7-9 October, 2026 Prague, Czechia View More Details & Registration Important Note:Timing of sessions and room locations are subject to change.
The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.
Sign up or log in to add sessions to your schedule and sync them to your phone or calendar.
This talk clarifies what Hafnium secure partition manager is, where it is useful, and how to port it to a compatible SoC. First, Marek explains the ARM CPU core exception levels and security states, elaborates which software usually runs in the secure world, which does include TEEs, and clarifies why running only a single TEE instance may no longer be sufficient. Next, Marek introduces Hafnium secure partition manager, which allows running multiple isolated software instances in S-EL1, called secure partitions. Marek explains where Hafnium and secure partitions fit into the CPU security model, how other components of the firmware stack interact with Hafnium, and how Linux interacts with the software in secure partitions. Finally, Marek explains how Hafnium port to Renesas R-Car X5H was implemented, provides tips for debugging the Hafnium port, and elaborates in detail what changes were necessary to the rest of the firmware stack components, specifically TFA, OPTEE-OS and U-Boot, to make them compatible with the newly added Hafnium in S-EL2.
U-Boot, Linux, OE contributor and freelance consultant. My work involves helping customers bring up to date upstream software on their devices, and contributing patches back upstream.