Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: Club A (Floor 1) clear filter
Thursday, October 8
 

10:50 CEST

Sponsored Session: Advancing Trust in Open Source: CIP IEC-62443-4-x Achievement and CRA Compliance Readiness - Dinesh Kumar, CIP Security WG Chair / Toshiba Software & Pasquale Nieddu, CIP Security WG / Siemens Mobility
Thursday October 8, 2026 10:50 - 11:30 CEST
With increasing regulatory pressure and evolving cybersecurity requirements, product teams must navigate complex standards while maintaining speed to market.

This session provides a practical, implementation-focused deep dive into achieving IEC 62443-4-x compliance for components, alongside insights into aligning with the EU Cyber Resilience Act (CRA).

We will showcase how the CIP Security Workgroup has developed precise engineering artefacts—including IEC layer test suites and supporting documentation—that significantly reduce the effort required for compliance.

In addition, we will examine recent investigations into CRA requirements and demonstrate how IEC 62443-4-x compliance can help bridge critical gaps toward CRA readiness.

Attendees will leave with actionable guidance, reusable assets, and a clear roadmap to streamline compliance efforts while future-proofing their products against regulatory demands.

Speakers
PN

Pasquale Nieddu

Job DevOps Engineer, CIP Security WG / Siemens Mobility
Pasquale Nieddu is a DevOps Engineer within the CoreShield Secure Operating Systems team at Siemens Mobility s.r.o. in Prague. Passionate about railways, open source, and Linux, he has been an active contributor to the Civil Infrastructure Platform (CIP) project since February 2025... Read More →
DK

Dinesh Kumar

CIP Security WG Chair / Toshiba Software
Dinesh Kumar is an experienced embedded software engineer specializing in Embedded Linux, secure boot, Debian package development, board support packages (BSPs), and Android application and framework development. His research interests include Embedded Linux, Linux kernel security... Read More →
Thursday October 8, 2026 10:50 - 11:30 CEST
Club A (Floor 1)

13:50 CEST

Sponsored Session: Building Secure and Compliant Critical Infrastructure with Open Source - Benjamin Weber, Hitachi Energy & Bernhard Denner, Hitachi Rail
Thursday October 8, 2026 13:50 - 14:30 CEST
Critical infrastructure operators face growing pressure to modernize their systems while maintaining the highest levels of security, reliability, and regulatory compliance in an era shaped by regulations such as the EU Cyber Resilience Act (CRA) and NIS2. In this session, Hitachi shares two real-world modernization journeys with open source from the energy and railway sectors.

The first half focuses on Hitachi Energy’s adoption of Embedded Linux and Yocto for next-generation grid automation products. Hitachi Energy actively contributes to the modernization of energy systems, making electricity more accessible worldwide. In product development, adopting Embedded Linux and Yocto enhances flexibility and maintainability, with strong legal compliance, license management, and open-source collaboration. Hitachi Energy is rolling out Linux-based energy grid automation products and this talk covers their transition to embedded Linux via Yocto, addressing industry protocol support, impacts of the EU Cyber Resilience Act, OSS license challenges, and navigating these within a slow-evolving sector.

The second half presents Hitachi Rail’s modernization of mission-critical railway management systems using Keycloak, an an open source identity and access management platform. As railway systems become increasingly interconnected, cybersecurity and identity management have become fundamental architectural concerns. We show how secure-by-design principles were applied to modernizing legacy environments, with Keycloak. We also demonstrate how Keycloak helps address several IEC 62443-4-2 requirements and provides a strong foundation for meeting emerging regulatory expectations such as CRA.


Speakers
avatar for Bernhard Denner

Bernhard Denner

Chief Architect, Hitachi Rail
Bernhard is the Chief Architect of a cloud-native application platform that forms the foundation of many Hitachi Rail products. With a strong background in IT system administration and software engineering, he began automating infrastructure long before “DevOps” became widely... Read More →
avatar for Benjamin Weber

Benjamin Weber

Business R&D Manager, Hitachi Energy
Benjamin holds a PhD in electrical engineering from ETH Zurich and is with Hitachi Energy in the role of "Team Lead and Project Manager Linux". He held various positions in diverse industries as firmware developer for Linux and other systems as well as design engineer for a fabless... Read More →
Thursday October 8, 2026 13:50 - 14:30 CEST
Club A (Floor 1)

14:40 CEST

Sponsored Session: LLM-Assisted Vulnerability Research in Yocto - Anders Heimer, Ericsson Software Technology
Thursday October 8, 2026 14:40 - 15:20 CEST
The Yocto Project provides several building blocks for supply-chain security, including pinned sources, checksums, source mirroring, SBOM support, and reproducible builds. These mechanisms are invaluable, but only as strong as the code behind them.

In this talk, I will describe a project in which I used LLMs to assist security research on selected Yocto Project components. I will explain how candidate findings were identified, manually triaged, reproduced, and filtered before being reported upstream.

The talk will cover how I separated real issues from false positives, assessed whether suspicious code patterns were exploitable, prepared reports that maintainers could act on, and upstreamed patches where appropriate.

Speakers
avatar for Anders Heimer

Anders Heimer

Senior Specialist Linux Build, Packaging and Integration, Ericsson Software Technology
Anders Heimer is a Senior Specialist at Ericsson Software Technology, where he provides Yocto expertise across Ericsson. His work focuses on embedded Linux, build systems, and software supply-chain and product security. He is a BitBake and OpenEmbedded contributor.
Thursday October 8, 2026 14:40 - 15:20 CEST
Club A (Floor 1)

16:40 CEST

OpenGrid: An Open-Source Electric Grid Modeling Ecosystem - Alice Yake, David Paolella, James Hewett & Ryan Attig, Breakthrough Energy
Thursday October 8, 2026 16:40 - 17:20 CEST
Modeling underlies the grid we all rely on. Every decision to build a new power plant or transmission line starts with a model run, yet planning models are often opaque, expensive, and difficult to replicate. That lack of transparency, along with uneven access to high-fidelity tools and data, breeds distrust and delay in the planning processes essential to decarbonizing the grid and expanding energy access worldwide. Open-source planning tools are growing in number and capability, but real barriers to adoption remain. OpenGrid aims to build a shared infrastructure foundation for open-source modeling, so open tools and data can become a credible industry standard. This session introduces the OpenGrid initiative, announced as a project under Linux Foundation fiscal sponsorship, covering both the thinking behind it, the plans to build it out and how you can get involved.
Speakers
avatar for David Paolella

David Paolella

Director, Research and Analytics, GRIDS, Breakthrough Energy

JH

James Hewett

Breakthrough Energy

RA

Ryan Attig

Breakthrough Energy
avatar for Alice Yake

Alice Yake

VP GRIDS, Breakthrough Energy
Alice Yake, Vice President of GRIDS at Breakthrough Energy, leads efforts to develop an open-source modeling ecosystem for delivering reliable, low-emission electricity globally, addressing the complexities of system design, regulations, and zero-carbon goals. With over 25 years of... Read More →
Thursday October 8, 2026 16:40 - 17:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any
 
Friday, October 9
 

11:05 CEST

Safety Critical Software BoF - Philipp Ahmann, ETAS GmbH & Olivier Charrier, Wind River
Friday October 9, 2026 11:05 - 11:45 CEST
Interest in safety critical open source software is high, yet opportunities to connect and openly discuss challenges remain limited. This BoF creates a focused forum for practitioners and newcomers to exchange experiences, ask questions, and gain visibility into existing projects and initiatives.

It also highlights the role of initiatives such as the Linux Foundation ELISA project as a central interface within the ecosystem, helping to connect efforts across communities, share practices, and make ongoing work more discoverable. The project brings together horizontal working groups covering features, processes, architecture, and tooling, while also addressing vertical domains such as automotive, aerospace, space, railways, and medical. This reflects the growing relevance of Linux and open source in safety critical systems.

By enabling direct interaction and cross project exchange, the session supports alignment, reduces duplication, and fosters collaboration in an evolving safety critical OSS landscape.

Participants at all levels of experience are encouraged to join, contribute their perspective, and engage with the community.
Speakers
avatar for Philipp Ahmann

Philipp Ahmann

Automotive OSS Process Lead, Etas GmbH (BOSCH)
Philipp Ahmann is a Senior OSS Community Manager at ETAS (a Bosch subsidiary), specializing in safety-critical automotive open source software. With 15+ years' experience in Linux automotive platforms, he has held roles from software engineer to project & line manager.
He currently holds the position of the technical steering committee chair for the Linux Foundation ELISA project to Enable Linux in Safety Applications. Additionally, he is member of the Linux Foundation Europe Advisory Board... Read More →
avatar for Olivier Charrier

Olivier Charrier

Principal Technologist - Functional Safety, Wind River
Olivier Charrier obtained a Master’s degree in Software Engineering (DESS) from Bordeaux University in 1989.
After working for Alsys/Aonix on Ada development environment for embedded systems, Olivier joined Wind River in June 2001 where his focus is to help Wind River's customers define, implement and certify Safety Critical Systems for multiple market segments including Avionics, Automotive... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
Club A (Floor 1)
  Safety-Critical Software

11:55 CEST

A Safety BOM Is a Contract: Producing and Consuming the SPDX Functional Safety Profile - Tobias Kästner, inovex GmbH & Nicole Pappler, AlektoMetis
Friday October 9, 2026 11:55 - 12:35 CEST
SPDX 3.1's Functional Safety profile recently grew to model a safety case end to end: requirements and their refinement, verification, pass/fail evaluations, evidence, and assumptions of use. It standardizes how a safety case is exchanged, but not how one is produced, nor what a consumer does with one received. We demonstrate SEGkit, a prototype, open-source, project-agnostic engine that extracts a design and evidence graph from content repositories to recompute a verdict over the graph—a judgment recomputed from content, not merely recorded—and detects which evidence goes stale as code evolves; in this talk we also show how we plan to use it within Zephyr to automate safety evidence creation. This makes SEGkit interesting to projects maintaining their safety BOM as well as downstream users who want to work with one. For the latter case we argue a received BOM is best consumed as a contract—its requirements and evidence being guarantees and its assumptions the conditions the consumer must discharge against its own case. Lastly, we talk about what the profile might add for machine-checkable discharge: assumptions as checkable conditions, linked to the guarantees they constrain.
Speakers
avatar for Nicole Pappler

Nicole Pappler

Senior Safety Expert, AlektoMetis.com
Nicole has worked in different projects developing safety relevant embedded software before starting as an independent assessor.
With now more than twenty years of experience in the industry, she supported several customers to show their compliance with safety, security and quality standards. Currently she is utilizing her experience regarding the development of highly reliable software to enable open source... Read More →
avatar for Tobias Kästner

Tobias Kästner

Safety Architect, Zephyr Project, inovex GmbH
A physicist by training, Tobias Kaestner has long been fascinated by where the physical and digital worlds meet. He began as a software team lead in a medical device start-up and has since spent 15+ years in the industry. As a solution architect for Medical IoT at inovex GmbH he helps... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
Club A (Floor 1)
  Safety-Critical Software

14:00 CEST

Let's Perform a Hazard Assessment! - Chuck Wolber, The Boeing Company & Pete Brink, Underwriter Laboratories (UL)
Friday October 9, 2026 14:00 - 14:40 CEST
A hazard assessment is “a process that allows the identification and evaluation of potential hazards related to [...] system function regardless of the details of its implementation” (SAE ARP4761A, section C.1). The outcome of a hazard assessment has far-reaching consequences for overall project design and the degree of engineering rigor required during development. In this session, Chuck will take the audience through a hazard assessment exercise based on a simplified model and describe the effects of the assessment on the design and development process. In addition to exposing the audience to a relatively simple but rigorous method for thinking about failure conditions during design, Chuck will also touch on gaps in non-safety-critical software engineering that can benefit from best practices developed by the safety engineering community.
Speakers
PB

Peter Brink

Functional Safety Engineering Leader, Underwriter Laboratories (UL)

avatar for Chuck Wolber

Chuck Wolber

Associate Technical Fellow, The Boeing Company
Chuck Wolber is a Boeing Associate Technical Fellow primarily focused on embedded platform engineering. He has developed multiple DO-178C certified Linux platforms currently in service on Boeing production aircraft. Chuck is co-author of the book Linux Toys, he is credited with contributions... Read More →
Friday October 9, 2026 14:00 - 14:40 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

14:50 CEST

Failure Propagation in Linux: Challenges for Safety Qualification - Alessandro Carminati, NVIDIA
Friday October 9, 2026 14:50 - 15:30 CEST
Linux was not developed around fault-containment properties expected of safety-certifiable software.

The linear map lets kernel code access memory across userspace ownership boundaries, so corruption can affect another process or container. Shared slab/page allocators and per-CPU caches compound this risk: corrupted state may remain latent and later affect unrelated subsystems. MMIO can cause external interference when a faulty driver accesses the wrong register or device because of corrupted state or an incorrect Device Tree or ACPI-derived base address.

Building on ELISA Linux Features WG (LFSCS) work, we use ks-nav call-tree artifacts to show that even narrow services depend on shared infrastructure across subsystems.

Reducing the configuration lowers function count but also usability; restoring functionality introduces transitive dependencies, so assessment cannot be limited to newly enabled code.

These findings challenge treating Linux as safe by default or relying on proven-in-use arguments alone. In a monolithic, shared-address-space kernel, fault containment and qualification scope must be demonstrated, not assumed.
Speakers
avatar for Alessandro Carminati

Alessandro Carminati

Senior Safety Architect for Linux, NVIDIA
Senior Safety Architect for Linux at NVIDIA, working on Linux kernel performance, tooling, community engagement, and its adoption in safety-critical applications. Previously a Linux Kernel Engineer in Red Hat’s Automotive Team, with a background in embedded Linux, Linux security... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
Club A (Floor 1)
  Safety-Critical Software

15:40 CEST

Feasibility of an Open-Source Linux Platform for Autonomous Train Operation - Daniel Weingaertner & Sebastian Hetze, Red Hat
Friday October 9, 2026 15:40 - 16:20 CEST
Autonomous train operation requires a new generation of computing platforms capable of running AI-based perception, sensor fusion, and safety-critical control functions. Traditionally, railway systems have been delivered as tightly integrated proprietary hardware-software stacks, limiting software reuse, innovation, and vendor independence.
This talk presents the results of the Automated Train research project and explores whether a Linux-based platform can become the foundation for safety-critical rail applications. We examine the technical feasibility of using Linux to support mixed-criticality workloads while meeting stringent railway safety requirements.
Beyond technology, we discuss a fundamental challenge for open source in regulated industries: how can continuously evolving software be certified in environments governed by legally binding functional safety standards?
Finally, we explore the governance and business implications of a shared open-source platform for the railway sector. The lessons learned extend far beyond railways and provide a blueprint for applying Linux and open-source collaboration to other safety-critical and sovereign digital infrastructure domains.
Speakers
avatar for Daniel Weingaertner

Daniel Weingaertner

Senior Software Engineer, Daniel Weingaertner
A seasoned technical leader and former professor, Daniel Weingaertner brings expertise in High-Performance Computing (HPC) and automotive software engineering. He has a track record of delivering open-source and Linux solutions for the public sector and possesses specialized knowledge... Read More →
avatar for Sebastian Hetze

Sebastian Hetze

Principal Software Engineer, Field CTO, Red Hat
Sebastian Hetze has been developing free software since the 1980s. From 1992 to 2012, he ran his own Linux companies. He has been working for Red Hat since 2012, most recently as a Principal Software Engineer in the Field CTO organization. He is also an elected board member of the... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
Club A (Floor 1)
  Safety-Critical Software
  • Audience Experience Level Any

16:30 CEST

TLA+ in the Age of AI-Assisted Engineering - Igor Konnov & Thomas Pani, Independent
Friday October 9, 2026 16:30 - 17:10 CEST
Over several decades, TLA+ has been immensely useful for finding safety and liveness issues in concurrent and distributed systems. As developers of Apalache, the symbolic model checker for TLA+, our work with engineers has changed how we think specification tooling should look. Three obstacles to adoption arise repeatedly: (1) the steep learning curve, (2) the gap between formal specs and the code, and (3) scalability issues.

This talk reflects on our 10 year journey with TLA+ into the age of AI. We first show how we addressed (1) through a less mathematical syntax and modern developer experience. For (2) and (3), model-based testing and proofs have long been promising, but traditionally required too much expert labor. Frontier AI tooling changes this balance: it lowers onboarding costs, helps generate test drivers, and can automate proof work to a useful degree.

At the same time, formal tooling allows us to gate AI-generated code, catching plausible but incorrect implementations. We argue that AI and formal tooling complement each other, making both more practical.
Speakers
avatar for Igor Konnov

Igor Konnov

Independent Researcher in Formal Verification and Security
Igor Konnov is an independent security and formal methods researcher, practicing formal verification, differential testing, and fuzzing of distributed protocols. He is the principal maintainer of Apalache, a symbolic model checker for TLA+, under the Linux Foundation and TLA+ Fou... Read More →
avatar for Thomas Pani

Thomas Pani

Independent Consultant, Specification and Reliability Tools
Thomas Pani is an open source developer working on specification languages, developer tooling around executable specifications, and high-assurance distributed systems. He is a maintainer of Apalache, a symbolic model checker for TLA+, and an early contributor to Quint, a modern specification... Read More →
Friday October 9, 2026 16:30 - 17:10 CEST
Club A (Floor 1)
  Safety-Critical Software
 


Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.