Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Company: Any clear filter
arrow_back View All Dates
Friday, October 9
 

09:05 CEST

Buildroot LTS in the CRA Era: 18 Months of Keeping a 3-Year Branch Secure - Thomas Perale & Titouan Christophe, Mind OSS NV
Friday October 9, 2026 09:05 - 09:45 CEST
The Buildroot Long-Term Support (LTS) sponsorship initiative was launched in March 2025. Its goal is to help Buildroot users maintain stable and secure products over longer periods, particularly in light of upcoming security regulations such as the Cyber Resilience Act (CRA).

We transitioned from a day-to-day maintenance workflow to a more systematic, weekly peer-reviewed approach. After more than a year and a half of maintaining the Buildroot LTS branch, we have encountered both successes and unforeseen challenges. We had to develop custom tooling to deal with a growing number of vulnerability reports, all while preserving stability for the releases.

This talk covers:

* How we tackle the maintenance task as a distributed team.
* Maintenance challenges with the constant flow of CVEs.
* Keeping the package metadata up-to-date and improving the vulnerability
monitoring across branches.
* What worked and what didn't.
* How we plan to evolve and improve for the future.
Speakers
avatar for Thomas Perale

Thomas Perale

Embedded Software Engineer, Mind OSS NV
Thomas Perale is a Belgian embedded software engineer working for Mind with a strong passion for free software development and embedded systems.

He is involved in maintaining Buildroot stable and LTS releases.
avatar for Titouan Christophe

Titouan Christophe

Embedded Software Engineer, Mind OSS NV
Titouan is an embedded and backend developer. He has worked in remote railway vehicle monitoring and automated visual quality control for the manufacturing industry.

Titouan is now working at Mind OSS, helping customers with Zephyr, embedded Linux and open source in general. He is the author of Zephyr's USB-MIDI and Network MIDI 2.0 stacks, and co-steward of the Buildroot LTS initiative... Read More →
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

09:50 CEST

Seeing Inside the NPU: Open-Source Hardware Counter Profiling for Ethos-U on Linux and Zephyr - Vibhore Vardhan, BayLibre
Friday October 9, 2026 09:50 - 10:20 CEST
Edge AI runs on dozens of NPUs — Ethos-U, Hexagon, APUs, DSPs — each with its own closed toolchain and proprietary profiling tools. Application developers have no standard way to answer the basic question: what is my NPU actually doing?

This talk walks through the edge AI software stack — frameworks, delegates, drivers, hardware counters — and shows what it takes to make performance visible. Building on Tomeu Vizoso's Ethos-U PMU kernel work (upstream), we are instrumenting ONNX Runtime and TFLite operators with per-operator CPU PMU data (cycles, cache miss, bandwidth), surfaced via open trace formats, and wiring NPU hardware counter values into ExecuTorch ETDump traces on Zephyr.

The goal: per-operator timing, CPU cache and bandwidth data, and NPU cycle counts in a single open trace — without a proprietary tool.

Contributing to the Linux perf subsystem, this work lays the groundwork for open profiling support on other NPU targets.
Speakers
avatar for Vibhore Vardhan

Vibhore Vardhan

Senior Software Engineer, BayLibre
Vibhore Vardhan is a senior embedded systems engineer and researcher at BayLibre, leading R&D with a current focus on Edge AI. He brings a background in system-level power management on TI SoCs, now applied to NPU toolchain observability and profiling across the Edge AI software... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

09:50 CEST

Apps, Not Firmware: A Service-Oriented Application Layer for Zephyr - Sylvio Alves, Espressif Systems
Friday October 9, 2026 09:50 - 10:20 CEST
Microcontroller firmware is monolithic: one image, one failure domain, where a bug anywhere can crash everything. Yet modern MCUs ship with memory protection (MPU, MMU, or PMP), and Zephyr already has the isolation pieces - userspace, memory domains, kernel-object capabilities, watchdogs, zbus - never assembled into an application model.

This talk presents a service-oriented application layer for Zephyr: multiple memory-isolated apps running as managed units, each reaching hardware and the network only through a capability-gated service broker, so a misbehaving app cannot corrupt, starve, or crash its neighbors.

We build the missing keystone - an app-group lifecycle and a service broker - on top of existing Zephyr, and demonstrate it live: two isolated apps share one Wi-Fi stack, each making independent network requests; one hangs and another faults, both are killed and reclaimed, while the healthy app runs on. We close with hardware lessons and upstreamable RFC targets.
Speakers
avatar for Sylvio Alves

Sylvio Alves

Software Engineer, Espressif Systems
Sylvio Alves is an Embedded Software Engineer at Espressif Systems, driving ESP32-family support in Zephyr RTOS. Over 15+ years in embedded - as both a hardware and firmware developer - he has worked across many chip families and frameworks, and today focuses on low-level bring-up... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

11:05 CEST

Pairing PX4 and ROS 2 Through Micro XRCE-DDS and Zenoh-pico, a Comparison - Beniamino Pozzan, Archangel Autonomy
Friday October 9, 2026 11:05 - 11:25 CEST
Since Micro XRCE-DDS replaced Fast-RTPS in PX4 version 1.14 the support for direct communication between ROS 2 and PX4 never stopped improving.
With PX4 stable version 1.17 recently released and version 1.18 close to enter its beta testing phase this presentation aims to cover the latest changes, imporvents and limitations of the Micro XRCE-DDS and Zenoh-pico interfaces.
The presentation will also compare the two communication methods to give the audience all the information necessary to choose the best approach given their requirements and application contraints.
Speakers
avatar for Beniamino Pozzan

Beniamino Pozzan

Senior Robotics Engineer, Archangel Autonomy
B. Pozzan is a PX4 Maintainer and Senior Robotics Engineer at Archangel Autonomy. He has extensive experience integrating autopilots with ROS 2 for UAV control and GNSS-denied navigation. With a Ph.D. in Automation Engineering from the University of Padova, he has extensive experience... Read More →
Friday October 9, 2026 11:05 - 11:25 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

11:05 CEST

Proofs of Personhood: Managing Identity in the Age of AI - Hart Montgomery, The Linux Foundation; Drummond Reed, First Person Cooperative; Glenn Gore, Affinidi
Friday October 9, 2026 11:05 - 11:45 CEST
“On the internet, nobody knows you’re a dog,” the famous New Yorker comic goes, and that aphorism couldn’t ring truer today. In a world of AI agents, how can we be sure that we (or our agents) are interacting with other trusted, reputable systems and agents rather than impersonators or scammers? As open source maintainers, how can we be sure that new contributors are responsible, trustworthy individuals rather than adversarial state actors, helping to thwart compromises like the XZUtils attack? More generally, how do we deal with digital identity in the age of AI?

Our proposal is to use cryptographic proofs of personhood. These can be built from a decentralized, privacy-preserving reputation system, which we can build with tools and standards we have developed in several projects in LFDT. The session will cover some background on how proofs of personhood work, including privacy guarantees from cryptography (at a beginner level). Then, we will explain some applications in agentic AI and open source software maintenance. Finally, we will give an end-to-end demo of how our systems work in practice which will include audience participation in a “verifiable trust graph”.
Speakers
avatar for Drummond Reed

Drummond Reed

Director, First Person Cooperative
30+ years working on Internet identity, security, privacy & trust
Co-Editor, W3C Decentralized Identifiers (DID) Specification
Steering Member, Trust Over IP (ToIP) Foundation
Co-Author, Self-Sovereign Identity (Manning, 2021)
avatar for Hart Montgomery

Hart Montgomery

CTO, LFDT, Linux Foundation
Hart Montgomery serves as the CTO of LFDT and the ED of the PQCA. Hart previously worked in blockchain and cryptography research at Fujitsu Research where he helped lead Fujitsu’s contributions to Hyperledger. Prior to Fujitsu, Hart received a Ph.D. in cryptography at Stanford under... Read More →
avatar for Glenn Gore

Glenn Gore

CEO, Affinidi
30+ year Veteran of building Internet-scale infrastructure (OzEmail, UUNet, AWS, Affinidi). CEO of Affinidi, board member to tech startups. Glenn is still a hands-on developer, building next-generation security and privacy services that are open by design and open-source in devel... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club H (Floor 1)
  Digital Trust
  • Audience Experience Level Any

11:05 CEST

Is It Time To Retire Kas? - Jan Kiszka & Felix Mößbauer, Siemens
Friday October 9, 2026 11:05 - 11:45 CEST
You are using kas, the user-friendly orchestration tool for bitbake projects, and you just got nervous? Sorry for that.

With your full attention now, this talk shall bring you up to date with latest developments in kas. Among them are the diff plugin, buildtools support, build attestations, improved lock file handling, unprivileged containers, commit signature validation, easier CI builds, and more.

But we would also like to hear from you what could be further improved. Are there use cases or workflows that should be added to kas or could be better handled than so far. Be prepared for an interactive part.

Last but not least, we will relieve you from worries that kas might be retired by explaining our motivations and plans to drive this project also in the foreseeable future.
Speakers
avatar for Jan Kiszka

Jan Kiszka

Principal Key Expert, Siemens
Jan Kiszka is working as consultant, open source evangelist and Principal Key Expert Engineer in the Linux Expert Center at Siemens Technology. He is supporting Siemens businesses with adapting, enhancing or strategically driving open source as platform for their product demands... Read More →
avatar for Felix Mößbauer

Felix Mößbauer

Senior Embedded Developer, Siemens AG
Having a strong background in High Performance Computing, Felix is currently focusing on embedded Linux platforms for realtime applications. Hereby, he works across country and company boundaries to unify patterns that are recurring and mandatory for embedded products (like secure... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:05 CEST

Scaling OSS Code Quality With Multi-Agent Swarms - Vikram Vaswani, Independent
Friday October 9, 2026 11:05 - 11:45 CEST
Development teams are seeing a rapid increase in code contributions, many of them from AI tools and pair-programming copilots. As AI-generated code increases, human reviewers can quickly get overwhelmed.

The instinct to throw "an AI reviewer" at the problem mostly doesn't work. A single agent produces shallow comments, misses context, and either over-flags or under-flags depending on how it's prompted.

This talk presents a pattern that works better, built and demonstrated from scratch: three specialized reviewing agents in parallel, followed by a developer agent that applies the fixes. One reviewer focuses on architecture, one on security, one on test coverage. When all three finish, a fourth agent rewrites the code to address each issue and opens a new PR for human sign-off.

The architecture is adaptable: teams with data sovereignty requirements can swap the hosted model for a self-hosted open-weight alternative (Llama 3, Mistral) served via vLLM or Ollama.

Attendees leave with a concrete, working pattern they can adapt to their own projects, and a clearer picture of where AI can genuinely reduce review bottlenecks.

Includes live demo.
Speakers
avatar for Vikram Vaswani

Vikram Vaswani

Developer Advocate

Friday October 9, 2026 11:05 - 11:45 CEST
Forum Hall (Floor 2)
  Open AI & Data
  • Audience Experience Level Any

11:05 CEST

This Talk Is Already Out of Date: Planning for the Long Term in a Short Term World - Rebecca Rumbul, Rust Foundation
Friday October 9, 2026 11:05 - 11:45 CEST
Successful Open Source projects have always had to balance the need to work towards long term sustainability and growth with meeting shorter term issues such as immediate funding and human resourcing needs. Projects would generally work to an annual rhythm to align with budgeting and funding decisions made by corporate supporters, and annual planning cycles were in many places well established. However, this rhythm has been hugely impacted by the new age of AI and the pivots in focus of the commercial tech industry. Long term planning feels impossible, and funding work sustainably feels increasingly out of reach when projects are reliant on companies engaged in an AI arms race. Once-robust human processes now move too slowly to be effective, and the key individuals that still need to be a part of this new world increasingly feel like they are a day late and a dollar short for everything. This talk looks at how the human side of Open Source is being affected by these shifts, and how communities can consider how to respond to these challenges.
Speakers
avatar for Dr. Rebecca Rumbul

Dr. Rebecca Rumbul

Executive Director & CEO, Rust Foundation
Rebecca is the Executive Director and CEO of the Rust Foundation. She holds a PhD in Politics and Governance, and has worked as a consultant and researcher with governments, parliaments and development agencies all over the world, advocating for openness and transparency, and developing... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Conference Hall (Floor 4)

11:05 CEST

500,000 Containers, 5 Minutes, 10x Load: Scaling Uber’s Container Registry for Disaster Recovery - Sambhav Jain & Anton Kalpakchiev, Uber
Friday October 9, 2026 11:05 - 11:45 CEST
Kraken is Uber's open-source P2P container registry. It serves 23 petabytes of data daily with 99.9% reliability. However, during recovery from a complete regional failure, Kraken was pushed over its historical peak load by 10 times. It had to distribute over 100,000 container images every minute. The registry that "just worked" became the bottleneck blocking disaster recovery.

Adding capacity proved insufficient. So, the team reworked the caches and tuned download parallelism. But closing such a large performance gap required architectural changes. If downloads are too slow, move the data closer to the client. If you cannot serve everything at once, tier images by criticality. These optimizations eventually broke Uber’s deployment throughput record.

This talk presents a case study of evolving Kraken to deliver 10x performance under extreme load - the architectural changes, necessary trade-offs, and hard-won lessons. All optimizations are open-sourced in Kraken.

Speakers
avatar for Sambhav Jain

Sambhav Jain

Software Engineer, Uber
Sambhav Jain currently works as a Software Engineer at Uber on the container runtime team. Primarily working on container resource metrics and distributed container registry systems at Uber.
Before Uber, Sambhav worked at Cockroach Labs in the Database Performance team and at Confluent in the Kafka Connect team... Read More →
avatar for Anton Kalpakchiev

Anton Kalpakchiev

Software Engineer, Uber
Anton works as a software engineer at Uber's Compute team. He works on Kraken - Uber's P2P open-source Docker registry that distributes ~30PB of data per day. Additionally, Anton works on developer tooling used by thousands of software engineers at Uber to debug their containers live... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

11:05 CEST

Functional Safety Certification in Upstream Xen for Automotive and Avionics - Ayan Kumar Halder, AMD
Friday October 9, 2026 11:05 - 11:45 CEST
Safety-critical systems in avionics, automotive, and industrial domains increasingly rely on mixed-criticality architectures where workloads of different safety levels share hardware. This talk presents ongoing work to bring functional safety to the upstream Xen hypervisor, composed with Zephyr RTOS and Linux, to meet standards including DO-178C (avionics), ISO 26262 (automotive), and IEC 61508 (industrial).
We walk through concrete upstreamed and published contributions: MISRA C fixes, MPU support in Xen, requirements and architecture specifications, and test specifications. We describe how Xen is validated as a Safety Element out of Context using domain-based tests, fault injection, gdb-based interface testing, fuzzing, platform emulation, Ceedling unit testing, and coverage analysis (line, branch, function, MC/DC).
We also cover efforts to shrink the safety-certifiable codebase through fine-grained hardware configuration, and how Xen enforces freedom from interference between VMs via isolation. We close with opportunities to collaborate with the ELISA and Xen FuSa communities toward an open safety case for open-source systems.
Speakers
avatar for Ayan Kumar Halder

Ayan Kumar Halder

SMTS, AMD
Ayan has been working on Arm based low based software stack for the past 14 years. He has worked on variety of projects ranging from board bringup, post silicon validation to developing new features. He has contributed upstream to Xen, Linux and Zephyr.
More recently he is been actively involved within AMD on the Xen FuSa project... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

11:25 CEST

Lightning Talk: Beyond Immutable Machines: Introducing Cluster API In-Place Updates - Lennart Jern, Ericsson Software Technology
Friday October 9, 2026 11:25 - 11:35 CEST
Cluster API (CAPI) is by now a relatively mature project with many adopters using it in production already for years. Despite this, or perhaps rather thanks to it, CAPI keeps evolving, growing and adding new features. In this session, I'll present one of the most recent features: in-place updates.

In-place updates marks an important change to a fundamental assumption in CAPI. Traditionally, the Machines were considered mostly immutable. Any change required a replacement where new Machines were created and old Machines deleted. This method of operation has served CAPI well, and continues to do so, but it is not without pain points. With in-place updates, it is now finally possible to avoid replacement. This opens the door for unique use-cases and solutions, such as Talos, where each node's lifecycle can be managed through a built-in controller in the node itself.

Come learn about this new feature in CAPI, and how to make use of it!
Speakers
avatar for Lennart Jern

Lennart Jern

Senior Developer, Ericsson Software Technology
Lennart Jern is a senior developer at Ericsson with more than 6 years experience from the CNCF ecosystem. He works mainly on open source projects related to the Cluster API and is a maintainer for the Cluster API Metal3 and OpenStack infrastructure providers as well as the Baremetal... Read More →
Friday October 9, 2026 11:25 - 11:35 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

11:25 CEST

Cryptographic Flight Security: Implementing Hardware-Enforced FAA Remote ID and Trusted Identities - Ashok Kumar, gotoashok
Friday October 9, 2026 11:25 - 11:45 CEST
Global regulatory shifts—driven by strict NDAA requirements and EASA U-Space mandates—require drone manufacturers to implement verifiable supply chain security. Software-only implementations of FAA Remote ID remain vulnerable to key spoofing and firmware tampering. This session delivers a practical breakdown of how to enforce a hardware root of trust by embedding physical Secure Elements (like the OPTIGA Trust M) into open flight controllers running PX4 and NuttX.
We will bypass high-level concepts to dive straight into the embedded architecture:
Configuring the SPI/I2C bus interface between the flight MCU (PSoC C3M) and the security peripheral.
Modifying the NuttX driver layer to offload ECDSA signing keys for broadcast messages without blocking safety-critical flight loop threads.
Structuring secure boot sequences to protect downstream firmware from local physical exploits.
We will share timing benchmarks showing how to manage cryptographic latency within standard PX4 task frequencies to build compliant systems without sacrificing real-time flight performance.
Speakers
avatar for Ashok Kumar

Ashok Kumar

Ashok Kumar, gotoashok
I am a Systems Architect and Embedded Engineer with a 26-year obsession: defining what actually constitutes 'good' design in an era of over-engineering. I operate at the high-stakes intersection of Silicon and Software, translating complex hardware capabilities into mission-critical... Read More →
Friday October 9, 2026 11:25 - 11:45 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

11:55 CEST

Bitbake-setup Has Shipped in Yocto: Producing Complete Linux Systems From One File - Alexander Kanavin, Linutronix
Friday October 9, 2026 11:55 - 12:35 CEST
The Yocto project is a toolkit for creating custom Linux distributions for the embedded use cases. Historically it has not provided tools and standards for setting up and replicating build configurations in a reproducible manner, leaving that to third party projects and custom scripts.

This has changed with the latest Yocto LTS release (6.0 'wrynose'), which includes a tool called bitbake-setup. This talk will give an overview of what is available and how it can be used to write a record of how to build a complete system, and to replicate that build elsewhere with that record. I will also briefly cover possible future directions for build configuration management.
Speakers
avatar for Alexander Kanavin

Alexander Kanavin

Open Source Software Engineer, Linutronix
Alexander is an open source developer specializing in distribution engineering using vendor-neutral tooling and userspace stacks. He is one of the primary contributors to the Yocto project and has an interest in developing foundations of digital infrastructure in a sustainable ma... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:55 CEST

Mainline Allwinner Support Status Update - Paul Kocialkowski, sys-base
Friday October 9, 2026 11:55 - 12:35 CEST
Support for Allwinner SoC chips in mainine projects like Linux, U-Boot and TrustedFirmware-A has been thriving for over a decade, enabling a large number of use cases and applications. This ongoing effort is lead by the linux-sunxi community and supported by various companies and individuals.

This talk presents an overview of the current status of support on the boot, firmware and kernel sides, along with a comprehensive list of the supported chips with specific information for each aspect. This includes advanced topics like power management, multimedia, graphics and accelerators. The latest developments and ongoing chip support efforts is also highlighted.

Context and history regarding Allwinner and the linux-sunxi community is also presented, as well as related tools and resources.
Speakers
avatar for Paul Kocialkowski

Paul Kocialkowski

Multimedia, Graphics and Embedded Linux Expert, sys-base
Paul is a free software developer working on hardware support in mainline projects like Linux and U-Boot.

Since 2014, he has contributed hundreds of patches to the kernel, in areas that include v4l2 (decoder, capture, isp, sensor), drm (display, bridge) and platform support for... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:55 CEST

Measuring What Matters: Introducing Hardware Performance Counters in Zephyr RTOS - Kedareswara Rao Appana, AMD
Friday October 9, 2026 11:55 - 12:35 CEST
Embedded developers optimizing Zephyr applications often rely on software timers and GPIO toggles—intrusive techniques that alter the behavior they try to measure. Modern SoCs instead provide rich hardware performance counters across the system: CPU PMUs, interconnect/NoC monitors, and memory subsystem telemetry that capture cycles, cache behavior, bandwidth, and contention with near-zero overhead. Until now, Zephyr lacked a unified way to access these metrics.

This talk introduces Zephyr’s new portable **pmu.h** API, a cross-architecture abstraction for hardware performance monitoring. We present the first backend: an ARMv8-A PMUv3 driver that probes counters at runtime, self-calibrates CPU frequency, and maintains per-CPU state using IRQ-locked sequences for SMP safety.

Using real hardware benchmarks, we show how to measure context-switch cost, IRQ latency, cache behavior, branch prediction, and memory bandwidth. Attendees will learn how to add low-overhead profiling to their applications today and how the API will extend to RISC-V HPM, Cortex-M DWT, and SoC-level monitors without changing application code.

Pull request: https://github.com/zephyrproject-rtos/zephyr/pull/107016
Speakers
avatar for Kedareswara Rao Appana

Kedareswara Rao Appana

Member of Technical Staff, AMD
Device driver developer (linux and Baremetal), Expertise on the ARM, Microblaze and Microblaze Risc-v processors, Zephyr OS and System device-tree concepts and Lopper tool, Contributed to open source Linux Up streamed CAN and Xilinx DMA drivers and contributed to axi ethernet and... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

14:00 CEST

Container Metrics on Diverse Hardware: Driving Observability, Efficiency, and Real-Time Autoscaling - Sambhav Jain & Digvijay Singh Shekhawat, Uber
Friday October 9, 2026 14:00 - 14:40 CEST
Uber runs about 4 million containers on over 150,000 hosts. Our fleet includes a mix of cgroupv1 and v2 hosts, multiple cloud providers, and multiple Linux kernel versions. Tracking container performance at this massive scale is a difficult engineering challenge, including the cost of storing them. We currently process 60 million data points every second to keep everything running smoothly.

We run Cadvisor and open-source Nvidia and AMD GPU metrics exporters to reliably and affordably collect and store these metrics. This infrastructure is vital for our real-time autoscaling, which ensures our services stay online. We also use these metrics to track memory usage and keep costs low for our AI workloads. Despite maintaining all the critical use cases, we have saved around $ 4 million compared to last year by changing how we collect and store data.

We will share how we use these metrics to detect and prevent system failures before they affect users. Attendees will learn practical patterns for operating container metrics at scale. We will also discuss the hard lessons we learned while building a reliable metrics system for a complex global fleet.
Speakers
avatar for Sambhav Jain

Sambhav Jain

Software Engineer, Uber
Sambhav Jain currently works as a Software Engineer at Uber on the container runtime team. Primarily working on container resource metrics and distributed container registry systems at Uber.
Before Uber, Sambhav worked at Cockroach Labs in the Database Performance team and at Confluent in the Kafka Connect team... Read More →
avatar for Digvijay Singh Shekhawat

Digvijay Singh Shekhawat

Software Engineer, Uber
I've always loved solving problems. As a kid, that passion started with mathematics, which led me to competitive programming and eventually computer science.

At Uber, I was one of the founding engineers on the AI Solutions team, helping build Uber's new gig platform from the gr... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

14:00 CEST

Buildroot at 25: A Quarter Century of Making Embedded Linux Easy - Peter Korsgaard, Barco
Friday October 9, 2026 14:00 - 14:40 CEST
Buildroot started in 2001 with the goal of having a simple and easy way to build embedded Linux systems. Now, 25 years later the size and complexity of embedded Linux systems have increased dramatically and so have the required features of the build system, but the goals are still the same.

This talk celebrates Buildroot's 25th anniversary by exploring the project evolution, the community that shaped it and the technical decisions that enabled it to remain relevant for modern projects before finishing up with some thoughts about what the future may bring.

Attendees will gain both a historical perspective, insight into how Buildroot is developed and a view to what lies ahead.
Speakers
avatar for Peter Korsgaard

Peter Korsgaard

Senior Expert Embedded Development Engineer, Barco
Peter is an embedded Linux developer and long time Buildroot maintainer with 20+ years of experience
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

14:00 CEST

The Foundational Misnomer Hiding in Plain Sight - Powen Shiah, Sovereign Tech Agency
Friday October 9, 2026 14:00 - 14:40 CEST
"Foundation" is a word that carries weight: endowments, permanence, institutional resources. In the philanthropic world, foundations often have millions or billions in their endowments. In open source, the same word describes organizations that range from trademark holders and event hosts to genuine funders of development work.
That gap between expectation and reality matters. When developers, companies, and governments hear "foundation," many assume someone already has it covered. That assumption is one reason so many critical open source projects remain underfunded: the name signals security that often doesn't exist.
This talk unpacks the spectrum of what open source foundations actually do and don't fund, why the word creates a misleading picture of available resources, and what genuine infrastructure funding looks like in practice. Drawing on the work of the Sovereign Tech Agency, which funds critical open source projects and the ecosystem infrastructure sustaining them, this session offers a clearer picture of where the money is, where it isn't, and what that means for the long-term health of open source.
Speakers
avatar for Powen Shiah

Powen Shiah

Communications Lead, Sovereign Tech Agency
Powen handles communications at the Sovereign Tech Agency, highlighting the importance of open source digital infrastructure and the government's role in supporting it in the public interest. He’s worked in product marketing, communications, and internationalization in technology... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Terrace 2A (Floor 2)
  Open Source 101
  • Audience Experience Level Any

14:00 CEST

Let's Perform a Hazard Assessment! - Chuck Wolber, The Boeing Company & Pete Brink, Underwriter Laboratories (UL)
Friday October 9, 2026 14:00 - 14:40 CEST
A hazard assessment is “a process that allows the identification and evaluation of potential hazards related to [...] system function regardless of the details of its implementation” (SAE ARP4761A, section C.1). The outcome of a hazard assessment has far-reaching consequences for overall project design and the degree of engineering rigor required during development. In this session, Chuck will take the audience through a hazard assessment exercise based on a simplified model and describe the effects of the assessment on the design and development process. In addition to exposing the audience to a relatively simple but rigorous method for thinking about failure conditions during design, Chuck will also touch on gaps in non-safety-critical software engineering that can benefit from best practices developed by the safety engineering community.
Speakers
PB

Peter Brink

Functional Safety Engineering Leader, Underwriter Laboratories (UL)

avatar for Chuck Wolber

Chuck Wolber

Associate Technical Fellow, The Boeing Company
Chuck Wolber is a Boeing Associate Technical Fellow primarily focused on embedded platform engineering. He has developed multiple DO-178C certified Linux platforms currently in service on Boeing production aircraft. Chuck is co-author of the book Linux Toys, he is credited with contributions... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

14:00 CEST

Multiple Cores, One Zephyr: The Path To Cortex-M SMP in Zephyr - Sanjay Vallimanalan, Linumiz
Friday October 9, 2026 14:00 - 14:40 CEST
Multi-core ARM Cortex-M SoCs are becoming increasingly common in today's market. Yet Zephyr RTOS only supports Asymmetric Multiprocessing (AMP) for these devices. The problem with AMP is that it limits true resource sharing, and leaves hardware parallelism underutilized. Symmetric Multiprocessing (SMP) addresses these issues by running a single Zephyr RTOS image with a unified scheduler across all cores. Zephyr RTOS currently lacks support for Symmetric Multiprocessing on ARM Cortex-M based SoCs and hence limits multi-core Cortex-M devices to AMP configurations. This talk presents a Proof-of-Concept implementation of SMP on Dual Core Cortex-M7 cores using the Infineon Traveo T2G (CYT4DN) SoC which runs a single Zephyr image with true parallel execution across cores.

The key framework challenges are: lack of a secondary boot up path for the secondary cores and the complications of unified timekeeping with per-core SysTick timers.

The talk details what has been achieved, the limitations that remain in timeout-driven context switching and scheduling, and outlines a path toward upstream-ready Cortex-M SMP support in Zephyr.
Speakers
avatar for Sanjay Vallimanalan

Sanjay Vallimanalan

Embedded Software Engineer, Linumiz
Sanjay Vallimanalan is an embedded software engineer with experience in Embedded Linux and real-time operating systems. He is currently working with technologies such as Yocto, Zephyr RTOS, and board support package development for embedded devices.
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

14:50 CEST

The PX4 Airspeed Pipeline - Mahima Yoga, Auterion
Friday October 9, 2026 14:50 - 15:10 CEST
Airspeed sits at the center of fixed-wing flight. It determines how much lift the wings generate, how effective the control surfaces are, and ultimately how the aircraft can be controlled. As a result, it influences nearly every aspect of flight, from stability and maneuvering to energy management. Yet the airspeed value used throughout PX4 is far from a simple sensor reading. Behind a seemingly simple number lies a surprisingly large stack of sensor physics, conversions, calibration procedures, validation logic, control scaling, and TECS handling.

This talk traces the airspeed pipeline end-to-end: from pitot-tube measurements, through IAS → CAS → TAS conversion, in-flight calibration, and validation, to the controllers that ultimately use it. We'll also examine real-world failure modes from the PX4 community and show how to diagnose them from flight logs.
Speakers
avatar for Mahima Yoga

Mahima Yoga

GNC Engineer, Auterion
A Guidance, Navigation, and Control (GNC) engineer at Auterion with a focus on fixed-wing vehicles.
Friday October 9, 2026 14:50 - 15:10 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

14:50 CEST

Landscape of the Quantum Open Source Ecosystem - Mathys Rennela, Unitary Foundation
Friday October 9, 2026 14:50 - 15:30 CEST
The discussion on quantum computers often focuses on abstract physics, but for the engineers manipulating those systems, the underlying software stack is becoming a very pressing reality. As the field matures, we are witnessing the emergence of a collaborative, open-source ecosystem.

This session provides a comprehensive tour of the current quantum open source landscape, and will aim to demystify programming for quantum computers. Community-led projects are currently providing the necessary plumbing (compilers, simulators, verification tools, ...) to ensure that quantum technologies are not only scalable and useful, but also transparent and interoperable.

No prior background in quantum physics or quantum computing is required. The session will actually aim to argue that most quantum software challenges are very known problems in software engineering and computer science, and that one can contribute to quantum open source projects without any knowledge of quantum physics.
Speakers
avatar for Mathys Rennela

Mathys Rennela

Fellow, Unitary Foundation
Mathys Rennela is a quantum software researcher. His main focus is on building the foundational & open source quantum software infrastructure to ensure that quantum computers can also be transparent & of public utility.
Friday October 9, 2026 14:50 - 15:30 CEST
Terrace 2A (Floor 2)
  Open Source 101
  • Audience Experience Level Any

14:50 CEST

Two Sides of the Same Coin: What Software and Data Research Repositories Can Learn From Each Other - Kairo De Araujo, TU Delft
Friday October 9, 2026 14:50 - 15:30 CEST
Research data repositories and software package registries serve different audiences, but they answer the same four questions:
- who published this and can we trust them
- has it been tampered with
- where did it come from
- how long will it stay available and verifiable?

Both communities have answered them in parallel, different vocabularies, different tooling, little exchange.

This talk maps that exchange both ways, grounded in my work on Djehuty (behind 4TU.ResearchData) and as a maintainer of TUF and in-toto and an OpenSSF Securing Software Repositories contributor.

Data repositories can borrow from software: delegated, verifiable signing (TUF, Sigstore), in-toto provenance for AI training data, and the OpenSSF security-maturity model.

Software registries can borrow from data: FAIR's verifiable provenance, persistent identifiers (DOIs, ORCIDs) for durable SBOMs, OAIS preservation against dependency rot, and pre-publication curation.

It closes on the problem neither has solved: permanence versus incident response revoking trust without deleting an immutable, citable record.
Speakers
avatar for Kairo De Araujo

Kairo De Araujo

Senior Software Engineer, TU Delft
Kairo de Araujo maintains TUF and in-toto, two CNCF-graduated supply-chain security projects, and authored RSTUF. He contribute to the OpenSSF Securing Software Repositories Working Group. As a Senior Software Engineer at TU Delft, Kairo now works on Djehuty, the open source platform... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

15:10 CEST

Total Energy Control: A Deep Dive Into TECS in PX4 - Silvan Fuhrer, Auterion
Friday October 9, 2026 15:10 - 15:30 CEST
The Total Energy Control System (TECS) coordinates throttle and pitch to manage a fixed-wing vehicle's airspeed and altitude as a single energy problem — but for many users it remains a black box of tuning parameters. This talk opens it up.
We start from first principles, deriving how TECS balances kinetic and potential energy and why throttle and pitch are the natural levers to control them. We then cover the controller's concept, its architecture in PX4, a structured approach to tuning, and the shortcomings every operator eventually hits. Finally, we distill seven years of hands-on TECS tuning into the heuristics and hard-won insights that don't appear in the documentation.
Whether you're tuning your first fixed-wing or maintaining a fleet, you'll leave with a clearer mental model of what TECS is really doing.
Speakers
avatar for Silvan Fuhrer

Silvan Fuhrer

GNC Engineer, Auterion
Flight control engineer with a particular focus on fixed-wing and VTOL applications.
Friday October 9, 2026 15:10 - 15:30 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any

15:40 CEST

Cloud Native Open RAN Across 1,000 Km: A GitOps Deployment With Duranta and Sylva - Sagar Arora, OpenAirInterface Software Alliance & Guillaume Grao, Orange Innovation
Friday October 9, 2026 15:40 - 16:20 CEST
The telco industry has been on a cloudification journey for over a decade. In the context of Radio Access Networks (RAN), this deep transformation is primarily driven by Open RAN initiatives. This talk illustrates how RAN is gradually embrassing cloud native benefits. Key synergies between Sylva and Duranta open-source projects are driving this transformation:
- Sylva provides a telco-grade cloud stack, enabling scalable and reliable cloud infrastructure.
- The Duranta project focuses on developing RAN network functions using cloud-native design patterns to promote innovation and interoperability.

A live demo will highlight the role of Open RAN interfaces in Duranta. It will showcase a FluxCD-based GitOps deployment of Duranta’s Open RAN Distributed Unit (O-DU), Centralized Unit Control Plane (O-CU-CP), and Centralized Unit User Plane (O-CU-UP) network functions on a Telco Cloud. The deployment will follow the Sylva GitOps approach. Sylva will orchestrate multiple Telco Clouds to showcase central, regional, and far-edge deployment scenarios across two labs located approximately 1,000 km apart.
Speakers
avatar for Sagar Arora

Sagar Arora

Solutions Architect, OpenAirInterface Software Alliance, OpenAirInterface Software Alliance
Sagar Arora holds a Ph.D. in mobile communications from Sorbonne University, France. His thesis title was “Cloud-native Network Slice Orchestration in 5G and Beyond”. At OpenAirInterface, he takes care of the on-premises data center, 5G radio equipment, and CD pipelines. He engages... Read More →
avatar for Guillaume Grao

Guillaume Grao

O-RAN and 5G Solution integrator, Orange Innovation
Working for Orange Innovation in different position: from C++ developper to an O-RAN and 5G Solution integrator
Friday October 9, 2026 15:40 - 16:20 CEST
Small Hall (Floor 0)
  Cloud & Orchestration
  • Audience Experience Level Any

15:40 CEST

AI-Assisted CVE Triage in Yocto-Based Supply Chains: Designing the Human–Agent Judgment Boundary - Kazuyoshi Akiyama & Takashi Ninjouji, Honda
Friday October 9, 2026 15:40 - 16:20 CEST
Automotive Linux products must assess supply chain security at every release.
Yocto-based SBOMs can serve as the foundation, but many teams have yet to answer how much CVE triage to automate and where humans should make the call.
An OSS toolchain also enables the same foundation to be shared with suppliers, with no license barriers.

Yocto-generated VEX and rule-based filtering handle many CVEs, but ambiguity remains — provenance of third-party components, applied patches, unintended dependencies.
AI agents can handle that ambiguity, but opaque and non-deterministic outputs make it impossible to explain a missed CVE or a false positive that blocked a release.

This talk presents a design for that, with a Yocto-based CVE triage pipeline as the example.

The workflow begins with frozen inputs, passes through layered triage, and ends with human approval: inputs locked at CI trigger time (Input Freezing); rule-based and lightweight LLM filtering of straightforward cases (Layered Triage); a high-performance LLM presenting suggestions, with humans making the final call (Suggestion-and-Approval Loop).
These patterns apply to embedded supply chain management beyond automotive Linux.
Speakers
avatar for Kazuyoshi Akiyama

Kazuyoshi Akiyama

Software Engineer, Honda R&D Co., Ltd.
Kazuyoshi Akiyama is a software engineer specializing in embedded Linux for the automotive industry, with years of experience in Linux kernel driver development and Yocto-based integration. Recently joined Honda R&D Co., Ltd., where he is exploring how AI agents can automate compliance... Read More →
avatar for Takashi Ninjouji

Takashi Ninjouji

Chief Engineer, Honda R&D Co., Ltd.
Takashi Ninjouji is a Chief Engineer at Honda Motor Co., Ltd., with a focus on Software-Defined Vehicles (SDV). He is a manager of the Open Source Program Office (OSPO). His interests also include AI-assisted engineering automation.
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 C (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:40 CEST

The Netdev Upstreaming Journey: Process, Pitfalls, and Best Practices - Maxime Chevallier, Bootlin
Friday October 9, 2026 15:40 - 16:20 CEST
Network interfaces are a common thing on embedded devices, so it's no surprise that getting a device supported upstream involves interacting with the netdev community on mailing lists.

The netdev list is a very busy place, and like other subsystems, has its own sets of written and non-written rules. Recently, it's been busier than ever, partly due to new tooling making it more accessible to make first contributions, or finding bugs. This means the netdev community has had to adapt and put new tools, processes and rules in place to deal with this heavy influx of contributions.

This talk will discuss what the upstream process for network-related patches currently looks like. We'll discuss the common pitfalls when upstreaming patches, either due to common technical mistakes or traps when following the netdev process. This may also be a chance for other subsystems to take a peek at how netdev deals with the recent surge of new contributors.

We'll see how reviews are being promoted, what the recently created Netdev Foundation has been setting-up to ease the testing and CI effort, and how as a developer you can help this community and get your patches accepted in a smoother manner.
Speakers
avatar for Maxime Chevallier

Maxime Chevallier

Embedded Linux and Kernel Engineer, Bootlin
Maxime Chevallier is an Embedded Linux and Kernel engineer at Bootlin, where he has been working on Ethernet Controller drivers and PHY drivers for more than 6 years. He contributed to the Marvell PPv2 driver, and to various PHY, Switch and PCS drivers.
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 A (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:40 CEST

Yocto’s Hidden Gems: Lesser-Known Tools for Daily Development - Anna-Lena Marx, inovex GmbH
Friday October 9, 2026 15:40 - 16:20 CEST
Yocto is a complex and huge ecosystem. Getting started may feel hard, but there are various tools to make our daily development easier right out of the box—if you know about them. Unfortunately, many developers are only used to a small subset of the available tools and their capabilities, which often leads to writing additional custom tooling for already solved problems.
In this presentation, we will dive into a selection of these existing tools and demonstrate how to take advantage of them in everyday workflows. For example, we’ll discuss how `bitbake-getvar` helps with debugging variables and overrides, and how to find all packages generated by a recipe with `oe-pkgdata-util`. We will also look into `yocto-check-layer`, `patchtest`, `bitbake-config-help`, and more.
The session will focus on practical use cases, showing how to leverage already available tools to save time and reduce the need for custom scripts.
Speakers
avatar for Anna-Lena Marx

Anna-Lena Marx

Tech Lead Embedded Linux, inovex GmbH
Anna-Lena Marx is TechLead for Embedded Linux at inovex, where she helps build robust systems. With an academic background in Computer Science, Electrical Engineering, and Embedded Systems, she bridges the hardware-software gap. Her core focus is the Yocto Project, guiding companies... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

15:40 CEST

One Scan To Rule Them All: Towards Shared Open Data Infrastructure - Philippe Ombredanne, AboutCode & Stephen Augustus, Bloomberg
Friday October 9, 2026 15:40 - 16:20 CEST
Open source supply chain decisions such as what to depend on, what to ship, and what to trust are only as good as the open data behind them.

The organizations working hardest to produce that open data are largely doing it in parallel. OpenSSF Scorecard scans 1.3 million packages a week. ClearlyDefined has scanned over 55 million and AboutCode over 20 million, both with ScanCode. We share the same problem: we're scanning and rescanning the same packages for the same (or similar) data.

That redundancy has real costs. Compute, maintainer time, and contributor energy spent on work that's already done is capacity not spent on expanding coverage, improving accuracy, or hardening infrastructure.

It's time to build together. This talk is a conversation about what it would look like to join forces on open software supply chain data, produced with open source tools and backed by open standards with shared infrastructure and aligned and unlocked datasets for wider usage. We'll explore where our data models overlap, where they diverge, and what collaboration would require, so we all can get sustainable, high-quality, and open supply chain data at ecosystem scale faster together.
Speakers
avatar for Philippe Ombredanne

Philippe Ombredanne

Lead Maintainer, AboutCode
Philippe Ombredanne is a FOSS hacker passionate about enabling easier and safer reuse of open source code. He is the lead maintainer of the AboutCode stack of open source tools for Software Composition Analysis and license and security compliance, including the industry-leading ScanCode... Read More →
avatar for Stephen Augustus

Stephen Augustus

Technical Architect — Office of the CTO, Bloomberg
Technical Architect, Office of the CTO at Bloomberg
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 1 A (Floor 1)

15:40 CEST

Securing the Builder: CI/CD Supply Chain Security for an Open Source African Community - Caleb Poku Ackom, Cellulant
Friday October 9, 2026 15:40 - 16:20 CEST
Who secures the teams building open source security tooling? At Open Source & Security Africa (OSSAfrica) — a Linux Foundation Special Interest Group supporting the pan-African open source ecosystem — we asked that exact question and built the answer into our pipelines.
This lightning talk walks through the CI/CD architecture powering OSSAfrica's projects: GitHub Reusable Workflows for DRY, composable pipelines across repositories; CodeQL and Semgrep running automated SAST on every PR; and Cloudflare Pages and Render handling deployments with zero operational overhead for a volunteer-driven team.
The core argument: supply chain security isn't a luxury reserved for enterprise platforms. With the right reusable workflow patterns, a lean community team can ship with the same security guarantees as a well-staffed engineering org — and share those patterns across every project they maintain.
Attendees leave with a concrete, replicable blueprint for community-scale secure CI/CD, and a fresh perspective on what open source infrastructure looks like when it's built from and for the African tech ecosystem.
Speakers
avatar for Caleb Poku Ackom

Caleb Poku Ackom

Site Reliability Engineer, Cellulant
Caleb is a Site Reliability Engineer at Cellulant, a Pan-African payments platform operating across 30+ markets, where he manages multiple EKS clusters supporting 40+ microservices in production. He also serves as DevOps Lead at Open Source & Security Africa (OSSAfrica), where he... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

15:40 CEST

Feasibility of an Open-Source Linux Platform for Autonomous Train Operation - Daniel Weingaertner & Sebastian Hetze, Red Hat
Friday October 9, 2026 15:40 - 16:20 CEST
Autonomous train operation requires a new generation of computing platforms capable of running AI-based perception, sensor fusion, and safety-critical control functions. Traditionally, railway systems have been delivered as tightly integrated proprietary hardware-software stacks, limiting software reuse, innovation, and vendor independence.
This talk presents the results of the Automated Train research project and explores whether a Linux-based platform can become the foundation for safety-critical rail applications. We examine the technical feasibility of using Linux to support mixed-criticality workloads while meeting stringent railway safety requirements.
Beyond technology, we discuss a fundamental challenge for open source in regulated industries: how can continuously evolving software be certified in environments governed by legally binding functional safety standards?
Finally, we explore the governance and business implications of a shared open-source platform for the railway sector. The lessons learned extend far beyond railways and provide a blueprint for applying Linux and open-source collaboration to other safety-critical and sovereign digital infrastructure domains.
Speakers
avatar for Daniel Weingaertner

Daniel Weingaertner

Senior Software Engineer, Red Hat
A seasoned technical leader and former professor, Daniel Weingaertner brings expertise in High-Performance Computing (HPC) and automotive software engineering. He has a track record of delivering open-source and Linux solutions for the public sector and possesses specialized knowledge... Read More →
avatar for Sebastian Hetze

Sebastian Hetze

Principal Software Engineer, Field CTO, Red Hat
Sebastian Hetze has been developing free software since the 1980s. From 1992 to 2012, he ran his own Linux companies. He has been working for Red Hat since 2012, most recently as a Principal Software Engineer in the Field CTO organization. He is also an elected board member of the... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

16:00 CEST

Crash Dumps Without Cables: Live Coredump Capture Over UDP/Ethernet in Zephyr RTOS - Kedareswara Rao Appana, AMD
Friday October 9, 2026 16:00 - 16:20 CEST
When an embedded system crashes in the field, recovering the coredump often determines whether debugging takes hours or weeks. Zephyr has long supported coredumps over UART, but in modern industrial, IoT, and edge deployments the serial port is rarely accessible. Devices may be sealed in cabinets, deployed remotely, or connected only via network.

This talk introduces a new Zephyr coredump backend that streams crash data over UDP (IPv4/IPv6) at the moment of a fatal exception—no USB cable or physical access required. We will explore the design challenges of networking in the fatal path, including safely re-enabling interrupts so the NIC can transmit, and the ZCDU framing protocol used to packetize and reliably reassemble dumps from UDP datagrams. We also show how the host receiver integrates seamlessly with the existing Zephyr GDB workflow, making the switch from UART to Ethernet a simple Kconfig option. Attendees will learn how to enable fleet-scale crash capture and dramatically reduce time-to-root-cause for deployed Zephyr devices.

pull request : https://github.com/zephyrproject-rtos/zephyr/pull/108410
Speakers
avatar for Kedareswara Rao Appana

Kedareswara Rao Appana

Member of Technical Staff, AMD
Device driver developer (linux and Baremetal), Expertise on the ARM, Microblaze and Microblaze Risc-v processors, Zephyr OS and System device-tree concepts and Lopper tool, Contributed to open source Linux Up streamed CAN and Xilinx DMA drivers and contributed to axi ethernet and... Read More →
Friday October 9, 2026 16:00 - 16:20 CEST
South Hall 2 A (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

16:30 CEST

State of the OSS Union: Assessing Your Stack’s Autonomy Under EU Law - Emiel Brok, SUSE / DOSBA
Friday October 9, 2026 16:30 - 17:10 CEST
Open source is the bedrock of European digital sovereignty, but a wave of aggressive new EU legislation is transforming how organizations must build, source, and secure their digital environments. Navigating this shift requires unpacking complex regulatory mandates and understanding their operational impact on modern enterprise and cloud software architecture.

This fast-paced session strips away the legal jargon to deliver a real-time status update on Europe’s changing digital roadmap. We will analyze the mandatory software bill-of-materials (SBOM) rules of the Cyber Resilience Act (CRA) and the open standards driving the Interoperable Europe Act. Crucially, we dive into the European Commission's freshly unveiled Cloud and AI Development Act (CADA) to unpack its cloud sovereignty tiers and its "open-source first" procurement principles.

Moving from compliance theory to practical execution, attendees will gain a concrete framework to audit their own production IT stacks. We will walk through the web-based SUSE Cloud Sovereignty Self-Assessment tool to measure true autonomy using weighted SEAL (Sovereignty Effective Assurance Level) metrics.
Speakers
avatar for Emiel Brok

Emiel Brok

Global Sovereignty Ambassador, SUSE / DOSBA
Open Source & Sovereignty Ambassador at SUSE.
Co-founder DOSBA (Dutch Open Source Business Alliance)
Social Media activities through #FridayKetchup and #GeekOnTour.
Mission in life: Make the world a better place by evangelizing open source.
Friday October 9, 2026 16:30 - 17:10 CEST
Club H (Floor 1)
  Digital Trust
  • Audience Experience Level Any

16:30 CEST

BoF: The Yocto Project and OpenEmbedded - Josef Holzmayr, Mender.io & The Yocto Project & Philip Balister, OpenSDR
Friday October 9, 2026 16:30 - 17:10 CEST
This BoF provides an open forum for the Embedded Linux community to ask questions and discuss issues with the Yocto Project and OpenEmbedded community.

We open with a Yocto Project summary and OpenEmbedded State of the Union.

All users, contributors and maintainers as well as curious minds are invited to bring their thoughts and topics.
Speakers
avatar for Josef Holzmayr

Josef Holzmayr

Developer Enablement Expert & Community Manager, Mender.io & The Yocto Project
Josef has been active for more than 20 years as a "Complete"-Stack developer by now. He's done everything from debugging hardware over application development to web front ends.

A passion for showing, telling, and teaching people in both entertaining and engaging ways led Josef... Read More →
avatar for Philip Balister

Philip Balister

Minister of Progress, OpenSDR
I have a bio
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

16:30 CEST

How We Stopped Shai Hulud V4: Hunting a Self-Replicating Npm Worm With AI Toolchain Poisoning - Kush Pandya, Socket
Friday October 9, 2026 16:30 - 17:10 CEST
The Shai Hulud worm family has stalked the npm supply chain across multiple variants, stealing credentials from developer and CI environments, propagating via stolen npm and GitHub identities, poisoning workflows, and carrying a dead switch that can wipe home directories on command. Version four just crossed a new line. SANDWORM_MODE, deployed across 19 malicious npm packages, keeps the full prior playbook and adds AI toolchain poisoning via MCP server injection into Claude Code, Claude Desktop, Cursor, and Windsurf. The rogue MCP server uses prompt injection to instruct AI assistants to silently exfiltrate SSH keys, AWS credentials, and LLM API tokens from nine providers, without alerting the user. We present the full story: the Shai Hulud lineage, how the obfuscated three-layer loader was detected, how 19 packages were linked to one operator, how a bidirectional CI worm loop was built from a weaponized GitHub Action, and how coordinated takedown with npm, GitHub, and Cloudflare dismantled the infrastructure, along with what the dormant polymorphic engine tells us about where version five is heading.
Speakers
avatar for Kush Pandya

Kush Pandya

Security Researcher, Socket
Security researcher at Socket.dev. Securing Open Source Supply chain, for various fortune 500 customers like Netflix, Salesfore, etc. and other leading AI companies like Anthropic, OpenAI and many more.
Friday October 9, 2026 16:30 - 17:10 CEST
Club E (Floor 1)
  Packages & Images & Containers
  • Audience Experience Level Any

16:30 CEST

From Specification To Merge: Implementing a Standards-Compliant DALI Driver for Zephyr - Sven Hädrich, sevenlab engineering GmbH
Friday October 9, 2026 16:30 - 17:10 CEST
DALI (Digital Addressable Lighting Interface) is the dominant standard for professional lighting control, yet firmware support for it has been absent from the Zephyr ecosystem — until now. This talk walks through the full journey of designing and upstreaming a DALI low-level driver into Zephyr mainline: from understanding the protocol's precise timing and bus requirements, to crafting an API that fits naturally within Zephyr's driver model, to surviving the community review process through multiple rounds of discussion and refactoring.

Along the way we also experimented with AI-assisted code review as part of our workflow, and we'll share what that was actually like in the context of a real upstream contribution.

We'll be honest about what was hard, what the community pushed back on, and what we'd do differently.
Speakers
avatar for Sven Hädrich

Sven Hädrich

Co-Founder, sevenlab engineering GmbH
Sven started programming when the Tandy TRS-80 was a novelty. After studying physics and earning a PhD, he co-founded a laser company where he led electronics and software development. He then built a career as a freelance embedded systems developer before joining Grandcentrix, where... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 2 B (Floor 2)
  Zephyr Developer Summit
  • Audience Experience Level Any

16:50 CEST

Self-Defending Swarms: MAVLink Signing Meets Peer-Consensus Exclusion Onboard PX4 - Yogesh Sardana, Airtel
Friday October 9, 2026 16:50 - 17:10 CEST
This isn't just about Airtel but for every organisation as MAVLink has supported per-message signing since MAVLink 2, yet almost no real-world PX4 fleet enables it, because key distribution, rotation & revocation across dozens of airborne vehicles has no production-ready tooling, so most swarms still accept any correctly formatted command from whatever radio reaches them. A single spoofed ground station or one drone with cloned key can inject commands rest of swarm has no way to reject. Talk introduces swarm-native trust layer that issues short-lived, mission-scoped MAVLink signing keys from a lightweight onboard authority, lets every drone verify signatures independently without round-tripping to a ground station & adds a peer-consensus exclusion protocol so that if one drone starts broadcasting commands inconsistent with its own attested mission profile, the rest of swarm votes to ignore it mid-flight without operator intervention. We demonstrate this on PX4 SITL & real hardware over a Zenoh-based inter-drone link, show a live command-injection attack being rejected by consensus & discuss key rotation strategy under degraded or fully lost ground-station connectivity mid-mission.
Speakers
avatar for Yogesh Sardana

Yogesh Sardana

Deputy General Manager - AI & Cloud Engineering, Airtel
I'm working as a Cloud Engineering Leader & Researcher, leading Open Source Stack R&D wing, known as Jack of all trades, master of Cloud. Been into various tech stacks of Software Development Life Cycle, having fun with tech.
Friday October 9, 2026 16:50 - 17:10 CEST
South Hall 1 B (Floor 1)
  PX4 Dev Summit
  • Audience Experience Level Any
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -