Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Type: Safety-Critical Software clear filter
Thursday, October 8
 

13:50 CEST

Sponsored Session: Building Secure and Compliant Critical Infrastructure with Open Source - Benjamin Weber, Hitachi Energy & Bernhard Denner, Hitachi Rail
Thursday October 8, 2026 13:50 - 14:30 CEST
Critical infrastructure operators face growing pressure to modernize their systems while maintaining the highest levels of security, reliability, and regulatory compliance in an era shaped by regulations such as the EU Cyber Resilience Act (CRA) and NIS2. In this session, Hitachi shares two real-world modernization journeys with open source from the energy and railway sectors.

The first half focuses on Hitachi Energy’s adoption of Embedded Linux and Yocto for next-generation grid automation products. Hitachi Energy actively contributes to the modernization of energy systems, making electricity more accessible worldwide. In product development, adopting Embedded Linux and Yocto enhances flexibility and maintainability, with strong legal compliance, license management, and open-source collaboration. Hitachi Energy is rolling out Linux-based energy grid automation products and this talk covers their transition to embedded Linux via Yocto, addressing industry protocol support, impacts of the EU Cyber Resilience Act, OSS license challenges, and navigating these within a slow-evolving sector.

The second half presents Hitachi Rail’s modernization of mission-critical railway management systems using Keycloak, an an open source identity and access management platform. As railway systems become increasingly interconnected, cybersecurity and identity management have become fundamental architectural concerns. We show how secure-by-design principles were applied to modernizing legacy environments, with Keycloak. We also demonstrate how Keycloak helps address several IEC 62443-4-2 requirements and provides a strong foundation for meeting emerging regulatory expectations such as CRA.


Speakers
avatar for Bernhard Denner

Bernhard Denner

Chief Architect, Hitachi Rail
Bernhard is the Chief Architect of a cloud-native application platform that forms the foundation of many Hitachi Rail products. With a strong background in IT system administration and software engineering, he began automating infrastructure long before “DevOps” became widely... Read More →
avatar for Benjamin Weber

Benjamin Weber

Business R&D Manager, Hitachi Energy
Benjamin holds a PhD in electrical engineering from ETH Zurich and is with Hitachi Energy in the role of "Team Lead and Project Manager Linux". He held various positions in diverse industries as firmware developer for Linux and other systems as well as design engineer for a fabless... Read More →
Thursday October 8, 2026 13:50 - 14:30 CEST
Club A (Floor 1)

16:40 CEST

OpenGrid: An Open-Source Electric Grid Modeling Ecosystem - Alice Yake, David Paolella, James Hewett & Ryan Attig, Breakthrough Energy
Thursday October 8, 2026 16:40 - 17:20 CEST
Modeling underlies the grid we all rely on. Every decision to build a new power plant or transmission line starts with a model run, yet planning models are often opaque, expensive, and difficult to replicate. That lack of transparency, along with uneven access to high-fidelity tools and data, breeds distrust and delay in the planning processes essential to decarbonizing the grid and expanding energy access worldwide. Open-source planning tools are growing in number and capability, but real barriers to adoption remain. OpenGrid aims to build a shared infrastructure foundation for open-source modeling, so open tools and data can become a credible industry standard. This session introduces the OpenGrid initiative, announced as a project under Linux Foundation fiscal sponsorship, covering both the thinking behind it, the plans to build it out and how you can get involved.
Speakers
avatar for David Paolella

David Paolella

Director, Research and Analytics, GRIDS, Breakthrough Energy

JH

James Hewett

Breakthrough Energy

RA

Ryan Attig

Breakthrough Energy
avatar for Alice Yake

Alice Yake

VP GRIDS, Breakthrough Energy
Alice Yake, Vice President of GRIDS at Breakthrough Energy, leads efforts to develop an open-source modeling ecosystem for delivering reliable, low-emission electricity globally, addressing the complexities of system design, regulations, and zero-carbon goals. With over 25 years of... Read More →
Thursday October 8, 2026 16:40 - 17:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any
 
Friday, October 9
 

08:00 CEST

Safety-Critical Systems Community Hub
Friday October 9, 2026 08:00 - 17:20 CEST
Find your people. Share what you're building. Get unstuck.

Looking to swap ideas, troubleshoot a tricky problem, or meet others working on the same things you are?

This dedicated space is organized around this specific track interests and community. Drop in between sessions to talk shop, share what you’re working on, ask questions, or simply connect with people who get it.
Friday October 9, 2026 08:00 - 17:20 CEST
Congress Hall Foyer 1 B (Floor 1)

11:05 CEST

Safety Critical Software BoF - Philipp Ahmann, ETAS GmbH & Olivier Charrier, Wind River
Friday October 9, 2026 11:05 - 11:45 CEST
Interest in safety critical open source software is high, yet opportunities to connect and openly discuss challenges remain limited. This BoF creates a focused forum for practitioners and newcomers to exchange experiences, ask questions, and gain visibility into existing projects and initiatives.

It also highlights the role of initiatives such as the Linux Foundation ELISA project as a central interface within the ecosystem, helping to connect efforts across communities, share practices, and make ongoing work more discoverable. The project brings together horizontal working groups covering features, processes, architecture, and tooling, while also addressing vertical domains such as automotive, aerospace, space, railways, and medical. This reflects the growing relevance of Linux and open source in safety critical systems.

By enabling direct interaction and cross project exchange, the session supports alignment, reduces duplication, and fosters collaboration in an evolving safety critical OSS landscape.

Participants at all levels of experience are encouraged to join, contribute their perspective, and engage with the community.
Speakers
avatar for Philipp Ahmann

Philipp Ahmann

Automotive OSS Process Lead, Etas GmbH (BOSCH)
Philipp Ahmann is a Senior OSS Community Manager at ETAS (a Bosch subsidiary), specializing in safety-critical automotive open source software. With 15+ years' experience in Linux automotive platforms, he has held roles from software engineer to project & line manager.
He currently holds the position of the technical steering committee chair for the Linux Foundation ELISA project to Enable Linux in Safety Applications. Additionally, he is member of the Linux Foundation Europe Advisory Board... Read More →
avatar for Olivier Charrier

Olivier Charrier

Principal Technologist - Functional Safety, Wind River
Olivier Charrier obtained a Master’s degree in Software Engineering (DESS) from Bordeaux University in 1989.
After working for Alsys/Aonix on Ada development environment for embedded systems, Olivier joined Wind River in June 2001 where his focus is to help Wind River's customers define, implement and certify Safety Critical Systems for multiple market segments including Avionics, Automotive... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club A (Floor 1)
  Safety-Critical Software

11:55 CEST

A Safety BOM Is a Contract: Producing and Consuming the SPDX Functional Safety Profile - Tobias Kästner, inovex GmbH & Nicole Pappler, AlektoMetis
Friday October 9, 2026 11:55 - 12:35 CEST
SPDX 3.1's Functional Safety profile recently grew to model a safety case end to end: requirements and their refinement, verification, pass/fail evaluations, evidence, and assumptions of use. It standardizes how a safety case is exchanged, but not how one is produced, nor what a consumer does with one received. We demonstrate SEGkit, a prototype, open-source, project-agnostic engine that extracts a design and evidence graph from content repositories to recompute a verdict over the graph—a judgment recomputed from content, not merely recorded—and detects which evidence goes stale as code evolves; in this talk we also show how we plan to use it within Zephyr to automate safety evidence creation. This makes SEGkit interesting to projects maintaining their safety BOM as well as downstream users who want to work with one. For the latter case we argue a received BOM is best consumed as a contract—its requirements and evidence being guarantees and its assumptions the conditions the consumer must discharge against its own case. Lastly, we talk about what the profile might add for machine-checkable discharge: assumptions as checkable conditions, linked to the guarantees they constrain.
Speakers
avatar for Nicole Pappler

Nicole Pappler

Senior Safety Expert, AlektoMetis.com
Nicole has worked in different projects developing safety relevant embedded software before starting as an independent assessor.
With now more than twenty years of experience in the industry, she supported several customers to show their compliance with safety, security and quality standards. Currently she is utilizing her experience regarding the development of highly reliable software to enable open source... Read More →
avatar for Tobias Kästner

Tobias Kästner

Safety Architect, Zephyr Project, inovex GmbH
A physicist by training, Tobias Kaestner has long been fascinated by where the physical and digital worlds meet. He began as a software team lead in a medical device start-up and has since spent 15+ years in the industry. As a solution architect for Medical IoT at inovex GmbH he helps... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Club A (Floor 1)
  Safety-Critical Software

14:00 CEST

Let's Perform a Hazard Assessment! - Chuck Wolber, The Boeing Company & Pete Brink, Underwriter Laboratories (UL)
Friday October 9, 2026 14:00 - 14:40 CEST
A hazard assessment is “a process that allows the identification and evaluation of potential hazards related to [...] system function regardless of the details of its implementation” (SAE ARP4761A, section C.1). The outcome of a hazard assessment has far-reaching consequences for overall project design and the degree of engineering rigor required during development. In this session, Chuck will take the audience through a hazard assessment exercise based on a simplified model and describe the effects of the assessment on the design and development process. In addition to exposing the audience to a relatively simple but rigorous method for thinking about failure conditions during design, Chuck will also touch on gaps in non-safety-critical software engineering that can benefit from best practices developed by the safety engineering community.
Speakers
PB

Peter Brink

Functional Safety Engineering Leader, Underwriter Laboratories (UL)

avatar for Chuck Wolber

Chuck Wolber

Associate Technical Fellow, The Boeing Company
Chuck Wolber is a Boeing Associate Technical Fellow primarily focused on embedded platform engineering. He has developed multiple DO-178C certified Linux platforms currently in service on Boeing production aircraft. Chuck is co-author of the book Linux Toys, he is credited with contributions... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

14:50 CEST

Failure Propagation in Linux: Challenges for Safety Qualification - Alessandro Carminati, NVIDIA
Friday October 9, 2026 14:50 - 15:30 CEST
Linux was not developed around fault-containment properties expected of safety-certifiable software.

The linear map lets kernel code access memory across userspace ownership boundaries, so corruption can affect another process or container. Shared slab/page allocators and per-CPU caches compound this risk: corrupted state may remain latent and later affect unrelated subsystems. MMIO can cause external interference when a faulty driver accesses the wrong register or device because of corrupted state or an incorrect Device Tree or ACPI-derived base address.

Building on ELISA Linux Features WG (LFSCS) work, we use ks-nav call-tree artifacts to show that even narrow services depend on shared infrastructure across subsystems.

Reducing the configuration lowers function count but also usability; restoring functionality introduces transitive dependencies, so assessment cannot be limited to newly enabled code.

These findings challenge treating Linux as safe by default or relying on proven-in-use arguments alone. In a monolithic, shared-address-space kernel, fault containment and qualification scope must be demonstrated, not assumed.
Speakers
avatar for Alessandro Carminati

Alessandro Carminati

Senior Safety Architect for Linux, NVIDIA
Senior Safety Architect for Linux at NVIDIA, working on Linux kernel performance, tooling, community engagement, and its adoption in safety-critical applications. Previously a Linux Kernel Engineer in Red Hat’s Automotive Team, with a background in embedded Linux, Linux security... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Club A (Floor 1)
  Safety-Critical Software

15:40 CEST

Feasibility of an Open-Source Linux Platform for Autonomous Train Operation - Daniel Weingaertner & Sebastian Hetze, Red Hat
Friday October 9, 2026 15:40 - 16:20 CEST
Autonomous train operation requires a new generation of computing platforms capable of running AI-based perception, sensor fusion, and safety-critical control functions. Traditionally, railway systems have been delivered as tightly integrated proprietary hardware-software stacks, limiting software reuse, innovation, and vendor independence.
This talk presents the results of the Automated Train research project and explores whether a Linux-based platform can become the foundation for safety-critical rail applications. We examine the technical feasibility of using Linux to support mixed-criticality workloads while meeting stringent railway safety requirements.
Beyond technology, we discuss a fundamental challenge for open source in regulated industries: how can continuously evolving software be certified in environments governed by legally binding functional safety standards?
Finally, we explore the governance and business implications of a shared open-source platform for the railway sector. The lessons learned extend far beyond railways and provide a blueprint for applying Linux and open-source collaboration to other safety-critical and sovereign digital infrastructure domains.
Speakers
avatar for Daniel Weingaertner

Daniel Weingaertner

Senior Software Engineer, Daniel Weingaertner
A seasoned technical leader and former professor, Daniel Weingaertner brings expertise in High-Performance Computing (HPC) and automotive software engineering. He has a track record of delivering open-source and Linux solutions for the public sector and possesses specialized knowledge... Read More →
avatar for Sebastian Hetze

Sebastian Hetze

Principal Software Engineer, Field CTO, Red Hat
Sebastian Hetze has been developing free software since the 1980s. From 1992 to 2012, he ran his own Linux companies. He has been working for Red Hat since 2012, most recently as a Principal Software Engineer in the Field CTO organization. He is also an elected board member of the... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

16:30 CEST

TLA+ in the Age of AI-Assisted Engineering - Igor Konnov & Thomas Pani, Independent
Friday October 9, 2026 16:30 - 17:10 CEST
Over several decades, TLA+ has been immensely useful for finding safety and liveness issues in concurrent and distributed systems. As developers of Apalache, the symbolic model checker for TLA+, our work with engineers has changed how we think specification tooling should look. Three obstacles to adoption arise repeatedly: (1) the steep learning curve, (2) the gap between formal specs and the code, and (3) scalability issues.

This talk reflects on our 10 year journey with TLA+ into the age of AI. We first show how we addressed (1) through a less mathematical syntax and modern developer experience. For (2) and (3), model-based testing and proofs have long been promising, but traditionally required too much expert labor. Frontier AI tooling changes this balance: it lowers onboarding costs, helps generate test drivers, and can automate proof work to a useful degree.

At the same time, formal tooling allows us to gate AI-generated code, catching plausible but incorrect implementations. We argue that AI and formal tooling complement each other, making both more practical.
Speakers
avatar for Igor Konnov

Igor Konnov

Independent Researcher in Formal Verification and Security
Igor Konnov is an independent security and formal methods researcher, practicing formal verification, differential testing, and fuzzing of distributed protocols. He is the principal maintainer of Apalache, a symbolic model checker for TLA+, under the Linux Foundation and TLA+ Fou... Read More →
avatar for Thomas Pani

Thomas Pani

Independent Consultant, Specification and Reliability Tools
Thomas Pani is an open source developer working on specification languages, developer tooling around executable specifications, and high-assurance distributed systems. He is a maintainer of Apalache, a symbolic model checker for TLA+, and an early contributor to Quint, a modern specification... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Club A (Floor 1)
  Safety-Critical Software
 


Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.