Loading…
7-9 October, 2026
Prague, Czechia
View More Details & Registration
Important Note: Timing of sessions and room locations are subject to change.

The Sched app allows you to build your schedule but is not a substitute for your event registration. You must be registered for Open Source Summit Europe 2026 to participate in the sessions. If you have not registered but would like to join us, please go to the event registration page to purchase a registration.



Venue: South Hall 3 B (Floor 3) clear filter
Wednesday, October 7
 

09:05 CEST

Triaging CVEs for the Linux Kernel - Christoph Steiger & Negar Masoudifar, Siemens AG
Wednesday October 7, 2026 09:05 - 09:45 CEST
The Linux kernel currently sees around 60 CVEs per week. With the EU Cyber Resilience Act (CRA) rapidly approaching this creates a serious challenge for anyone shipping commercial products based on it: a lot of additional vulnerability management and compliance work.

In this talk, we will introduce kernel-cve-triage, a tool developed under the umbrella of the Civil Infrastructure Platform (CIP). It addresses these compliance challenges with a unique approach, using the kernel’s Kconfig build configuration to determine which reported CVEs actually apply. With this method, we base our assessment only on the kernel source tree and its configuration and are build-system independent. This reduces false-positive CVEs by up to 95%, depending on the exact configuration and the set of vulnerabilities considered.

We will also cover the key differences compared to another major kernel CVE automation tool: the Yocto Project and its cve-check. Finally, we will give an outlook and suggestions on how to improve the current situation for the Linux kernel's users.
Speakers
avatar for Christoph Steiger

Christoph Steiger

Embedded Linux Engineer, Siemens AG
Open Source enthusiast who is working on embedded Linux systems. He focuses on all things Linux Kernel: from driver implementation to real-time applications and supply chain security.
avatar for Negar Masoudifar

Negar Masoudifar

Working Student – Embedded Linux, Siemens AG
Negar Masoudifar is a working student at Siemens focused on Linux kernel development and embedded systems. She works on the CIP kernel CVE triage project, building tools to help figure out which vulnerabilities actually matter for a given kernel setup.
Wednesday October 7, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:50 CEST

An Approach To Managing CVEs With Vendor Kernels - Jan Pfiffner, Grossenbacher Systeme AG
Wednesday October 7, 2026 09:50 - 10:30 CEST
Managing vulnerabilities in the kernel has gotten more attention but also needs more effort due to the exploding number of CVEs. With the kernel now being a CNA since 2024, options have evolved, and most recently, since 596ad6c on openembedded-core/master, it has gotten "easy".

But this is not working for vendor kernels, as they lag mainline and a rebase is impractical, if not impossible, due to the vendor delta.
As vendor kernels are heavily used in the industry and a switch to linux-yocto is often not possible due to budget, timeline or vendor lock-in, a solution is needed.

I've built a solution that locates the fix for each detected CVE on the matching stable branch, emits a candidate backport patch, verifies it applies cleanly, checks (via koverage, at line granularity) whether the affected code is compiled, and classifies results into actionable buckets.
Output is a list of unaffected CVEs and a collection of patches for review. In my opinion, this is verified and evidence-backed patching rather than just a cherry-picked list.

I'd like to present a solution (layer) which includes this workflow and start a broader discussion about the issue with vendor kernels.
Speakers
avatar for Jan Pfiffner

Jan Pfiffner

Head of Software Engineering, Grossenbacher Systeme AG
I'm Head of Software Engineering at Grossenbacher Systeme AG (GESYS), a Swiss embedded systems manufacturer. After several years in PLC and machine vision software development, I moved into embedded and have spent the last four years working with Yocto, building, producing and maintaining... Read More →
Wednesday October 7, 2026 09:50 - 10:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

11:20 CEST

FIT Happens: How Secure Boot Wasn't - Ahmad Fatoum, Pengutronix e.K.
Wednesday October 7, 2026 11:20 - 12:00 CEST
Flat Image Tree (FIT) is Das U-Boot’s preferred boot image format and underpins billions of embedded Linux boot flows, with adoption extending into other bootloaders such as barebox.

Its core idea of using the flattened device tree format for flexibility and code reuse, enabled widespread adoption, but also became a fertile source of subtle security flaws.

This talk traces FIT’s evolution from a pragmatic design choice to a widely trusted format, highlighting how its structure led to recurring weaknesses, culminating in CVE-2026-33243, a decade-old vulnerability whose exploitation bypassed verified boot for millions of devices.

Finally, Ahmad presents a proposal to improve FIT: a backwards-compatible scheme for whole-image signing that requires limited parsing, aiming to deliver stronger security guarantees without the format’s historical pitfalls.
Speakers
avatar for Ahmad Fatoum

Ahmad Fatoum

Kerningenieur, Pengutronix e.K.
Ahmad joined the kernel team at Pengutronix in 2018 to work full-time on furthering Linux world domination. He does so by helping automotive and industrial customers build embedded Linux systems based on the mainline Linux kernel.
Having a knack for digging in low-level guts, his... Read More →
Wednesday October 7, 2026 11:20 - 12:00 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

13:30 CEST

Secure by Default in Embedded Linux: The Features You Are Probably Not Using - Marta Rybczynska, Ygreky
Wednesday October 7, 2026 13:30 - 14:10 CEST
Linux offers an impressive collection of security mechanisms, and recent years have added even more to the stack. Yet when reviewing embedded Linux products, I repeatedly run into a different problem: security features that are available, mature, and practical are simply not enabled.

Many embedded projects still start from vendor examples, reference BSPs, or existing products. As a result, design decisions made years ago often become the default for the next generation of devices. This talk focuses on a set of practical security mechanisms that embedded developers can deploy from the beginning of a project with relatively little effort.

Using examples from Yocto Project-based systems, we will examine features and tools such as:
- overlayfs with its advanced features
- filesystem permission hardening
- seccomp-based system call filtering
- fs-verity for file integrity protection
- fscrypt for protecting data belonging to different users and use cases.

We will discuss why they should be part of a base configuration and and show practical examples on how to do it.
Speakers
avatar for Marta Rybczynska

Marta Rybczynska

Founder and CEO, Ygreky
Marta Rybczynska has a network security background, with 20 years of experience in Open Source.
She has worked with embedded operating systems like Linux and various real-time OSes, and with
system libraries and frameworks up to user interfaces. Contributed to various projects in... Read More →
Wednesday October 7, 2026 13:30 - 14:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

14:25 CEST

SELinux in Embedded Linux: From Basics To Best Practices - Tobias Kaufmann, BMW Car IT
Wednesday October 7, 2026 14:25 - 15:05 CEST
Modern vehicles employ a highly integrated architecture with a relatively small number of powerful Electronic Control Units (ECUs). Many of these ECUs run Linux and present a sizable attack surface. To mitigate the resulting threats, SELinux offers an enhanced mechanism for enforcing the principle of least privilege.

Despite its strengths, SELinux remains complex and is not widely adopted. This talk offers a pragmatic introduction to SELinux, with concrete guidance you can apply to your embedded Linux project.

This session will cover basic permissions and type enforcement in SELinux, including which permissions are required for an application start-up. It will introduce the reference policy and guide you through writing a first “hello-world” policy. We will also discuss SELinux in the context of Yocto. Finally, we will conclude with lessons learned from our experience in large-scale projects.
Speakers
avatar for Tobias Kaufmann

Tobias Kaufmann

Security Architect for Head-Units, BMW Car IT
Tobias holds an M.Sc. in Electrical Engineering. After several years working on smart grid projects, he joined BMW Car IT in 2018. He currently serves as the Security Architect for head units at BMW Car IT.
Wednesday October 7, 2026 14:25 - 15:05 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

15:35 CEST

OP-TEE Footguns: Lessons From the Integration Trenches - Richard Weinberger, sigma star gmbh
Wednesday October 7, 2026 15:35 - 16:15 CEST
OP-TEE is a widely adopted Trusted Execution Environment (TEE) commonly used on ARM-based SoCs. While it is highly portable and often features strong vendor support, achieving a functionally working setup is only half the battle. There are surprisingly many pitfalls where a developer can successfully integrate OP-TEE, only to introduce subtle security misconfigurations that silently undermine the entire system's threat model.

In this talk, Richard will outline the hidden security traps and integration challenges he has encountered over the past few years on custom hardware. Attendees will learn which footguns to watch out for, ultimately saving them the countless hours Richard spent debugging these exact issues.
Speakers
avatar for Richard Weinberger

Richard Weinberger

CTO, sigma star gmbh
Richard Weinberger is co-founder of sigma star gmbh where he offers consulting services around Linux and IT security. Upstream he maintains various subsystems of the Linux kernel such as UserModeLinux and UBIFS. Beside of low level and security aspects of computers he enjoys growing... Read More →
Wednesday October 7, 2026 15:35 - 16:15 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

16:30 CEST

Securing Embedded Linux Buildsystems Against Supply Chain Attacks - Alejandro Enedino Hernandez Samaniego, Microsoft Corporation
Wednesday October 7, 2026 16:30 - 17:10 CEST
Embedded Linux build systems such as The Yocto Project and Buildroot rely on reused build artifacts and external inputs, while these represent an improvement in build time for subsequent builds, also create opportunities for supply chain attacks that are difficult to detect.

This talk demonstrates practical attack vectors, showing how intermediate object files produced by make in Buildroot can be modified during the build to introduce malicious behavior without changing source code, and also demonstrate its possible to poison Yocto Project shared state (sstate) cache artifacts to propagate compromised binaries.
These attacks are validated end-to-end by executing poisoned binaries in the final Linux image under QEMU.

I will then present mitigation strategies, focusing on signing and verification of the sstate artifacts and improved control over build inputs. The discussion covers integration approaches and tradeoffs between security, performance, and developer workflows.

Attendees will gain practical insight into real-world risks when creating customized Linux distributions and concrete steps to improve their build system's security.
Speakers
avatar for Alejandro Enedino Hernandez Samaniego

Alejandro Enedino Hernandez Samaniego

Principal Software Engineer, Microsoft Corporation
Alejandro is an Principal Software Engineer at Microsoft, he works as a Yocto Project developer in the Linux Systems Group, designing software to improve system's developers experience when building customized embedded Linux distributions and applications, currently maintains the... Read More →
Wednesday October 7, 2026 16:30 - 17:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

17:25 CEST

Secure by Default: Building Locked-Down Embedded Linux Devices With Systemd - Mohammad Abdoli, Segula Technologies
Wednesday October 7, 2026 17:25 - 18:05 CEST
Modern embedded Linux devices must balance security, maintainability, and operational flexibility. While the Linux kernel provides powerful security primitives such as namespaces, cgroups, eBPF, and dm-verity, integrating them consistently across products remains a challenge.

This session explores how systemd has evolved beyond a traditional init system into a security and lifecycle management framework for embedded Linux platforms.

Using practical examples, we will examine how systemd Portable Services enable immutable application deployment, how dm-verity protects software integrity from storage to execution, how systemd leverages eBPF for kernel-enforced sandboxing and policy enforcement, and how cgroup-based resource management can contain both faults and attacks.

Attendees will learn how these mechanisms interact, how they can be integrated into Yocto-based systems, and how systemd can act as the orchestration layer between applications and modern Linux kernel security features.

Rather than presenting isolated hardening techniques, this session introduces a practical architecture for designing maintainable, resilient, and secure-by-default embedded Linux products.
Speakers
avatar for Mohammad Abdoli

Mohammad Abdoli

Senior Embedded systems consultant, Segula technologies
Mohammad Abdoli (mominux) is an Embedded Systems Engineer specializing in the safety and security of embedded platforms, Linux system architecture, and open-source technologies. His interests include Linux security, systemd, virtualization, and secure-by-design embedded systems.
Wednesday October 7, 2026 17:25 - 18:05 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
 
Thursday, October 8
 

09:05 CEST

Enabling Multi-Stream Camera Sensors in Linux: RGB+IR Streams and Embedded Metadata - Rishikesh Donadkar & Devarsh Thakkar, Texas Instruments
Thursday October 8, 2026 09:05 - 09:45 CEST
Camera sensors are evolving beyond single-stream models to generate multiple concurrent streams like RGB+IR video and embedded metadata alongside image data. Supporting these sensors in Linux introduces new challenges for the V4L2 and media controller subsystem, particularly around per-stream configuration and stream identification.

This talk presents two practical use cases for enabling multi-stream cameras in Linux. First, RGB+IR sensor support through V4L2 control framework extensions using array-based controls, enabling independent per-stream configuration while preserving a unified sensor model. Second, sensors transmitting embedded metadata, leveraging RAW sensor model proposed by Sakari Ailus, internal pads for metadata propagation, and data-type filtering in V4L2 bridge drivers to separate and route metadata and image streams.

Ref (lkml) : [PATCH v11 00/66] Generic line based metadata support, internal pads

These concepts are demonstrated through POC implementations on TI AM62A platform using OV2312 and IMX219 sensors, with integration into GStreamer and libcamera.

Attendees will gain practical insight into Linux multi-stream camera sensor implementation
Speakers
avatar for Rishikesh Donadkar

Rishikesh Donadkar

Senior Software Engineer, Texas Instruments
Rishikesh is a 2024 graduate from VJTI, Mumbia. He has been involved in open-source community from 1st year of his college. He has completed GSoC in the year 2024 with the organization libcamera. He has been quite active in the media community contributing mainly to Linux media s... Read More →
avatar for Devarsh Thakkar

Devarsh Thakkar

Linux Media Lead at Texas Instruments, Texas Instruments
Devarsh Thakkar works as an Embedded Linux developer at Texas Instruments. He has 13+ years of experience in software development ranging from open-source bootloaders to the Linux kernel, middleware frameworks and applications. His expertise lies in Audio/Video related multimedia... Read More →
Thursday October 8, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

09:50 CEST

Multi-Display Pipelines on Allwinner: Upstream Kernel DRM To Mesa3D - Parthiban N, Linumiz
Thursday October 8, 2026 09:50 - 10:30 CEST
Most Allwinner based products still runs on vendor BSP kernels with out-of-tree display drivers. But with recent upstream Linux Kernel improvements, its now possible to simultaneously drive multiple display panels over different interfaces like LVDS and MIPI, using mainline DRM subsystem on Allwinner A133 and A523 SoCs.

In this talk, I will share my experience bringing up a multi-display setup with 2 x LVDS and 1 x MIPI panels on Allwinner A133 using upstream kernel [1] and [2]. We will go through how the Allwinner display engine works, what the device tree topology looks like when you have multiple active display pipelines, and what DRM/KMS changes matters to get this working correctly.

We will also look at the userspace side - how a compositor like Weston handles multi-display and the limitations you hit in practice. I will cover some of the real problems I hit during bringup, not just the happy path.

[1]: https://lore.kernel.org/linux-sunxi/[email protected]/
[2]: https://lore.kernel.org/linux-sunxi/[email protected]/
Speakers
avatar for Parthiban

Parthiban

Director of Engineering, Linumiz
With over 14 years of experience in software engineering, Parthiban founded Linumiz, a company that provides domain-neutral software services for U-Boot, Linux, and Zephyr, ranging from board bringup, board supported package, customization, device drivers, to over the air software... Read More →
Thursday October 8, 2026 09:50 - 10:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

10:50 CEST

Evolving Video4Linux2 To Support Modern Camera Use Cases - Jacopo Mondi, Ideas On Board
Thursday October 8, 2026 10:50 - 11:30 CEST
Modern camera use cases are realized by complex pipelines of several IPs blocks that process frames produced by an image sensor to deliver great looking images to applications.

Support for the most advanced use cases is implemented by time-multiplexing the underlying hardware resources, performing job scheduling at the hardware/firmware level and orchestrating the image processing steps across multiple drivers and IPs.

The Video4Linux2 kernel subsystem currently doesn't provide any abstraction for drivers and applications to fully support modern designs and vendors that intend to make use of the capabilities of their hardware had so far worked around this
limitations by implementing downstream solutions.

This talk describes the most recent and the forthcoming developments in the Video4Linux2 kernel framework to support modern camera use cases, including but not limited to multi-driver pipelines, multi-context time multiplexing of hardware resources and job scheduling, with practical examples from the field on recent SoC designs.
Speakers
avatar for Jacopo Mondi

Jacopo Mondi

Linux camera specialist, Ideas On Board
Jacopo is an embedded Linux engineer with 10 years of experience in the field of camera and multimedia systems.

With the Ideas On Board team he's trying hard to "make cameras work on every platform" with mainline Linux and libcamera
Thursday October 8, 2026 10:50 - 11:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

11:40 CEST

FOSS Camera Support for the Qualcomm OPE ISP - Hans de Goede & Loic Poulain, Qualcomm
Thursday October 8, 2026 11:40 - 12:20 CEST
Until recently camera software stacks have mainly been a proprietary closed source affair. Thanks to the linux-media and libcamera communities this has been slowly changing.

We are happy to present the first Free and Open Source Software stack for a Qualcomm camera hardware ISP, the Offline Processing Engine found on the QRB2210 (Agatti) SoC used on the Arduino UNO Q SBC. Using a standard mainline V4L2 ISP kernel driver together with libcamera.

This talk will cover the following topics:

* Overview of the Qualcomm camera subsystem architecture
* Mainline V4L2 ISP kernel driver for the Agatti OPE block
* CAMSS libcamera pipeline-handler and camss IPA for OPE
* Image processing steps supported by the presented FOSS stack
* Future plans for more image processing steps
* Future plans for supporting the ISP on other Qualcomm SoCs
Speakers
avatar for Hans de Goede

Hans de Goede

Senior Staff Engineer, Qualcomm
Hans is a FOSS developer and enthusiast with 20 years of experience. He is co-maintainer for the kernel’s x86 platform drivers subsystem.

He has worked on various projects such as USB redirection for VMs, laptop support and flicker free boot. Currently Hans focuses on MIPI cam... Read More →
avatar for Loic Poulain

Loic Poulain

Software Engineer, Qualcomm
Loïc Poulain is a software engineer working on embedded and low-level systems, with contributions to open-source projects such as the Linux kernel, U-Boot, and the Zephyr real-time operating system. His work focuses on device drivers, hardware enablement, and system bring-up. More... Read More →
Thursday October 8, 2026 11:40 - 12:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

13:50 CEST

Cursed Camera Connectors - Kieran Bingham, Ideas on Board
Thursday October 8, 2026 13:50 - 14:30 CEST
An exploration into the complexities of physically connecting cameras to your embedded development board, and configuring them through device tree, and hopefully how we can make it easier in the future!


Small board computers are now prolific with their ability to connect RAW MIPI cameras directly to the board, and now that libcamera provides an open camera stack, connecting cameras to all your favourite boards should be easy.

But it's not. The connectors might have 15, 22 or 30 pins. The functions of each pin differ between boards. There's TypeA and TypeB cables.... And they better not be too long!

The lack of standardisation means it can still be difficult to connect your camera, and the combinatorial explosion of potential device tree overlays will soon become unmaintainable.

Lets look at suggestions that have been around for a decade already, and where that work is now leading to make connecting cameras easier!
Speakers
avatar for Kieran Bingham

Kieran Bingham

Director of Engineering, Ideas on Board
Kieran Bingham is an embedded software engineer working with Ideas on Board and specialising in Linux kernel developments with a focus on media related subsystems.

Kieran has worked with embedded Linux systems for 20 years through professional service companies and silicon vendo... Read More →
Thursday October 8, 2026 13:50 - 14:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

14:40 CEST

From Power Sequences To Zink: Mainlining Hardware Accelerated 3D for RISC-V - Michał Wilczyński, Samsung Electronics
Thursday October 8, 2026 14:40 - 15:20 CEST
RISC-V is evolving into a capable desktop replacement, driven by boards like the Lichee Pi 4A, but a major barrier remains: the lack of a fully open, upstream graphics stack.

This talk explores enabling hardware accelerated graphics on modern RISC-V SoCs by extending the open source Imagination PowerVR driver for the TH1520. We dive into the architectural challenges of this port, including the complex power sequencing that necessitated the new pwrseq-thead-gpu driver. We break down how the kernel DRM driver interacts with the Mesa PVR Vulkan driver, and how leveraging the Zink translation layer finally brings standard OpenGL desktop acceleration to the platform. Finally, we cover the current mainline status and next steps for the StarFive JH7110 display controller integration.

Key Takeaways / What Attendees Will Learn:
- Porting the open PowerVR driver to the RISC-V TH1520 SoC.
- Implementing kernel power sequencing (pwrseq) for complex GPU domains.
- Interacting between DRM, Mesa Vulkan, and Zink for desktop GL support.
- Current mainline status of the JH7110 Display Controller.

https://mwilczynski.dev/posts/riscv-gpu-zink/
Speakers
avatar for Michał Wilczyński

Michał Wilczyński

Principal Software Engineer, Samsung Electronics
Michał Wilczyński is a Linux Kernel Engineer at Samsung, working on Tizen OS—where he gets to hack on the heart of smart devices. Before that, he spent time at Intel building networking drivers for the Linux kernel, and earlier in his career, he worked at Nokia and F5 Networks... Read More →
Thursday October 8, 2026 14:40 - 15:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

15:50 CEST

WPE Hands-On: Writing a Launcher for Embedded Devices With the New WPEPlatform API - Mario Sanchez-Prada, Igalia
Thursday October 8, 2026 15:50 - 16:30 CEST
WPE WebKit is the WebKit port for Linux-based embedded devices, powering Web-based user interfaces on platforms such as set-top boxes, smart appliances, and industrial systems. With the 2.54 release, a stable version of the new WPEPlatform API is now available, radically simplifying how the Web engine is embedded: thanks to built-in support for Wayland, DRM/KMS, and headless rendering, libwpe and external backends are no longer needed unless you target a different platform. Zero-copy buffer sharing via DMA-BUF is also available for efficient video and graphics pipelines on modern Linux kernels and supported platforms.

After a quick introduction to WPE WebKit, the session will demonstrate the new API in practice, showing how simple it has become to write a custom launcher to run Web-based applications on embedded devices. It will also offer practical guidance for migrating existing integrations to WPEPlatform, whether they are based on Cog or built directly on the legacy API.

Whether you are evaluating WPE for the first time or maintain devices already shipping it and wonder what it means for you, this talk will help you get started with the next generation of the WPE public API.
Speakers
avatar for Mario Sanchez-Prada

Mario Sanchez-Prada

Software Engineer and WebKit Team coordinator at Igalia, Igalia
Software engineer and partner at Igalia with 18+ years of experience working on the development of Linux-based Operating Systems, the GNOME platform, Web engines (i.e. WebKit, Blink) and Web browsers (Epiphany, Chromium).

Past experience includes work on the Maemo project, Litl... Read More →
Thursday October 8, 2026 15:50 - 16:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

16:40 CEST

State of Embedded Linux - Walt Miner, The Linux Foundation
Thursday October 8, 2026 16:40 - 17:20 CEST
This talk offers a comprehensive look at what's changed in the embedded Linux world over the past year. Walt will walk through the latest kernel developments most relevant to embedded developers, survey key userspace projects shaping modern embedded designs, and cover the broader community, industry, and legal landscape — from the status of major processor architectures to initiatives at the Linux Foundation and beyond.

Whether you're tracking changes to subsystems you already rely on or looking for new tools and techniques to improve your workflow, this session will help you stay current in a fast-moving ecosystem. Come find out what's new, what's shifting, and what it means for your embedded Linux work.
Speakers
avatar for Walt Miner

Walt Miner

Senior Director - Automotive Grade Linux, The Linux Foundation
Walt Miner is the Senior Director of Community at The Linux Foundation and has served as Community Manager for Automotive Grade Linux since 2014. Walt has spoken at numerous conferences throughout the worlds and brings over 30 years of embedded software development and management... Read More →
Thursday October 8, 2026 16:40 - 17:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any
 
Friday, October 9
 

09:05 CEST

Buildroot LTS in the CRA Era: 18 Months of Keeping a 3-Year Branch Secure - Thomas Perale & Titouan Christophe, Mind OSS NV
Friday October 9, 2026 09:05 - 09:45 CEST
The Buildroot Long-Term Support (LTS) sponsorship initiative was launched in March 2025. Its goal is to help Buildroot users maintain stable and secure products over longer periods, particularly in light of upcoming security regulations such as the Cyber Resilience Act (CRA).

We transitioned from a day-to-day maintenance workflow to a more systematic, weekly peer-reviewed approach. After more than a year and a half of maintaining the Buildroot LTS branch, we have encountered both successes and unforeseen challenges. We had to develop custom tooling to deal with a growing number of vulnerability reports, all while preserving stability for the releases.

This talk covers:

* How we tackle the maintenance task as a distributed team.
* Maintenance challenges with the constant flow of CVEs.
* Keeping the package metadata up-to-date and improving the vulnerability
monitoring across branches.
* What worked and what didn't.
* How we plan to evolve and improve for the future.
Speakers
avatar for Thomas Perale

Thomas Perale

Embedded Software Engineer, Mind OSS NV
Thomas Perale is a Belgian embedded software engineer working for Mind with a strong passion for free software development and embedded systems.

He is involved in maintaining Buildroot stable and LTS releases.
avatar for Titouan Christophe

Titouan Christophe

Embedded Software Engineer, Mind OSS NV
Titouan is an embedded and backend developer. He has worked in remote railway vehicle monitoring and automated visual quality control for the manufacturing industry.

Titouan is now working at Mind OSS, helping customers with Zephyr, embedded Linux and open source in general. He is the author of Zephyr's USB-MIDI and Network MIDI 2.0 stacks, and co-steward of the Buildroot LTS initiative... Read More →
Friday October 9, 2026 09:05 - 09:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

09:50 CEST

Yocto BSP Layers: Breaking Free From Complexity - Mathieu Dubois-Briand & Köry Maincent, Bootlin
Friday October 9, 2026 09:50 - 10:20 CEST
Many Yocto layers provided by silicon vendors prioritize vendor-specific tooling, demos, and opinionated decisions often at the expense of simplicity, flexibility and maintainability. This makes
them challenging to integrate for custom boards or to adapt to specific customer needs.

Additionally, some of those vendor-provided layers create a maintenance burden: when you need to update, you become dependent on the vendor's choices and changes, which are often hard to understand and follow.

In this talk, we'll examine common issues found in vendor-provided Yocto layers and show how they introduce unnecessary complexity into embedded Linux projects. Much of what new users perceive as “Yocto complexity” actually comes from the design and maintenance practices used in vendor layers.

We'll then introduce yocto-kiss as an example of a simpler and more maintainable approach to vendor support layers. The talk will cover practical best practices for layer design, common pitfalls to avoid, and strategies for building vendor layers that are clean, flexible, and pleasant to maintain.
Speakers
avatar for Mathieu Dubois-Briand

Mathieu Dubois-Briand

Embedded Linux engineer, Bootlin
Mathieu Dubois-Briand is an Embedded Linux engineer at Bootlin since 2024, specializing in Yocto integration, kernel development, device drivers and bootloaders.
He is part of the Yocto Build Failure "SWAT" team, in charge of testing patches submitted to OpenEmbedded core layer and Bitbake master branches... Read More →
avatar for Köry Maincent

Köry Maincent

Embedded Linux engineer, Bootlin
Köry Maincent is an Embedded Linux engineer at [Bootlin](https://bootlin.com/) since 2020, working on kernel, device drivers, bootloaders and build system integration, and on upstreaming on all the above.
He is the maintainer of the [ST Buildroot External](https://github.com/boo... Read More →
Friday October 9, 2026 09:50 - 10:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

11:05 CEST

Is It Time To Retire Kas? - Jan Kiszka & Felix Mößbauer, Siemens
Friday October 9, 2026 11:05 - 11:45 CEST
You are using kas, the user-friendly orchestration tool for bitbake projects, and you just got nervous? Sorry for that.

With your full attention now, this talk shall bring you up to date with latest developments in kas. Among them are the diff plugin, buildtools support, build attestations, improved lock file handling, unprivileged containers, commit signature validation, easier CI builds, and more.

But we would also like to hear from you what could be further improved. Are there use cases or workflows that should be added to kas or could be better handled than so far. Be prepared for an interactive part.

Last but not least, we will relieve you from worries that kas might be retired by explaining our motivations and plans to drive this project also in the foreseeable future.
Speakers
avatar for Jan Kiszka

Jan Kiszka

Principal Key Expert, Siemens
Jan Kiszka is working as consultant, open source evangelist and Principal Key Expert Engineer in the Linux Expert Center at Siemens Technology. He is supporting Siemens businesses with adapting, enhancing or strategically driving open source as platform for their product demands... Read More →
avatar for Felix Mößbauer

Felix Mößbauer

Senior Embedded Developer, Siemens AG
Having a strong background in High Performance Computing, Felix is currently focusing on embedded Linux platforms for realtime applications. Hereby, he works across country and company boundaries to unify patterns that are recurring and mandatory for embedded products (like secure... Read More →
Friday October 9, 2026 11:05 - 11:45 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

11:55 CEST

Bitbake-setup Has Shipped in Yocto: Producing Complete Linux Systems From One File - Alexander Kanavin, Linutronix
Friday October 9, 2026 11:55 - 12:35 CEST
The Yocto project is a toolkit for creating custom Linux distributions for the embedded use cases. Historically it has not provided tools and standards for setting up and replicating build configurations in a reproducible manner, leaving that to third party projects and custom scripts.

This has changed with the latest Yocto LTS release (6.0 'wrynose'), which includes a tool called bitbake-setup. This talk will give an overview of what is available and how it can be used to write a record of how to build a complete system, and to replicate that build elsewhere with that record. I will also briefly cover possible future directions for build configuration management.
Speakers
avatar for Alexander Kanavin

Alexander Kanavin

Open Source Software Engineer, Linutronix
Alexander is an open source developer specializing in distribution engineering using vendor-neutral tooling and userspace stacks. He is one of the primary contributors to the Yocto project and has an interest in developing foundations of digital infrastructure in a sustainable ma... Read More →
Friday October 9, 2026 11:55 - 12:35 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

14:00 CEST

Buildroot at 25: A Quarter Century of Making Embedded Linux Easy - Peter Korsgaard, Barco
Friday October 9, 2026 14:00 - 14:40 CEST
Buildroot started in 2001 with the goal of having a simple and easy way to build embedded Linux systems. Now, 25 years later the size and complexity of embedded Linux systems have increased dramatically and so have the required features of the build system, but the goals are still the same.

This talk celebrates Buildroot's 25th anniversary by exploring the project evolution, the community that shaped it and the technical decisions that enabled it to remain relevant for modern projects before finishing up with some thoughts about what the future may bring.

Attendees will gain both a historical perspective, insight into how Buildroot is developed and a view to what lies ahead.
Speakers
avatar for Peter Korsgaard

Peter Korsgaard

Senior Expert Embedded Development Engineer, Barco
Peter is an embedded Linux developer and long time Buildroot maintainer with 20+ years of experience
Friday October 9, 2026 14:00 - 14:40 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

14:50 CEST

Yocto: From Scarthgap To Wrynose, 2 Years of LTS Evolution - Jérémie Dautheribes, Bootlin
Friday October 9, 2026 14:50 - 15:30 CEST
Yocto Project has become the de-facto standard for embedded Linux build systems, and its LTS releases serve as the key milestones driving industry adoption and long-term platform decisions.

Wrynose (6.0), released in May 2026, is the new LTS: teams and community members running Scarthgap in production are now facing the migration question.

This talk covers what actually changed over those two years: build tooling and configuration workflow, CVE and SBOM handling in the context of the upcoming EU Cyber Resilience Act, toolchain updates, and the breaking changes that affect existing layers and distro configurations. By the end of this talk, attendees should have a clear picture of what it takes to migrate from Scarthgap to Wrynose in a real production environment.
Speakers
avatar for Jérémie Dautheribes

Jérémie Dautheribes

Embedded Linux and Kernel engineer and trainer, Bootlin
Jérémie Dautheribes is an embedded Linux engineer and trainer at Bootlin since 2022.
He has been working with Yocto for 5 years.
His expertise also extends to BSP maintenance and evolution.
As a trainer, he has also helped many people improve their skills on the Yocto Project and Embbeded Linux in general... Read More →
Friday October 9, 2026 14:50 - 15:30 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference

15:40 CEST

Yocto’s Hidden Gems: Lesser-Known Tools for Daily Development - Anna-Lena Marx, inovex GmbH
Friday October 9, 2026 15:40 - 16:20 CEST
Yocto is a complex and huge ecosystem. Getting started may feel hard, but there are various tools to make our daily development easier right out of the box—if you know about them. Unfortunately, many developers are only used to a small subset of the available tools and their capabilities, which often leads to writing additional custom tooling for already solved problems.
In this presentation, we will dive into a selection of these existing tools and demonstrate how to take advantage of them in everyday workflows. For example, we’ll discuss how `bitbake-getvar` helps with debugging variables and overrides, and how to find all packages generated by a recipe with `oe-pkgdata-util`. We will also look into `yocto-check-layer`, `patchtest`, `bitbake-config-help`, and more.
The session will focus on practical use cases, showing how to leverage already available tools to save time and reduce the need for custom scripts.
Speakers
avatar for Anna-Lena Marx

Anna-Lena Marx

Tech Lead Embedded Linux, inovex GmbH
Anna-Lena Marx is TechLead for Embedded Linux at inovex, where she helps build robust systems. With an academic background in Computer Science, Electrical Engineering, and Embedded Systems, she bridges the hardware-software gap. Her core focus is the Yocto Project, guiding companies... Read More →
Friday October 9, 2026 15:40 - 16:20 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any

16:30 CEST

BoF: The Yocto Project and OpenEmbedded - Josef Holzmayr, Mender.io & The Yocto Project & Philip Balister, OpenSDR
Friday October 9, 2026 16:30 - 17:10 CEST
This BoF provides an open forum for the Embedded Linux community to ask questions and discuss issues with the Yocto Project and OpenEmbedded community.

We open with a Yocto Project summary and OpenEmbedded State of the Union.

All users, contributors and maintainers as well as curious minds are invited to bring their thoughts and topics.
Speakers
avatar for Josef Holzmayr

Josef Holzmayr

Developer Enablement Expert & Community Manager, Mender.io & The Yocto Project
Josef has been active for more than 20 years as a "Complete"-Stack developer by now. He's done everything from debugging hardware over application development to web front ends.

A passion for showing, telling, and teaching people in both entertaining and engaging ways led Josef... Read More →
avatar for Philip Balister

Philip Balister

Minister of Progress, OpenSDR
I have a bio
Friday October 9, 2026 16:30 - 17:10 CEST
South Hall 3 B (Floor 3)
  Embedded Linux Conference
  • Audience Experience Level Any
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.