Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Type: Linux clear filter
arrow_back View All Dates
Friday, October 9
 

11:05 CEST

An Native API for Linux Systems With Systemd + Varlink - Lennart Poettering, Amutable
Friday October 9, 2026 11:05 - 11:45 CEST
Modern Linux based distributed systems generally rely on bespoke "agent" services on each node for introspecting their state or issuing operations.

In this talk I'd like to explain systemd's vision of improving and cleaning up this logic, with the ultimate goal of avoiding any local agents but nonetheless making the system nicely introspectable and accessible, with modern technologies.

For this, we'll talk about the Varlink IPC system, and the numerous Varlink APIs systemd provides these days. We'll also cover the HTTP Varlink proxy, which opens up these APIs in a web-native way, with modern authorization mechanisms. We'll also discuss systemd's metrics collection/report generation subsystem, it's cryptographic properties and remote access to it.
Speakers
avatar for Lennart Poettering

Lennart Poettering

Chief Engineer, Amutable
Lennart is a systemd creator & maintainer. He's also the Chief Engineer @ Amutable.
Friday October 9, 2026 11:05 - 11:45 CEST
Panorama Hall (Floor 1)
  Linux

11:55 CEST

The Little-Known Mechanism for Securely Parameterizing Systemd Services - Lennart Poettering, Amutable
Friday October 9, 2026 11:55 - 12:35 CEST
In this talk I'd like to discuss the "systemd Credentials" concept, which was introduced back in systemd v250 and became a powerful mechanism for parameterizing Linux systems and services.

These credentials can be passed into systems and services, can be authenticated and encrypted by TPMs. They can be acquired from SMBIOS, via Cloud IMDS services, the UEFI System Partition, or local file systems and IPC. They have a well-defined life-cycle, and can be securely inherited down the process, container and VM hierarchy.

We'll compare them with other ways to parameterize systems and services, such as the kernel command line or environment blocks, and explain why systemd's credentials are often the much better approach.
Speakers
avatar for Lennart Poettering

Lennart Poettering

Chief Engineer, Amutable
Lennart is a systemd creator & maintainer. He's also the Chief Engineer @ Amutable.
Friday October 9, 2026 11:55 - 12:35 CEST
Panorama Hall (Floor 1)
  Linux

14:00 CEST

Keeping Track of Resources in the Kernel - Overview and Pitfalls of Resource Management Mechanisms - Bartosz Golaszewski, Qualcomm
Friday October 9, 2026 14:00 - 14:40 CEST
While C is a spartan language by design and, as such, doesn't offer any automatic memory management, the linux kernel over the years has acquired several mechanisms that attempt to make it easier for developers to keep track of resources and control their lifetime.

These mechanisms use C compiler extensions for scope-based memory management, count object references, or rely on control flow provided by the lower-level subsystem code. They can also be an arbitrary mixture of multiple approaches.

As the C compiler by definition is unable to enforce ownership or reference counting and scope correctness, the users of these helpers must still leverage them correctly and respect the API contract.

The kernel has struggled with object lifetime issues for decades now and, while there are legitimate issues with the design of certain subsystems, some of these issues resulted from incorrect use of the kernel resource management APIs. A good example of this is scheduling devres actions for devices that will never be bound to drivers.

This talk will present different resource management mechanisms in the kernel along with examples of how to use them correctly and what mistakes to avoid.
Speakers
avatar for Bartosz Golaszewski

Bartosz Golaszewski

Linux Kernel Engineer, Qualcomm
Bartosz Golaszewski has over 16 years of engineering experience in the embedded systems domain ranging from low-level, real-time operating systems, through the linux kernel up to user-space plumbing, libraries and build systems. Bartosz has contributed hundreds of patches to a wide... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Panorama Hall (Floor 1)
  Linux

14:50 CEST

Anatomy of a Mainline Linux Driver - Neil Armstrong, Linaro
Friday October 9, 2026 14:50 - 15:30 CEST
Getting a driver into mainline Linux is a great step, but it is very different from downstream development. In downstream, the people writing the driver are often not the ones making the final product. Because of this, they have to implement 100% of the hardware features. But in the end, maybe only 60% of these features are actually used by product integrators. This creates dead code and increased driver complexity.

In this talk, I will show you the anatomy of a mainline Linux driver and guide you on how to write it for the upstream tree inclusion. We will see how to write generic code that is easy for the community to maintain in the long term. We will talk about using and extending existing kernel frameworks instead of making custom control paths or abusing current interfaces, which helps reduce ecosystem fragmentation. For embedded systems, we will also see how to make clean and extensible Device Tree bindings.

I will explain why we need to drop untestable downstream features to keep the code clean. Finally, we will look at how to format and check your patchset with tools like checkpatch, smatch, and new AI tools like Sashiko to ensure high kernel quality.
Speakers
avatar for Neil Armstrong

Neil Armstrong

Senior Linux Engineer, Linaro
Neil joined Linaro in September 2022 to work full-time on Qualcomm Upstreaming of their high-end SoC platforms.
Neil has been hacking on embedded platforms since he was 16 years old, from Casio Calculators to Phones platforms in the last months.
He maintains the Amlogic Linux & U-Boot baseport, Linux DRM Bridge & Panel codebase. In addition to Qualcomm, Neil regularly contributes to the Linux Kernel and U-Boot supporting the Amlogic SoCs support and DRM codebase... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Panorama Hall (Floor 1)
  Linux

15:40 CEST

Who Watches the Watcher? Hardening eBPF in Production Security Deployments - Hanshal Mehta, Independent
Friday October 9, 2026 15:40 - 16:20 CEST
eBPF has become the backbone of modern Linux security tooling. Cilium, Tetragon, Falco, etc they all depend on eBPF's ability to hook kernel execution paths and enforce policy without a kernel patch or reboot. But there's a question the community has been slow to ask: who secures eBPF itself?
Working on bpfman, an eBPF program manager, exposed me to the trust assumptions baked into how programs get loaded, pinned, and granted kernel access. This talk covers what I found concrete attack surfaces that show up in real deployments, not theory.

We'll cover: the verifier's historical CVEs and what they reveal about its actual threat model, privilege escalation through CAP_BPF and unprivileged eBPF in distros that ship with it enabled, what program signing protects and what it quietly doesn't, and LSM hooks on BPF program loading that most teams aren't using yet.
The second half: BPF token scoping, how Ubuntu and Fedora are locking down the attack surface without breaking legitimate tooling,and a threat model checklist you can apply to your own eBPF deployment the same week.
If you're running eBPF-based security tooling in production, this is the talk I wished existed before I started.
Speakers
avatar for Hanshal Mehta

Hanshal Mehta

Open Source Developer, Self
Open-source developer contributing to projects across the cloud-native and security space including OpenTelemetry, bpfman, Glasskube, Cyclops, and BuildSafe. Currently at SecurableAI working on open-source security tooling. Deep interest in performance engineering, cloudsecurity... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Panorama Hall (Floor 1)
  Linux

16:30 CEST

A Surprisingly Hard Question: How Much Memory Does My System Use? - Richard Weinberger, sigma star gmbh
Friday October 9, 2026 16:30 - 17:10 CEST
When everything runs smoothly, memory usage is just another metric. But when out-of-memory situations strike, or you are tasked with cutting a workload's RAM in half, it suddenly becomes the most important metric in your system.

While Linux exposes dozens of memory-related counters, answering basic questions is notoriously difficult. Developers and system administrators often struggle to pinpoint exactly how much memory the system is actually using, what the true footprint of a single application is, and how much memory that application can safely consume before causing issues.

In this talk, Richard will demystify Linux memory metrics and break down how the OS organizes memory across kernel and userspace.

Attendees will learn how to accurately read and make sense of Linux memory counters, giving them a better understanding of how internal memory management actually works. The session will also cover practical techniques for debugging memory-related issues and OOM kills, leaving the audience with actionable ways to optimize their application memory footprints.
Speakers
avatar for Richard Weinberger

Richard Weinberger

CTO, sigma star gmbh
Richard Weinberger is co-founder of sigma star gmbh where he offers consulting services around Linux and IT security. Upstream he maintains various subsystems of the Linux kernel such as UserModeLinux and UBIFS. Beside of low level and security aspects of computers he enjoys growing... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Panorama Hall (Floor 1)
  Linux
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.
Filtered by Date -