.
- Why MCP wins: AI agents and dashboards evolve independently while sharing the same data layer.

We eliminated duplicate code, reduced maintenance burden, and shipped faster. All code is open source.
Speakers
avatar for Harika Chebrolu

Harika Chebrolu

Software Engineer | Multi-Agent Systems, IBM
Harika Chebrolu is a software engineer building autonomous systems for infrastructure operations. She architected a multi-agent platform managing 200+ storage nodes and extracted MCP servers for safe, interoperable infrastructure tooling. Her open-source work includes multi-agent... Read More →
Friday October 9, 2026 14:20 - 14:30 CEST
Forum Hall (Floor 2)
  Open AI & Data

14:20 CEST

Are Open Source Licenses for AI Models a Hallucination? - Jimmy Ahlberg, Ericsson & Eleftheria Stefanaki, Nokia Technologies
Friday October 9, 2026 14:20 - 14:40 CEST
For decades, the Open Source Software world has run on a simple, elegant legal hack: standard open-source licenses (like GPL, BSD, or Apache 2.0) use copyright law to enforce openness and collaboration. But as the industry shifts to AI models are we are hitting a catastrophic legal wall? AI models and weights aren't code, they aren't traditional "data" either. Is the licensing regimes we have been reliant on for so long no longer an adequate solution for how to license AI Models and wights when we want to make them available and keep them as Open Source, and if so why do we keep on licensing them this way?

This panel hopes to brings together experts from various fields and industries to discuss some of the challenges and potential risks you may run into then using or sharing AI models and wights under Open Source licenses, and explore some high level ideas of what mechanisms could be used instead of "traditional" Open Source licenses to keep the openness and collaboration we all depend on to further innovation.
Speakers
avatar for Jimmy Ahlberg

Jimmy Ahlberg

Expert & Senior Legal Counsel, Ericsson
Currently Mr Ahlberg is the Director of Open Source Policy with the Ericsson OSPO. Prior to the inception of the Ericsson OSPO he worked in different roles with various aspects of Open Source in the Ericsson organization, This included consumption of and contribution to Open Source... Read More →
avatar for Eleftheria Stefanaki

Eleftheria Stefanaki

FOSS Legal Counsel, Nokia Technologies
I am a lawyer from Greece, specialized in technology and passionate about open source. I have started my 'open source journey' in Ericsson, assisting and participating in the activities and day-to-day of the OSPO since 2022. Currently, I am the FOSS Legal Counsel for Nokia Technologies... Read More →
Friday October 9, 2026 14:20 - 14:40 CEST
South Hall 1 A (Floor 1)

14:20 CEST

PX4 on Open Silicon: Flight Control and AI Workloads on Multi-Core RISC-V - Afonso Oliveira, AiNekko
Friday October 9, 2026 14:20 - 14:40 CEST
While PX4 is open source, the underlying hardware often remains tied to proprietary vendor black boxes. This creates a gap for PX4 developers and sovereignty-sensitive applications that need an inspectable full stack all the way down to silicon.

This session presents CORE-ET, a fully open-source RISC-V platform that can scale from a 16-hardware-thread Erbium configuration to systems with more than 2000 cores. We will show a simulation demo of Erbium running PX4 alongside onboard AI: PX4/control runs on two hardware threads, while the remaining 14 run workloads such as vision, depth, VIO, or object detection.

We will discuss the porting structure, real-time capabilities, and measurements needed to show flight control running alongside local inference. The result is a path toward drones where both software and hardware are open and inspectable.
Speakers
avatar for Afonso Oliveira

Afonso Oliveira

Computer Engineer, AiNekko
Building RISC-V systems across specs, boot ROMs, HALs, emulators, firmware, RTOS, and OS. Currently at Ainekko, working full-stack on custom RISC-V AI accelerators. Previously at Synopsys, contributed to RISC-V tooling, specifications, Zephyr support, and ML quantization research... Read More →
Friday October 9, 2026 14:20 - 14:40 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

14:50 CEST

The PX4 Airspeed Pipeline - Mahima Yoga, Auterion
Friday October 9, 2026 14:50 - 15:10 CEST
Airspeed sits at the center of fixed-wing flight. It determines how much lift the wings generate, how effective the control surfaces are, and ultimately how the aircraft can be controlled. As a result, it influences nearly every aspect of flight, from stability and maneuvering to energy management. Yet the airspeed value used throughout PX4 is far from a simple sensor reading. Behind a seemingly simple number lies a surprisingly large stack of sensor physics, conversions, calibration procedures, validation logic, control scaling, and TECS handling.

This talk traces the airspeed pipeline end-to-end: from pitot-tube measurements, through IAS → CAS → TAS conversion, in-flight calibration, and validation, to the controllers that ultimately use it. We'll also examine real-world failure modes from the PX4 community and show how to diagnose them from flight logs.
Speakers
avatar for Mahima Yoga

Mahima Yoga

GNC Engineer, Auterion
A Guidance, Navigation, and Control (GNC) engineer at Auterion with a focus on fixed-wing vehicles.
Friday October 9, 2026 14:50 - 15:10 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

14:50 CEST

Panel: Found It. Filed It. Forgotten? The Open Source Fix Problem in AI Era - Rao Lakkakula, Microsoft; Amanda Casari, Google; Stormy Peters, AWS
Friday October 9, 2026 14:50 - 15:30 CEST
We have become highly effective at finding vulnerabilities, accelerated by AI-driven analysis. We can scan at scale, assign scores, and generate reports with unprecedented speed. The breakdown happens after discovery.

For many maintainers, security reports arrive as noise: limited context, unclear expectations, and little support to carry fixes through to completion. Backlogs grow, trust declines, and critical issues remain unresolved.

This panel brings together security and open source leaders from Microsoft, Google and AWS to confront an uncomfortable reality: discovery is the easy part. Remediation, especially in shared infrastructure maintained by a small number of overextended contributors, is where the system fails.

We will explore what actually helps maintainers move from report to resolution. What makes a report actionable? How do we reduce noise and avoid drive-by reporting? How do we support fixes through triage, patching, and downstream adoption without taking over projects?

If you are a struggling maintainer or an industry consumer who wants to support OSS you depend on without overloading it, this session is for you. The focus is simple: fixes that land.
Speakers
avatar for Rao Lakkakula

Rao Lakkakula

Partner Director, Microsoft
Rao Lakkakula is Director of Open Source Ecosystems at Microsoft. He brings over 25 years of experience in security and software development, with prior leadership roles at JPMorgan Chase, The Climate Corporation, Amazon, and several startups. Rao serves on the Linux Foundation Research... Read More →
avatar for Amanda Casari

Amanda Casari

Staff Developer Relations Engineer, Google
amanda casari is a researcher and engineer in the Open Source Programs Office at Google, where she is co-leading research and engineering to better understand risk and resilience in open source ecosystems. She was named an External Faculty member of the Vermont Complex Systems Center... Read More →
avatar for Stormy Peters

Stormy Peters

Head of Strategy & Marketing, AWS
Stormy Peters is Head of Open Source Strategy & Marketing at AWS.
Friday October 9, 2026 14:50 - 15:30 CEST
Club H (Floor 1)
  Digital Trust

14:50 CEST

Entering Linux Upstream-First: How a Newcomer MCU Vendor Builds Its Kernel Development Processes - Gustavo Henrique Nihei, Espressif Systems
Friday October 9, 2026 14:50 - 15:30 CEST
Most silicon vendors claim to support upstream Linux. Few show what it actually takes to sustain that when customer deadlines and upstream changes compete for limited engineering resources. Espressif Systems, the company behind the ESP32 wireless MCUs and open-source ecosystems around them, is debuting in embedded Linux, but no stranger to open source communities: ESP-IDF is widely supported, and its engineers are active contributors to Zephyr RTOS, including a member on the TSC. This is a candid look at how a newcomer builds its development process with the community in mind.

We walk through the concrete processes we established: a branching strategy and sync cadence that track each stable kernel release, a pipeline for preparing and submitting patches to mainline, and immutable, reproducible release branches. We also cover the organizational model, a chip verification team that confirms silicon works quickly and a separate upstreaming team that refactors drivers to upstream standards, collaborating continuously to shrink the porting gap. The supporting infrastructure rounds this out with CI across multiple build systems, a LAVA CI board farm, and QEMU for pre-hardware testing.
Speakers
avatar for Gustavo Henrique Nihei

Gustavo Henrique Nihei

Staff Engineer, Espressif Systems
Gustavo Henrique Nihei is a Staff Engineer at Espressif Systems working on Linux platform support for Espressif SoCs, across the embedded Linux stack: kernel driver development targeting mainline, build system integration (Buildroot, Yocto, OpenWrt), and hardware-in-the-loop CI with... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

14:50 CEST

RDMA on the Edge - Michael Jost, ETH Zurich
Friday October 9, 2026 14:50 - 15:30 CEST
Processing large volumes of sensor data (e.g. Cameras, IMUs, Radar, etc.) on embedded hardware for real-time machine learning inference requires two critical performance metrics: high throughput and minimal latency.

Remote Direct Memory Access (RDMA) which originated in high-performance computing and cloud datacenters was designed for this use case . By enabling direct host-to-host memory transfers without kernel or CPU intervention, RDMA delivers throughputs exceeding 100 Gbps with microsecond-level latency.

In this talk, we present a complete, open-source sensor acquisition pipeline that brings RDMA to an embedded device. We demonstrate how camera data is acquired on an AMD Kria KR260, packetized into RDMA frames entirely within the FPGA fabric, and transmitted over Ethernet to a Jetson AGX Orin platform. The goal of this talk is that attendees will leave with a practical understanding of RDMA’s benefits in the embedded sector and have access to a powerful, open-source tool for high-performance data transfer.
Speakers
avatar for Michael Jost

Michael Jost

Researcher, ETH Zurich
Michael Jost received a B.Sc. from the University of Applied Sciences Rapperswil, Switzerland, and a M.Sc. in Electrical Engineering and Information Technology from the Swiss Federal Institute of Technology, ETH Zürich, Switzerland, in 2012 and 2017, respectively. He spend several... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

14:50 CEST

Yocto: From Scarthgap To Wrynose, 2 Years of LTS Evolution - Jérémie Dautheribes, Bootlin
Friday October 9, 2026 14:50 - 15:30 CEST
Yocto Project has become the de-facto standard for embedded Linux build systems, and its LTS releases serve as the key milestones driving industry adoption and long-term platform decisions.

Wrynose (6.0), released in May 2026, is the new LTS: teams and community members running Scarthgap in production are now facing the migration question.

This talk covers what actually changed over those two years: build tooling and configuration workflow, CVE and SBOM handling in the context of the upcoming EU Cyber Resilience Act, toolchain updates, and the breaking changes that affect existing layers and distro configurations. By the end of this talk, attendees should have a clear picture of what it takes to migrate from Scarthgap to Wrynose in a real production environment.
Speakers
avatar for Jérémie Dautheribes

Jérémie Dautheribes

Embedded Linux and Kernel engineer and trainer, Bootlin
Jérémie Dautheribes is an embedded Linux engineer and trainer at Bootlin since 2022.
He has been working with Yocto for 5 years.
His expertise also extends to BSP maintenance and evolution.
As a trainer, he has also helped many people improve their skills on the Yocto Project and Embbeded Linux in general... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

14:50 CEST

Anatomy of a Mainline Linux Driver - Neil Armstrong, Linaro
Friday October 9, 2026 14:50 - 15:30 CEST
Getting a driver into mainline Linux is a great step, but it is very different from downstream development. In downstream, the people writing the driver are often not the ones making the final product. Because of this, they have to implement 100% of the hardware features. But in the end, maybe only 60% of these features are actually used by product integrators. This creates dead code and increased driver complexity.

In this talk, I will show you the anatomy of a mainline Linux driver and guide you on how to write it for the upstream tree inclusion. We will see how to write generic code that is easy for the community to maintain in the long term. We will talk about using and extending existing kernel frameworks instead of making custom control paths or abusing current interfaces, which helps reduce ecosystem fragmentation. For embedded systems, we will also see how to make clean and extensible Device Tree bindings.

I will explain why we need to drop untestable downstream features to keep the code clean. Finally, we will look at how to format and check your patchset with tools like checkpatch, smatch, and new AI tools like Sashiko to ensure high kernel quality.
Speakers
avatar for Neil Armstrong

Neil Armstrong

Senior Linux Engineer, Linaro
Neil joined Linaro in September 2022 to work full-time on Qualcomm Upstreaming of their high-end SoC platforms.
Neil has been hacking on embedded platforms since he was 16 years old, from Casio Calculators to Phones platforms in the last months.
He maintains the Amlogic Linux & U-Boot baseport, Linux DRM Bridge & Panel codebase. In addition to Qualcomm, Neil regularly contributes to the Linux Kernel and U-Boot supporting the Amlogic SoCs support and DRM codebase... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Panorama Hall (Floor 1)
  Linux

14:50 CEST

Building Fine-Grained Permissions for AI Agents - Sohan Maheshwar, AuthZed
Friday October 9, 2026 14:50 - 15:30 CEST
This talk could prevent the next big data breach.

Building enterprise-ready AI poses challenges around data security, scalability, and integration, especially in compliance-regulated industries. We're already seeing security breaches with AI Agents in the news. This is a complex problem - Imagine having N users, M Agents and O actions. How do you design permissions around that?

This session will cover how modern permissions systems can ensure AI Agents have access only to authorized data. The talk will look at why the Google Zanzibar model of authorization which uses Relationship-Based Access Control (ReBAC) is well suited for fine-grained authorization at scale. The talk covers the nuts and bolts of how a Google Zanzibar system works under the hood, and how to apply it to AI Agents with techniques such as pre-filteration and post-filteration.

The talk will also include a live code demo implementing authorization for AI Agents + RAG using Open Source tools such as Weaviate, Langchain, and SpiceDB.
Speakers
avatar for Sohan Maheshwar

Sohan Maheshwar

Lead Developer Advocate, AuthZed
Sohan is a Lead Developer Advocate at AuthZed, based in the Netherlands. He started his career as a developer building mobile apps and has been living in the cloud since 2013, in companies such as Amazon, Fermyon and Gupshup. He is also an AAIF Ambassador and an O' Reilly author... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Forum Hall (Floor 2)
  Open AI & Data

14:50 CEST

Landscape of the Quantum Open Source Ecosystem - Mathys Rennela, Unitary Foundation
Friday October 9, 2026 14:50 - 15:30 CEST
The discussion on quantum computers often focuses on abstract physics, but for the engineers manipulating those systems, the underlying software stack is becoming a very pressing reality. As the field matures, we are witnessing the emergence of a collaborative, open-source ecosystem.

This session provides a comprehensive tour of the current quantum open source landscape, and will aim to demystify programming for quantum computers. Community-led projects are currently providing the necessary plumbing (compilers, simulators, verification tools, ...) to ensure that quantum technologies are not only scalable and useful, but also transparent and interoperable.

No prior background in quantum physics or quantum computing is required. The session will actually aim to argue that most quantum software challenges are very known problems in software engineering and computer science, and that one can contribute to quantum open source projects without any knowledge of quantum physics.
Speakers
avatar for Mathys Rennela

Mathys Rennela

Fellow, Unitary Foundation
Mathys Rennela is a quantum software researcher. His main focus is on building the foundational & open source quantum software infrastructure to ensure that quantum computers can also be transparent & of public utility.
Friday October 9, 2026 14:50 - 15:30 CEST
Terrace 2A (Floor 2)
  Open Source 101
  • Audience Experience Level Any

14:50 CEST

CRA Compliance Paths and Where the Real Responsibility Sits - Madalin Neag, OpenSSF/The Linux Foundation
Friday October 9, 2026 14:50 - 15:30 CEST
The EU CRA is now law, yet confusion persists across the software ecosystem. Many developers still fear personal liability for upstream contributions, while organizations struggle to understand what compliance actually requires.
This talk clarifies the four CRA compliance pathways: Self-Assessment, Standards, 3rd party Conformity Assessment, and the EUCC, and explains how they apply across the software supply chain.

We demystify the CRA’s approach to open source, focusing on OSS stewards such as foundations and legal entities, and their limited obligations compared to manufacturers. A key message: upstream contributors and individual maintainers have no direct CRA compliance responsibilities.
We also examine supply chain security implications, including the need for stronger upstream-downstream collaboration, better dependency transparency, and clearer security ownership at integration points. Misinterpretation of CRA roles risks shifting compliance burden incorrectly upstream, undermining ecosystem resilience.
Attendees will leave with a clear understanding of CRA responsibility boundaries, compliance routes, and the role of open source in a secure European software supply chain.
Speakers
avatar for Madalin Neag

Madalin Neag

EU Policy Advisor, OpenSSF/The Linux Foundation
Madalin is the EU Policy Advisor at OpenSSF, working at the intersection of cybersecurity, open source software, and European technology policy. He helps connect open source technical communities and policymakers, supporting the development of practical regulatory frameworks, aligning... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 1 A (Floor 1)

14:50 CEST

X-Road: The Open Source Project That Runs Countries (And What It Can Teach Your Project) - Gbemisola Mary Oladetoun, Fleetfox
Friday October 9, 2026 14:50 - 15:30 CEST
X-Road started as Estonia's internal government data exchange layer. Today it is open source, deployed in over 20 countries including Finland, Iceland, and Japan, and maintained by a cross-border foundation. I build software on top of X-Road every day in Tallinn, so I interact with this system as a practitioner, not just someone who read about it.

This talk covers: the governance model that allows countries with different legal systems to contribute to the same codebase. How X-Road handles backwards compatibility when your users are governments that cannot afford breaking changes. The trust model that lets citizens see exactly who accessed their data. And what this journey from closed government software to open source infrastructure teaches other projects about sustainability.

I am not an X-Road maintainer. I am a software engineer who uses it in production and an HCI researcher who thinks about how people interact with systems like this. Most talks about X-Road come from the people who built it. This one comes from someone who lives with it.
Speakers
avatar for Gbemisola Mary Oladetoun

Gbemisola Mary Oladetoun

Full Stack Developer, Fleetfox
Gbemisola Oladetoun is a Full Stack Developer and HCI researcher at Tallinn University, Estonia. Originally from Nigeria, she has built AI-powered products serving 1,500+ users across three African countries and now builds fleet software for the European market. Her talks blend technical... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Conference Hall (Floor 4)

14:50 CEST

Two Sides of the Same Coin: What Software and Data Research Repositories Can Learn From Each Other - Kairo De Araujo, TU Delft
Friday October 9, 2026 14:50 - 15:30 CEST
Research data repositories and software package registries serve different audiences, but they answer the same four questions:
- who published this and can we trust them
- has it been tampered with
- where did it come from
- how long will it stay available and verifiable?

Both communities have answered them in parallel, different vocabularies, different tooling, little exchange.

This talk maps that exchange both ways, grounded in my work on Djehuty (behind 4TU.ResearchData) and as a maintainer of TUF and in-toto and an OpenSSF Securing Software Repositories contributor.

Data repositories can borrow from software: delegated, verifiable signing (TUF, Sigstore), in-toto provenance for AI training data, and the OpenSSF security-maturity model.

Software registries can borrow from data: FAIR's verifiable provenance, persistent identifiers (DOIs, ORCIDs) for durable SBOMs, OAIS preservation against dependency rot, and pre-publication curation.

It closes on the problem neither has solved: permanence versus incident response revoking trust without deleting an immutable, citable record.
Speakers
avatar for Kairo De Araujo

Kairo De Araujo

Senior Software Engineer, TU Delft
Kairo de Araujo maintains TUF and in-toto, two CNCF-graduated supply-chain security projects, and authored RSTUF. He contribute to the OpenSSF Securing Software Repositories Working Group. As a Senior Software Engineer at TU Delft, Kairo now works on Djehuty, the open source platform... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

14:50 CEST

Failure Propagation in Linux: Challenges for Safety Qualification - Alessandro Carminati, NVIDIA
Friday October 9, 2026 14:50 - 15:30 CEST
Linux was not developed around fault-containment properties expected of safety-certifiable software.

The linear map lets kernel code access memory across userspace ownership boundaries, so corruption can affect another process or container. Shared slab/page allocators and per-CPU caches compound this risk: corrupted state may remain latent and later affect unrelated subsystems. MMIO can cause external interference when a faulty driver accesses the wrong register or device because of corrupted state or an incorrect Device Tree or ACPI-derived base address.

Building on ELISA Linux Features WG (LFSCS) work, we use ks-nav call-tree artifacts to show that even narrow services depend on shared infrastructure across subsystems.

Reducing the configuration lowers function count but also usability; restoring functionality introduces transitive dependencies, so assessment cannot be limited to newly enabled code.

These findings challenge treating Linux as safe by default or relying on proven-in-use arguments alone. In a monolithic, shared-address-space kernel, fault containment and qualification scope must be demonstrated, not assumed.
Speakers
avatar for Alessandro Carminati

Alessandro Carminati

Senior Safety Architect for Linux, NVIDIA
Senior Safety Architect for Linux at NVIDIA, working on Linux kernel performance, tooling, community engagement, and its adoption in safety-critical applications. Previously a Linux Kernel Engineer in Red Hat’s Automotive Team, with a background in embedded Linux, Linux security... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Club A (Floor 1)
  Safety-Critical Software

14:50 CEST

Linkable Loadable Extensions and the Extension Developer Kit - Lauren Murphy, Intel
Friday October 9, 2026 14:50 - 15:30 CEST
The Linkable Loadable Extensions (LLEXT) subsystem supports loading and linking ELF files at runtime, enabling developers to add sandboxed plugin-like functionality to Zephyr applications. This session offers a discussion of how LLEXT works and how it can work for you, as well as an overview of the Extension Developer Kit (EDK). The EDK allows users to build extensions without building the main binary, enabling teams working on complex firmware to neatly divide efforts between individual loadable modules and the main binary.
Speakers
avatar for Lauren Murphy

Lauren Murphy

OS Development Engineer, Intel
Lauren Murphy has been a software engineer on the Intel team of Zephyr contributors since 2021. As a LLEXT contributor, she added support for ARC and x86, as well as Harvard architectures.
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

14:50 CEST

Zephyr-Based VIRTIO Backend on Xen: From Tiny Driver Domains To Real Hardware Integration - Hiroshi Tokita, Indivisual
Friday October 9, 2026 14:50 - 15:30 CEST
Linux-based Xen Driver Domains are powerful, but they increase the trusted computing base and add complexity to systems that need tight isolation, fast startup, and auditable software components.

This talk updates the Zephyr-based VIRTIO backend for Xen, an effort to run selected VIRTIO backend functions in small, purpose-built Zephyr driver domains. The goal is to preserve Xen’s proven architecture while enabling a finer-grained model: separate lightweight domains for network, storage, or platform-specific services.

Over the past half year, the project has moved toward platform integration. Upstreaming work has progressed, real-hardware demos are being developed on Renesas R-Car V4H, and integration with SoDeV, an SDV platform by Automotive Grade Linux, is underway.

The session will cover the architecture, current upstream status, and obstacles to using it across platforms. Attendees will leave with a realistic view of where Zephyr-based driver domains can reduce the trusted computing base, what challenges remain, and how to contribute to lightweight open-source driver domains for edge and automotive systems.
Speakers
avatar for Tokita Hiroshi

Tokita Hiroshi

Embedded system developer, Indivisual
TOKITA Hiroshi has been working at Fujitsu as an embedded systems developer for 20 years.
He mainly has knowledge of in-vehicle Linux, especially in the infotainment area.
He is also involved in the Japanese translation of KiCad, and is involved in development and writing activit... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

15:10 CEST

Total Energy Control: A Deep Dive Into TECS in PX4 - Silvan Fuhrer, Auterion
Friday October 9, 2026 15:10 - 15:30 CEST
The Total Energy Control System (TECS) coordinates throttle and pitch to manage a fixed-wing vehicle's airspeed and altitude as a single energy problem — but for many users it remains a black box of tuning parameters. This talk opens it up.
We start from first principles, deriving how TECS balances kinetic and potential energy and why throttle and pitch are the natural levers to control them. We then cover the controller's concept, its architecture in PX4, a structured approach to tuning, and the shortcomings every operator eventually hits. Finally, we distill seven years of hands-on TECS tuning into the heuristics and hard-won insights that don't appear in the documentation.
Whether you're tuning your first fixed-wing or maintaining a fleet, you'll leave with a clearer mental model of what TECS is really doing.
Speakers
avatar for Silvan Fuhrer

Silvan Fuhrer

GNC Engineer, Auterion
Flight control engineer with a particular focus on fixed-wing and VTOL applications.
Friday October 9, 2026 15:10 - 15:30 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

15:40 CEST

VTOL Control Architecture - A Birds-eye View - Balduin Dettling, Auterion
Friday October 9, 2026 15:40 - 16:00 CEST
Is it a multicopter? Is it a fixed-wing? Not quite: It is a quantum superposition of both, and only upon flipping the transition switch we can observe the VTOL state with certainty.

VTOL vehicles bridge the design space between either pure vehicle type and enable long, efficient flights combined with accurate and soft landings. However, they challenge our software engineering and architecture skills, and properly supporting all VTOL vehicles in PX4 is quite the balancing act.

In this talk, we will go over the architecture and implementation decisions that connect those two vehicle types within a running system. We will visit some VTOL specific features and see where they slot in, and finally we will conclude with possible paths for further improving VTOL support in PX4.
Speakers
avatar for Balduin Dettling

Balduin Dettling

GNC Engineer, Auterion
Balduin has found his enthusiasm for VTOL drones as a student and then controls engineer at TwingTec, an airborne wind energy startup coming out of ETHZ. While that company ironically lacked some runway, he has now found a home at Auterion, where he can improve the state of open source... Read More →
Friday October 9, 2026 15:40 - 16:00 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

15:40 CEST

Let Your CI Catch Your Stack Overflows, Before They Hit Your Testing or the Field - Paul Würtz, Independent & Juan-Felipe Gutiérrez-Gómez, Technical University of Braunschweig
Friday October 9, 2026 15:40 - 16:00 CEST
Static program analysis can help us to save a lot of time to catch bugs before they cause real-world issues. Inspired by the already in west integrated puncover target I want to present and discuss my advances and experiments and how this especially can help during code review and development as part as the CI pipeline in application development to correctly configure necessary stack sizes and get warned on potential stack overflows.

Further ideas around how this could also benefit zephyr development are presented like checking subsystem enabled threads stack sizes across multiple boards.
Speakers
avatar for Paul Würtz

Paul Würtz

Full-time hacker on parental leave - otherwise Embedded Software Engineer :), Visiting as a Hobbyist
Studied electrical engineering and computer science. Worked across IoT, packaging, tractors and battery storage on embedded applications for the last 8 years.
avatar for Juan-Felipe Gutiérrez-Gómez

Juan-Felipe Gutiérrez-Gómez

Research Assistant, Technical University of Braunschweig
Juan Gutierrez received the B.Sc. degree in Electronic Engineering in 2013, the M.Sc. degree in Telecommunications Engineering in 2019, and the Ph.D. degree in Electrical Engineering in 2026, all from Universidad Nacional de Colombia. His current research interests include embedded... Read More →
Friday October 9, 2026 15:40 - 16:00 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

15:40 CEST

Cloud Native Open RAN Across 1,000 Km: A GitOps Deployment With Duranta and Sylva - Sagar Arora, OpenAirInterface Software Alliance & Guillaume Grao, Orange Innovation
Friday October 9, 2026 15:40 - 16:20 CEST
The telco industry has been on a cloudification journey for over a decade. In the context of Radio Access Networks (RAN), this deep transformation is primarily driven by Open RAN initiatives. This talk illustrates how RAN is gradually embrassing cloud native benefits. Key synergies between Sylva and Duranta open-source projects are driving this transformation:
- Sylva provides a telco-grade cloud stack, enabling scalable and reliable cloud infrastructure.
- The Duranta project focuses on developing RAN network functions using cloud-native design patterns to promote innovation and interoperability.

A live demo will highlight the role of Open RAN interfaces in Duranta. It will showcase a FluxCD-based GitOps deployment of Duranta’s Open RAN Distributed Unit (O-DU), Centralized Unit Control Plane (O-CU-CP), and Centralized Unit User Plane (O-CU-UP) network functions on a Telco Cloud. The deployment will follow the Sylva GitOps approach. Sylva will orchestrate multiple Telco Clouds to showcase central, regional, and far-edge deployment scenarios across two labs located approximately 1,000 km apart.
Speakers
avatar for Sagar Arora

Sagar Arora

Solutions Architect, OpenAirInterface Software Alliance, OpenAirInterface Software Alliance
Sagar Arora holds a Ph.D. in mobile communications from Sorbonne University, France. His thesis title was “Cloud-native Network Slice Orchestration in 5G and Beyond”. At OpenAirInterface, he takes care of the on-premises data center, 5G radio equipment, and CD pipelines. He engages... Read More →
avatar for Guillaume Grao

Guillaume Grao

O-RAN and 5G Solution integrator, Orange Innovation
Working for Orange Innovation in different position: from C++ developper to an O-RAN and 5G Solution integrator
Friday October 9, 2026 15:40 - 16:20 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

15:40 CEST

When the LLMs Come Knocking: Surviving AI-Powered Vulnerability Reports - Vincent Demeester, Red Hat
Friday October 9, 2026 15:40 - 16:20 CEST
In early 2026 our vulnerability inbox suddenly exploded. Tekton, the Kubernetes-native CI/CD framework we maintain, received more security reports in four months than in all the previous years combined: detailed, with working reproducers and CVSS scores. Many were genuinely valid. They were also, overwhelmingly, AI-generated.

LLM-powered research has changed the game. Tools now audit codebases systematically and surface real bugs humans missed for years: a path traversal reading arbitrary files from the controller pod, an SSRF exfiltrating cloud credentials, a JSON injection enabling RCE. These aren't hallucinations, and they arrive faster than a small team can patch, disclose, and backport.

But the flood carries noise too: variants of fixed CVEs, reports that misunderstand the threat model, duplicates. The challenge has shifted from "find vulnerabilities" to "triage an AI-accelerated firehose without your disclosure process collapsing."

This is an honest, in-progress survival guide from maintainers living through it: how triage holds up under pressure, how we separate signal from noise, what we got right, and what we got wrong.
Speakers
avatar for Vincent Demeester

Vincent Demeester

Senior Principal Software Engineer, Red Hat
I'm a french developer 🐻, Gopher 🐹, sysadmin 🐺, factotum 🦁, free-software fan 👼 and unicode lover 🐸. I'm working at Red Hat 🎩 as a senior principal software engineer, previously at Docker 🐳 and Zenika 🐯. I am a maintainer of the docker project (moby/moby... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club H (Floor 1)
  Digital Trust

15:40 CEST

AI-Assisted CVE Triage in Yocto-Based Supply Chains: Designing the Human–Agent Judgment Boundary - Kazuyoshi Akiyama & Takashi Ninjouji, Honda
Friday October 9, 2026 15:40 - 16:20 CEST
Automotive Linux products must assess supply chain security at every release.
Yocto-based SBOMs can serve as the foundation, but many teams have yet to answer how much CVE triage to automate and where humans should make the call.
An OSS toolchain also enables the same foundation to be shared with suppliers, with no license barriers.

Yocto-generated VEX and rule-based filtering handle many CVEs, but ambiguity remains — provenance of third-party components, applied patches, unintended dependencies.
AI agents can handle that ambiguity, but opaque and non-deterministic outputs make it impossible to explain a missed CVE or a false positive that blocked a release.

This talk presents a design for that, with a Yocto-based CVE triage pipeline as the example.

The workflow begins with frozen inputs, passes through layered triage, and ends with human approval: inputs locked at CI trigger time (Input Freezing); rule-based and lightweight LLM filtering of straightforward cases (Layered Triage); a high-performance LLM presenting suggestions, with humans making the final call (Suggestion-and-Approval Loop).
These patterns apply to embedded supply chain management beyond automotive Linux.
Speakers
avatar for Kazuyoshi Akiyama

Kazuyoshi Akiyama

Software Engineer, Honda R&D Co., Ltd.
Kazuyoshi Akiyama is a software engineer specializing in embedded Linux for the automotive industry, with years of experience in Linux kernel driver development and Yocto-based integration. Recently joined Honda R&D Co., Ltd., where he is exploring how AI agents can automate compliance... Read More →
avatar for Takashi Ninjouji

Takashi Ninjouji

Chief Engineer, Honda R&D Co., Ltd.
Takashi Ninjouji is a Chief Engineer at Honda Motor Co., Ltd., with a focus on Software-Defined Vehicles (SDV). He is a manager of the Open Source Program Office (OSPO). His interests also include AI-assisted engineering automation.
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:40 CEST

The Netdev Upstreaming Journey: Process, Pitfalls, and Best Practices - Maxime Chevallier, Bootlin
Friday October 9, 2026 15:40 - 16:20 CEST
Network interfaces are a common thing on embedded devices, so it's no surprise that getting a device supported upstream involves interacting with the netdev community on mailing lists.

The netdev list is a very busy place, and like other subsystems, has its own sets of written and non-written rules. Recently, it's been busier than ever, partly due to new tooling making it more accessible to make first contributions, or finding bugs. This means the netdev community has had to adapt and put new tools, processes and rules in place to deal with this heavy influx of contributions.

This talk will discuss what the upstream process for network-related patches currently looks like. We'll discuss the common pitfalls when upstreaming patches, either due to common technical mistakes or traps when following the netdev process. This may also be a chance for other subsystems to take a peek at how netdev deals with the recent surge of new contributors.

We'll see how reviews are being promoted, what the recently created Netdev Foundation has been setting-up to ease the testing and CI effort, and how as a developer you can help this community and get your patches accepted in a smoother manner.
Speakers
avatar for Maxime Chevallier

Maxime Chevallier

Embedded Linux and Kernel Engineer, Bootlin
Maxime Chevallier is an Embedded Linux and Kernel engineer at Bootlin, where he has been working on Ethernet Controller drivers and PHY drivers for more than 6 years. He contributed to the Marvell PPv2 driver, and to various PHY, Switch and PCS drivers.
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:40 CEST

Yocto’s Hidden Gems: Lesser-Known Tools for Daily Development - Anna-Lena Marx, inovex GmbH
Friday October 9, 2026 15:40 - 16:20 CEST
Yocto is a complex and huge ecosystem. Getting started may feel hard, but there are various tools to make our daily development easier right out of the box—if you know about them. Unfortunately, many developers are only used to a small subset of the available tools and their capabilities, which often leads to writing additional custom tooling for already solved problems.
In this presentation, we will dive into a selection of these existing tools and demonstrate how to take advantage of them in everyday workflows. For example, we’ll discuss how `bitbake-getvar` helps with debugging variables and overrides, and how to find all packages generated by a recipe with `oe-pkgdata-util`. We will also look into `yocto-check-layer`, `patchtest`, `bitbake-config-help`, and more.
The session will focus on practical use cases, showing how to leverage already available tools to save time and reduce the need for custom scripts.
Speakers
avatar for Anna-Lena Marx

Anna-Lena Marx

Tech Lead Embedded Linux, inovex GmbH
Anna-Lena Marx is TechLead for Embedded Linux at inovex, where she helps build robust systems. With an academic background in Computer Science, Electrical Engineering, and Embedded Systems, she bridges the hardware-software gap. Her core focus is the Yocto Project, guiding companies... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:40 CEST

Who Watches the Watcher? Hardening eBPF in Production Security Deployments - Hanshal Mehta, Independent
Friday October 9, 2026 15:40 - 16:20 CEST
eBPF has become the backbone of modern Linux security tooling. Cilium, Tetragon, Falco, etc they all depend on eBPF's ability to hook kernel execution paths and enforce policy without a kernel patch or reboot. But there's a question the community has been slow to ask: who secures eBPF itself?
Working on bpfman, an eBPF program manager, exposed me to the trust assumptions baked into how programs get loaded, pinned, and granted kernel access. This talk covers what I found concrete attack surfaces that show up in real deployments, not theory.

We'll cover: the verifier's historical CVEs and what they reveal about its actual threat model, privilege escalation through CAP_BPF and unprivileged eBPF in distros that ship with it enabled, what program signing protects and what it quietly doesn't, and LSM hooks on BPF program loading that most teams aren't using yet.
The second half: BPF token scoping, how Ubuntu and Fedora are locking down the attack surface without breaking legitimate tooling,and a threat model checklist you can apply to your own eBPF deployment the same week.
If you're running eBPF-based security tooling in production, this is the talk I wished existed before I started.
Speakers
avatar for Hanshal Mehta

Hanshal Mehta

Open Source Developer, Self
Open-source developer contributing to projects across the cloud-native and security space including OpenTelemetry, bpfman, Glasskube, Cyclops, and BuildSafe. Currently at SecurableAI working on open-source security tooling. Deep interest in performance engineering, cloudsecurity... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Panorama Hall (Floor 1)
  Linux

15:40 CEST

When Coding Agents Cheat: Measuring the Security of AI-Generated Code With an Open Benchmark - Luca Compagna, Endor Labs & Danqing Wang, Carnegie Mellon University
Friday October 9, 2026 15:40 - 16:20 CEST
Vibe coding is now the norm, and more open-source code is AI-generated. But is it secure?

We present the Agent Security League, an open leaderboard built on SusVibes (200 real-world tasks, 108 OSS projects, 77 CWEs). Unlike benchmarks frontier labs cite to showcase progress, SusVibes evaluates what developers actually use: a harness coupled with an LLM, not the model alone. Across 15+ combinations — GPT-5.5, Gemini 3.5, Fable 5 — with agents like Cursor and Claude Code, functional correctness can exceed 80%, yet our best fair security score is 29%.

This means ~7/10 working AI patches leave the bug open.

Strikingly, even models (e.g., Fable 5) that lead model-only benchmarks score no better on security once wrapped in a real agent.

Agents also cheat: early on they reverse-engineered fixes from git history, inflating scores up to 42×. Our 3-layer pipeline—prompt hardening, workspace sanitization, LLM-based anti-cheating eval—nearly killed that, but memorization of upstream fixes from training data persists.

We show cheating examples, share fair results, what actually improves security, and argue anti-cheating and contamination controls must be standard for agentic benchmarks.
Speakers
avatar for Luca Compagna

Luca Compagna

Security Researcher, Endor Labs
Security Research Consultant at Endor Labs, after more than 15 years at SAP, researching and innovating in the areas of security testing, security engineering, and AI.

Regular presenter at industrial and community venues (OWASP) and leading security conferences, he has published... Read More →
avatar for Danqing Wang

Danqing Wang

PhD, Carnegie Mellon University
Danqing is a Ph.D. candidate at LTI in Carnegie Mellon University (CMU), advised by Prof. Lei Li. Her research focuses on Strategic Planning and Reasoning in LLM Agents, including agent collaboration, agent competition, agent communication and agentic safety.
Friday October 9, 2026 15:40 - 16:20 CEST
Forum Hall (Floor 2)
  Open AI & Data

15:40 CEST

Kids Programming in Turtlegrove - Making Beautiful Things Together - Pascal van Dam, pascalvandam.com
Friday October 9, 2026 15:40 - 16:20 CEST
In 1967, Seymour Papert, Wally Feurzeig, and Cynthia Solomon built a language based on studies of Piaget whose radical premise still hasn't been fully cashed in: children should program the computer, not be programmed by it. Logo gave them a turtle an "object to think with" and a place to live in mathematics by walking it, drawing it, and making it their own.

Half a century later, most kids meet software as something to consume, not construct. This talk argues that Papert's constructionism and the free-software ethos are the same idea one generation apart, both are about the freedom to understand and reshape your own tools and that open source is exactly how we finally deliver Logo's promise at scale.

I'll show TurtleGrove: a UCBLogo compatible interpreter we created that runs in any browser, with a Rust core and a vanilla-JS frontend, fully open source and self-hostable.

In the OpenSource mindset children can even show-and-share their code with other children. Working on their own canvas or creating art together. Children learn the best, when learning together. We use this also in the Living OpenSource project to introduce kids in African countries into programming.
Speakers
avatar for Pascal van Dam

Pascal van Dam

Trainer & Architect, pascalvandam.com
Pascal has been working with Linux and Opensource since the early days of 1991. He's having almost 30 years of experience in of UNIX and Linux. He has been delivering courses since 1997.

Next to being a trainer Pascal is the hired Linux/K8S architect for ATOS.

Pascal has a fond... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Terrace 2A (Floor 2)
  Open Source 101

15:40 CEST

A Strategic Outlook for Digital Commons: Technology, Communities, and Governance - Nick Gates, OpenForum Europe
Friday October 9, 2026 15:40 - 16:20 CEST
Sovereignty rhetoric is creating new openings for commons-based approaches to organising around, governing, and investing in public digital infrastructure that works for a plurality of Member States. This is partly what is proposed via ongoing initiatives like the Digital Commons EDIC and the Open Internet Stack. That said, the European Commission risks absorbing them while adopting largely statist, protectionist, or purely industrial framings that hollow out their meaning.

This talk navigates that tension directly, drawing on research from the NGI Commons project to offer a clear-eyed account of where things stand and what communities, researchers, and advocates can do about it. This talk begins by mapping these concepts with precision: what each means, how they relate, and why the distinctions matter for anyone trying to advance a genuinely commons-based agenda as part of these existing initiatives.

From there, the talk examines the current EU policy moment: the sovereignty turn, the competitiveness and industrial policy logic now dominating digital debates, the AI race framing, and what these shifts mean for the digital commons and the EU’s broader tech sovereignty ambitions.
Speakers
avatar for Nick Gates

Nick Gates

Senior Policy Advisor, OpenForum Europe
Nick Gates is a Policy Advisor at OpenForum Europe, where he leads OFE’s work on the NGI Commons initiative and manages projects related to open source research and policy. Nick has significant experience in digital government, particularly around open source, public financial management... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Conference Hall (Floor 4)

15:40 CEST

One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
Friday October 9, 2026 15:40 - 16:20 CEST
Open source supply chain decisions such as what to depend on, what to ship, and what to trust are only as good as the open data behind them.

The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million, both with ScanCode. We share the same problem: we're scanning and rescanning the same packages for the same (or similar) data.

That redundancy has real costs. Compute, maintainer time, and contributor energy spent on work that's already done is capacity not spent on expanding coverage, improving accuracy, or hardening infrastructure.

It's time to build together. This talk is a conversation about what it would look like to join forces on open software supply chain data, produced with open source tools and backed by open standards with shared infrastructure and aligned and unlocked datasets for wider usage. We'll explore where our data models overlap, where they diverge, and what collaboration would require, so we all can get sustainable, high-quality, and open supply chain data at ecosystem scale faster together.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead Maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect — Office of the CTO, Bloomberg
Technical Architect, Office of the CTO at Bloomberg
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 1 A (Floor 1)

15:40 CEST

Securing the Builder: CI/CD Supply Chain Security for an Open Source African Community - Caleb Poku Ackom, Cellulant
Friday October 9, 2026 15:40 - 16:20 CEST
Who secures the teams building open source security tooling? At Open Source & Security Africa (OSSAfrica) — a Linux Foundation Special Interest Group supporting the pan-African open source ecosystem — we asked that exact question and built the answer into our pipelines.
This lightning talk walks through the CI/CD architecture powering OSSAfrica's projects: GitHub Reusable Workflows for DRY, composable pipelines across repositories; CodeQL and Semgrep running automated SAST on every PR; and Cloudflare Pages and Render handling deployments with zero operational overhead for a volunteer-driven team.
The core argument: supply chain security isn't a luxury reserved for enterprise platforms. With the right reusable workflow patterns, a lean community team can ship with the same security guarantees as a well-staffed engineering org — and share those patterns across every project they maintain.
Attendees leave with a concrete, replicable blueprint for community-scale secure CI/CD, and a fresh perspective on what open source infrastructure looks like when it's built from and for the African tech ecosystem.
Speakers
avatar for Caleb Poku Ackom

Caleb Poku Ackom

Site Reliability Engineer, Cellulant
Caleb is a Site Reliability Engineer at Cellulant, a Pan-African payments platform operating across 30+ markets, where he manages multiple EKS clusters supporting 40+ microservices in production. He also serves as DevOps Lead at Open Source & Security Africa (OSSAfrica), where he... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

15:40 CEST

Feasibility of an Open-Source Linux Platform for Autonomous Train Operation - Daniel Weingaertner & Sebastian Hetze, Red Hat
Friday October 9, 2026 15:40 - 16:20 CEST
Autonomous train operation requires a new generation of computing platforms capable of running AI-based perception, sensor fusion, and safety-critical control functions. Traditionally, railway systems have been delivered as tightly integrated proprietary hardware-software stacks, limiting software reuse, innovation, and vendor independence.
This talk presents the results of the Automated Train research project and explores whether a Linux-based platform can become the foundation for safety-critical rail applications. We examine the technical feasibility of using Linux to support mixed-criticality workloads while meeting stringent railway safety requirements.
Beyond technology, we discuss a fundamental challenge for open source in regulated industries: how can continuously evolving software be certified in environments governed by legally binding functional safety standards?
Finally, we explore the governance and business implications of a shared open-source platform for the railway sector. The lessons learned extend far beyond railways and provide a blueprint for applying Linux and open-source collaboration to other safety-critical and sovereign digital infrastructure domains.
Speakers
avatar for Daniel Weingaertner

Daniel Weingaertner

Senior Software Engineer, Red Hat
A seasoned technical leader and former professor, Daniel Weingaertner brings expertise in High-Performance Computing (HPC) and automotive software engineering. He has a track record of delivering open-source and Linux solutions for the public sector and possesses specialized knowledge... Read More →
avatar for Sebastian Hetze

Sebastian Hetze

Principal Software Engineer, Field CTO, Red Hat
Sebastian Hetze has been developing free software since the 1980s. From 1992 to 2012, he ran his own Linux companies. He has been working for Red Hat since 2012, most recently as a Principal Software Engineer in the Field CTO organization. He is also an elected board member of the... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

15:40 CEST

Zephyr on the Big Core: Real-Time on the I.MX93 Cortex-A55 With Zephyr - Ryan Erickson, Ezurio
Friday October 9, 2026 15:40 - 16:20 CEST
The NXP i.MX93 almost always gets the same software answer: Linux on the Cortex-A55, an RTOS on the Cortex-M33. But what if you don't need Linux?

Zephyr formally supports the i.MX93 A55 cores upstream (imx93_evk/mimx9352/a55 and /a55/smp), including GICv3 interrupts, PSCI power management, SMP, and the full peripheral set — Ethernet, CAN-FD, USB, MIPI-DSI, and more. Boot time drops, interrupt latency decreases, and memory footprint shrinks. And unlike other RTOS solutions, there are no per-unit royalties.

This session covers two things: first, a technical deep-dive into how Zephyr runs on an arm64 application core and looking at various peripherals and proving they work. Second, a live walkthrough of authoring a Zephyr BSP for the Ezurio Nitrogen93 SMARC — an i.MX93 SOM in the SMARC 2.2 form factor — covering DTS porting, pinctrl, driver enablement, and hardware validation.

Attendees leave with a clear framework for when Zephyr on Cortex-A beats Linux or a proprietary RTOS, and a practical template for porting any i.MX9x board to Zephyr.
Speakers
avatar for Ryan Erickson

Ryan Erickson

Staff Software Engineer, Ezurio
Ryan Erickson has been developing wireless products at Ezurio for 17 years. His areas of expertise include Zephyr development and maintenance (modem drivers), Wi-Fi, BLE, Bluetooth Classic, 802.15.4, cellular, IoT, manufacturing automation, mobile apps, and more.
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit

16:00 CEST

Infected Drones: How Compromised Autonomous Systems Pwn Ground Control Stations - Nick Aleks, ASEC
Friday October 9, 2026 16:00 - 16:20 CEST
Modern drone operations have moved from one pilot, one aircraft to multi-agent autonomous fleets. Dozens and even hundreds of vehicles now fly missions while only a handful of operators supervise from the ground. More drones, fewer ground stations, and the station is where all the value is, the operator, the mission data, a full-blown OS, and even access to other drones.

For years, drone security researchers have focused on attacking the vehicle. I flip the target and show how a single infected drone becomes a beachhead, reaching up the command chain to own the very station meant to control it, and the fleet.

This research audited six popular independent ground-control and middleware projects across the MAVLink ecosystem, Mission Planner, QGroundControl, MAVSDK, MAVProxy, MAVROS, and DroneKit and found the same broken trust boundary in all of them. The result is 14 findings rooted in one systemic flaw, including two novel full remote code execution chains against the operator's own machine.
Speakers
avatar for Nick Aleks

Nick Aleks

Chief Hacking Officer, ASEC
Nick Aleks is a renowned cybersecurity researcher, engineer and author of Black Hat Bash, and Black Hat GraphQL, (as well as the upcoming Drone Hacker's Handbook). Nick Aleks founded ASEC (asec.io) and established DEFCON Toronto (DC416). He has spent over a decade spearheading cybersecurity... Read More →
Friday October 9, 2026 16:00 - 16:20 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

16:00 CEST

Crash Dumps Without Cables: Live Coredump Capture Over UDP/Ethernet in Zephyr RTOS - Kedareswara Rao Appana, AMD
Friday October 9, 2026 16:00 - 16:20 CEST
When an embedded system crashes in the field, recovering the coredump often determines whether debugging takes hours or weeks. Zephyr has long supported coredumps over UART, but in modern industrial, IoT, and edge deployments the serial port is rarely accessible. Devices may be sealed in cabinets, deployed remotely, or connected only via network.

This talk introduces a new Zephyr coredump backend that streams crash data over UDP (IPv4/IPv6) at the moment of a fatal exception—no USB cable or physical access required. We will explore the design challenges of networking in the fatal path, including safely re-enabling interrupts so the NIC can transmit, and the ZCDU framing protocol used to packetize and reliably reassemble dumps from UDP datagrams. We also show how the host receiver integrates seamlessly with the existing Zephyr GDB workflow, making the switch from UART to Ethernet a simple Kconfig option. Attendees will learn how to enable fleet-scale crash capture and dramatically reduce time-to-root-cause for deployed Zephyr devices.

pull request : https://github.com/zephyrproject-rtos/zephyr/pull/108410
Speakers
avatar for Kedareswara Rao Appana

Kedareswara Rao Appana

Member of Technical Staff, AMD
Device driver developer (linux and Baremetal), Expertise on the ARM, Microblaze and Microblaze Risc-v processors, Zephyr OS and System device-tree concepts and Lopper tool, Contributed to open source Linux Up streamed CAN and Xilinx DMA drivers and contributed to axi ethernet and... Read More →
Friday October 9, 2026 16:00 - 16:20 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

16:30 CEST

Updates on Sbom-cve-check: An Open-source CVE Analysis Tool for Embedded Systems - Benjamin Robin, Bootlin
Friday October 9, 2026 16:30 - 16:50 CEST
With embedded devices now everywhere, from home appliances to industrial systems, it is vital to regularly scan them so that any known vulnerability (CVE) in software components can be identified and addressed before they become security risks.

Regularly monitoring these CVEs will be mandatory in various cases to comply with the EU Cyber Resilience Act (CRA), which pushes the industry towards more accountable and proactive security in embedded systems.

Released in December 2025, sbom-cve-check is an open-source automated vulnerability analysis tool. It operates directly on a Software Bill of Materials (SBOM), without requiring access to the original build environment. SBOMs can be generated from build systems such as Yocto, enabling post-build security analysis even when the build infrastructure is unavailable.

This talk will present sbom-cve-check, highlight its major improvements over the past six months, and explain how it is now fully integrated into Yocto, replacing the built-in cve-check class.

sbom-cve-check is provided under the GPLv2 license, and contributions are, of course, welcome :)
Speakers
avatar for Benjamin Robin

Benjamin Robin

Embedded software engineer, Bootlin
Benjamin Robin is an embedded Linux engineer with 14 years of experience. He joined Bootlin in 2025. Before joining Bootlin, he held roles as both an embedded software engineer and an embedded Linux engineer. Over the years, he gained extensive experience across a wide range of industries... Read More →
Friday October 9, 2026 16:30 - 16:50 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

16:30 CEST

Robotics Is Becoming Distributed Systems - Lessons Learned Building Multi-UAV Architectures - Pawel Sawicki, UfoCourier.com
Friday October 9, 2026 16:30 - 16:50 CEST
PX4 and MAVSDK have made controlling individual drones remarkably accessible. Building systems around fleets, however, introduces a different class of challenges.

While developing a distributed multi-UAV architecture, we repeatedly discovered that many problems that initially appeared to be robotics problems were, in fact, distributed-systems problems. Task execution, telemetry aggregation, observability, fault tolerance, and fleet coordination quickly became more important than vehicle control itself.

This talk presents the architectural lessons that emerged from this work. It covers the separation of control and orchestration, the shift from commands to tasks, event-driven architectures, spatial state, and observability.

A recurring theme is that fleet management can be viewed as a space-time scheduling problem involving heterogeneous resources. From this perspective, many challenges beyond individual vehicles are problems of state, scheduling, and coordination.

The session connects PX4 and MAVSDK with ideas from distributed systems and scheduling theory, highlighting reusable patterns for scalable autonomous systems.
Speakers
avatar for Pawel Sawicki

Pawel Sawicki

Founder and CTO, UfoCourier.com
Pawel Sawicki is a Machine Learning Engineer and Software Architect with 15+ years of experience in distributed systems and AI. His work focuses on deep learning, LLM-based systems, and scalable agentic architectures. He combines hands-on experience with modern AI frameworks and cloud-native... Read More →
Friday October 9, 2026 16:30 - 16:50 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit

16:30 CEST

Scatter-Gather in Sharded Worlds: Implementing Resilient Cluster Scans Without Starving Shards - Sakshi Nasha, Cohesity & Primanshu Choudhary, GetYourGuide
Friday October 9, 2026 16:30 - 17:10 CEST
Have you ever run a global pattern search or database scan across a large cluster, only to watch your application latency skyrocket and healthy nodes suddenly drop offline?

When applications outgrow a single instance, global data scanning becomes a major distributed systems bottleneck. High-level frameworks try to mask this complexity with simple abstractions, forcing the client driver to execute a "scatter-gather" pattern: fanning out parallel cursor queries to thousands of logical shards and merging the reactive results on the fly. If designed naively, a single slow shard or an unindexed query can exhaust the client's connection pool, leak memory, and starve production read/write traffic.

In this practical, code-focused session, we will open up the engine hood of high-performance drivers using live examples from the Valkey-Glide ecosystem. We will show you how to safely bridge high-level data abstractions down to sharded sockets without risking cascading timeouts.
Come Join us, to build Resilient Cluster Scans Without Starving Shards!
Speakers
avatar for Sakshi Nasha

Sakshi Nasha

Software Engineer, OpenSource Contributor, Cohesity
Sakshi Nasha is a Software Engineer with a passion for building software and driving diversity in tech. An open-source enthusiast and OpenSearch Ambassador, she actively contributes to FOSS communities and speaks internationally on topics including GO, APIs, Security, PostgreSQL and... Read More →
avatar for Primanshu Choudhary

Primanshu Choudhary

Software Engineer 2, GetYourGuide
Primanshu is a Software Engineer at GetYourGuide, working in the Reviews team, he focuses on improving the performance and scalability of reviews system serving 400M+ requests per day with low latencies. He is a database enthusiast who enjoys solving real world problems, applies pragmatic... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Small Hall (Floor 0)
  Cloud & Orchestration

16:30 CEST

State of the OSS Union: Assessing Your Stack’s Autonomy Under EU Law - Emiel Brok, SUSE / DOSBA
Friday October 9, 2026 16:30 - 17:10 CEST
Open source is the bedrock of European digital sovereignty, but a wave of aggressive new EU legislation is transforming how organizations must build, source, and secure their digital environments. Navigating this shift requires unpacking complex regulatory mandates and understanding their operational impact on modern enterprise and cloud software architecture.

This fast-paced session strips away the legal jargon to deliver a real-time status update on Europe’s changing digital roadmap. We will analyze the mandatory software bill-of-materials (SBOM) rules of the Cyber Resilience Act (CRA) and the open standards driving the Interoperable Europe Act. Crucially, we dive into the European Commission's freshly unveiled Cloud and AI Development Act (CADA) to unpack its cloud sovereignty tiers and its "open-source first" procurement principles.

Moving from compliance theory to practical execution, attendees will gain a concrete framework to audit their own production IT stacks. We will walk through the web-based SUSE Cloud Sovereignty Self-Assessment tool to measure true autonomy using weighted SEAL (Sovereignty Effective Assurance Level) metrics.
Speakers
avatar for Emiel Brok

Emiel Brok

Global Sovereignty Ambassador, SUSE / DOSBA
Open Source & Sovereignty Ambassador at SUSE.
Co-founder DOSBA (Dutch Open Source Business Alliance)
Social Media activities through #FridayKetchup and #GeekOnTour.
Mission in life: Make the world a better place by evangelizing open source.
Friday October 9, 2026 16:30 - 17:10 CEST
Club H (Floor 1)
  Digital Trust
  • Audience Experience Level Any

16:30 CEST

BoF: The Yocto Project and OpenEmbedded - Josef Holzmayr, Mender.io & The Yocto Project & Philip Balister, OpenSDR
Friday October 9, 2026 16:30 - 17:10 CEST
This BoF provides an open forum for the Embedded Linux community to ask questions and discuss issues with the Yocto Project and OpenEmbedded community.

We open with a Yocto Project summary and OpenEmbedded State of the Union.

All users, contributors and maintainers as well as curious minds are invited to bring their thoughts and topics.
Speakers
avatar for Josef Holzmayr

Josef Holzmayr

Developer Enablement Expert & Community Manager, Mender.io & The Yocto Project
Josef has been active for more than 20 years as a "Complete"-Stack developer by now. He's done everything from debugging hardware over application development to web front ends.

A passion for showing, telling, and teaching people in both entertaining and engaging ways led Josef... Read More →
avatar for Philip Balister

Philip Balister

Minister of Progress, OpenSDR
I have a bio
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

16:30 CEST

Fast, Safe, and Asleep: Bringing Runtime PM To Modern IOMMUs - Pranjal Shrivastava, Google
Friday October 9, 2026 16:30 - 17:10 CEST
Modern IOMMUs are deployed across wildly different environments. In enterprise servers, they require massive scalability, heavy virtualization support, and a zero-tolerance policy for lock contention. On the other hand, as these high-performance IOMMUs increasingly find their way into mobile, automotive, and edge SoCs, aggressive dynamic power management becomes mandatory.

Using arm-smmu-v3 as a case study, this talk explores the design challenges in integrating the Linux Runtime Power Management (RPM) framework into high-performance IOMMU drivers. Modern IOMMU drivers operate primarily with in-memory data structures, rely on HW-shared queues and are designed for lockless, concurrent access, often from strictly atomic contexts.

The RPM framework’s reliance on locks fundamentally clashes with this lockless architecture and atomic execution constraints. This session walks through the design choices evaluated while implementing runtime power management for a modern IOMMU driver, without sacrificing its lockless, concurrent, and efficient behavior.

The talk is backed by the arm-smmu-v3 RPM Series upstream: lore.kernel.org/all/[email protected]/
Speakers
avatar for Pranjal Shrivastava

Pranjal Shrivastava

Software Engineer - III, Google
Pranjal is a Linux kernel engineer at Google and an active upstream contributor. He focuses on virtualization and networking, with a background in low-level software/firmware development. Outside of work, Pranjal divides his processing power between making music and enjoying great... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference

16:30 CEST

A Surprisingly Hard Question: How Much Memory Does My System Use? - Richard Weinberger, sigma star gmbh
Friday October 9, 2026 16:30 - 17:10 CEST
When everything runs smoothly, memory usage is just another metric. But when out-of-memory situations strike, or you are tasked with cutting a workload's RAM in half, it suddenly becomes the most important metric in your system.

While Linux exposes dozens of memory-related counters, answering basic questions is notoriously difficult. Developers and system administrators often struggle to pinpoint exactly how much memory the system is actually using, what the true footprint of a single application is, and how much memory that application can safely consume before causing issues.

In this talk, Richard will demystify Linux memory metrics and break down how the OS organizes memory across kernel and userspace.

Attendees will learn how to accurately read and make sense of Linux memory counters, giving them a better understanding of how internal memory management actually works. The session will also cover practical techniques for debugging memory-related issues and OOM kills, leaving the audience with actionable ways to optimize their application memory footprints.
Speakers
avatar for Richard Weinberger

Richard Weinberger

CTO, sigma star gmbh
Richard Weinberger is co-founder of sigma star gmbh where he offers consulting services around Linux and IT security. Upstream he maintains various subsystems of the Linux kernel such as UserModeLinux and UBIFS. Beside of low level and security aspects of computers he enjoys growing... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Panorama Hall (Floor 1)
  Linux

16:30 CEST

From Hours To Minutes: Building Production-Ready Agentic Systems on Kubernetes - Purnanand Kumar & Dipali Chatterjee, IBM
Friday October 9, 2026 16:30 - 17:10 CEST
Agentic AI systems are rapidly evolving from research experiments into production workloads. However, while building a proof-of-concept agent can take only a few hours, building a reliable, scalable, and observable agentic platform remains a significant challenge.

This session explores how modern open source technologies can be combined to build production-ready agentic systems on Kubernetes. We will walk through a complete architecture that includes large language models, agent orchestration, retrieval systems, tool execution, memory management, observability, and infrastructure automation.

Using technologies such as Kubernetes, Kubeflow, LangGraph, Model Context Protocol (MCP), vector databases, and open-source serving frameworks, we will demonstrate how to move from a simple agent prototype to a resilient platform capable of supporting enterprise-scale workloads.
Speakers
avatar for Purnanand Kumar

Purnanand Kumar

Advisory software engineer, IBM
Led the development efforts in creating robust and scalable back-end systems for various projects, focusing on storage domain solutions. Leveraged Golang to build high-performance applications, optimizing data processing and storage operations. Collaborated with cross-functional teams... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Forum Hall (Floor 2)
  Open AI & Data

16:30 CEST

Generative AI and FOSS - Not Just the How but Also the Why - Carol Chen, Red Hat
Friday October 9, 2026 16:30 - 17:10 CEST
I've given several talks & workshops on various GenAI tools in the past couple of years. Generally the goals of the presentations are to demonstrate the how - how to fine tune a model, how to prepare data for RAG systems, how to use this framework or optimize that pipeline - I find that a lot of the discussions which happen during and after the workshop are around the why.

Why is structured data important? Why do we care about open source and open weights in models? Why does context size matter? Why can't I run/reproduce the same AI set up on my laptop? Why do I even have to use GenAI??

These and many more questions have popped up and quickly drowned in the rush to keep up with the next new AI tool or agent. I'd like to provide a space for everyone, especially those new to GenAI and/or open source, to pose these questions and discuss them without worring about missing out. Whether you are a skeptic or have your fully agentic workflow set up, we might share similar concerns and doubts. Bring your ideas and opinions!

During the BoF, I will also share various open source resources that may be relevant and useful in answering your questions and better prepare you on the AI journey.
Speakers
avatar for Carol Chen

Carol Chen

Principal AI Community Architect, Red Hat
Carol Chen is a Community Architect at Red Hat, having led several upstream communities including InstructLab, Ansible and ManageIQ. She has been actively involved in open source communities while working for Jolla and Nokia previously. In addition, she also has experiences in software... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Terrace 2A (Floor 2)
  Open Source 101

16:30 CEST

Running OSPOs at Scale: Hard-Won Lessons From Germany Industry - Thomas Steenbergen, OSSYN & Helio Chissini de Castro, Cariad
Friday October 9, 2026 16:30 - 17:10 CEST
Most organizations know they should manage open source strategically and efficiently. Few know how to actually do it when you're moving fast, resources are tight, and a supply chain incident can land on the front page.

Over the past several years, we've helped build and run Open Source Program Offices across multiple large German automotive and technology organizations. This session distills what actually worked - and what didn't.

We'll share concrete lessons on: getting buy-in from C-level to developer teams; surviving and learning from supply chain security incidents; scaling compliance without drowning engineers in process; using AI to cut OSPO workflow overhead; and growing open source contribution and compliance culture.

Along the way, we'll show how we used OSS Review Toolkit (ORT), a Linux Foundation project, as the automation backbone - and what we learned making it work in large, regulated industries.

You'll leave with a clearer picture of what it takes to scale open-sourcing and compliance in a regulated industry, and the mistakes worth skipping.
Speakers
avatar for Thomas Steenbergen

Thomas Steenbergen

Principal Consultant / ORT co-founder and maintainer, OSSYN
Thomas Steenbergen specializes in strategic open source management, helping organizations align their practices with business goals. An expert in open source adoption, community building, and compliance (including SBOMs), he is freelance consultant currently working for OSPOs of CARIAD... Read More →
avatar for Helio Chissini de Castro

Helio Chissini de Castro

Software Tooling Lead, Cariad
Helio Chissini de Castro has 25 years of open source experience in multiple areas, from contributions to community management and entire project design. His entire professional life was around bring open source to the most possible areas. On recent years, Helio has an ongoing effort... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 1 A (Floor 1)

16:30 CEST

Voluntary Transparency, Involuntary Security: A Maintainer's Guide To CRA Readiness - Roman Zhukov, Red Hat
Friday October 9, 2026 16:30 - 17:10 CEST
The enforcement window for the EU Cyber Resilience Act (CRA) is arriving, triggering corporate compliance panic. While individual open-source developers and volunteer maintainers have zero obligations under the CRA, their downstream commercial adopters face mandatory due diligence requirements. How do Maintainers survive being bombarded with manual security questionnaires and subtle attempts to shift regulatory liability upstream?

The co-chair of the OpenSSF Global Cyber Policy Working Group and co-creator of the CRA Readiness Guide for Maintainers will walk you through converting the OpenSSF voluntary checklist into automated repository-level defenses. Attendees will see how to deploy the open-source OSPS Baseline Scanner GitHub Action to perform security gap analysis, expose standardized project postures via machine-readable security-insights.yaml files, and anchor liability disclaimers into repositories to push due-diligence burdens back downstream.
Speakers
avatar for Roman Zhukov

Roman Zhukov

Security Community Lead, Red Hat
Roman is a cybersecurity expert with 20+ years of experience securing complex systems and products. As Principal Architect at Red Hat, he drives open-source security strategy and cross-industry collaboration to build trusted software ecosystems. Formerly, he led Product Security... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Conference Hall (Floor 4)

16:30 CEST

How We Stopped Shai Hulud V4: Hunting a Self-Replicating Npm Worm With AI Toolchain Poisoning - Kush Pandya, Socket
Friday October 9, 2026 16:30 - 17:10 CEST
The Shai Hulud worm family has stalked the npm supply chain across multiple variants, stealing credentials from developer and CI environments, propagating via stolen npm and GitHub identities, poisoning workflows, and carrying a dead switch that can wipe home directories on command. Version four just crossed a new line. SANDWORM_MODE, deployed across 19 malicious npm packages, keeps the full prior playbook and adds AI toolchain poisoning via MCP server injection into Claude Code, Claude Desktop, Cursor, and Windsurf. The rogue MCP server uses prompt injection to instruct AI assistants to silently exfiltrate SSH keys, AWS credentials, and LLM API tokens from nine providers, without alerting the user. We present the full story: the Shai Hulud lineage, how the obfuscated three-layer loader was detected, how 19 packages were linked to one operator, how a bidirectional CI worm loop was built from a weaponized GitHub Action, and how coordinated takedown with npm, GitHub, and Cloudflare dismantled the infrastructure, along with what the dormant polymorphic engine tells us about where version five is heading.
Speakers
avatar for Kush Pandya

Kush Pandya

Security Researcher, Socket
Security researcher at Socket.dev. Securing Open Source Supply chain, for various fortune 500 customers like Netflix, Salesfore, etc. and other leading AI companies like Anthropic, OpenAI and many more.
Friday October 9, 2026 16:30 - 17:10 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

16:30 CEST

Safety Critical Software BoF - Philipp Ahmann, ETAS GmbH & Olivier Charrier, Wind River
Friday October 9, 2026 16:30 - 17:10 CEST
Interest in safety critical open source software is high, yet opportunities to connect and openly discuss challenges remain limited. This BoF creates a focused forum for practitioners and newcomers to exchange experiences, ask questions, and gain visibility into existing projects and initiatives.

It also highlights the role of initiatives such as the Linux Foundation ELISA project as a central interface within the ecosystem, helping to connect efforts across communities, share practices, and make ongoing work more discoverable. The project brings together horizontal working groups covering features, processes, architecture, and tooling, while also addressing vertical domains such as automotive, aerospace, space, railways, and medical. This reflects the growing relevance of Linux and open source in safety critical systems.

By enabling direct interaction and cross project exchange, the session supports alignment, reduces duplication, and fosters collaboration in an evolving safety critical OSS landscape.

Participants at all levels of experience are encouraged to join, contribute their perspective, and engage with the community.
Speakers
avatar for Philipp Ahmann

Philipp Ahmann

Automotive OSS Process Lead, ETAS GmbH
Philipp Ahmann is a Senior OSS Community Manager at ETAS (a Bosch subsidiary), specializing in safety-critical automotive open source software. With 15+ years' experience in Linux automotive platforms, he has held roles from software engineer to project & line manager.
He currently holds the position of the technical steering committee chair for the Linux Foundation ELISA project to Enable Linux in Safety Applications. Additionally, he is member of the Linux Foundation Europe Advisory Board... Read More →
avatar for Olivier Charrier

Olivier Charrier

Principal Technologist - Functional Safety, Wind River
Olivier Charrier obtained a Master’s degree in Software Engineering (DESS) from Bordeaux University in 1989.
After working for Alsys/Aonix on Ada development environment for embedded systems, Olivier joined Wind River in June 2001 where his focus is to help Wind River's customers define, implement and certify Safety Critical Systems for multiple market segments including Avionics, Automotive... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Club A (Floor 1)
  Safety-Critical Software

16:30 CEST

From Specification To Merge: Implementing a Standards-Compliant DALI Driver for Zephyr - Sven Hädrich, sevenlab engineering GmbH
Friday October 9, 2026 16:30 - 17:10 CEST
DALI (Digital Addressable Lighting Interface) is the dominant standard for professional lighting control, yet firmware support for it has been absent from the Zephyr ecosystem — until now. This talk walks through the full journey of designing and upstreaming a DALI low-level driver into Zephyr mainline: from understanding the protocol's precise timing and bus requirements, to crafting an API that fits naturally within Zephyr's driver model, to surviving the community review process through multiple rounds of discussion and refactoring.

Along the way we also experimented with AI-assisted code review as part of our workflow, and we'll share what that was actually like in the context of a real upstream contribution.

We'll be honest about what was hard, what the community pushed back on, and what we'd do differently.
Speakers
avatar for Sven Hädrich

Sven Hädrich

Co-Founder, sevenlab engineering GmbH
Sven started programming when the Tandy TRS-80 was a novelty. After studying physics and earning a PhD, he co-founded a laser company where he led electronics and software development. He then built a career as a freelance embedded systems developer before joining Grandcentrix, where... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

16:30 CEST

Scaling Zephyr Hardware CI Across Continents - Anıl Özrenk, Analog Devices
Friday October 9, 2026 16:30 - 17:10 CEST
Most Zephyr CI talks focus on Twister with a single board. This talk covers what happens when your hardware spans continents, operating systems, and team boundaries, and every PR still needs to test against all of it.

Our Zephyr firmware targets proFPGA systems programmed via Windows-only scripts, Protium emulators on Linux servers with J-Links on Windows machines, MAX32xxx boards on Linux, and virtual platforms. Discrete teams — hardware, virtual platform, proFPGA, Protium, bare-metal, Debugger Scripts, and Zephyr — each own a different piece on different platforms.

We built CI that unifies all of this so a developer opening a PR gets feedback from real hardware regardless of board, country, or OS. The talk covers device-specific flashing automation, reusable workflows scaling from PRs to nightly runs, observability beyond pass/fail (memory footprint tracking, runner dashboards, test analytics), and the technical interfaces between teams that make it sustainable.

Every pattern is in production today, testing across 28+ boards in multiple countries and different toolchains on every pull request.
Speakers
avatar for Anıl Özrenk

Anıl Özrenk

Embedded Software Engineer, Analog Devices
I'm an Embedded Software Engineer at Analog Devices with five years of experience in embedded systems. I build and maintain the hardware test infrastructure for ADI's Zephyr-based embedded platforms.
I'm passionate about the Zephyr ecosystem and its testing framework, Twister. I focus on pushing Twister's capabilities to production scale. Making it work across heterogeneous hardware, multiple operating systems, and distributed teams... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit

16:50 CEST

Optimizing AI for Resource-Constrained Edge Devices - Pavel Macenauer, NXP Semiconductors
Friday October 9, 2026 16:50 - 17:10 CEST
Eliminating cloud dependency and making connectivity optional is becoming essential for applications where data privacy, low latency, and reliability are critical. Running AI locally allows the system to respond immediately and keeps sensitive data on device which guarantees security. However, the cost is high. It introduces significant challenges due to computing, memory, and power constraints.

This session explores optimization techniques and algorithms mandatory for deploying vision, audio, and language models on resource-constrained edge devices. We will dive into methods such as quantization, model compression, and graph optimization, and show how to balance latency, accuracy, and energy efficiency.

Using widely adopted open-source frameworks like PyTorch and TensorFlow, along with intermediate ecosystems such as ONNX, we will demonstrate how to efficiently deploy from training a model to highly optimized edge inference. We will provide insight into making AI models smaller, faster, and more efficient with minimal impact on their accuracy, allowing them to run on microprocessor and microcontroller-class devices.
Speakers
avatar for Pavel Macenauer

Pavel Macenauer

R&D Manager, NXP Semiconductors
An R&D software director and architect at NXP Semiconductors leading teams developing tools, runtime libraries, and enabling AI on Edge-class devices. Both professionally and out of human curiosity, Pavel always developed software visualizing the World around us. Initially through... Read More →
Friday October 9, 2026 16:50 - 17:10 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference

16:50 CEST

Self-Defending Swarms: MAVLink Signing Meets Peer-Consensus Exclusion Onboard PX4 - Yogesh Sardana, Airtel
Friday October 9, 2026 16:50 - 17:10 CEST
This isn't just about Airtel but for every organisation as MAVLink has supported per-message signing since MAVLink 2, yet almost no real-world PX4 fleet enables it, because key distribution, rotation & revocation across dozens of airborne vehicles has no production-ready tooling, so most swarms still accept any correctly formatted command from whatever radio reaches them. A single spoofed ground station or one drone with cloned key can inject commands rest of swarm has no way to reject. Talk introduces swarm-native trust layer that issues short-lived, mission-scoped MAVLink signing keys from a lightweight onboard authority, lets every drone verify signatures independently without round-tripping to a ground station & adds a peer-consensus exclusion protocol so that if one drone starts broadcasting commands inconsistent with its own attested mission profile, the rest of swarm votes to ignore it mid-flight without operator intervention. We demonstrate this on PX4 SITL & real hardware over a Zenoh-based inter-drone link, show a live command-injection attack being rejected by consensus & discuss key rotation strategy under degraded or fully lost ground-station connectivity mid-mission.
Speakers
avatar for Yogesh Sardana

Yogesh Sardana

Deputy General Manager - AI & Cloud Engineering, Airtel
I'm working as a Cloud Engineering Leader & Researcher, leading Open Source Stack R&D wing, known as Jack of all trades, master of Cloud. Been into various tech stacks of Software Development Life Cycle, having fun with tech.
Friday October 9, 2026 16:50 - 17:10 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

17:20 CEST

ELC Closing Game
Friday October 9, 2026 17:20 - 18:20 CEST
Come join us for the Embedded Linux Conference Annual Closing Game! Walt Miner, ELC Program Co-chair, will host the event, which is a fun opportunity for attendees to win amazing prizes.
Friday October 9, 2026 17:20 - 18:20 CEST
South Hall 3 C (Floor 3)
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -