Schedule
- List
- Calendar
<p>Digital Public Infrastructure is needed for resilient societies in Europe, but not just there: All over the world, government and civil society offer digital services to their constituencies. And increasingly, they have become aware of the risks that come with using infrastructure owned by a few large companies under a jurisdiction that traditionally was not necessarily ranking their interests very high and these days have become rather unpredictable. The judges and employees of the International Criminal Court are making this very visible, losing their digital life due to being sanctioned.</p> <p>This session shows how the GovStack [1] initiative empowers government and societies by openly specifying building blocks for such services, thus avoiding the dependencies. The presenter has contributed to the cloud building block [2]. Naturally, the specifications also need implementations which can be qualified for the GovMarket [3], with a strong preference for Open Source solutions.</p> <p>The presenter will present the specifications and will also provide insight into the OSS implementation for the cloud building block. He can report on cloud trainings in African countries and work done with GIZ, ITU and UNICC to empower these countries to create modern IT without falling into the dependency trap that European countries by and large have fallen into.</p> <p>[1] https://govstack.global/ [2] https://cloud.govstack.global/ [3] https://govstack.global/our-offerings/govmarket/</p>
<p><b>Digital public products need sustainable vehicles</b></p> <p>https://www.publiccode.net/public-product-organizations</p> <p>For almost 10 years, the Foundation for Public Code has been working with public administrations and their partners to better develop public digital infrastructure together. Through many collaborations between cities., states, and other public institutions, we have come to realize that all projects that hope to become sustainable implementations in the context of the public sector would benefit from a well formed nonprofit vehicle that has a strong governance model, financial model, community practice, open license, and continuous integration process. We have been working with multiple members state governments in the European Union, and with several in the European commission, on defining a legal form for a new type of NGO that we call the public product organization. </p> <p>The PPO, a non-profit vehicle built specifically to develop and steward an open digital public asset [like a software product, dataset, content database, or machine learning model] would become the hub for collaborations among a constellation of public and private partners and establish a strong governance model, provide context and support for a community of practice, and maintain access to an array of developers who could take on specific work packages set out in a shared roadmap, or do bespoke implementations for specific local administrations.</p> <p>We believe that building the policy infrastructure to enable the easy creation of vehicles that allow for this type of collaboration will unlock an economy that thrives based on the contribution of a huge network of small software development studios across Europe. By enabling the creation of an NGO subtype that is specifically qualified to serve as a steward of digital assets, we can de-risk institutional engagement with open source options in procurement, and begin to design sustainable funding mechanisms that support a newly flourishing ecosystem of digital public infrastructure.</p> <p>The Foundation for Public Code have served in the process of the creation of products, born from the pioneering work of teams in public administrations and their vendors, who have created some of the most celebrated digital public infrastructure in Europe. In the past, we have called ourselves "codebase doulas", helping products move out of a development cycle funded by a single public institution, which leaves them vulnerable to political change and less capable of engaging with an array of partners at peer administrations. Now we are helping guide projects toward realization as fully collaborative nonprofit stewardship vehicles. Projects like Decidim [https://decidim.org/], X Road [https://x-road.global/], DIIA [https://expo.diia.gov.ua/], and Gov.UK Notify [https://www.notifications.service.gov.uk/]</p>
<p>This roundtable will bring together FOSS product owners and governments to engage in a strategic discussion around two interrelated areas: 1) How to assess the technical maturity using the draft Universal Software Maturity Indicators (v0.1) https://github.com/DPGAlliance/CoP-Maturity-Indicators 20 How to assess institutional readiness of government to adopt, scale, and maintain FOSS projects in the context of Digital Public Infrastructure (DPI) </p> <p>The discussion will explore how these two dimensions: software maturity and institutional readiness can be better aligned to guide investment decisions, promote responsible implementation, and reduce barriers to adoption across countries and sectors.</p> <p>Specifically, this session aims to: - Collect multi-stakeholder feedback on the draft Universal Software Maturity Indicators, including their structure, clarity, and relevance across diverse implementation contexts. - Explore what governance or incentive mechanisms are needed to ensure that such assessments are actually used—for example, in procurement, donor funding, or partnership processes. - Initiate dialogue on how to assess government readiness to adopt and scale FOSS and DPIs, with reference to the existing tools, such as the E-government Development Index, the World Bank's Open Data Readiness Assessment</p> <p>The roundtable will provide space for constructive discussion, exchange of experiences, and co-creation of next steps toward strengthening maturity and scalability of FOSS from both sides, software and government readiness. This session will ultimately build alignment with stakeholders to explore solutions to share challenges regarding maturity indicators.</p>
<p>1 year ago, EU OS put out an architecture for a common Desktop Linux for the public sector. Since then, EU OS had many closed-room conversations with public servants from several member states and with various open source communities. EU OS also published a how-to for a DIY Proof-of-Concept (PoC). This talk explains briefly the vision and PoC of EU OS, gives a summary of the feedback received so far and formulates the public sector expectations on the underlying Linux distribution.</p>
<p>Across Europe, institutions are seeking credible, sovereign, open alternatives to proprietary cloud platforms. France’s public digital agency, DINUM, took a bold step in that direction by developing La Suite, a fully open-source service stack. What is unique is not only the openness of the code, but the ambition: that a public administration can edit and publish digital commons for the public good.</p> <p>But building a commons is only the first step. Ensuring long-term adoption, usability, and sustainability requires an ecosystem. This is the role of LaSuite.coop, a SCIC (Société Coopérative d’Intérêt Collectif), which extends La Suite beyond the administration to local governments, universities, associations, cooperatives, and civil society. As a democratic, multi-stakeholder cooperative, LaSuite.coop enables users not just to access the tools, but to co-govern them — reclaiming strategic control over their digital environment.</p> <p>LaSuite.coop brings together several open-source service providers — Open Source Politics, Yaal, lebureau.coop, Galae— who mutualise development, DevOps, hosting, support, UX, and community engagement. This model funds open-source development sustainably without enclosure, venture capital, or extractive business models.</p> <p>This talk explores how La Suite and LaSuite.coop illustrate a public–private–commons partnership model:</p> <p>a public entity creating and guaranteeing the commons,</p> <p>a cooperative ecosystem maintaining and scaling it,</p> <p>a community steering its evolution,</p> <p>and a sustainable business model aligned with the public good.</p> <p>We believe this hybrid model offers a concrete blueprint for future European digital commons.</p>
<p>In late 2023, DINUM (the French Interministerial Digital Directorate) set out to answer a simple question: How do you turn promising national open-source products into shared European products? Two years later, after 2 consortium projects, cross-border hackathons, and several experiments with EU funding mechanisms, we have accumulated a set of practical insights forged through coordination with other EU partners</p> <p>This talk offers an experience-based walkthrough of what worked, what didn’t, and what we wish we had known earlier. Attendees will leave with concrete takeaways for initiating or strengthening cross-border open-source collaborations within public administrations. We hope to invite partners like Zendis or the Lisbon Council to bring their perspective to these cooperations.</p> <p><strong>1. Why we started</strong></p> <p>For some of DINUM products communities grew rapidly inside France, but we wanted to test whether it could become part of Europe’s shared digital infrastructure (Eurostack). Our goal was not to “export” code, but to evaluate:</p> <ul> <li>how to co-develop open-source modules with other Member States,</li> <li>how to make reuse realistic across different administrative cultures</li> <li>and how to try to pool efforts and resources and leverage EU funding to support sustainability rather than siloted prototypes.</li> </ul> <p><strong>2. What we tried (and what we learned)</strong></p> <p>This objective can be accomplished through the establishment of a European strategy for the funding and development of open source products led by member states</p> <ul> <li>Seek out other enthusiastic European partners capable of co-developing or utilizing open source digital products to increase the number of active users in the EU</li> <li>Pinpoint the most appropriate European funds for these topics to pool and leverage national investments</li> <li>Submit applications for relevant project calls with suitable partners</li> <li>Promote awareness within member states, particularly among product/project managers, about the opportunities to work with open source with European partners.</li> </ul> <p><strong>Use case 1 : The 100Days Challenge: iterative hackathons, real code</strong> <strong>Use case 2 : GovTech4All: 16 partners, 3 pilots, 3 sustainability challenges</strong></p> <p>We also see this talk as an opportunity to inform and connect with European partners across various administrations to encourage cooperation and lay the groundwork for future projects</p>
<p>While digital sovereignty is increasingly prompted on European and National levels, the urgency and risks implied have yet to reach the regional and local levels of government. Building robust public digital infrastructure and services on open source foundations have potential both in addressing risks while also providing a substantial economic up-side considering how public digital services are mirrored across regional and local borders. This talk shares insights from a cross-country, multiple-case study investigating how collaboration, sharing, and reuse among local governments are actively forging sovereignty from the ground up.</p> <p>Drawing on detailed examples—including democratic engagement platforms, public desktop solutions, open data infrastructure, parliamentary transparency tools, and national public transport systems —the session highlights governance models and practical mechanisms enabling local actors to translate policy ambitions into operational, interoperable, and sovereign public digital infrastructure. By foregrounding how municipal IT teams partner with foundations, non-profits, and each other, the presentation illustrates how public digital infrastructure that can be adapted and reused across borders, tailored to local needs yet scalable for European cooperation.</p> <p>Attendees will gain concrete recommendations for institutionalising open source in public service delivery, developing community capacity, and ensuring public values are embedded in digital infrastructure. The session advocates for bottom-up, collaborative approaches, demonstrating that digital sovereignty is not merely a national top-down project. Attendees, including policymakers, practitioners, and technologists eager to operationalise digital sovereignty at local and regional levels, will benefit from actionable narratives and strategies grounded in real, European experience.</p> <p>The full report with all case studies are openly available via OSOR: https://interoperable-europe.ec.europa.eu/collection/open-source-observatory-osor/news/multiple-case-study-public-sector-open-source</p>
<p>Sovereign software in the cloud? Many projects are taking care of that. FOSS services running on servers? Lots of excellent choice.<br /> But what about your office, the place where you work? Is your local network just invisible infrastructure at the mercy of whatever vendor you picked?</p> <p>This talk will show you how we built and operate the "Flurfunk" network prototype at BSI (German Federal Office for Information Security). Flurfunk is a Proof of Concept wireless and wired network with a sizable number of human users with purely FOSS infrastructure: Routers, Switches, WiFi Access Points and a Certificate Authority, all of them running FOSS firmware, operating systems and services. This whole infrastructure is centrally orchestrated and requires almost zero maintenance.</p> <p>The magic lies in OpenWrt https://openwrt.org/ (for the network components) and Smallstep step-ca https://smallstep.com/open-source/ combined with OpenSSL https://www.openssl.org/ (for the CA), as well as Debian https://www.debian.org/ , Das U-Boot https://u-boot.org/ and coreboot https://www.coreboot.org/ (behind the scenes).</p> <p>Yes, the network supports the latest and greatest in authentication standards (WPA3 Enterprise), but it also offers user-friendly setup for users and admins. This includes automated certificate rollout to all centrally managed laptops and smartphones for WLAN access via WPA3 Enterprise. Yes, Flurfunk aims to be CRA compliant ahead of time.</p> <p>Yes, all components are current off-the-shelf hardware and yes, installing OpenWrt on them is easy (no tools needed).</p> <p>No, Flurfunk is not a production network nor does it come with support, it's a PoC.</p> <p>Do you want to stand on the shoulders of giants as we do, and replicate the setup for your own network? Of course the configuration files for all components as well as links to the relevant firmware/OS images will be provided for download. Where applicable, existing tutorials/wikis have been improved.</p>
<p>Building Mzansi Xchange: Open Source Approaches to Secure Data Exchange in South Africa's Digital Public Infrastructure</p> <p>South Africa’s digital future depends on robust, scalable, and inclusive Digital Public Infrastructure (DPI). My talk introduces the core components and foundational principles of DPI, highlighting the latest directions in the South African Digital Transformation Roadmap, as unveiled by The Presidency. We’ll discuss why governments globally—including South Africa—are embracing Open Source solutions to reduce vendor lock-in, foster innovation, and ensure transparency, while exploring local challenges around adoption, interoperability, security, and compliance with regulations like POPIA.</p> <p>The heart of my session is a real-world use case: building Mzansi Xchange, a secure, national data exchange platform co-designed with government and built primarily on Open Source software. We’ll unpack the architectural choices, implementation milestones, and hands-on lessons the project team learned, from aligning with the National Data and Cloud Policy to establishing federated data governance and deploying secure Open Source software.</p>
<p>The openCode Badge Programme promotes quality, security, and reusability of open source software in public administration. Part of the openCode platform run by the German Centre for Digital Sovereignty (ZenDiS), it automatically evaluates repositories against defined criteria and awards badges in areas such as security and maintenance, which are visible in the openCode catalogue. The Badge Programme is an integral part of ZenDiS and the German Federal Office for Information Security’s (BSI) strategy to strengthen the security of software supply chains in public administration. By creating clear incentives to meet standards and supporting informed decisions when reusing software, the programme shows how open source development and use can be fostered in the public sector.</p>
<p>In 2024 France and Germany signed an agreement to cooperate on building an open source digital workspace. As part of this collaboration, DINUM (France), ZenDiS (Germany) and MinBZK collaborated on building a modern Open Source Document editing product (Docs) on top of modern </p> <p>As part of this, they collaborated with the existing open source libraries: BlockNote and Yjs.</p> <p>This talk will share our joint experience in financing core features such as exports, comments, edit attribution, and suggestions. We'll explain: - What the collaboration looked like in practice - How funding core libraries can help you build your own Sovereign solutions efficiently - Challenges and differences between funding libraries and Application-Level solutions - Broader ecosystem benefits</p>
<p>As European public sector organizations pursue digital sovereignty, the technical migration from proprietary to open source solutions is only half the battle. Technology is often the easy part. The real challenge lies in transforming not just infrastructure, but mindsets, workflows, and institutional culture. True independence requires successfully leading organizational change - preparing teams, managing resistance, and building confidence in open source alternatives.</p> <p>This talk shares proven change management strategies from leading IT transformations and guiding public sector clients through transitions from Jira to OpenProject, demonstrating how to build sustainable and resilient digital ecosystems that serve citizens rather than vendors. You'll learn how to:</p> <ul> <li>Co-create change through proven leadership best practices</li> <li>Create ownership for the open source solutions within public sector</li> <li>Build the business case and frame the open source narrative that resonates with public sector stakeholders and decision-makers</li> <li>Drive the mindset shift to FOSS</li> <li>Identify your use cases and foster transition to open source products</li> <li>Build internal champions who drive adoption across departments</li> </ul> <p>Drawing from real-world public sector experiences and Rosanna Sibora's experience in driving IT transformations, this session reveals the human factors that make or break digital sovereignty initiatives. Whether you're planning your first migration or looking to improve your change management approach, you'll leave with actionable frameworks for leading successful transitions to independent and interoperable digital workspaces.</p>
<p>Many public bodies, NGOs and small providers in Europe want to move away from US‑dominated cloud platforms, but struggle to build and run their own stack with small teams and limited capacity. At the same time, the threat landscape makes it urgent to build more resilient infrastructure for critical public services.</p> <p>TAPPaaS is a trusted, automated and privacy‑friendly Platform as a Service, built only with Free and Open‑Source Software, that makes it easier for small teams to run sovereign workspaces and public digital services. In this talk, we present the TAPPaaS blueprint and show how we combine existing FOSS building blocks into a sovereign, standards‑based stack that can be operated by SMBs, NGOs and local governments with limited resources. We highlight how automation and common patterns reduce operational effort, improve security and resilience, and avoid lock‑in to proprietary hyperscalers.</p> <p>TAPPaaS is work in progress, so we share what already works well in pilots and prototypes, where we still hit hard problems, and which trade‑offs we made along the way. Attendees will leave with a concrete blueprint for running a sovereign PaaS with a small team. TAPPaaS comes with pre selected modules and integrations that can reuse in their own public or civic infrastructure, and clear ways to get involved as consumer, operators or contributors in shaping TAPPaaS as a building block of Europe’s public digital infrastructure.</p>
<p>Attacks on the software supply chain are becoming increasingly common. Attackers are trying to access critical systems via the software supply chain. Such attacks can have serious consequences, particularly in the public sector. In our talk, we will demonstrate how DevGuard, as an open-source vulnerability management project, helps ZenDiS by finding and closing vulnerabilities before the release of the software and deliver a toolchain for the hardening of base images. DevGuard itself is an OWASP Incubator Project which is available via the openCode-DevGuard instance or as 100% open-source software on GitHub for community use.</p>
<p>In France, thanks to the deployment of 37 million Linky smart meters, a vibrant open-source community has emerged, developing smarter, greener, and more open energy-management systems powered by Linky’s locally emitted data. Enedis, the main French DSO, now works alongside this community to accelerate the use of its meters’ data for the energy transition. Open hardware, open software, open data—all of this is key to meeting the challenges !</p>
<p>Presenting the Energy System Description Language (ESDL) open-source community, which is currently being built around the open standard ESDL and the ecosystem of open-source tools that work with ESDL. There is a dozen tools that are being used by several companies and initiatives to design energy hubs, heat networks and develop scenario's to best integrate new battery, hydrogen, solar and wind assets within grid with limited available capacity.</p>
<p><a href="https://github.com/Akkudoktor-EOS/EOS">Akkudoktor-EOS</a> (Energy Optimization System) is an open-source platform designed to generate highly optimized energy management plans for home energy management systems. Initially developed by Dr. Andreas Schmitz (<a href="https://www.youtube.com/@Akkudoktor">“Akkudoktor”</a>), EOS has been publicly available for just over a year and has already built a community of users who integrate it into their home automation environments.</p> <p>At its core, EOS is a self-hosted server that calculates optimal schedules for batteries, electric vehicles, and household devices. These plans are derived from user configuration, real measurement data, and automatically retrieved or self-generated forecasts. EOS focuses on long-term optimization over a day or longer. The home automation system manages short-term control. Together, they combine strategic planning with real-time execution, delivering the best of both worlds in home energy management.</p> <p>Common applications include optimizing consumption under dynamic electricity tariffs, ensuring cost-efficient EV charging, shifting flexible loads to cheaper periods, and connecting seamlessly with systems such as Home Assistant or NodeRED.</p> <p>EOS stands out through its genetic algorithm, enabling optimization of any behavior that can be simulated—without the limitations of linear or convex models. Non-linear battery degradation, grid-stress signals, comfort models, or heat pumps with non-linear COP fields can be used directly, without artificial simplification. This makes EOS highly modular and flexible, allowing new components or physical models to be added and immediately included in the optimization.</p>
<p>Optimally planning the energy flows across multiple sites becomes more important, e.g. for orchestrating the aggregated flows due to grid congestion, or for implementing energy sharing. This approach can break bottlenecks and increase savings - as such, energy communities are an important topic for the European Commission.</p> <p>In this talk, we present our ongoing work towards a Community Energy Management System (CEMS) with FlexMeasures. We discuss our architectural approach: optimizing the flows for each sites by themselves and then adding an orchestration layer on top. This approach is being tested in a project with TNO in the Netherlands. The goal is to manage neighbourhoods as well as commercial sites optimally.</p> <p>In addition, we want to discuss how scalable any CEMS system can be, as many circumstances and conditions often vary, per site and per energy community. We chose our CEMS architecture approach for this reason, but versatility has been a design principle for FlexMeasures since the beginning. In this talk, we will showcase a complete example script of a setup orchestrating a few homes. This script is written with the FlexMeasures client and is also open source. FlexMeasures being 100% scriptable is a design choice that lets many developers built just what they need in energy intelligence.</p> <p>This is also an opportunity to visit some fundamental improvements we have made in the last year in the documentation of FlexMeasures and its flexibility options - both for developers and users.</p>
<p>Solar energy is predicted to be the largest form of power generation globally by 2040 and having accurate forecasts is critical to balancing the grid. Unlike fossil fuels, renewable energy resources are unpredictable in terms of power generation from one hour to the next. In order to balance the grid, operators need a close estimate of when and how much solar and wind power will be generated on a given day. </p> <p>Open Climate Fix (an open source AI company) developed and deployed PVNet, a large ML model which forecasts solar generation for the next 36 hours. The forecasts are used by the UK electricity grid operator for real-time decision making and for reserve planning. These forecasts can save 300,000 tonnes of CO₂ and £30 million per year. </p> <p>But how do we have a global impact? We decided to build a lightweight solar forecast that works anywhere in the world, which we showcased last year at FOSDEM. Combining this with every country's solar capacity, we are able to produce a solar forecast for every country in the world. In this talk, we'll demo our Global Forecast and discuss how this forecast can support grid transition as well as open-source renewable energy projects all over the globe. </p> <p>Open Climate Fix is an open-source not for profit company using machine learning (ML) to respond to the need for accurate renewable energy forecasts. Connecting energy industry practitioners with ML researchers doing cutting-edge energy modelling is our aim, and one way we seek to do this is by making much of our code open-source.</p>
<p>Storing energy reversibly is useful. For clean energy, electrochemical batteries are one of the most attractive options. Most battery technology is proprietary, hard to recycle, and complicated to manufacture. What if that wasn't the case?</p> <p>We will present our collective and individual efforts with the Flow Battery Research Collective (https://fbrc.dev/) to build open-source batteries for stationary storage applications. This includes our flow battery work, such as efforts to build a larger-format cell with simple manufacturing techniques like laser cutting and FDM printing, as well as our different experiments with flow battery electrolytes based on zinc, iodine, iron, and manganese.</p> <p>We will also cover our individual efforts to build conventional, non-flow flooded batteries based on water and the above elements (including this work by the speaker Daniel: https://chemisting.com/2025/05/23/a-low-cost-open-source-cu-mn-rechargeable-static-battery/). We will discuss the economic hurdles facing practical implementations of these systems.</p>
<p>As a student in electronics, I was already passionate about renewable energy. Then after many years of open-source software development, I am now finally starting to engage with the Energy community. By attending various events, meeting a whole range of inspiring people, hacking around existing projects and completing a <a href="https://gtucker.io/tags/energy/">blog posts</a> series on Digital Substations and <a href="https://lf-energy.atlassian.net/wiki/spaces/SEAP/overview">SEAPATH</a>, I have made the first steps in this personal journey. It is already a very rewarding one and I believe many other developers would relate to it. Open source culture and renewable energy both contribute to a more sustainable world.</p> <p>This lightning talk tells the story of how I became an active contributor in the Energy community.</p>
<p>Standards like OCPP and ISO 15118 describe how EV charging should work, yet real-world deployments often behave differently. This session explains why a full stack of tools, testing methods, and feedback loops is essential for true interoperability, and how the open-source EVerest ecosystem has become a practical integration point for these technologies. We will show how Software-in-the-Loop testing, Golden SUT validation, conformance tooling, virtual charger parks, testing-hackathons, and cloud-based remote debugging work together to close the gap between specification and reality. The talk demonstrates how open-source reference implementations can strengthen standards, improve certification tools, and reduce interoperability pain across the EV charging industry.</p>
<p>OpenLEADR-rs is an opinionated, open-source Rust implementation of the OpenADR 3.0 protocol, which is already being used for real-world pilots.</p> <p>In this joint presentation, Stijn van Houwelingen (ElaadNL) and Maximilian Pohl (Tweede Golf) will kick things off with a quick primer on demand response: what it is, and why it’s essential to accelerate the energy transition. From there, they’ll dive into some design decisions behind OpenLEADR-rs.</p> <p>Among the decisions explored: why Rust was a good choice for the protocol and why OpenLEADR-rs did not implement real-time updates yet.</p> <p>Next, the focus shifts to adoption, specifically focusing on the use case of Grid-Aware Charging in the Netherlands.</p> <p>The talk then wraps up with a look at what’s next for OpenLEADR-rs, including our effort to implement OpenADR version 3.1, how developers and organizations can get involved, and what early adopters can expect in terms of support and collaboration.</p>
<p>See how the open-source Transformer Thermal Model helps safely push the limits of the grid. This to lighten the net congestion problem we have in the Netherlands.<br /> We demonstrate how simulating hotspot and oil temperatures reveals new acceptable load limits. By sharing this model openly, we are able to work with other TSOs and DSOs to benefit and strengthen sector-wide collaboration! Within this talk we want to show you our journey in going open source and how this strengtens our effort in lighten the net congestion problem with pushing the limits of the grid!</p> <p>The model: https://github.com/alliander-opensource/transformer-thermal-model Github Discussions: https://github.com/alliander-opensource/transformer-thermal-model/discussions</p>
<p>The lack of global access to electricity, and the push towards renewable energies and electrification requires us to develop our grids. However, globally, data of the power grids are outdated, incomplete or closed off, which makes it challenging for us to effectively plan and research grid developments. </p> <p>Therefore, we created an initiative called MapYourGrid where anyone can map, contribute and own the data of our grids. We created a fully open and free toolchain, combining developed and existing free tools and software, in order to empower people around the world to be able to map their grid. Instead of reinventing the wheel, we collaborated with existing communities and incorporated existing open-source tools, as this leads to higher quality workflows and higher community impact.</p> <p>By mapping the world’s power grids, anyone can learn and understand the backbone of what lets us turn our lights on, as well as owning this valuable data. This can then be used by researchers, local communities and authorities, NGO’s and many more, to help solve pressing issues our world faces. MapYourGrid: https://mapyourgrid.org/</p>
<p>The Smart Beach Net in The Hague is a privately owned network by an energy cooperation consisting of The City of The Hague and multiple beach pavilions. As Stedin, the regional network operator (DSO) is facing net congestion challenges, the cooperation is offering it’s flexibility of both shared and individual EV charging, batteries, heating and solar assets, to help resolving congestion. </p> <p>The challenge is to design and implement a multi objective and multi layer energy management system which can optimise both on dynamic network capacity and dynamic energy tariffs. Moreover optimisation should optimise both on household/individual level with individual assets, as well as cooperation level with shared assets.</p> <p>Continuing the learnings from the Amsterdam Sporenburg pilot we presented last year, we will share the latest results from Amsterdam and demonstrate the further developments in The Hague, integrating with day ahead and intraday congestion markets, introducing advanced forecasting models for consumption as well as forecasting EPEX Spot prices, and automated controlling of assets, both on individual as well as cooperation level.</p> <p>The Hague pilot: https://openremote.io/solution/slim-strandnet-scheveningen-ems-stedin/ Build your open source EMS, get started: https://docs.openremote.io/docs/user-guide/domains/create-your-energy-management-system</p>
<p>The electricity grid faces increasing complexity as solar panels, wind turbines, EVs, and heat pumps reshape both supply and demand patterns. Grid congestion has become one of the most pressing challenges for utilities navigating this transition. Accurate short-term load forecasting is essential—not only for congestion management, but also for transport forecasts, EV charging capacity estimation, and grid loss prediction.</p> <p>OpenSTEF is an open-source Python package that provides accurate short-term forecasting for all of these use cases. As demand grows beyond congestion management, we have been working with the community on a major redesign to make it more flexible and easier to adopt across different contexts and user types—from researchers and small-scale teams to large-scale deployments within complex enterprise landscapes.</p> <p>In this presentation, we will share the journey and architecture of the OpenSTEF V4 redesign, how we did it, the lessons we learned, and a sneak peek of the features of the current alpha release.</p> <p>To learn more about OpenSTEF, visit: https://www.lfenergy.org/projects/openstef/</p>
<p>In this talk, we introduce <strong>µSolarVerter</strong>, our open-hardware micro-inverter designed to support decentralized solar production while giving users full control over the information their system generates. The project grew from a simple question: <em>how do we make small-scale solar both understandable and adaptable, without locking people into a black box</em>?</p> <p>Our presentation will be split into three parts: </p> <h3>1. OwnTech Recap — What we have done so far</h3> <p>We'll recap who we are and how we have been working to provide people with the tools to act on the energy transition. We'll recap our previous advancements in terms of repairability, sovererignty and cooperation. </p> <h3>2. Why an open-source micro-solar inverter?</h3> <p>We’ll explain what a micro-solar inverter actually is and why it is important as a tool for impact on the field. We'll walk you through the specifications of the open uSolarVerter. And the challenges we faced while designing it. </p> <h3>3. Invitation — Join the movement</h3> <p>We will present you the repository of our project and the remaining challenges in terms of software and hardware related to the uSolarVerter.</p> <h3>More information</h3> <p>Project's repository: https://github.com/owntech-foundation/micro-inverter</p> <p>OwnTech's Forum: https://forum.owntech.org/</p> <p>OwnTech's documentation center: https://docs.owntech.org/latest/</p>
<p>This talk explores the evolution of VeraGrid (formerly GridCal), a power-system simulation tool, over the past decade; From its humble and simple beginnings to a fully integrated software capable of performing all power-system calculations, ranging from electromagnetic transient (EMT) simulations to multi-year investment planning.</p> <p>Throughout its development, the software has undergone seven major refactors to accommodate new functionalities. As the system evolved, the effort required for each refactor decreased, highlighting an organic, evolutionary structure shaped by practical needs and use cases. </p> <p>I will discuss the challenges and insights gained during this evolution, focusing on how we integrated static network models, time-series data, transient analysis, and long-term planning. Additionally, I will cover how we overcame the challenges of multi-binary pitfalls and ensured seamless interaction between these diverse functionalities.</p> <p>This session will provide an overview of how these continuous improvements have produced an open-source tool that bridges the gap between research, operational applications, and long-term infrastructure planning. See: https://github.com/SanPen/VeraGrid</p>
<p><a href="https://pypsa.org/"><strong>PyPSA</strong></a> is an open-source Python framework for optimising and simulating modern power and energy systems, designed to scale well with large networks and long time series. It is made for researchers, planners and utilities with basic coding aptitude who need a fast, easy-to-use and transparent tool for power and energy system analysis.</p> <p>The first public version was released in 2016 and has since gained many users and contributors from around the world, becoming one of the most <a href="https://docs.pypsa.org/latest/home/users/">widely used</a> energy system modeling tools. In October 2025, <a href="https://docs.pypsa.org/latest/user-guide/v1-guide/">version 1.0</a> was released, which now enables modeling under uncertainty with a two-stage stochastic programming framework. This allows for more realistic decision making by accounting for multiple possible futures with uncertain renewable generation, demand, and prices, rather than optimizing for a single expected scenario.</p> <p>The talk will give a general overview of PyPSA and showcase the new stochastic programming functionality by solving an energy system planning problem under uncertainty. It is suitable for both experienced PyPSA users and newcomers to energy system modeling.</p>
<p>There is a vast ecosystem of open-source energy system modelling (ESM) tools. Hundreds of tools have been published to date, mostly originating from research organisations. However, few have gained enough traction to be considered by practitioners for infrastructure planning. If we are to make open-source the norm in decision making, we need to ensure it is possible to explore and compare the range of tools available. </p> <p>This has not been possible. Until now.</p> <p>In this talk, we introduce the <a href="https://openmod-tracker.org/">Open Energy Modelling Tool Tracker (openmod-tracker)</a>, a platform that aggregates data on open ESM tool source code repositories and their development communities, created by <a href="https://openenergytransition.org/">Open Energy Transition</a> with support from <a href="https://www.breakthroughenergy.org/">Breakthrough Energy GRIDS</a>. We will share insights drawn from repository activity and user engagement, highlighting which tools demonstrate the strongest momentum and why these should be the focus of collaborative development efforts.</p> <p>Complementing this, we present our <a href="https://github.com/open-energy-transition/openmod-features">open-source tool feature platform</a>, designed to help practitioners select tools and developers identify feature gaps. Our goal is to expand the platform’s coverage and refine its taxonomy with input from the wider community. We see FOSDEM as an opportunity to kick-start this collaboration and invite you to join us in shaping the future of open-source energy modelling.</p>
<p>Energy systems are undergoing rapid transformation as sector coupling intensifies and variable renewable generation grows, creating a pressing need for flexible and transparent modeling tools. While many open-source frameworks offer rich features, extending them with new mathematical models typically requires writing custom software—a barrier for many analysts.</p> <p>We present GEMS (Generic Energy Systems Modelling Scheme), a high-level modelling language designed to make multi-energy system adequacy and planning studies both more expressive and more accessible. GEMS brings model definitions out of the codebase and into simple YAML configuration files, where users describe variables, parameters, and constraints using natural mathematical expressions. These expressions are parsed into abstract syntax trees and automatically expanded—across time structures, scenario trees, and study data—into a complete optimization problem. This model-agnostic architecture enables rapid experimentation, lowers development and maintenance costs, and promotes true reusability: adding a new component requires no code, only data. The language is already supported in Antares Simulator and in the Python package GemsPy.</p> <p>We present how GEMS could paves the way for interoperability between modelling tools, offering a neutral and extensible modeling layer that can be shared across the open-source energy modeling ecosystem.</p>
<p>When choosing observability platforms, we rarely consider their carbon footprint. Yet every metric collected, every log retained, and every dashboard query consumes energy and at scale, the environmental impact becomes significant. This talk explores the principles and real-world advantages of green observability. We’ll examine how open source observability ecosystems are beginning to address carbon awareness and promote more efficient data practices. Through examples, I’ll show how teams can reduce ingestion volume, lower storage requirements, improve performance and enhance reliability through green coding practices. By linking observability design choices to the Green Software Foundation’s principles, attendees will see how green observability supports a broader sustainable software strategy. They’ll also learn why sustainability in observability isn’t just an organizational obligation, it's a responsibility each engineer carries in the way we collect, store, and interpret data.</p>
<p>E-Paper technology is often highlighted for its reflective readability and near-zero static power consumption, making it an attractive choice in a world where digital displays are becoming increasingly ubiquitous. From public transport signage to smart meters and IoT devices, the number of deployed displays continues to grow—and with it, the cumulative energy they consume. A sustainable future does not require removing or avoiding displays, but rather designing and driving them intelligently.</p> <p>If you work with E-Paper displays, you will inevitably encounter a situation where the manufacturer provides only partially documented driver code—or, in many cases, a binary blob packed with initialization parameters and so-called waveform lookup tables (LUTs). Experimenting with these values often leads to unwanted side effects such as ghosting, low contrast, long-term image retention, or even permanently damaged panels. A solid understanding of the physics behind E-Paper driving is essential for safely modifying LUTs and optimizing them for lower active energy usage through improved waveform design and voltage-generation strategies. In this talk, we break down the electrical and algorithmic principles that govern E-Paper operation and show how waveform LUTs influence update speed, ghosting behavior, image quality, and—critically—energy consumption.</p> <p>Key Takeaways</p> <ul> <li>Understand why display energy matters in a world with rapidly increasing numbers of screens—and how E-Paper fits into a sustainable future.</li> <li>Learn the physical and algorithmic principles behind E-Paper waveform driving and how LUTs impact image quality, speed, ghosting, and energy use.</li> </ul> <p>Links: https://github.com/Blueloop/E-Paper-driving-Waveforms https://matrix.to/#/!xlOgXcWcKOYkMyPsIg:matrix.org?via=matrix.org https://lcd-mikroelektronik.de/news/e-paper-waveforms/ https://lcd-mikroelektronik.de/kategorie/e-paper/</p>
<p>Welcome to the Geospatial devroom</p>
<p>PyQGIS. A not so well guarded secret in the most popular open-source geospatial system. You struggle doing a thing, and then open this one panel... And turns out, every single thing that you can click on, is available for programmatic calls. Load data, style it and process, prepare layouts for exporting, add panels and interactive modes, even add games using the GIS user interface. Everything.</p> <p>Geospatial is hard. Software is hard. Making a new software for a one-time or an obscure process would be prohibitively complex. So no wonder many people turn towards QGIS for its extensive plugin capabilities. But what if we need to make something for the mobile?</p> <p>This talk is about Every Door plugins. Every Door is an OpenStreetMap editor for going outside and collecting data. It's been custom designed for the OSM schema. But turns out, we've got thousands other services and processes on top of OSM, and many people would like "just one more button" or a panel. Let's see what has changed in Every Door over the winter that enables you to do so.</p>
<p>The MapLibre community is currently in the midst of developing the MapLibre Tile Format, a modern, open, and fully community-governed successor to the ubiquitous Mapbox Vector Tile (MVT) format. While MVT has served the mapping ecosystem well for over a decade, it also carries historical constraints that limit interoperability, formal specification quality, extensibility, and independence from proprietary platforms. As MapLibre continues to grow as the central open-source foundation for web-based map rendering, it has become increasingly clear that a future-proof, openly specified, and collaboratively designed tile format is essential.</p> <p>This talk will offer a look into why we initiated this engineering effort and what gaps the new format aims to close. I will explain the core design principles behind the specification—clarity, strictness where needed, optionality where useful, and full transparency throughout the process. Attendees will gain a technical understanding of how the format works, including its data model, feature encoding strategy, metadata approach, and compatibility considerations for existing infrastructure.</p> <p>Beyond the current specification draft, I will outline the major areas still under active development. These include discussions about schema evolution, advanced geometry representations, compression strategies, and interoperability with raster, elevation, 3D and non-geographic datasets. I will also provide insight into the collaborative workflow between maintainers, researchers, vendors, and the wider open-source community, highlighting where contributions and feedback are particularly welcome.</p> <p>Finally, the talk will cover how the rollout is progressing in practice. This includes early tooling support, reference implementations, testing frameworks, and real-world trials by organizations exploring migration paths away from MVT. The session will present an honest, up-to-date snapshot of the project’s status and a forward-looking roadmap for the next stages of development, helping the community understand both what is ready today and what is still on the horizon.</p>
<p>Boost.Geometry is a C++ library defining concepts, primitives and algorithms for solving geometry problems. It contains a dimension-agnostic, coordinate-system-agnostic and scalable kernel, on top of which algorithms are built: area, distance, convex hull, intersection, within, simplify, transform etc.</p> <p>The library contains instantiable geometry classes, but library users can also use their own legacy geometry types. It also contains spatial index allowing to perform spatial and knn queries on a collection of geometries.</p> <p>In this talk we will introduce Boost.Geometry focusing on mapping and GIS. Boost.Geometry is the engine behind MySQL’s spatial query capabilities. The presentation will highlight recent developments in the library and conclude with a roadmap of the future work in Boost.Geometry.</p>
<p><a href="https://www.openstreetmap.org/">OpenStreetMap</a> community often seek for tooling to organize topic-focused contribution projects and monitoring is crucial to set appropriate encouragement in the areas were it's most needed. Dealing with significant amount of daily change files or oversized historical data can be challenging if you want to focus on a given topic among the whole OSM changelog like the needle in the haystack. <a href="https://github.com/osm-fr/podoma">Podoma</a> is a free software intended to do this hard work for you, guiding you through the change log and counting as quick as no one. It provides web interface, useful API and KPI to be at ease with monitoring specific topics worldwide or around your house in OpenStreetMap.</p> <p>This talk will introduce Podoma, its basic functionalities and showcase the build of a monitoring project live from the raw OpenStreetMap data.</p>
<p>This talk presents a FOSS stack for building, rendering, and using OpenStreetMap vector tiles. Ascend Maps ( https://github.com/styluslabs/maps ) is a cross-platform application for interactive maps. It is extremely customizable, with hiking, cycling, and transit views for the base map, user-editable sources, styles, and shaders for custom maps and overlays, and plugins for search, routing, and map sources. </p> <p>tangram-ng ( https://github.com/styluslabs/tangram-ng ) extends the Tangram ES map engine originally created by Mapzen, adding support for 3D terrain, embedded SVG, and additional raster formats, along with substantial performance and stability improvements.</p> <p>geodesk-tiles ( https://github.com/styluslabs/geodesk-tiles ) builds vector tiles on demand from a GeoDesk library, making it possible to start serving tiles for the whole world instantly.</p>
<p>For a year <a href="https://citybik.es">Citybikes</a> has been publishing bike share time-series <a href="https://data.citybik.es">data</a>, as monthly parket files.</p> <p>Join me in this demo session on which we will explore bike share data, both official trip data and citybikes data, using duckdb to generate usage heatmaps, all around the world!</p>
<p>Writing scripts that involve spatial data often gets messy fast, because of the number of formats, plethora of tools, and volume of data.</p> <p>Jupyter and similar notebook environments help with some of these problems, but can tend to favor one language at a time, and require a GUI or other environment for execution rather than a single "script". </p> <p>In this talk we introduce a new experimental console-based tool -- samaki -- which provides</p> <ul> <li> <p>a simple text format for combining source code and tools from multiple languages</p> </li> <li> <p>a flow for iteratively generating files in many data formats that are interdependent</p> </li> <li> <p>a mechanism for adding bespoke visualization and other tooling during the coding lifecycle</p> </li> </ul> <p>And we look at examples of using this fast flow for doing things like pulling from OpenStreetMap, manipulating geoJSON, analyzing with DuckDB, leveraging PostGIS and using LLMs judiciously.</p> <p><a href="https://github.com/bduggan/raku-samaki">https://github.com/bduggan/raku-samaki</a></p> <p><a href="https://raku.land/zef:bduggan/App::samaki">https://raku.land/zef:bduggan/App::samaki</a></p>
<p>⚠️ Spoiler Alert ⚠️ One day, you are going to die.</p> <p>You may not get a blue plaque on the side of a building, or a statue, or even a Wikipedia entry. But perhaps you’ll get a memorial bench?</p> <p>We built https://openbenches.org where anyone can add to a collection of open data.</p> <p>We’ll show you why & how we built this collection of >39,000 memorial benches from around the world, how it integrates with OSM, and what we learned along the way.</p>
<p>BIMS is an open-source platform for serving, analysing and sharing biodiversity data, built on top of the Django framework. It started as the Freshwater Biodiversity Information System (FBIS) in South Africa and has since grown into a family of portals across Africa and beyond, supporting water resource managers, conservation agencies and researchers. One of the long-running public instances is <a href="https://freshwaterbiodiversity.org">freshwaterbiodiversity.org</a>. BIMS is a multi-tenant application, so a single deployment can host multiple, independent biodiversity portals on the same codebase.</p>
<p>It started as a simple idea — teaching colleagues how to use OpenStreetMap. A few sessions later, more than a hundred people had learned not just how to map, but why it matters.</p> <p>This talk follows two parallel stories: the trainees who discovered new tools, confidence, and purpose through digital mapping, and the company that found a new way to connect its volunteer days with growth and community impact. </p> <p>Together, they show how learning to map the world can also reshape how we see our own roles, our teams, and our shared capacity to make a difference.</p>
<p>Geospatial analysis and GIS workflows are traditionally tied to heavy desktop applications, steep learning curves, and complex toolchains. JupyterGIS transforms this paradigm by enabling fully interactive, browser-based GIS workflows inside JupyterLab. Researchers, educators, and developers can now visualize, analyze, and edit spatial data collaboratively, leveraging modern web technologies while retaining the power of native geospatial engines.</p> <p>This talk presents how the Project Jupyter, WebAssembly, and GDAL communities collaborated to build a complete, interactive GIS environment for both desktop and browser platforms. JupyterGIS integrates OpenLayers, GDAL compiled to WebAssembly, and Python or non-Python kernels to deliver: - Real-time collaborative editing of GIS datasets, including QGIS formats - Fully client-side geospatial analysis pipelines with raster and vector support - Customizable symbology and interactive visualizations, including graduated, categorized, and multi-band styling - Notebook integration for embedding, documenting, and sharing workflows - Support for cloud-based and local spatial datasets, as well as STAC asset catalogs</p> <p>Technical Highlights: - WebAssembly (WASM): GDAL compiled to WASM enables high-performance spatial operations directly in the browser, without server dependencies. - Collaborative Editing: Built on Jupyter’s collaborative document model (PyCRDT & Y.js), multiple users can edit layers simultaneously with conflict-free synchronization. - Extensible Architecture: Modular command system allows custom tools, plugins, and integration with Python or other kernels. - Integration with Modern Stacks: Seamless support for xarray, Pangeo ecosystem, and upcoming features like story maps and R kernel integration.</p> <p>Demos & Use Cases: - Interactive vector and raster layer editing with live symbology updates - Performing geospatial analysis entirely in-browser using GDAL WASM pipelines - Collaborative multi-user editing sessions with conflict-free layer management - Story maps and visualization dashboards for environmental, policy, and STEM applications</p> <p>Target Audience: Researchers, educators, geospatial developers, students, and open source enthusiasts interested in GIS, WebAssembly, or interactive computing.</p>
<p>In an era of unprecedented availability of Earth Observation (EO) data, the Copernicus Data Space Ecosystem (CDSE)(https://dataspace.copernicus.eu/) plays a key role in bridging the gap between data accessibility and actionable insights. Despite the availability of freely accessible satellite data, the widespread adoption of EO applications remains limited due to challenges in extracting meaningful information. Many EO-based projects struggle with non-repeatable, non-reusable workflows, mainly due to the lack of standardized, scalable solutions. CDSE tackles these barriers by adopting common standards and patterns, most notably through openEO(https://dataspace.copernicus.eu/analyse/openeo). This open-source solution is a community-driven standard that simplifies access to, processing, and analysis of remote sensing data by offering a unified platform. It empowers developers, researchers, and data scientists to use cloud-based resources and distributed computing environments to tackle complex geospatial challenges. Adhering to the FAIR principles (Findable, Accessible, Interoperable, and Reusable), it supports the global sharing and reuse of algorithms, enhancing collaboration and scalability. <br /> Furthermore, by promoting the development of reusable, scalable, and shareable workflows, openEO enhances the efficiency and reproducibility of the EO workflow. Its feature-rich capabilities have also been used and validated in large-scale operational projects such as ESA WorldCereal and the JRC Copernicus Global Land Cover and Tropical Forestry Mapping and Monitoring Service (LCFM), which relies on its robust and reliable infrastructure. Through this session, we aim to present users with openEO and its capabilities. We will highlight how users can seamlessly convert algorithms into a process graph, thereby creating reusable services.</p>
<p>Frontline health managers are on the sharp end of climate change, yet rarely have practical ways to use local climate signals in routine planning. Climate × Health Pulse (Climate Pulse, pulse.datakind.org) is an early-stage open prototype that fuses localized climate and health datasets into sub-county geospatial views and decision cues for county health teams.</p> <p>In this talk and demo we’ll show an end-to-end, FOSS-first workflow: ingesting heterogeneous climate (e.g., temperature, rainfall, drought indices) and health indicators (facility reports, disease surveillance, vulnerability proxies), harmonizing them with open standards, and publishing actionable map layers for operational use. The initial pilot focuses on Kajiado County, Kenya, where heat stress, water scarcity, and shifting vector-borne disease risk create urgent planning needs.</p> <p>We’ll highlight what works, what’s hard, and what’s next: data interoperability, scalable analytics, offline-friendly UX for low-bandwidth contexts, and governance for sustainable local ownership. We’re actively seeking collaborators to co-develop Climate Pulse—especially on geospatial data layers, standards alignment, and field testing—so that open climate intelligence can meaningfully support health systems under pressure.</p>
<p>In this session, we'll create an analytical application from the ground up, covering the entire workflow: data collection, processing, and visualization. It will use Leaflet, ClickHouse, and a bunch of shell scripts. The result is published at https://adsb.exposed/, and I will uncover how it's done.</p>
<p>Caves surveying is a pretty obscure niche in mapping, with its own set of software. There have been great FLOSS tools since the 1980s, and in the last few years cavers realised that they could use 'normal GIS' too, so a slow convergence is underway. This talk will give a brisk tour of the FLOSS tools we use, and also talk about the complicated problem of managing datasets spanning 40, 50 or even 100 years, with changing equipment, formats, personnel and computing kit.</p> <p>And we'll touch on the future of Lidar and VR for 3D space modelling.</p> <p>Prominent projects are Survex: http://survex.com Therion: https://therion.speleo.sk/ Loser Expo/Troggle: expo.survex.com Tunnelx/Tunnelvr: https://github.com/goatchurchprime/tunnelx/ SexyTopo: https://github.com/richsmith/sexytopo Topodroid: https://sites.google.com/site/speleoapps/home/topodroid</p>
<ul> <li>review of current GNSS-based positionning systems</li> <li>what's RTK (Real-time Kinematic)</li> <li>RTCM and NTRIP : industry classics, walled gardens...</li> <li>Centipede-RTK: a collaborative global open-data RTK network</li> <li>RTKBase: a free/open-source RTK Base station software</li> <li>Create your own base and participate!</li> <li>Millipede: a scalable/free/open-source RTCM caster for the next step</li> <li>C-based</li> <li>libevent, multithreaded, TLS</li> <li>RTCM streams: ideal use-case for IP anycasting</li> <li>return of experience on Millipede development</li> <li>multithreading + event-based: best of both worlds</li> <li>tests</li> <li>valgrind</li> <li>returns about AI assistance during development</li> <li>what's next?</li> </ul> <p>https://github.com/pbeyssac/millipede-caster https://www.centipede-rtk.org/fr</p>
<p>The open-source tool <a href="http://osm2world.org/">OSM2World</a> turns OpenStreetMap data into detailed 3D models of the world. This talk presents the current state of the project.</p> <p>3D visuals are increasingly becoming a standard feature of geospatial applications. Whether you want to explore the world in your browser, build games and virtual reality applications, or export content to modelling software as a starting point for creative projects, you need software tools which fully support the third dimension.</p> <p>OSM2World makes it possible to generate 3D content for these kinds of applications from freely available OpenStreetMap data. Usable as a library or stand-alone application, it generates seamless outdoor and indoor representations of buildings, displays road and railway networks, and creates models for a large number of other feature types found in OpenStreetMap data. With support for the glTF standard, physically based rendering (PBR) and 3D tiles displayed in the browser using WebGL, models produced by OSM2World serve a wide range of uses.</p>
<p>This talk gives a rundown of various potential improvements being thought about and experimented on for the CUBIC Congestion Control implementation in Neqo, Firefox's QUIC stack. Detecting and recovering from Spurious Congestion Events -- network hiccups mistaken as congestion signal. Reacting differently to Explicit Congestion Notifications (ECN) than to packet loss. Optimizing the Slow Start exit point to avoid unnecessary loss through various heuristics.</p> <p>While many of these make sense on paper and produce good results in simulations the reality of the internet is much more complicated. One ongoing challenge is designing metrics that measure impact of change in the real world without getting lost in the noise of wildly varying network conditions across millions of internet users to validate that those improvements genuinely make Firefox quic(k)er.</p>
<p>iroh is a library to establish peer-to-peer QUIC connections assisted by relay servers. It needs to route UDP datagrams carrying QUIC payloads over relayed and holepunched network paths. While this used to be done outside of QUIC's knowledge, over the past year we have worked to adopt the QUIC multipath proposed standard so that QUIC itself is aware of multiple paths.</p> <p>This talk will cover iroh's experience of adding QUIC multipath to the Quinn library and the challenges of adopting it. The multipath draft does only cover how to send packets over the wire, and does not specify how path selection works, consequently we'll also cover iroh's choices for path selection as well as changes we will still be experimenting with.</p> <p>Finally iroh has also moved holepunching into a QUIC extension, which integrates tightly with multipath. The mechanism of how holepunching with multipath support works in iroh will covered as well.</p>
<p>The Web’s transport stack is changing rapidly, with QUIC, HTTP/3, and encrypted DNS seeing broad adoption. This talk gives an overview of the modern network protocols Firefox already deploys and invests in, including QUIC and HTTP/3’s growing share of Web traffic. It will highlight what Firefox actually sends on the wire today, what benefits we observe in practice, and where the Web’s protocol landscape stands in early 2026.</p> <p>The session will also offer an outlook on what’s likely to land in Firefox and across the Web in 2026 and beyond. This includes emerging mechanisms like Happy Eyeballs v3 to manage increasingly complex protocol selection, WebTransport as a modern WebSocket primitive, MASQUE-based proxying for new tunneling use cases, and ongoing work around encrypted DNS, resolver discovery, and Encrypted Client Hello. Together these protocols form the foundation of a faster and more private Web.</p>
<h1>Harnessing Hardware for High-Performance Traffic Management in VPP</h1> <p><strong>Traffic Management (TM)</strong> is critical for predictable network performance. It controls packet priority, shapes transmission rates, and allocates bandwidth to meet SLAs in large-scale deployments such as ISPs, telecom networks, and data centers.</p> <p><strong>FD.io Vector Packet Processing (VPP)</strong>, a widely adopted high-performance networking stack across these environments, currently relies on <strong>software-based TM</strong>. This introduces bottlenecks at scale: CPU overhead grows with traffic classes, latency spikes under load, and token bucket waste cycles. At 100G/200G and beyond, these limitations pose a critical risk of <strong>SLA violations</strong>. </p> <p>The new TM framework addresses these challenges by <strong>offloading shaping and scheduling to hardware</strong> through a <strong>vendor-neutral</strong> architecture and a <strong>unified API</strong> that works across all platforms supporting traffic management in silicon. </p> <h2>Overview</h2> <p>The proposed TM framework integrates VPP with hardware traffic management engines in supported NICs, SmartNICs, and DPUs. It detects hardware capabilities, classifies flows in software, and steers them to hardware queues where TM policies are enforced at line rate—eliminating software-based per-packet arbitration.</p> <h2>Key Features</h2> <p><strong>Hierarchical Scheduling:</strong> Organizes traffic into multi-level queues to prioritize critical services while preserving fairness across remaining traffic. <strong>Dual-Rate Shaping:</strong> Applies committed and peak rate control with burst handling, compliant with RFC 2698, to prevent congestion and maintain predictable performance. <strong>Priority and Fairness:</strong> Combines strict priority for latency-sensitive traffic with weighted sharing for bulk flows to balance resources. <strong>Policing:</strong> Enforces traffic limits at line rate by dropping or marking packets appropriately.</p> <h2>Advantages of Traffic Management in Hardware</h2> <p><strong>Performance:</strong> Delivers line-rate Traffic Management with high accuracy and low latency. <strong>Scalability:</strong> Supports thousands of queues at line rates without proportional CPU costs. <strong>Efficiency:</strong> Shifts workload to hardware, enabling CPUs to focus on application logic while reducing energy usage <strong>Reliability:</strong> Ensures stable Quality of Service under peak load conditions. </p> <h2>Conclusion</h2> <p>Hardware-assisted TM is no longer optional—it is mission-critical for networks scaling toward 400G/800G with diverse traffic and tight latency budgets. The VPP TM framework delivers this through a vendor-neutral API, <strong>making VPP ready for demanding telecom and data center workloads</strong> while preserving its modular design. For open-source stacks like VPP, this is not just an enhancement—it’s a long-overdue capability.</p>
<p>Have you heard about HTTP Archive (HAR) files and wondered how you could leverage this data for deeper insights into your web applications? </p> <p>Imagine analyzing your page load request data as <a href="https://opentelemetry.io/">OpenTelemetry</a> traces in your favorite observability backend. This talk will explore the lessons learned from transforming HAR into an OpenTelemetry trace and streaming it to <a href="https://www.jaegertracing.io/">Jaeger</a>. Learn how to convert HAR data into spans following OpenTelemetry semantic conventions.</p>
<p>Suricata is a high performance, open source network analysis and threat detection software used by most private and public organizations, and embedded by major vendors to protect their assets. Suricata provides network protocol, flow, alert, anomaly logs, file extraction and PCAP capture at very high speeds and provides a wide range of deployment options - IDS/IPS/FW/NSM.</p> <p>Suricata 8 is the latest stable edition that has been in development for 2 years, powered by collaborative work of the OISF team, Suricata community and consortium members. This talk will highlight the new and groundbreaking features available in the latest Suricata 8 edition. The new additions include runmodes, deployment options, detection, logging and protocol parsing that empower the cyber defenders with improved capabilities for network security monitoring in terms of efficiency, detection, accuracy, performance and flexibility. Don't miss this opportunity to get a firsthand overview at how Suricata 8 is shaping the future of network detection and prevention.</p>
<p>Everyone's building MCP servers for network automation. Your agents can finally talk to each other and share context about your infrastructure. But what context are they actually sharing?</p> <p>If your agent's understanding of the network comes from vector embeddings and RAG, MCP is just helping you share incomplete topology understanding and missed policy dependencies faster. Vector similarity can't represent "which devices are upstream of this link" or "what routing policies affect this prefix."</p> <p>MCP makes context sharing easy. Knowledge graphs make that context actually correct.</p> <p>This talk will discuss lessons learned as a developer advocate maintaining coffeeAGNTCY, an open-source multi-agent system. Mainly, sharing the discovery of why knowledge graphs with LangGraph are essential for network automation agents.</p> <p>We'll cover:</p> <p>-What MCP servers can't fix (the context representation problem) -Knowledge graphs for network topology, routing, and policy dependencies -LangGraph for reasoning over graph-structured network data -Real patterns from coffeeAGNTCY project (lungo) . Code: https://github.com/agntcy/coffeeAgntcy/tree/main/coffeeAGNTCY/coffee_agents/lungo</p>
<p>Network operations still depend heavily on manual workflows. Engineers move between CLIs, dashboards, and scripts to answer operational questions, validate configurations, and enforce compliance across diverse network platforms. These tasks are repetitive, error-prone, and hard to scale.</p> <p>This talk presents a practical AgenticOps architecture for network operations built with open source tools. It shows how low-code visual orchestration can be combined with LLM-based reasoning to automate both interactive and scheduled tasks while preserving native CLI access.</p> <p>The system uses n8n for workflow orchestration, Model Context Protocol servers written in Python with FastMCP to expose network capabilities, and Cisco pyATS to execute platform-aware CLI commands across multiple device families. Operators interact through a chat interface using natural language. The LLM classifies intent, discovers device type, selects the correct commands, executes them via pyATS, and returns structured results.</p> <p>The same workflows also handle automated compliance checks, report generation, and scheduled validations. The session includes a live demonstration and a GitHub repository with MCP servers, n8n workflows, and deployment examples ready to adapt to real environments.</p>
<p>"For better or worse, benchmarks shape a field." FD.io's approach to the better: open, reproducible benchmarks-as-code that guide development and guard against regressions in the VPP data plane, via CSIT. Problem: a race-track number doesn't translate to production deployments. CSIT's approach: MLRsearch (IETF BMWG, RFC in publication) for conditional throughput (NDR/PDR) with explicit stopping rules and inspectable artifacts; a continuous open-source benchmarking pipeline spanning packets and sessions; and a test matrix covering IMIX, QUIC/TLS, NAT, IPsec, ACL, SRv6, and NGFW/proxy use cases. This methodology drives terabit-class packet and session performance on commodity x86/Arm - reliably and repeatably. Takeaways: a replicable recipe (tools, configs, artifacts) for your lab; why benchmarks-as-code beat ad-hoc testing; and concrete contribution paths across CSIT and VPP (tests, profiles, analysers, data visualisation).</p> <p>Relevant links: https://fd.io/ https://csit.fd.io/ https://wiki.fd.io/ https://github.com/FDio/</p>
<p>As enterprises and service providers transition to virtualized and cloud-native infrastructures, the need for scalable, high-performance security becomes critical. <a href="https://fd.io/">FD.io's Vector Packet Processing (VPP) platform</a> has emerged as a leading open-source framework for fast packet processing, but how well does it handle modern IPsec workloads in Virtual Network Functions (VNFs) and Cloud-Native Network Functions (CNFs)?</p> <p>In this talk, we dive deep into the architecture and implementation of IPsec within <a href="https://fd.io/">FD.io VPP</a>. We'll explore real-world performance benchmarks, discuss recent improvements, and present best practices for deploying secure, high-throughput IPsec tunnels in containerized and virtualized environments. Attendees will see how VPP's modular pipeline enables flexible integration with orchestration systems, and how it can be tuned for different network function scenarios-from high-density edge sites to large-scale data centers.</p> <p>Whether you're building secure SD-WAN, 5G core, or edge networking solutions, this session will provide actionable insights on leveraging open-source VPP to deliver robust, scalable, and efficient IPsec-powered VNFs and CNFs.</p> <p><strong>Key Takeaways:</strong> - How FD.io VPP implements and accelerates IPsec for virtualized and cloud-native deployments - Tuning and scaling techniques for maximizing IPsec throughput and minimizing latency - Integration patterns for orchestration and real-world deployment considerations - Lessons learned from operational use cases and performance testing</p> <p>Join us to learn how open-source innovation is redefining secure, high-performance networking for the next generation of infrastructure!</p>
<h2>Description</h2> <ul> <li>RDMA programming is comparatively complex to something like sockets.</li> <li>RDMA is the industry standard for data centers and high-performance computing (HPC) environments.</li> <li>RTRS is a reliable high speed transport library, which provides a simple interface to perform RDMA. It is a stable, and proven transport library, running on more than 5000 servers across our data centers.</li> <li>RTRS establishes a stateful session which provides features like multipath, heartbeats, reusability, etc.</li> <li>It creates an optimal number of connections based on the number of CPUs, and uses IRQ pinning for data transfers.</li> <li>It allows users to send and receive data in the form of sg lists.</li> <li>RTRS is multipath capable (with different policies to choose from) and provides I/O fail-over and load-balancing functionality.</li> <li>RTRS pre-allocates and pre-maps DMA buffers on the server side to speed up data paths.</li> </ul> <h2>Benefit to the ecosystem</h2> <ul> <li>An easy to use, reliable and stable RDMA transport library to build any kind of module upon. RTRS will provide an entry point for newcomers to RDMA.</li> <li>The pre mapping abilities have use-cases in high performance use cases like ML and AI training.</li> </ul> <h2>Link to the module</h2> <p>https://elixir.bootlin.com/linux/v6.17.7/source/drivers/infiniband/ulp/rtrs</p>
<p>This presentation traces a five-year cat-and-mouse chase between a small VPN provider — more than 150 servers worldwide, millions of users, available on all major platforms — and the Russian state censorship machine. A real-world “Tom and Jerry” scenario where survival hinges on constant adaptation.</p> <p>I’ll walk through the evolving technical and non-technical tactics used by Russian authorities to block VPN access for ordinary users. Every story comes from real, first-hand experience. The methods used five years ago and the methods used today are on entirely different levels; Tom keeps learning new tricks, and Jerry’s struggle to stay alive only gets harder.</p> <p>This talk aims to be useful and insightful for network security engineers, business decision-makers, and human rights activists. Russia is not the only dictatorship experimenting with these techniques — and we expect more dictators to learn from the Russian playbook and adopt similar methods.</p>
<p>Rethink Firewall is the most downloaded FOSS network security tool on F-Droid for Android devices. For seemingly always-on, always-connected smartphones, on-device firewalls are notoriously hard to implement and maintain. This talk is about how 3 unsuspecting developers frustrated by digital surveillance and internet censorship got together, using the $12k in grant awarded by Mozilla in 2020, to build the missing "network sandbox" for 3B+ Android users, and the financial, technical, systemic challenges they faced along the way: From fighting the networking gods to make IPv6 work across a garden variety of topologies, to pushing the limits of SQLite for real-time stats & capturing network flows, to using Rethink itself to monitor & block its own egress, to testing the frontier of packet manipulation (for Deep Packet Inspection censorship resistance) and IP/domain filtering (supporting over 12 million entries) an Android app can achieve consuming limited resources (battery, processor, and memory), all the while supporting multiple WireGuard upstreams at once through open source virtualization layer (gVisor) Google built for its cloud servers! With a stream of recommendations from GrapheneOS, CalyxOS, DivestOS, the Guardian Project developers, and the varied feature-set Rethink packs, has made it the most downloaded (and probably the most confusing) WireGuard client on F-Droid.</p> <p>Since Aug 2020, we've also been operating Rethink DNS, an anycast, public, censorship-resistant, highly-available DNS resolver serving 40bn requests per month & 400 TB / month in traffic at peak. It has been subject to DDoS attempts & bans by state actors. It is used in the default configuration by some popular anti-censorship projects like VLess, Hiddify, and I2P. The costs for Rethink DNS is paid for by its lead developers and partially by grants from FOSS United, an Indian non-profit. Besides discussing the software optimizations on both the client and server to bring down the costs, an unexpected lending hand from Cloudflare played a major role in handling traffic surges and keeping bad actors in check.</p> <p>An anti-censorship and anti-surveillance tool for non-rooted Android devices is something we wished existed. We thought we'd be done in a year, but it is year #5 and we've so much left to do, as new users bring in newer feature requests, which mean more bugs and higher costs, too. To give a sense of our strong purpose, the toll of having drawn no salary for 5 years yet feeding our kids, living a frugal lifestyle just so this thing that we're building would exist, is not something our wives take very lightly!</p> <p>Code: https://github.com/celzero/rethink-app (the UI) https://github.com/celzero/firestack (the network engine) https://github.com/serverless-dns/serverless-dns (the resolver)</p>
<p>OpenPERouter is a lightweight, open-source Provider Edge (PE) router designed to bridge traditional networking with the cloud-native ecosystem. By running directly on Linux hosts and Kubernetes nodes, it terminates VPN protocols and exposes a standard BGP interface, simplifying complex network topologies. In this session, we will explore the architecture of OpenPERouter and demonstrate how to deploy and interact with host-level Layer 3 protocols and Layer 2 interfaces. We will showcase its seamless integration with the cloud-native ecosystem, specifically enabling L3 EVPN tunneling to common Kubernetes network components like Calico and MetalLB. Additionally, we will demonstrate how OpenPERouter naturally extends to virtual machine networks by achieving a cross-cluster Layer 2 overlay using EVPN, VXLAN, and KubeVirt. Finally, we will share the project roadmap, highlighting upcoming support for new VPN protocols and standalone deployment methods outside of Kubernetes. Join us to discover how to transform your nodes into advanced network endpoints and simplify fabric connectivity.</p>
<p>Border Gateway Protocol (BGP) has traditionally been associated with hardware routers and static configurations, but modern networks increasingly demand software‑defined, programmable control planes. GoBGP, an open source BGP implementation written in Go, offers a rich API surface that enables dynamic policy changes, on‑the‑fly route injection, and tight integration with automation systems and controllers. This talk explores the practical challenges and solutions involved in turning GoBGP into a multi‑tenant, production‑grade BGP control plane. We will start with a brief overview of GoBGP's architecture and its gRPC/HTTP APIs, then dive into how those APIs can be leveraged to build a flexible control plane that reacts in real time to external events (for example, service discovery, telemetry feedback, or orchestration workflows).</p> <p>The core of the session focuses on multi‑tenancy and operational aspects: - Building logical separation between tenants while sharing the same GoBGP control plane. - Mapping tenants to their own BGP server, route policies, and address families, and keeping configuration manageable as the number of tenants grows. - Handling dynamic tenant lifecycle events (creation, updates, deletion) through the API without disrupting existing sessions.</p>
<p>Building site-to-site VPNs over LTE/5G or behind NAT and stateful firewalls has always been painful. You either need a central relay server with a public IP, or spend hours configuring port forwarding and STUN. STUNMESH-go takes a different approach. It helps WireGuard peers find each other and establish direct P2P connections without running your own infrastructure.</p> <p>The key idea is simple. Reuse existing public services instead of running your own. STUNMESH-go uses STUN servers to discover NAT endpoints, encrypts peer information with Curve25519, and stores it using flexible plugins, whether that's Cloudflare DNS, a shell script, or any custom key-value storage backend. Peers fetch each other's information and WireGuard handles the rest.</p> <p>This session will cover:</p> <ul> <li>Cross-platform packet capture (Linux raw sockets vs BSD BPF)</li> <li>The plugin system and bringing your own storage without running servers</li> <li>Compatibility with WireGuard kernel module (no wireguard-go embedding needed)</li> <li>Minimizing binary size for embedded systems</li> <li>Real deployments (SD-WAN over LTE and site-to-site VPN mesh)</li> <li>Future IPv6 support for stateful firewall traversal</li> </ul> <p>This talk shares experience from building P2P networking that works across Linux, FreeBSD, macOS, and embedded routers like VyOS, EdgeOS, and OpenWrt.</p> <p>Github: https://github.com/tjjh89017/stunmesh-go/</p>
<p>IPv6 is nothing new yet IPv4 remains the default for the majority, despite IPv6 being ideal for containerized workloads. This talk covers the current state of IPv6 support in <a href="https://github.com/kubernetes/kubernetes">Kubernetes</a>.</p> <p>Discover why an IPv6 only Kubernetes environment <em>can</em> be a good idea. Potential challenges to anticipate, and valuable lessons from doing it in production using <a href="https://github.com/cilium/cilium">Cilium</a> as CNI.</p>
<p>The Internet of Threads (IoTh) is an experimental networking model that assigns full IPv6 identities—addresses, routing behavior, and protocol stacks—to processes or even individual threads. Instead of containers or VMs, IoTh leverages user-space TCP/IP stacks.</p> <p>This talk presents the open IoTh toolchain and its networking architecture: * libioth: the core IoTh library: a pluggable TCP/IP stack framework for user-space nodes. * nlinline: A quick and clean API for NetLink networking configuring (implemented in a header file). * libnlq: Netlink configuration library (for netlink clients and servers). * iothconf – Simple and expressive configuration for IoTh stacks. Common network setups can be defined with a single character string. * iothdns + iothnamed: DNS services supporting hash-based addressing and OTIP (One-Time IP) models * namedhcp: a DNS-driven DHCPv6/4 server for stateful, reproducible address assignment * otip-utils: tooling for ephemeral, privacy-oriented IPv6 addressing * iothradvd: an embeddable RA daemon for user-space IPv6 configuration</p>
<p>Deploying a Private 5G network has traditionally been the domain of proprietary vendors with complex, closed hardware. However, the maturity of open-source projects now allows engineers to build fully functional networks using standard servers and open software. Using purely open-source components requires precise orchestration of the hardware and software stack. This session aims to demonstrate a complete, end-to-end O-RAN deployment blueprint on top of OpenNebula. We will explain how to orchestrate the srsRAN suite (providing the centralized and distributed units) and Open5GS (the 5G Core). We will dive into the specific infrastructure requirements for running latency-sensitive telco workloads, focusing on Enhanced Platform Awareness (EPA) features. Attendees will learn how to configure SR-IOV and Passthrough for optimized network throughput, implement CPU Pinning and NUMA awareness for performance isolation, and manage Precision Time Protocol (PTP) synchronization from the host to the guest VM. The session will include a walkthrough of the automation blueprints used to configure 5G-ready edge nodes and instantiate verified telco appliances from the OpenNebula Marketplace.</p>
<p>Lightweight tunneling (LWT) has been supported on linux kernel since almost 10 years ago. It enables virtual environments to scale up their tunneling infrastructure, especially when containers are involved and container-to-container communication is needed.</p> <p>Nftables now allows to scale up with tunnel expression, combining it with the infrastructure existing ruleset and other powerful features like maps, sets and stateful objects. During this talk, we will get a good understanding of what is the lightweight tunneling, when it can be useful and how to use it together with Nftables.</p>
<p><a href="https://dn42.eu">dn42 (decentralized network 42)</a> is a community-driven overlay network over the Internet, it provides a testbed aimed at experimenting with Internet protocols such as BGP, IPv4 and v6, DNS, that can be used to skill-up, develop new ideas, or interconnect your local hackerspace(s) in a proper network without NAT.</p> <p>Think of it as a real-world lab where you can break things without taking down the Internet, with over a thousand routes, traffic exchanged, real-life links and latencies and actual peers around the world.</p> <p>This talk covers:</p> <ul> <li>A quick introduction to dn42</li> <li>How I've set up <a href="https://hcartiaux.github.io/dn42/">my network (<code>AS4242420263</code>, aka "Flip Flap Network")</a>, in different geographic zones using Ansible, Debian, WireGuard and Bird.</li> <li><a href="https://github.com/hcartiaux/dn42-sshd-autopeer">my automatic peering service, dn42-sshd-autopeer</a>, essentially a custom CLI over SSH, allowing other fellow network enthusiasts to request and set up a BGP peering session within a few minutes.</li> </ul> <p>Developed in Python under MIT license, this service has permitted my network to grow to the top 25 of dn42 networks by number of BGP peers and graph centrality.</p>
<p>eBPF programs often behave differently than developers expect, not because of incorrect logic, but because of subtle behaviours of the hookpoints themselves. In this talk, we focus on a small set of high-impact, commonly misunderstood attachment types — kprobes/fentry, tracepoints and uprobes, and expose the internal kernel mechanics that cause surprising edge cases.</p> <p>Rather than attempting to cover all eBPF hooks, this session distills a practical set of real-world gotchas that routinely affect production tools, explaining why they occur and how to work around them.</p>
<p>Training large models requires significant resources and failure of any GPU or Host can significantly prolong training times. At Meta, we observed that 17% of our jobs fail due to RDMA-related syscall errors which arise due to bugs in the RDMA driver code. Unlike other parts of the Kernel RDMA-related syscalls are opaque and the errors create a mismatched application/kernel view of hardware resources. As a result of this opacity and mismatch existing observability tools provided limited visibility and DevOps found it challenging to triage – we required a new scalable framework to analyze kernel state and identify the cause of this mismatch.</p> <p>Direct approaches like tracing the kernel calls and capturing meta involved in the systems turned out to be prohibitively expensive. In this talk, we will describe the set of optimizations used to scale tracking kernel state and the map-based systems designed to efficiently export relevant state without impacting production workloads.</p>
<p>Any eBPF project that has started in the last couple of years is most likely written to take advantage of CO-RE, compiling your eBPF programs ahead of time, and being able to run that program on a wide range of kernels and machines.</p> <p>Before CO-RE it was common to ship the whole toolchain and compile on target. This is what Cillium currently still does. Compiling on target empowered a core value of Cilium: "you do not pay for what you do not use". But it turns out that with CO-RE sometimes you DO pay for what you do not use, which makes it painful to switch over.</p> <p>This payment mostly comes in the from of unused maps which still have to be created and loading tail calls which will never be called.</p> <p>We created what we call "reachability analysis" which allows us to predict in userspace which parts of an eBPF program will be unused when loaded with a given set of global constants. This allows us to avoid creating maps that will never be used or load tail calls that will never be called, opening the way for Cilium migration to CO-RE.</p> <p>I would like to show how this works.</p>
<p>This talk will go over a number of performance and reliability pitfalls of the different eBPF program types we have discovered building production ready eBPF based products at Datadog. This includes the changing performance characteristics of kprobes over different kernel versions, reliability issues with fentry due to a kernel bug, and the pains of scaling uprobes, among other things.</p>
<p><a href="http://github.com/parca-dev/oomprof">OOMProf</a> is a Go library that installs a eBPF programs that listen to Linux kernel tracepoints involved in OOM killing and records a memory profile before your Go program is dead and gone. The memory profile can be logged as a pprof file or sent to a <a href="http://parca.dev/">Parca</a> server for storage and analysis. This talk will be a deep dive into the implementation and its limitations and possible future directions.</p>
<p>XDP and AF_XDP provide a high-performance mechanism for driver-layer packet processing and zero-copy delivery of packets into userspace, while maintaining access to standard kernel networking constructs — capabilities that distinguish them from full kernel-bypass frameworks such as DPDK. However, the current AF_XDP implementation offers no efficient in-kernel mechanism for forwarding packets between AF_XDP sockets in a zero-copy manner. Because AF_XDP operates without the conventional full network stack socket abstraction, even basic localhost redirection requires an external switch or additional hardware-assisted NIC capabilities, limiting both performance and usability.</p> <p>In this talk, we introduce FLASH, an extension to the AF_XDP subsystem that enables low-overhead, in-kernel packet transfer between AF_XDP sockets. FLASH provides zero-copy delivery for sockets that share a memory area and a fast single-copy datapath for sockets backed by independent memories. The design incorporates several performance-oriented mechanisms, including smart blocking with backpressure for congestion handling and an adaptive interrupt-to-busypoll transition to reduce latency under load.</p> <p>We demonstrate that co-located applications using AF_XDP can leverage FLASH to achieve up to 2.5× higher throughput compared to SR-IOV-based approaches, while preserving the programming model and flexibility of the XDP/AF_XDP ecosystem. The talk will also outline future directions and how FLASH can be one of the use cases of XDP_EGRESS PoC.</p> <h3>Resources</h3> <p><a href="https://github.com/networkedsystemsIITB/flash-linux">FLASH PoC Linux Kernel</a> </br> <a href="https://github.com/networkedsystemsIITB/flash">FLASH userspace library</a> </br> <a href="https://dl.acm.org/doi/abs/10.1145/3772052.3772258">FLASH paper @ SoCC'25</a> </br></p>
<p>The eBPF eXpress Data Path (XDP) allows high-speed packet processing applications. Achieving high throughput requires careful design and profiling of XDP applications. However, existing profiling tools lack eBPF support. We introduce InXpect, a lightweight monitoring framework that profiles eBPF programs with fine granularity and minimal overhead, making it suitable for XDP-based in-production systems. We demonstrate how InXpect outperforms existing tools in profiling overhead and capabilities. InXpect is the first XDP/eBPF profiling system that provides real-time statistics streaming, enabling immediate detection of changes in program behavior</p>
<h1>XDP Virtual Server: An eBPF Load Balancer library</h1> <p>Faced with the looming retirement of our traditional load balancer appliances we decided to give XDP a try. Facebook's Katran library did not support layer 2 switching, which was still a requirement, so we built an eBPF application in C and a supporting library with Golang.</p> <p>We came across a few issues along the way - driver support for network cards gave me headaches - but on the whole eBPF has made what would have been practically unthinkable a few years ago into a relatively straightforward task.</p> <p>The library is used by an application which adds configuration management, BGP, metrics, etc., and after testing on smaller services for some time the balancer now handles streaming audio and website content for the UK's largest commercial radio broadcaster, delivering tens of gigabits per second to our audience. COTS servers handle high volumes of traffic and can be trivially scaled/migrated when updated hardware comes along as simply as running an Ansible job.</p> <p><a href="https://github.com/davidcoles/xvs">The library</a></p> <p><a href="https://github.com/davidcoles/vc5">The application</a></p>
<p>The interoperability of I/O monitoring and profiling tools is very limited due to their strong dependence on the underlying file system (LUSTRE, Spectrum Scale, NFS, etc) and resource managers (batch jobs, VMs, containerized workloads, etc). Widely adopted generic monitoring tools often lack the temporal information of the I/O activity which is often required to understand the I/O behavior of the applications. The increasing diversity of applications and computing platforms demands greater flexibility and scope in I/O characterization. This talk proposes a framework for monitoring I/O activity using extended Berkley Packet Filter (eBPF) technology which has gained much traction in observability and cloud-native landscape. By tracing the kernel’s Virtual File System (VFS) functions with eBPF, it is possible to monitor the I/O activity on different types of platforms like HPC, cloud hypervisors or Kubernetes. By storing the metrics traced by eBPF programs in a high performance time series database like Prometheus, it is possible to perform system-wide monitoring of computing platforms that use different types of local or remote file systems in a unified manner. The current talk presents the basics of eBPF and discusses the framework that is used to monitor I/O activity in a file system and application agnostic way. It also presents the experimental results of quantifying the overhead and accuracy of the proposed framework using IOR benchmark results as the reference. The results indicate that there is negligible overhead in using the framework and bandwidths reported by the proposed methodology are in a very good agreement with the ones from IOR tests. Finally, results from a production HPC platform that uses the proposed framework to monitor I/O activity on the LUSTRE file system are presented.</p>
<p>When it comes to string handling, C is not the most ergonomic language for the job. But, at least, the standard library provides a basic set of functions for finding characters, comparing strings, or finding sub-strings. The same has not been true for eBPF programs where developers had to implement all the operations manually by looking into individual bytes.</p> <p>This has changed in kernel version 6.17, which added a set of eBPF kernel functions (so-called kfuncs) to perform the most common string processing operations. While implementing these sounded like a very straightforward job at the beginning (just call the in-kernel implementations of the respective functions, right?), it turned out that eBPF programs have a number of specifics which required the implementation to be much more complicated.</p> <p>In this talk, I will walk you through this journey and show how and why the kfuncs have to be implemented differently from the in-kernel implementations. We'll also dive into the API specifics and demonstrate how string kfuncs have been adopted by bpftrace [1] and what benefits they brought.</p> <p>[1] https://bpftrace.org/</p>
<p>Setting up eBPF development environment often require some effort on getting the correct headers, manage compiler versions, tweaking kconfig knobs, just to get a program running. In this session, we'll cover how to solve these problems using <a href="https://nixos.org/">Nix</a> [1] (NixOS not required). Unlike traditional workflows that rely on imperative package managers, Nix allows us to define kernel, userspace tooling, and testing infrastructure reproducibly.</p> <p>We'll explore a workflow that bridges the gap between local prototyping and experiments/production environments using <a href="https://wiki.nixos.org/wiki/NixOS_VM_tests">NixOS VM tests</a> [2], which would allow developers easily to spin up multiple QEMU VMs with custom kernel (e.g. with patches or non-conventional config/build flags) and network connection.</p> <p>We'll then demonstrate how to scale the exact environment from a laptop to testbeds like <a href="https://www.grid5000.fr/w/Grid5000:Home">Grid'5000</a> [3]. With Nix and <a href="https://github.com/oar-team/nixos-compose">NixOS-Compose</a> [4], we can deploy multi-node experiments with bit-perfect* reproducibility. In the demo, we'll use a trivial eBPF program (using <a href="https://docs.ebpf.io/linux/helper-function/bpf_override_return/"><code>bpf_override_return</code></a> to mandate <code>CONFIG_BPF_KPROBE_OVERRIDE</code> + <code>ALLOW_ERROR_INJECTION</code> and mock syscalls), test it locally, and deploy to a cluster to collect live telemetry and visualizations.</p> <p>[1] https://nixos.org/</p> <p>[2] https://wiki.nixos.org/wiki/NixOS_VM_tests</p> <p>[3] https://www.grid5000.fr/w/Grid5000:Home</p> <p>[4] https://github.com/oar-team/nixos-compose</p> <p>[*] https://reproducible.nixos.org/</p>
<p>This talk aims to present the first major release of <a href="https://github.com/pythonbpf/Python-BPF">PythonBPF</a> and how other developers can start using it. The speakers will discuss the progress of this project since it was demoed at <a href="https://lpc.events/event/19/contributions/2158/">LPC 2025</a> in December 2025 (what actions were taken on the feedback gathered at LPC).</p> <p>PythonBPF is a project that enables developers to write eBPF programs in pure Python. We allow a reduced Python grammar to be used for the eBPF-specific parts of code. This allows users to: - Write both eBPF logic and userspace code in Python (and can be in the same file), so the Python dev-tools apply to the whole file instead of just the non-BPF parts. - Process eBPF data and visualize it using Python's ecosystem, and interactively develop and debug eBPF programs using Python notebooks.</p>
<p>eBPF is a powerful technology, but it is often hard to use, because its toolchain is non-trivial. In my talk I present <a href="https://github.com/tecki/ebpfcat">EBPFCat</a>, a pure Python library that can generate eBPF directly without any dependency on other code beyond the Linux kernel. Unlike most eBPF implementations, no compiler is involved. Instead, the user writes Python code which generates eBPF on-the-fly at runtime.</p> <p>In EBPFCat, user- and kernel space are tightly integrated, so that both eBPF and Python code can access the same data structures. This way, one can use eBPF to write the performance critical parts of a program, while retaining the versatility of Python for the bulk of the code. This opens eBPF to a large audience who are interested in the performance boost by eBPF, but are hesitant to learn an entirely new tool set for it.</p> <p>I will go through a simple example to show that using EBPFCat it is possible to fit an entire eBPF program including its user space counterpart on a single presentation slide. For this example I also show how EBPFCat generates the eBPF bytecode.</p> <p>While EBPFCat can be employed for usual eBPF use cases, I present one well beyond typical systems-level applications: motion control. EtherCAT is a standard field bus protocol based on EtherNet. Using eBPF we can reduce the latency of communication with EtherCAT devices, allowing for real-time performance. I will show a real-world combined motion system for physics research that routinely uses EBPFCat.</p> <p>Developers new to eBPF will get a jump start into everything needed for their first project, while experienced kernel developers will be surprised just how far eBPF can take you beyond system programming.</p> <p>Links: <a href="https://github.com/tecki/ebpfcat">EBPFCat on github</a> <a href="https://ebpfcat.readthedocs.io/en/latest/">EBPFCat on readthedocs</a></p>
<p><a href="https://aya-rs.dev/">Aya</a> is a library that allows writing <a href="https://ebpf.io/">eBPF</a> programs, as well as their user-space counterparts, entirely in Rust. It has been presented in previous editions of FOSDEM, but the project has evolved since then. In this talk, we will highlight what has changed, what’s coming next, and how these developments shape the Rust-and-eBPF ecosystem.</p> <p>Over the last year, Aya has gained support for several new eBPF program types, as well as additional map types, such as the family of storage maps (sk_storage, task_storage, inode_storage). We’ve worked with the LLVM community to enable <a href="https://docs.kernel.org/bpf/btf.html">BTF</a> generation for Rust eBPF programs. The overall developer experience has continued to improve, and an increasing number of open-source projects are now building on top of Aya.</p> <p>We will also share updates on our ongoing work, most notably our efforts to promote Rust’s eBPF targets to <a href="https://doc.rust-lang.org/rustc/target-tier-policy.html#tier-2-target-policy">Tier 2</a>, paving the way for building eBPF programs on Rust stable without requiring nightly toolchains. Alongside this, we are developing support for BTF relocation emission, refining the user-space XDP API, and broadening coverage of program and map types.</p> <p>The talk will dive into the technical details behind these features, the architectural decisions that shaped them, and the challenges ahead. We will conclude with our vision for Aya’s future and how we see it moving forward.</p>
<p>eBPF powers modern observability, but its behavior varies significantly across architectures. This talk examines whether eBPF can be used reliably on RISC-class systems—ARM64 and RISC-V—and what limitations appear in real workloads.</p> <p>We use reproducible test environments to run tracing, profiling, and networking eBPF tools on x86_64, ARM64, and RISC-V, revealing practical differences in verifier constraints, helper availability, JIT maturity, and performance overhead. RISC-V support exists but remains incomplete, and we show exactly which features succeed, fail, or behave unpredictably.</p> <p>Using a database benchmark as a workload generator, we compare instrumentation accuracy, latency impact, and stability across architectures. Attendees gain a clear understanding of eBPF’s practical portability and how to build a realistic multi-architecture observability testbed.</p>
<p>BPF Tokens are a new Linux kernel mechanism for delegating restricted eBPF privileges to unprivileged processes. This talk explains how distributions can adopt them to provide safer access to tracing, observability, and networking tools—without granting root or CAP_SYS_ADMIN.</p> <p>We’ll show how token-based delegation could reshape developer workflows, container runtimes, and system services in Fedora or other distros.</p> <p>The session includes a walkthrough of real token policies and discusses how distributions can help build a secure, less-privileged eBPF ecosystem.</p>
<p>Intro of the devroom</p>
<p>Web developers use open-source data all the time to help guide their decisions.</p> <p>In this talk, I'd like to tell you more about this data, and in particular about <a href="https://github.com/web-platform-dx/web-features">web-features</a>, an open-source project which aims at being a reference data point for the web platform.</p> <p>The project contains the list of <strong>all</strong> features of the web platform, at a level of granularity that's most useful to you, web developers. This project has gained a lot of traction over the past two years, in particular thanks to <a href="https://web-platform-dx.github.io/web-features/">Baseline</a>.</p> <p>Baseline banners help web developers make quicker decisions based on the maturity of the web features they use, and are now visible on <a href="https://developer.mozilla.org/">MDN</a>, <a href="https://caniuse.com">Can I use</a>, and many other development tools.</p> <p>Baseline isn't the only consumer of the web-features data though. The data is starting to get used in more and more web-platform-related data which you rely on every, sometimes without realizing it. The web-features project is making it easier to get access to information about the state of the web platform, in a practical way.</p> <p>In this talk, I'll go over the resources that make use of open source web-related data sources to help you stay aware of changes, but also discover new features, and make decisions.</p> <p>I'll also go over what web-features does not cover today, such as accessibility or progressive enhancements, and how these are areas that demand careful planning and implementation. I'll offer pointers showing how we're thinking about addressing these on the WebDX community group, and will invite contributions from those interested.</p>
<p>When talking about CSS, we generally speak about how it’s super nice to have good looking websites, introduce a new feature and how to use it, etc.</p> <p>But today, we’d like to speak about a feature that has been into the CSS specifications since 1998, and that we don’t talk about very often: CSS for print 🖨️.</p> <p>During this talk, we’ll show how CSS can be used not to only create web pages, but also beautiful and structured paged documents. Interested in generating reports, invoices, tickets, or even slideshows? Take a look at which tools − except your favorite web browser − you can use to accomplish that, and why it’s very convenient in particular for automating documents generation.</p>
<p>How does a website display a mathematical formula? More importantly, how can we ensure that all browsers show it the same way?</p> <p><a href="https://www.w3.org/TR/mathml-core/">MathML Core</a> is a small subset of <a href="https://www.w3.org/TR/MathML3/">MathML 3</a>, specifically crafted for web browsers. It addresses inconsistencies in mathematical rendering across different browser engines. <a href="https://www.igalia.com/">Igalia</a> has been actively working on <a href="https://conflor.es/blog/2025-11-27-interop-and-mathml">improving MathML interoperability</a>, aligning the implementations of Firefox, WebKit and Chromium with this standard.</p> <p>From <a href="https://w3c.github.io/mathml-core/#propdef-math-depth">nested exponents</a> to <a href="https://people.igalia.com/fwang/mathml-operator-mirroring-explainer.html">Arabic writing direction</a>, this session will explore the process of going from a specification to a feature release. MathML's unique history makes the task particularly interesting, as it often required deprecating existing features or implementing significant changes.</p> <p><strong>Slides</strong>: <a href="https://eri.pages.igalia.com/slides/2026/01_fosdem_mathml">https://eri.pages.igalia.com/slides/2026/01_fosdem_mathml</a></p> <p><strong>Bad Apple!! but it's MathML</strong> (run in your browser): <a href="https://conflor.es/bad-apple-mathml]">https://conflor.es/bad-apple-mathml</a></p>
<p><a href="https://caniwebview.com/about/">WebViews</a> are everywhere—but fragmented, inconsistent, and often invisible to web developers. Used for in-app browsers, hybrid apps, and <a href="https://www.w3.org/groups/wg/miniapps/">MiniApps</a>, WebViews form a significant part of the web platform that many developers unknowingly target. Some developers specifically build for WebViews in hybrid apps or MiniApps, while others create standard websites without realizing they'll run in WebView contexts with different behaviors and constraints. </p> <p>Through initiatives like <a href="https://caniwebview.com/baseline">Baseline</a>, <a href="https://caniwebview.com">CanIWebView</a>, <a href="https://caniwebview.com/apps">apps</a>, and the <a href="https://github.com/WebView-CG">WebView Community Group</a>, we're working to map this fragmented landscape and identify paths forward. MiniApps that are very popular in some markets also show a very strong fragmentation and very little standardization. With collaboration and improvements between WebViews, MiniApps, PWA, new technologies like <a href="https://chromeos.dev/en/web/isolated-web-apps">Isolated Web Apps</a> or new engines like Servo there is good potential to improve the web in this space, but it's complicated.</p> <p>The <a href="https://www.w3.org/community/webview/">W3C WebView Community Group</a> was formed to identify, understand, and reduce the issues arising from the use of software components (typically referred as WebViews) that are used to render Web technology-based content. As member and co-chair of the community group I'd like to give a little overview what WebViews are today, the work we've done to improve interoperability, and call to action to "fix things" in this overlooked but critical part of the web platform.</p>
<p>WebTransport is an upcoming protocol (standardized by the IETF) and Web API (standardized by the W3C) for bidirectional communication on the web. It provides multiplexed streams and unreliable datagrams on top of HTTP/3 and HTTP/2.</p> <p>This talk explains how WebTransport works at the protocol level, how it maps to QUIC when run on top of HTTP/3, and how its capabilities differ from WebSocket. The session will also cover the current state of browser and server support, and where the ecosystem is heading next.</p>
<p>Web Components have become a bit of a divisive topic in the Web community in recent years. On the one hand you have platform advocates arguing Web Components are a boon to interoperability, can simplify tooling and distribution, and provide a common bed for experimentation and innovation. On the other hand, framework authors often complain that they complicate runtime code with special-cases and that Custom Elements are the wrong level of abstraction for framework components.</p> <p>Lustre <a href="https://github.com/lustre-labs/lustre">1</a> - a frontend framework for the functional programming language Gleam [2] - is bucking this trend; quietly using Web Components as a core building block of its runtime. In this talk we'll explore how Lustre can lean harder into the platform by adopting a different idea of what "components" should be, and how this can end up benefit framework users too.</p> <p>[2] https://gleam.run</p>
<p>This presentation provides a comprehensive status update on WebKitGTK and WPE, the Open Source ports of the WebKit Web rendering engine that Igalia maintains for Linux devices. These ports are currently being used in millions of devices (e.g. phones, set-top boxes, smart home appliances...), leveraging the flexible architecture of WebKit to provide HW-accelerated graphics and multimedia capabilities with a minimal resource footprint (e.g., memory, binary size).</p> <p>We will begin by providing some context on what WebKit is and how WebKitGTK and WPE bring the power of the Web Platform to Linux-based devices and distributions. After that, we will summarize the current status of these ports, detailing the latest and most important highlights of the work done in the past year, followed by a description of what the new developments will be focused on during 2026.</p> <p>The Linux ports have experienced huge changes recently, including a massive refactoring of its graphics pipeline, the development of a new API for embedded devices, dma-buf support for zero-copy buffer sharing, a complete revamp of its QA infrastructure, and even adding support for Android. With all this in mind, this session should be useful for anyone interested in creating Web-based products on Linux devices, understanding the current state of these ports, and seeing where development is headed next.</p>
<p>The Servo project, now hosted under Linux Foundation Europe, is a modern Rust-based rendering engine pushing forward safety, modularity and high-performance web rendering. After its early foundations at Mozilla and a couple of years of impasse, Servo entered a new chapter in 2023 when Igalia took over stewardship, ensuring long-term maintenance, open governance, and a clear technical direction for the project. The Servo community has continued to grow steadily since then.</p> <p>In this talk we’ll review the recent evolution of the project together with the plans for the future. Apart from that, we’ll focus on the impact of this work in the whole web platform, by finding issues in specifications and improving them, reporting interop bugs, contributing new tests, etc.; showing that the development of new web engines benefits the whole ecosystem.</p>
<p>The goal is of this session is to have some folks representing some various browsers to have a panel discussion. it will be moderated</p>
<p>What does accessibility interoperability look like? This talk explores the edges of support between browsers, assistive tech, and specs.</p> <p>Accessibility Compat Data: https://github.com/lolaslab/accessibility-compat-data</p>
<p>Modern web applications face a constant barrage of attacks targeting authenticated user sessions, including Cross-Site Scripting (XSS), Cross-Site Request Forgery (CSRF), clickjacking, Cross-Site Leaks (XS-Leaks), and even Spectre. Fortunately, recent advancements in web browser security provide developers with powerful tools to mitigate these threats. This talk delves into the latest web platform security features, equipping you with the knowledge to protect your applications. We'll explore CSP3, Trusted Types, Fetch Metadata headers, and COOP, demonstrating how these mechanisms can effectively thwart entire classes of web vulnerabilities.</p>
<p>File uploads are a ubiquitous and fundamental part of modern web applications. While simple at first, they become increasingly challenging as file sizes grow. Users expect reliable data transfers, even when uploading multi-gigabyte files over unreliable mobile networks.</p> <p>Conventional file uploads over HTTP fail unrecoverably when the underlying connection is interrupted. Resumable uploads, on the other hand, allow an application to continue uploading a file exactly where it left off. This preserves previously transferred data and greatly improves the user experience.</p> <p>Historically, resumable uploads were implemented in proprietary ways, with each application building its own solution. Developers couldn’t benefit from the advantages of resumable uploads without investing significant engineering effort.</p> <p>In 2013, we started the <a href="https://tus.io">tus project</a> and created a free and open-source protocol for resumable uploads. The project and its community provide implementations for various client and server runtimes, making it easy today to add resumable uploads to any application.</p> <p>In 2022, we began engaging with the HTTP Working Group at the IETF to make resumable uploads a standardized extension to HTTP. Our goal is to integrate resumable uploads directly into browsers, HTTP clients, servers, and proxies so that even more developers can easily benefit from their capabilities.</p> <p>This talk explores the past and present of resumable uploads and how upcoming standards will help developers deliver exceptional file-upload experiences.</p> <p>Additional links: - Tus homepage: https://tus.io/ - GitHub organization: https://github.com/tus - “Resumable Uploads for HTTP” Internet-Draft: https://datatracker.ietf.org/doc/draft-ietf-httpbis-resumable-upload/</p>
<p>In June 2025, researchers exposed a major tracking vulnerability - Local Mess, where Meta Pixel and Yandex Metrica scripts were exploiting localhost access to track millions of Android users across the web. This talk presents Local Network Access (LNA) standards and how it addresses similar threats and helps fix long standing security vulnerabilities with localhost and local network devices. The talk explains the LNA specification and how it categorizes network requests into public, local, and loopback address spaces, requiring explicit user permission when websites access more private network zones. The presentation covers Firefox's implementation, key differences from Chrome's approach, real-world deployment challenges and mitigations.</p> <p>References: Local Mess - https://localmess.github.io/ Local Network Access Standard - https://wicg.github.io/local-network-access/ Local Network Standards Issues - https://github.com/WICG/local-network-access/issues/ Firefox Implementation Bug - https://bugzilla.mozilla.org/show_bug.cgi?id=1481298 List of long pending security vulnerabilities with localhost and local network - https://github.com/WICG/local-network-access/issues/21 </p> <p>About the Speaker <a href="https://bugzilla.mozilla.org/user_profile?user_id=711499">Sunil Mayya</a> is a software engineer on Mozilla's Firefox Networking team, and a core contributor to Firefox's implementation of the Local Network Access standard.</p>
<p>The WebAssembly (Wasm) 1.0 specification is a linear memory system suitable as a compiler target for static languages like C and Rust. However, the recently released Wasm 3.0 specification, which includes garbage collected reference type instructions, has opened the door to using all kinds of dynamic languages on the web. Wasm GC compilers already exist for languages such as Java, Scala, Kotlin, OCaml, and Scheme. However, the value of Wasm GC is often misunderstood! In this talk, I'll attempt to clear things up by examining the benefits and drawbacks of Wasm GC at present and how compiling to Wasm GC stacks up against compiling to JavaScript (or just using plain ol' Javascript). I'll conclude with a brief look at some proposals from the Wasm Community Group that could improve Wasm GC in the near future.</p>
<p>A large number of Linux applications have been developed over the years. Reusing them allows developers to reduce development costs, leverage well-established and battle-tested applications, and gain significant benefits by porting them to WebAssembly (Wasm). Migrating Linux applications to the browser as Wasm offers several advantages, such as: 1. Developing browser-based applications by reusing existing Linux libraries 2. Protecting client privacy and reducing server load by moving server-side Linux applications into the browser 3. Building browser-based systems that rely on Linux applications that are traditionally difficult to port (e.g., shells, compilers)</p> <p>In this session, I will introduce elfconv, a binary translator that directly converts existing Linux binaries into Wasm without requiring their source code and provides a layer for emulating Linux system calls. This enables Linux applications that depend on system calls unavailable in Wasm (e.g., fork/exec) to run inside the browser. Furthermore, by performing ahead-of-time (AOT) translation, elfconv achieves dramatically lower overhead compared to CPU-emulator-based projects such as container2wasm and v86. Our evaluation on several benchmark tests shows that elfconv delivers approximately 30× to 70× higher performance. At the moment, the system call emulation layer in particular is still under development, but I believe that as elfconv matures, it will greatly expand the potential of the browser.</p> <p>elfconv: https://github.com/yomaytk/elfconv container2wasm: https://github.com/container2wasm/container2wasm v86: https://github.com/copy/v86</p>
<p>The old Servo Streams implementation was relying on SpiderMonkey’s own stream implementation. In the latest SpiderMonkey versions, that stream implementation was removed, which prevented us from updating the version in Servo. So we reimplemented the Streams spec without the built-in SpiderMonkey implementation, and we ended up implementing WritableStream and TransformStream.</p> <p>Servo repo: https://github.com/servo/servo</p>
<p>Identifying the exact commits where bugs are introduced or regressed in web browsers is often a tedious and time-consuming task. As a result, mapping the full lifecycle of a newly reported bug rarely becomes part of the standard bug-fixing process, even though doing so can reveal valuable insights and support more effective fixes. With <a href="https://github.com/DistriNet/BugHog">BugHog</a>, we developed an automated bisection tool on steriods, simplifying the hunt for buggy commits.</p> <p>BugHog runs: - dynamic test cases against historical browser builds - in isolated Docker containers - guided by an adaptive binary search algorithm - across more than a decade of browser development history.</p> <p>Originally developed for browser security research, BugHog has already demonstrated its value by reconstructing the lifecycle of publicly disclosed Content Security Policy bugs in Chromium and Firefox. This gave new perspectives on how security bugs evolve over time, exposed ineffective fixes, and even uncovered prematurely disclosed vulnerabilities.</p> <p>In this talk, I will demonstrate how BugHog works, share lessons from large-scale browser analyses, and highlight how it can help both researchers and developers accelerate their bug investigations.</p>
<p>We will talk about how we are building the Midori browser, a lightweight, fast, secure browser that promotes privacy, is completely open source and free software, and at the same time we will talk about how we are building a pro-privacy ecosystem around Midori, including tools such as VPN, DNS, all without telemetry, without invasive advertising and, most importantly, all stored and hosted in the European Union to increase its technological independence.</p>
<p>The Cyber Resilience Act defines web browsers as an important product requiring special attention to cybersecurity requirements. What does this mean? How can <em>you</em> participate in defining in what it means for a web browser to be secure?</p>
<p>systemd supports a number of integration features that allow VMMs certain access to the inner state of VM guests for provisioning, synchronization and interaction, and many of them are little known, even though very very useful. In this talk I'd like to shed some light on many such integration points, such as SMBIOS type 11 based system credential provisioning; state propagation/readiness notification via AF_VSOCK; SSH support via AF_VSOCK, and so on.</p>
<p>Modern confidential computing technologies like AMD SEV-SNP and Intel TDX provide a reliable way to isolate guest workload and data in use from the virtualization or cloud infrastructure. Protecting data at rest is, however, not something you get ‘by default’. The task is particularly challenging for traditional operating systems where users expect to get full read/write experience. </p> <p>The good news is that Linux OS already offers a number of great technologies which can be combined to achieve the goal: dm-verity and dm-integrity, LUKS, discoverable disk images and others. Doing it all right, however, is left as an “exercise to the reader”. In particular, the proposed solution must allow for meaningful remote attestation at any time in the lifetime of the guest.</p> <p>The talk will focus on the recent developments in various upstream projects like systemd and dracut which are focused on making full disk encryption consumable by confidential computing guests running in a cloud.</p>
<p>It has been several years since the last <a href="https://github.com/rust-vmm/community">rust-vmm</a> update at FOSDEM, but the community has continued to grow. Our goal remains the same: to provide reusable Rust crates that make it easier and faster to build virtualization solutions.</p> <p>This talk will present the main progress and achievements from the past few years. It reviews how rust-vmm crates integrate into a variety of projects such as Firecracker, Cloud Hypervisor, Dragonball, and libkrun. We will discuss the ongoing efforts to consolidate all crates into a single monorepo and how we expect this to simplify development and releases. The talk will also cover recent work supporting new architectures like RISC-V and additional operating systems. Finally, we will review the support for virtio and vhost-user devices that can be used by any VMM.</p>
<p>QEMU 10.2 will introduce MSHV as a new accelerator option for Linux hosts.</p> <p>MSHV is a kernel driver maintained by Microsoft's Linux System Group that aims to expose HyperV capabilities to users in various virtualization topologies: on bare metal, in nested virtualization and most recently via a new model called "Direct Virtualization".</p> <p>Direct virtualization will allow owners of an L1 VM to commit parts of their assigned resources (CPU, RAM, Peripherals) to virtual L2 guests, that are technically L1 siblings. Users can take advantage of the hypervisor's isolation boundaries without the performance and functional limitations of a nested guest. Untrusted code can be sandboxed with near-native performance and access to GPUs or NVMe controllers.</p> <p>Adding support for MSHV acceleration to QEMU aims to broaden the reach of this technology to a Linux audience. The talk will cover the current state of the implementation, challenges that remain and future plans for both MSHV and QEMU.</p>
<p><a href="https://github.com/oasis-tcs/virtio-spec">VIRTIO</a> is the open standard for virtual I/O, supported by a wide range of hypervisors and operating systems. Typically, device emulation is performed directly inside the Virtual Machine Monitor (VMM), like <a href="https://www.qemu.org/">QEMU</a>. However, modern virtualization stacks support multiple implementation models: keeping the device in the VMM, moving it to the kernel (vhost), offloading it to an external user-space process (vhost-user), or offloading it directly to the hardware (vDPA).</p> <p>Each approach comes with specific trade-offs. Emulating in the VMM is straightforward but can be a bottleneck. In-kernel emulation offers high performance but increases the attack surface of the host system. External processes provide excellent isolation and flexibility, but introduce complexity. Finally, vDPA (vhost Data Path Acceleration) enables wire-speed performance with standard VIRTIO drivers, but introduces hardware dependencies.</p> <p>So, how do we decide which approach is best for a specific use case?</p> <p>In this talk, we will explore all four methods for emulating VIRTIO devices. We will analyze the architectural differences, discuss the pros and cons regarding performance and security, and provide guidance on how to choose the right architecture for your use case.</p>
<p>This talk shows how a Raspberry Pi can run a complete open-source cloud using OpenNebula. With MiniONE handling the installation and KVM doing the virtualization, a Raspberry Pi becomes a small but fully functional cloud node capable of running VMs, containers, lightweight Kubernetes clusters and edge services. The goal is simple: demonstrate that homelab users can build a full cloud stack with compute, networking, storage and orchestration on affordable hardware using only open-source tools. A short demo will show a VM launching on a Pi-based OpenNebula cloud, highlighting how the platform scales down to tiny devices while keeping the same clean and unified experience found on larger deployments.</p>
<p>To address the challenge of providing seamless Layer 2 connectivity and mobility for KubeVirt virtualized applications distributed across multiple clusters (for reasons like disaster recovery, scaling, or hybrid cloud), we integrated OpenPERouter, an open-source project that provides EVPN-based VXLAN overlays, solving the critical need for distributed L2 networking.</p> <p>OpenPERouter's declarative APIs and dynamic BGP-EVPN control plane enable L2 networks to stretch transparently between clusters, maintaining VM MAC/IP consistency during migrations and disaster recovery. This architecture facilitates deterministic cross-cluster live migrations, better supports legacy workloads needing broadcast/multicast, and enables migrating workloads into the KubeVirt cluster while preserving original networking using open components. Routing domains are also supported for traffic segregation and to provide direct routed ingress to VMs, eliminating the need for Kubernetes services to expose ports.</p> <p>Attendees will gain the practical knowledge to design and implement resilient, operationally safe, EVPN-based overlays with OpenPERouter, receiving actionable design patterns and configuration examples.</p>
<p>"GPU clouds" for AI application are the hot topic at the moment, but often these either end up being just big traditional HPC-style cluster deployments instead of actual cloud infrastructure or are built in secrecy by hyperscalers.</p> <p>In this talk, we'll explore what makes a "GPU cloud" an actual cloud, how requirements differ from traditional cloud infrastructure, and most importantly, how you can build your own using open source technology - all the way from hardware selection (do you <em>really</em> need to buy the six-figures boxes?) over firmware (OpenBMC), networking (SONiC, VPP), storage (Ceph, SPDK), orchestration (K8s, but not the way you think), OS deployment (mkosi, UEFI HTTP netboot), virtualization (QEMU, vhost-user), performance tuning (NUMA, RDMA) to various managed services (load balancing, API gateways, Slurm etc.)</p>
<p>What if your container image were a few megabytes instead of hundreds of megabytes? <a href="https://webassembly.org/">WebAssembly (WASM)</a> offers a radically lighter approach to running workloads on <a href="https://kubernetes.io/">Kubernetes</a> — right alongside your existing containers. In this talk, we'll dive deep into how WASM modules using the <a href="https://wasi.dev/">WebAssembly System Interface (WASI)</a> integrate into Kubernetes through <a href="https://containerd.io/">containerd</a> shims like <a href="https://github.com/containerd/runwasi">runwasi</a>. Using a <a href="https://rust-lang.org/">Rust</a> example, we'll demonstrate the dramatic reduction in image size and startup time compared to traditional containers. We'll explore the current state of WebAssembly in the cloud-native ecosystem: what's production-ready today, and where you should wait before adopting. Beyond the basics, we'll look at real-world Cloud-Native Compute Foundation (CNCF) projects already running WASM in production and discuss the two areas where WebAssembly shines: plugin architectures that benefit from small, secure, sandboxed extensibility, and event-driven systems that can quickly scale from zero. Whether you're optimizing for resource efficiency or exploring new isolation patterns, this session provides insights into WebAssembly on Kubernetes and serves as a great starting point.</p>
<p>With KubeVirt, Virtual Machines become first-class citizens in Kubernetes, allowing VMs and containers to be managed through a unified control plane. As organizations evolve their infrastructure, many early adopters face the challenge of upgrading systems without disrupting essential services. To support this, KubeVirt provides powerful mobility capabilities for both compute and storage.</p> <p>KubeVirt enables non-shared storage live migration through QEMU's block migration feature, which is orchestrated by libvirt and KubeVirt components. The core process involves copying the VM's disk data and memory state to the destination node while the VMI remains running.</p> <p>Cross-Cluster Live Migration (CCLM) extends this capability across Kubernetes clusters, allowing a running VM to be moved seamlessly between clusters. This enhances flexibility and resilience in multi-cluster environments and is especially useful for load balancing, maintenance operations, and infrastructure consolidation – all without interrupting critical workloads. CCLM requires L2 network connectivity between clusters and compatible CPU architectures.</p> <p>Storage Live Migration (SLM) allows you to move the VM’s disk data from one storage backend to another while the VM remains running. This is particularly valuable when rebalancing storage usage, retiring legacy systems, or adopting new storage classes – all without disrupting the applications inside the VM. SLM requires at least two compatible nodes.</p> <p>Both CCLM and SLM work with any storage backend, including those using the ReadWriteOnce access mode.</p> <p>After the session, you’ll be ready to migrate your running VMs – across clusters and across storage – with confidence, like a seasoned scheduler placing pods exactly where they need to be.</p>
<p>Lima (Linux Machines) is a command line tool to launch a local Linux virtual machine, with the primary focus on running containers on a laptop.</p> <p>While Lima was originally made for promoting containers (particularly containerd) to Mac users, it has been known to be useful for a variety of other use cases as well. One of the most edgy use cases is to run an AI coding agent inside a VM, in order to isolate the agent from direct access to host files and commands. This setup ensures that even if an AI agent is deceived by malicious instructions searched from the Internet (e.g., fake package installations), any potential damage is confined within the VM, or limited to files specified to be mounted from the host.</p> <p>This talk introduces the updates in Lima v2.0 (November 2025) that facilitates using Lima with AI: - Plugin infrastructure - GPU acceleration - MCP server - CLI improvements</p> <p>Web site: https://lima-vm.io GitHub: https://github.com/lima-vm/lima</p>
<p>In this session, we will present a new extension to Prowler, the widely adopted open-source cloud security auditing tool, adding native support for the OpenNebula cloud management platform.</p> <p>Our contribution delivers a modular, non-intrusive, and scalable auditing framework that integrates essential services and a growing catalogue of security checks aligned with established reference standards. This extension enables operators to detect misconfigurations and vulnerabilities more effectively, strengthening the overall security posture of OpenNebula deployments.</p> <p>We will walk through the design and implementation of the tool, share validation results from real test scenarios, and outline how this effort helps democratize cloud security within the open-source ecosystem. Finally, we will discuss opportunities for community-driven collaboration to expand and evolve this new security auditing capability.</p>
<p>KubeVirt allows running VMs and containers on Kubernetes, but traditional Kubernetes networking - which uses NAT (Network Address Translation) to expose workloads outside the cluster - can still lead to complex, opaque, and brittle setups that prevent direct integration and reachability.</p> <p>This presentation introduces a BGP-based solution to simplify KubeVirt networking. Kubernetes nodes dynamically exchange routes with the provider network, exposing workloads via their actual IPs, eliminating NAT and manual configurations.</p> <p>This BGP approach simplifies network design, speeds up troubleshooting, and ensures consistent connectivity for virtualized workloads.</p> <p>Attendees will learn practical, standard networking principles to simplify real-world Kubernetes environments and gain immediate, actionable insights to improve platform connectivity.</p>
<p>Platform engineering teams tackle complex, multi domain challenges, balancing governance and iterating quickly to enable developers. In this session we’ll detail how SUSE IT uses Kubewarden as a policy controller across both RKE2 and SUSE Virtualization environments. We’ll show how enforcing organizational policies with Kubewarden automatically integrates compliance and operational excellence into the core of the platform. We’ll discuss practical examples, e.g., how to restrict usage of resources, GPUs or VLANs to specific customers while providing the platform to a wider audience.</p> <ul> <li> <p>https://www.kubewarden.io/</p> </li> <li> <p>https://www.rancher.com/</p> </li> <li> <p>https://docs.rke2.io/</p> </li> </ul>
<p>In this talk, we will present the current state of remote VM access in KubeVirt [0] and the challenges associated with it. We will discuss in-guest approaches such as running an RDP server on Windows or Linux, as well as host-side mechanisms like QEMU’s built-in VNC server exposed through KubeVirt’s virt-api. Finally, we will introduce a new proposal that leverages QEMU’s display-over-D-Bus interface [1], a direction that could enable additional vendors to build their own remote-display integrations.</p> <p>[0] https://kubevirt.io/ [1] https://www.qemu.org/docs/master/interop/dbus-display.html</p>
<p>Serving AI models on a single GPU for multi tenant workload sounds challenging till you partition a GPU correctly. </p> <p>This talk is a deep technical exploration of running AI inference workloads on modern GPUs across using Multi-Instance GPU (MIG) isolation.</p> <p>We'll explore:</p> <ol> <li>The multi-tenant problem: MIG vs other GPU slicing methods.</li> <li>MIG Fundamentals: Key concepts, working and support.</li> <li>Managing MIG instances: creation, configuration, monitoring and deletion.</li> <li>Identifying right approaches based on your workload.</li> <li>Common issues and failures</li> </ol> <p>Whether you're building a multi-tenant inference platform, optimizing GPU utilization for your team, or exploring how to serve AI models cost-effectively, this talk provides practical configurations for your AI workloads.</p>
<p>Virtualization has transformed low-level debugging, system analysis, and malware research. By placing a thin hypervisor beneath the OS, developers gain a vantage point the OS cannot access. This blue-pill approach enables fine-grained control over CPU state, memory, interrupts, and hardware events without relying on OS components, supporting transparent breakpoints, VM-exit triggers, memory shadowing, and instruction tracing with minimal interference.</p> <p>We present HyperDbg, an open-source hypervisor-based debugger. Leveraging the former characteristics, unlike kernel debuggers that depend on drivers, APIs, or software breakpoints, HyperDbg operates entirely below the OS, combining virtualization-based introspection with interactive debugging. It inspects memory, CPU execution, and traps events without OS cooperation, bypassing anti-debugging and anti-analysis techniques.</p> <p>Using modern virtualization extensions like Mode Based Execution Control (MBEC) on top of Second Level Address Translation (SLAT), HyperDbg enforces breakpoints and traps through hardware transitions, independent of OS APIs or exceptions. This allows stealthy, artifact-free binary analysis, providing a powerful platform for reverse engineering and research. In its first iteration, HyperDbg introduced a hypervisor-powered kernel debugger. With the recent release of v0.15, HyperDbg enables cross-boundary debugging from kernel-mode into user-mode. For this talk, we will add special focus on how we implemented cross-boundary debugging, and how it enables users to intercept user-mode process execution using virtualization techniques.</p> <p>Resources:</p> <ul> <li> <p>HyperDbg repository: https://github.com/HyperDbg/HyperDbg/</p> </li> <li> <p>Documentation: https://docs.hyperdbg.org/</p> </li> <li> <p>Kernel-mode debugger design: https://research.hyperdbg.org/debugger/kernel-debugger-design/</p> </li> <li> <p>Research paper: https://dl.acm.org/doi/abs/10.1145/3548606.3560649</p> </li> </ul>
<p>Welcome to the FOSDEM 2026 RISC-V DevRoom</p>
<p>FFmpeg is the most versatile multimedia codec and format support library, and was one of the first open-source project to include some RISC-V-specific optimisations, though there is still a long way to go. The RISC-V Vector extension was also the first scalable vector extension to be supported. We will cover the background, challenges and outcomes of this effort.</p> <p>https://www.ffmpeg.org/</p>
<p>A discussion of historical lessons that RISC-V did learn from, and mistakes that it repeated. Focused on the design constraints forced by RVC and RVV, as well as the choices around breaking out the F and D profiles out from a mandatory vector unit, and the state changes that come with it. </p> <p>The broad context will be specific to OoO SS processors</p>
<p>Efforts to port Fedora Linux to RISC-V began in 2016, long before physical hardware was accessible to developers. Today, the vast majority of Fedora packages have already been ported to riscv64 (i.e. the RV64GC baseline) and OS images—both generic and board-specific—are available for recent releases.</p> <p>RISC-V is currently an <em>alternative</em> architecture in Fedora, so these (non-official) images are built by a dedicated team of community contributors, the Fedora RISC-V team. However, the end goal is to make RISC-V a <em>primary</em> architecture on Fedora.</p> <p>So, what changed since the last update at DevConf 2024? What does the path for RISC-V to become a primary architecture on Fedora look like? What are we currently working on and what are our future plans?</p> <p>Beyond software, we'll also survey the current hardware reality. Today several development boards are available. If one is getting started with RISC-V today, what board to pick? We'll review the available hardware, from the "VisionFive 2" to other capable boards, and outline our experience building Fedora on it.</p> <p>Finally, whether you have a board on your desk or just a desire to contribute, there are many ways to help push Fedora’s RISC-V journey across the finish line. Join us to learn more!</p>
<p>This talk will introduce the architecture and instruction set of the ET Minion, a RISC-V CPU with custom extensions used in the ET platform, AI Foundry's open-source manycore architecture.</p> <p>The talk will describe the details of the custom vector and tensor extensions implemented in this minimal RISC-V core.</p> <p>For more information about the ET-platform and AI Foundry, visit https://github.com/aifoundry-org/et-platform</p>
<p>In this talk I'll present the pain and joy of working on a BootROM we use for booting our RISC-V SoC prototypes in the lab, with networking capabilities. First I'll give an overview on how writing bare metal code looks like, the challenges one has to deal with, and how we solved it in a prototype-independent way. Then I'll present netboot as an example use case, give an idea of the constraints we had to deal with and where they came from, why such a thing is a requirement when working with SoC prototypes (or even in production), how I did it, and finally do a live demo if time permits.</p>
<p>Last year, I gave a talk about running upstream embedded Linux on RISC-V with the powerful SpacemiT K1-based Banana Pi BPI-F3 as an example. Fast forward one year, and we have many a new contender on the block. This talk first revisits the BPI-F3, looking at the upstreaming progress made and issues remaining. Secondly, it introduces the new Siflower SF21H8898-based Banana Pi BPI-RV2, the ESWIN Computing EIC7700-based EBC77 with SiFive HiFive Premier P550 cores and the Ky X1-based Orange Pi RV2 and R2S. The latter two I will leave to my subsequent speaker, Michael Opdenacker from Bootlin (;-p). Those are all interesting new boards I added to my embedded Linux testing lab. Comparing the various downstream vendor options with the upstreaming efforts will show us the overall progress embedded Linux has made on RISC-V. Last but not least, I will discuss the upcoming RVA23-compatible boards based on chips like the SpacemiT K3 SoC with its X100 cores, the Tenstorrent TT-Ascalon IP SoC, the UltraRISC UR-DP1000 and the Zhihe A600 SoC. The time is truly ripe for embedded Linux to shine on RISC-V!</p>
<p>RISC-V hardware momentum is everywhere: more tape-outs, more open cores, more startups, and increasingly affordable boards that everyone can try. But hardware alone doesn’t make a usable platform. From blinking LEDs to critical space exploration missions, adoption depends on the software ecosystem being mature, well-integrated, and ready for developers to rely on.</p> <p>So, how ready is RISC-V software today? Toolchains, kernel support, hypervisors, RTOSes and simulators are all evolving, but progress happens at different speeds across the stack. Users still encounter rough edges, and contributors often struggle to navigate the ecosystem and find where help is needed most.</p> <p>This talk shares a personal journey through RISC-V software enablement: from building Linux images and contributing to Zephyr, to enabling hypervisors and firmware. I’ll highlight what’s solid, what’s still forming, and the challenges faced along the way - and how anyone can begin contributing and using RISC-V.</p>
<p>Bringing <a href="https://github.com/kubernetes/kubernetes/">Kubernetes</a> to RISC-V isn't just about cross-compiling Go - it's a crash course in open hardware meets cloud-native reality. This talk walks through the journey of bringing a <a href="https://github.com/k0sproject/k0s/">FOSS Kubernetes distribution</a> to RISC-V: wrestling with missing cloud infra, build tooling, container images, CI pipelines, and everything else they conveniently gloss over when they say you "just" need to export GOARCH=riscv64.</p>
<p>The last decade of CPU vulnerabilities has shown how microarchitectural performance optimizations can undermine isolation. Transient execution attacks like Meltdown and Spectre exposed deep flaws in x86 CPUs. RISC-V, by contrast, enters with the promise of simplicity and transparency—a clean slate. Yet the question remains: will we repeat the same mistakes, or can we design a secure architecture from the start?</p> <p>This talk takes a critical look at how RISC-V implementations handle microarchitectural security today. We show that even "simple" in-order designs already suffer from architectural flaws and powerful side channels. In our earlier work, we demonstrated novel attacks, such as Cache+Time and CycleDrift, on the first commercial RISC-V CPUs, exploiting unprivileged access to instruction-retirement counters and cache-timing leakage.</p> <p>But manual analysis does not scale. RISCover, our open-source differential fuzzing framework, automatically discovers architectural vulnerabilities across closed-source RISC-V CPUs. By comparing instruction behavior across 8 commercial CPUs from 3 vendors, RISCover found what manual analysis missed: GhostWrite, a bug in T-Head's XuanTie C910 that lets unprivileged code write directly to physical memory, completely bypassing virtual memory isolation. We also discovered multiple "halt-and-catch-fire" sequences that crash CPUs from userspace, leading to denial-of-service.</p> <p>These findings reveal a pattern: while the RISC-V specification provides strong security primitives (e.g., PMP and cleaner privilege separation), implementations consistently choose insecure defaults—leaving unprivileged timing sources enabled, shipping undocumented vendor extensions like XTheadVec without proper validation, and omitting features to limit speculation. RISC-V is at an inflection point: the architecture is still young enough to fix, but adoption is accelerating fast. The decisions vendors make today—insecure defaults, unvalidated extensions, missing mitigations—will be baked into billions of chips we cannot patch.</p>
<p>Why buy a bottle when you can have your own keg? Open source hardware might not shout “free beer” but the new Unified RISC-V IP Access Platform, maintained by OpenHW Foundation, is just that – free recipes for your own free-flowing beer. From CVA6 superscalers to UVM support on Verilator, Chips JU project TRISTAN has united Europe’s biggest industry players with academia to move open source semiconductors from the lab to the real world. Now with the UAP, you can benefit from all of this hard work. In this talk, you’ll get uncensored access to recent advancements in European RISC-V, and a demonstration of how you can immediately leverage industry-ready open source designs from projects across Europe, all explained with glorious beer.</p>
<p>In the course of the past months, Michael has contributed to support for OrangePi RV2 and R2S in the mainline Linux kernel (6.19+), in Yocto's meta-riscv BSP layer and hopefully before FOSDEM 2026, in the U-Boot bootloader. Hoping to attract more users and contributors, and to inspire owners of other RISC-V boards, this presentation will review what has been done so far and the necessary steps to achieve this. It will also cover what's left to do on each board.</p>
<p>WordPress joined the fediverse more than 15 years ago and is still the underdog, but the potential is huge, after all, nearly 40% of the internet is powered by WordPress.</p> <p>WordPress doesn’t come from the same place as social platforms. Unlike platforms built purely for social interaction, WordPress is driven by a very different set of needs, priorities and expectations. I want to give a few insights into how running your own ActivityPub instance can feel as easy as installing a plugin (and why that’s only half of the truth). Plus, a short sneak peek into what we’re currently working on to make WordPress a full flavored, fully featured ActivityPub instance.</p>
<p>The social web is bigger than software. It’s a movement to build a liberated internet for the people, and it will take all of us working together to deliver on that promise. </p> <p>Mastodon is a decentralised social networking platform powered by free software which allows users and institutions to create and join independent communities. It's also the nonprofit foundation that supports them, and looking after the humans of the social web is core to the Mastodon foundation’s mission. If you’ve been following us closely, you’ll know we just completed a radical transformation of our foundation's operations. One reason we did this was to support more direct community participation in shaping and deciding the future of Mastodon. In the coming year, we’re also planning to increase our efforts with and on behalf of the communities we support and that surround us: from server admins to the broader social web and Fediverse. </p> <p>In this talk, Mastodon’s new Community Director Hannah Aubry will share the foundation’s plans for evolving how the project approaches its many communities, from server admins to the broader social web. Bear in mind this isn’t just a talk; it’s an invitation to co-create the future of Mastodon.</p>
<p>The web is facing a critical moment. In an era of geopolitical fragmentation and relentless platform <em><a href="https://en.wikipedia.org/wiki/Enshittification">enshittification</a></em>, we cannot afford to remain dependent on Big Tech gatekeepers for our digital voices. The Social Web offers an alternative—but only if we actively claim it.</p> <p>We'll show you how to establish genuine digital sovereignty by federating different content types across the Fediverse. Through live demos of Mastodon (microblogging), Pixelfed (images), and Castopod (podcasting), we'll demonstrate how these independent platforms seamlessly federate via ActivityPub—allowing you to own your content, control your audience relationships, and maintain your voice across media types without surrendering to corporate platforms.</p> <p><strong>What we'll do together:</strong> - <strong>Understand why now matters</strong>: We'll examine the geopolitical and economic forces driving platform consolidation and why decentralization is a democratic imperative - <strong>Break the enshittification trap</strong>: We'll show how platforms extract value by degrading service, and why federation breaks this cycle - <strong>See federation in action</strong>: We'll demo cross-platform federation live—posting from Castopod, watching interactions appear in Mastodon, building community across instances - <strong>Get you started</strong>: We'll give you concrete next steps to migrate your digital presence to the Social Web</p> <p>By the end of this session, you'll know exactly where to start. If you have a laptop, you can host a podcast on the Fediverse—and we'll show you how. The tools exist. The community is ready. Let's take back control of how we communicate, create, and connect online.</p> <p>Illustration: (CC BY-SA 4.0) <a href="https://en.wikipedia.org/wiki/User:Eukombos">Eukombos</a></p>
<p>The German-European initiative Save Social proposes a 25 minutes session focused on broadening the involvement of society in the development and stewardship of the open social web. Despite immense progress in establishing open alternatives like Mastodon or Friendica, today's open social web has struggled to connect with and empower the wider public, often because structural support has concentrated on technical advancements rather than inclusive engagement and content diversity. A handful of global platform monopolies dominate – as we all know - public discourse and information, undermining democratic exchange and transparency. While open alternatives exist, their reach is limited without the structural, content, and educational investment needed to engage broader segments of society. Current alternatives have not always made participation intuitive or relevant for users from fields outside the technology sector, which limits their impact and hinders genuine diversity in dialogue and innovation. Therefore the future of the social web is not just a matter for developers, but for everyone—requiring regulatory support, media education, and the creation of citizen committees to define public-good requirements. The session will highlight specific, actionable pathways for different sectors to join the open web movement, making digital democracy a society-wide project rather than a niche initiative, e. g.: • Frame the strategy around a clear democratic and social purpose, not only technical openness. • Frame strategies around stories and lived experiences instead of only technical roadmaps. • Treat communities as Co-desginers, move from “getting feedback” to “sharing authorship.” • Assume most people are not protocol experts and design engagement accordingly. • Build bridges to sectors of society Save Social's proposal is for a session that inspires and equips participants to break silos and bring the open social web to everyone, ensuring it serves as a democratic, accessible, and resilient foundation for the digital society of the future. Save Social is a network of 120 individuals, being supported by more that 260.000 signatories from Germany, collectively covering journalism, the arts, unions, startup founders, established economic leaders, public institutions, and research. This cross-sector representation is unique and powerful, fostering collaboration and a user-centric approach to digital democracy.</p>
<p>Many ActivityPub servers have a feature to follow a hashtag locally -- subscribing to receive all the content with a particular hashtag that your server knows about, as it arrives. Could we provide a similar feature across the Fediverse? tags.pub is a project to implement that feature -- collecting tagged content and redistributing it by hashtag. In this talk, Evan will discuss the motivations behind tags.pub, its implementation, and outline future steps for global hashtag services.</p>
<p>We will demo two small prototypes that are aimed at showcasing that a combination of domain-based identities and self-sovereign identities may be useful to help increase long-term stability of relations within the fediverse - in case DNS-based redirect/move methods fail.</p> <p>The core idea is to work towards something we like to refer to as ‘cross-network coherence’ of open social web identity: representations that are comprised of elements from both DNS and DID:PLC which are <em>referencing each other</em>, thereby creating an identity object that allows us to combine the advantages of both worlds. In other words: DNS actors would be referencing DID:PLC identities and, in the opposite direction, DNS based actors would be referenced by entries in the DID document of that same DID:PLC ID.</p> <p>Demo Part 1: ’Native bridging’: a fork of https://github.com/mastodon/mastodon that replicates posts from actors on the instance (who decide to opt-in) to a repo on an ATproto PDS on the same host. In this case AP activities by actor @user@domain are copied to ATproto networks via a DID:PLC anchored identity @user.domain (instead of @user.domain.ap.brid.gy in case of bridgyfed). </p> <p>Demo Part 2: ‘Identity convergence’: a fork of https://github.com/mastodon/mastodon that allows to add references to DID:PLC identities to AP actors (via ‘alsoKnownAs’), which can then be used to increase long term persistence of following/following relations within the fediverse. This is work in progress and will be released by the end of December 2025.</p> <p>Code: https://github.com/msonnb/mastodon</p>
<p>Since Mastodon, a prominent adopter of ActivityPub, developed its own client API, it has been embraced by various projects, even reaching beyond microblogging platforms. Despite its potential, the ActivityPub Client-to-Server API has received minimal attention, leading many platform developers to overlook it in favour of building bespoke or third-party solutions. </p> <p>My talk will explore the unfulfilled promise of a general-purpose client built on ActivityPub's Client API. By developing a general-purpose client app, participating in the specification work, and addressing its shortcomings, we can initiate a new cycle of client app development. This approach will empower platform developers to innovate new services, fostering broader adoption and exploration of ActivityPub’s Federation capabilities across diverse platforms.</p>
<p>I'm building <a href="https://github.com/raffomania/linkblocks">a project for sharing bookmarks on the fediverse</a>. I'll cover its unique mix of features from traditional social bookmarking sites such as del.icio.us and pinboard, feed readers, and graph-based tools like Obsidian or are.na. I'll explain how this works as a companion when exploring the small web as part of tightly knit communities.</p>
<p>In this talk, I will discuss the collaborative efforts that began in 2025 with the aim of establishing an advocacy network for the social web. While the developer community is flourishing with the support of the Social Web Foundation and others, few communicators have raised their voices and made demands addressed to the political sphere, such as the European Union. </p> <p>As social web engaged people with professional backgrounds in policy work and communication have become involved in social networks in Europe, interest and efforts to strengthen communication and political demands in the European digital policy landscape have grown. </p> <p>In order to be approachable by interested lawmakers and public organizations, we need advocacy networks. What goals and benefits could be achieved through such networks? They would enable regulatory influence and support, secure public funding, and help advocates to sit on public and non-public panels. This would enable them to raise awareness and advocate for decentralised social networks as a means of achieving digital sovereignty. </p> <p>One of our important political messages is to emphasize the importance of social networks as a fundamental building block in the pursuit of digital sovereignty in and for Europe. Social networks should also be recognized as a service that must be included in discussions about Eurostacks. </p> <p>To get those and other messages heard and repeated, we need more people to join these efforts. In my talk, I will discuss the current state of stewardship of the open social web, and the political goals we should aim to achieve in 2026.</p>
<p>This talk will provide a concise introduction to Fedimedia Italia, a federation of projects run by Fediverse admins, hacktivists, and developers, and its mission to promote the Fediverse and free software across Italy and explores the experiences of Mastodon.uno and the Devol collective in advancing the federated social-web (the Fediverse) in Italy. Since its creation, Mastodon.uno has become one of the largest and most active Mastodon instances worldwide, and a central hub for the Italian-language Fediverse community. The talk also presents some projects in development, focusing on FediPress, a WordPress plugin that enhances the official ActivityPub with a mobile-friendly, messenger-like PWA.</p> <p>Fedimedia Italia is a non-profit association promoting decentralized technologies, free software, and digital rights, aiming to build an ethical online ecosystem as an alternative to Big Tech platforms. Founded by a federation of hacktivists and developers committed to digital sovereignty, Fedimedia Italia is a key pillar of the Italian Fediverse, with members managing instances and contributing to projects such as Mastodon, Pixelfed, PeerTube, Mobilizon and additional 9 federated services. </p> <p>During the talk we will outline the technical challenges required to maintain a stable federated network: server infrastructure, moderation policies, interoperability, scalability issues.</p> <p>Examine the social and adoption challenges: how to attract and retain users, trust building, and overcoming network-effect inertia compared to centralized Big Tech platforms.</p> <p>Share the lessons learned by Fedimedia admins over 7 years of operation with mastodon.uno: successes, failures, tensions; and how they reflect the broader difficulties of establishing a truly distributed, privacy-centric alternative to corporate social media especially in a national/language-specific context.</p> <p>By exposing both the technical backbone and the human/community challenges, the presentation aims to provide a helpful roadmap for those who want to create a federated social networks. It will be particularly relevant for: developers, sysadmins and open-source activists interested in decentralized social infrastructure, community governance, and the practical trade-offs of building a “free web.”</p> <p>Links to mentioned projects:</p> <p><strong>Fedimedia:</strong> <a href="https://fedimedia.it">fedimedia.it</a></p> <p><strong>Mastodon.uno:</strong> <a href="https://mastodon.uno">mastodon.uno</a></p> <p><strong>Devol (services):</strong> <a href="https://servizi.devol.it">servizi.devol.it</a></p> <p><strong>Devol (newsletter):</strong> <a href="https://newsletter.devol.it">newsletter.devol.it</a></p> <p><strong>OpenForFuture:</strong> <a href="https://openforfuture.org/">openforfuture.org</a></p> <p><strong>Fedipress:</strong> <a href="https://openforfuture.org/fedipress/">openforfuture.org/fedipress</a></p>
<p>The fediverse isn't done! Or, at least, that's the opinions of ActivityPub co-authors Christine Lemmer-Webber and Jessica Tallon! Discover how we could improve the fediverse with ActivityPub-compatible improvements to add more robust and secure communication/cooperation patterns, decentralized storage and identity, etc! Plus: how Spritely is starting to apply its technology towards exactly this goal, bringing Spritely's next-generation internet tech to the fediverse!</p>
<p>FediVariety, a research initiative supported by the NLnet and SABOA foundations, has analyzed the European Data Protection Supervisor's pilot project, "EU Voice/Video". </p> <p>Our upcoming report, scheduled for publication in early 2026, will offer key insights and recommendations for integrating the Fediverse into public administrations. This report aims to spark open dialogue among diverse practitioners, encouraging experience sharing and fostering new collaborations. </p> <p>At FOSDEM, we will present preliminary insights from our research and invite participation in an unconference in Amsterdam on March 19-20, 2026.</p> <p>Building on our findings, we aim to explore how the Fediverse can effectively support public institutions in the long term, addressing critical questions about its future and strategies for developing and adopting decentralized social media. We seek to create a broad coalition and welcome developers, administrators, content managers, moderators, coders, digital activists, and open-source enthusiasts committed to fostering sustainable alternative social media and promoting an open social web.</p> <p>— "Nodes On A Web (NOAW): The Fediverse in/for Public Institutions", is supported by the Chief Information Office (CIO-Rijk) (Ministry of the Interior and Kingdom Relations) of the Netherlands, the Digitalisation & Innovation Department of the City of Amsterdam, NLnet foundation, and SABOA foundation.</p> <p>More information on the NOAW unconference, the format and registration can be found here: https://fedivariety.org/unconference</p> <p>Questions? Feedback? Contact us: https://mastodon.social/@FediVariety noaw@fedivariety.org</p> <p>FediVariety.org is a European collective of digital activists and researchers dedicated to promoting Free and Open Source Software (FOSS) for public administration, with an emphasis on the Fediverse.</p>
<p>Civil organizations like libraries, schools, government agencies and NGO’s base their efforts on public values over financial profit. In their everyday operation however they often rely on tools that do not align with these public values: Big Tech platforms that sell user data as a commodity, suppress voices, increase polarization and undermine democracy and mental health. </p> <p>While alternative tools and platforms are available, public institutions are often reluctant to start using them. At PublicSpaces, www.publicspaces.net, we work with 40 of these larger public institutions like libraries, museums, broadcasters, local governments and health and education institutions. All these partners share a common goal: to communicate on platforms that align with their public mission and public values.</p> <p>Doing this as a single institution is often difficult. Institutions often lack the knowledge, the funds or the expertise to create and manage new platforms. By working together we hope to strengthen our efforts, share knowledge and create a common ecosystem. Some of the project we worked on were PeerTube Spaces, a pilot to set up video as a digital commons, the Make Social Social again campaign in which we help institutions to take the first step together by using alternatives to Big Tech social media platforms and the Fediverse Helpdesk we will start in 2026.</p> <p>While we know from conversation with or partners what the common bottlenecks and holdback towards adoption of alternative platforms are, we would like to underpin this knowledge with actual data. For this talk we will send out a survey to a representative section of our partners institutions about what the mayor issues are with the use of alternatives are. </p> <p>We will analyze and visualize this data, combine it with our experience in working with public institutions and and present it in a developer friendly form. With this talk we hope to give insight into improvement the developer community can to help public institutions, and their clients, users, citizens, etc. adopt alternative platforms. We will try to answer questions as:</p> <pre><code>• What hare the main holdbacks for civil institutions towards wider adoption of Fediverse tools? • What technical and other improvements would help civil institutions adopt Fediverse tools? • What types of support and knowledge sharing are needed? • What type of organization and governance are needed to support this? • How can the Fediverse community help civil institutions and how can civil institutions help the Fediverse community? </code></pre>
<p>The Fediscovery project defines a protocol for "Fediverse Auxiliary Service Providers", standardised services which can provide common features like cross-instance search, recommendations, and the potential for many more. This talk will describe, from an outside-the-project perspective, how the protocol works, how you can build support into your apps, and how and why we did this for Manyfold.</p>
<p>A few years ago I volunteered at a non-profit where the go-to digital badge platform (e.g., Credly) was explicitly prohibited due to cost, vendor lock-in and rigid workflows. We needed a badge system for volunteer recognition, skill tracking and event participation — yet the high price and closed ecosystem killed it every time.</p> <p>This is how BadgeFed was born, an open-source, federated badge system built on the ActivityPub protocol and the Open Badges standard. Because it’s an instance you control, deployable in minutes, fully federated and self-hostable, it overcame the cost/lock-in barrier and unlocked recognition for our volunteer community. </p> <p>So how do we move digital badges out of locked-down platforms and into the federated social web? In this talk I’ll walk through how BadgeFed, an open-source credentialing system built on the ActivityPub protocol and aligned with the Open Badges spec, powers non-profits to issue, share and verify badges across Fediverse instances.</p> <p>I will share:</p> <ul> <li>Why traditional badge systems are brittle and siloed, and how a decentralised model flips that dynamic. </li> <li>How BadgeFed implements ActivityPub actors, badge issuance as federated objects, and federated discovery. </li> <li>How Community Credentials uses the stack to empower nonprofits and volunteer programs: federated badges that survive issuer shutdowns, open standards, self-hostable instances, social graph integration. communitycredentials.org</li> <li>What remains challenging: federation scaling, discovery/search of badges across instances, identity portability, moderation/trust issues.</li> <li>Next steps for BadgeFed and federated credentials in the Social Web ecosystem, and how you as a dev or org can pick it up.</li> </ul> <p>Attendees will leave with a clear understanding of how to deploy a federated badge service, integrate it with their tools, and contribute to a social-web native credentialing future..</p> <h2>Referentes</h2> <ul> <li><a href="https://github.com/tryvocalcat/badgefed">Github repo</a></li> <li><a href="https://communitycredentials.org">Community Credentials</a></li> </ul>
<p><a href="https://splinter.hastily.cc/">Splinter</a> is a tool for Mastodon threads. Splinter turns long articles into Mastodon threads and posts them for you automatically. It started as a project for educational purposes for using Mastodon's API. It ended up being a tool that people actually use! </p> <p>So let's make threads great again, see what Splinter offers, and which challenges exist when developing for Mastodon.</p>
<p>Bonfire is an open-source, modular platform for creating federated social networks and communities that put users and groups in control. Bonfire’s architecture is designed to be deeply extensible: each instance can enable or disable features, adapt its onboarding, workflows, or governance, and even fork or create extensions or apps for their own needs.</p> <p>This talk will showcase:</p> <ul> <li> <p><strong>Making federation easy for everyone</strong>: See how Bonfire enables developers to connect any new or existing app to the fediverse with much less effort, so these apps can instantly communicate and collaborate with other platforms just by plugging into our standards-based API (ActivityPub C2s).</p> </li> <li> <p><strong>Live demos in action</strong>: We’ll demonstrate this approach with real examples, like creating and sharing events that connect seamlessly between the Lauti events app, Bonfire, and Newsmast's mobile apps. Resulting in a seamlessly integrated networked ecosystem. We’ll also present our work on secure, interoperable, end-to-end encrypted (E2EE) messaging.</p> </li> <li> <p><strong>Bonfire's modular approach</strong> with extensions and "flavours" (collections of extensions and default settings) that adapt to diverse use cases, from research to activism to local news.</p> </li> <li> <p><strong>Lessons learned from co-designing</strong> features with scientists, activists, and other diverse communities. </p> </li> </ul> <p>Whether you’re curious about building your own platform, adding ActivityPub to a new tool, or shaping the “next layer” of federated protocols (groups, moderation, decisionmaking, trust), Bonfire’s approach, code, and community offer a living experiment in interoperability and mutual care.</p> <p>Links:<br /> - <a href="https://bonfirenetworks.org">Project</a> - <a href="https://docs.bonfirenetworks.org">Docs</a> - <a href="https://github.com/bonfire-networks">Code</a> - <a href="https://docs.bonfirenetworks.org/federation-interoperability.html">Interop & FEP/Protocol extensions</a></p>
<p>Implementing ActivityPub looks simple at first—it's just JSON over HTTP, right? Then you hit JSON-LD context resolution. Then HTTP Signature verification fails on Mastodon but works on Misskey. Then you realize the spec spans hundreds of pages across W3C documents and <a href="https://w3id.org/fep/">FEPs</a> (Fediverse Enhancement Proposals), and every implementation interprets them differently.</p> <p>I went through this pain building <a href="https://docs.hollo.social/">Hollo</a>, a single-user microblogging server. Halfway through, I realized I was building a framework instead of an app. So I extracted that framework and called it Fedify.</p> <p><a href="https://fedify.dev/">Fedify</a> is an opinionated ActivityPub framework for TypeScript. It handles the protocol plumbing so you can focus on your application logic.</p> <p>In this talk, I'll cover:</p> <ul> <li> <p><em>Type-safe vocabulary:</em> The Activity Vocabulary spec is loosely defined, but Fedify maps it to strict TypeScript types. Your IDE knows that <code>Note.content</code> is a <code>LanguageString</code>, and calling <code>await create.getActor()</code> returns an <code>Actor</code> object. No more guessing at property shapes.</p> </li> <li> <p><em>Comprehensive signature support:</em> Fedify implements four authentication mechanisms—HTTP Signatures (draft-cavage), HTTP Message Signatures (RFC 9421), Linked Data Signatures, and Object Integrity Proofs (FEP-8b32). For HTTP Signatures, it uses <a href="https://swicg.github.io/activitypub-http-signature/#how-to-upgrade-supported-versions">double-knocking</a>: trying RFC 9421 first, falling back to draft-cavage if rejected, and remembering the preference. This kind of interoperability work is exactly what you shouldn't have to do yourself.</p> </li> <li> <p><em>Framework-agnostic design:</em> Fedify works as middleware for Hono, Express, Fastify, Next.js, or any framework that speaks <code>Request</code>/<code>Response</code>. Bring your own database, ORM, and auth—Fedify only needs a key–value store for caching.</p> </li> <li> <p><em>CLI toolchain:</em> The <code>fedify inbox</code> command spins up an ephemeral server to receive and inspect activities. <code>fedify lookup</code> fetches any ActivityPub object by URL or fediverse handle—including from servers that require <a href="https://swicg.github.io/activitypub-http-signature/#authorized-fetch">authorized fetch</a>. No need to create throwaway accounts on production instances.</p> </li> </ul> <p>I'll also share production stories: <a href="https://activitypub.ghost.org/day-4/">Ghost chose Fedify</a> for federating their publishing platform rather than implementing the protocol themselves. Hollo demonstrates single-user microblogging with full Mastodon API compatibility. <a href="https://hackers.pub/">Hackers' Pub</a> shows how a developer community can integrate with the fediverse.</p> <p>Whether you're building a new federated service or adding ActivityPub to an existing app, this talk will show you how Fedify turns months of protocol wrangling into days of actual development.</p>
<p>Friendica has been part of the Fediverse since 2010, building bridges between Laconica and Diaspora*, making it one of the oldest active projects of the Fediverse - yet Friendica has flown under the radar most of the time. After the great success of part I of the saga, Michael and Tobias want to present you part II.</p> <p>In this talk, we will expand on <a href="https://archive.fosdem.org/2025/schedule/event/fosdem-2025-5289-friendica-under-the-radar-since-2010/">our brief introduction</a> from last year, showcasing additional features and the latest developments in the 2025 release of Friendica.</p> <p>You can find the Friendica project homepage at <a href="https://friendi.ca">friendi.ca</a>; the source code for the core is maintained on GitHub, and the add-ons are maintained on git.friendi.ca.</p>
<p>Death is inevitable, yet most of us are woefully unprepared. Fear and lack of time often prevent us from putting our affairs in any order, leaving our loved ones to pick up the pieces of a difficult period compounded by uncertainty. While a legal will can address the distribution of assets, it often falls short in capturing the nuanced personal wishes that truly matter.</p> <p>In this talk we will propose how machine readable wishes could be used to provide to connect to the fediverse and provide digital legacy to friends and followers. In line with the wishes of the dead.</p> <p>This is a 10min talk</p>
<p>Introduction</p> <p>For those who are not completely familiar with Mobilizon, a presentation of Mobilizon collaborative platforms and their main functionalities (create groups, publish events...) https://mobilizon.org/</p> <p>1/ New features</p> <p>An introduction to the new features developed in 2025, thanks to an NLNet grant (https://nlnet.nl/project/Empowering-Mobilizon/).</p> <p>2/ Mobilizon and the fediverse</p> <p>Some feedbacks after implementing Fediverse Enhancement Proposoal regarding events: "FEP-8a8e" (https://codeberg.org/fediverse/fep/pulls/430</p> <p>Conclusion</p> <p>Road map and vision for 2026</p>
<p>The "social web" is at a crossroads. To have a meaningful impact on society means growing beyond our roots among tech enthusiasts and social misfits. But growth and change cannot sacrifice the core values that differentiate the social web from closed media systems.</p> <p>This talk will be one part a manifesto for the social web, and one part technology demonstration showcasing Emissary -- my proposed solutions for the challenges ahead.</p> <p>https://emmissary.dev https://bandwagon.fm https://atlasmaps.org https://qwertylicious.dev</p>
<p>Let’s gather designers, frontend developers and WordPress users interested in free/libre workflows for building modern websites. We’ll discuss static front-ends, no-code visual builders, headless CMS, and how tools like Silex can fit into this ecosystem. The goal is to share experiences, compare approaches and connect people who want a more sustainable, maintainable and libre way to build websites</p>
<p>There is something between binary and quantum. Binary computing has reached the limits of scaling while Quantum computing needs a century more research to become practical available. Ternary computing is possible and exciting. We are enthusiastic on what we have done so far (motherboard, CPU in FGPA, communication via serial, an assembler, a deassembler, a compiler for a rust-like language, emulator, debugger and many plans.</p> <p>Let's talk about ternary logic, gates, practical applications and what you'll need.</p> <hr /> <p>changing the world, -1 trit at a time</p>
<p>Free Software is a great way to share ideas, solutions and make the world a better place. We all know that already, but sometimes it is helpful to gather with like minded people in my own country, to drink something and have fun, while we think about how can we leverage free/open source for a better society.</p> <p>This BoF is the place for gathering Portuguese and get to know each other. Also, a light overview about "Public Money? Public Code!" and "ANSOL - Associação Nacional para o Software Livre"</p>
<p>GNU Radio users and developers getting together to have a chat!</p>
<p>A collaborative working session on mapping, triaging, and coordinating 2038-class rollover remediation across the open source ecosystem — where the real problem isn’t ancient systems, but invisible dependencies.</p> <p>The 2038 problem isn’t waiting in retired Unix servers. It’s 32-bit <em>time_t</em> assumptions still being baked into modern libraries, protocol implementations, and embedded toolchains shipping today. Many 64-bit systems depend on components that simply cannot represent time beyond 2038 — asbestos in the walls, not a single leaky pipe.</p> <p>This BoF runs a collaborative thought experiment: if your government demanded a credible 2038 exposure assessment in 12 weeks, where would you actually start? What tooling exists? What’s missing? How do findings at the repository level roll up into something actionable?</p> <p>To ground the discussion, we’ll introduce the <em>2038-Class Risk Exposure Matrix</em> — a lightweight framework for comparing unlike risks across impact, uncertainty, remediation difficulty, and blast radius — along with a <a href="https://creativecommons.org/licenses/by/4.0/">CC BY 4.0</a> workshop and full facilitation plan designed to help teams inventory their systems, surface unknowns, and translate technical findings into clear, decision-grade signals.</p> <p>→ <a href="https://propertools.be/commons/2038-exposure-matrix/">Here is the Matrix, with workshop and facilitation materials</a></p> <p>Distro maintainers, embedded developers, and infrastructure engineers are invited to share inventories, swap remediation strategies, identify high-impact targets, and surface coordination gaps. We’ll map the technical landscape and connect the people already working on the problem.</p> <p>Bring your war stories — your known-knowns and your known-unknowns.</p>
<p><a href="https://archlinux.org">Arch Linux</a> is a lightweight and flexible rolling release Linux distribution that focuses on simplicity, modernity, pragmatism, user centrality and versatility.</p> <p>Members of the Arch Linux staff have historically always attended FOSDEM. This BoF session will give a status update on the distribution, adjacent projects and future plans.</p> <p>There will be a short presentation followed by a Q&A session with Arch Linux distribution maintainers and project developers.</p>
<p>Localization of free software is essential, yet often left in an unwell condition even in significant projects used by many. But it's what makes software truly yours! Come and share your experience with the localization process of your projects. Leave inspired. Let's chat about what you find important in localization, what makes you happy, and what complicates it for you. What do you want the best libre localization to have and provide to its users?</p> <p>A space for the localization community where every hacker can share their experience and make FOSS localization better, not only confident speakers with selected talks.</p> <p>Like each year, every person interested in localization is welcome! The Weblate team will be there. We will be gathering feedback, discussing collaboration within the community, Weblate plans, features, bugs, and more.</p> <p><a href="https://weblate.org/">project website</a> <a href="https://github.com/WeblateOrg/weblate/">main repository</a></p>
<p>In this BoF teams from PenPot and KDE will come together to review:</p> <ul> <li>Challenges in sharing PenPot files in a distributed development model like KDE</li> <li>Organizing best practices for sharing and organizing public design system information</li> <li>Review ways to receive updates to design system libraries</li> <li>Review access restrictions in PenPot to secure design systems</li> <li>Develop easy entry points for new designers to help with an Open Source design system</li> </ul>
<p>Come discuss Bevy Engine !</p> <p>Bevy is a thriving permissively-licensed open source game engine written in Rust. It focuses on modularity, performance and developer ergonomics, using a modern GPU-driven rendering architecture and an ECS-first approach to engine and game logic. Check it out at https://bevy.org/.</p> <p>As an ice-breaker, we'll start with a short demonstration of a mobile game built with Bevy, followed by an open chat about its inner workings or any other topic about bevy, come if you're curious!</p>
<p>SURF is the IT cooperative of education and research in the Netherlands. SURF Research Cloud is one of SURF's services. Since 2020, we provide thousands of Researchers from all Dutch Institutes with powerful, easy to use infrastructure and tools. SURF Research Cloud is a portal that can serve resources from a variety of cloud providers. Our main cloud provider is our own private data center, running OpenStack. We have also provided resources of other European OpenStack clusters (Ireland, Switzerland, Sweden) and commercial clouds like AWS, Azure and Oracle. Our software will go Open Source. Get in contact with us if you are interested in the adventure.</p>
<p>This Zabbix Community Meetup is an interactive session focused on open discussion, questions, and peer-to-peer knowledge sharing. Rather than formal presentations, the meetup encourages open dialogue around real-world use cases, challenges, and best practices when working with Zabbix. Participants are invited to share experiences, ask questions, exchange ideas, and connect with fellow community members in an informal setting, fostering collaboration and strengthening the Zabbix open-source community.</p>
<p>Meet and chat about open source in automotive !</p> <p>This Birds of a Feather (BoF) session at FOSDEM will focus on the growing intersection of open source and the automotive industry, highlighting the latest advancements, challenges, and opportunities for collaboration. As the automotive sector increasingly adopts open-source software, it is driving innovation in areas such as in-vehicle systems, autonomous driving, and vehicle connectivity. Key projects like Automotive Grade Linux (AGL) and the ELISA (Enabling Linux in Safety Applications) initiative are at the forefront of this transformation, providing open-source frameworks for developing scalable, secure, and reliable automotive software. This session will bring together developers, engineers, and enthusiasts to discuss how these initiatives are shaping the future of mobility and explore how open-source communities can work together to solve the unique challenges of the automotive domain.</p> <p>Attendees will have the opportunity to share experiences, discuss key technical topics such as real-time operating systems, safety-critical systems, and compliance with automotive standards (e.g., ISO 26262), and explore potential new collaborations. The session will delve into the importance of open standards, the growing need for security in connected vehicles, and how projects like AGL and ELISA enable safer, more efficient automotive software development. By fostering cross-industry dialogue and strengthening the automotive open-source ecosystem, this session aims to inspire future collaborations that can help define the next generation of smart, connected, and autonomous vehicles.</p>
<p>BoF dedicated to introduce newcomers on how to make their first contribution to GNOME.</p>
<p>Join the Zephyr RTOS community for an informal BoF session where maintainers, contributiors, and and anyone interested in hearing more about Zephyr will be discussing:</p> <ul> <li>Roadmap -- As Zephyr turns 10 this year, where should the community be focusing for the next 10 years?</li> <li>Feedback from product makers -- If you are building actual products with Zephyr (yes, even as a hobby!) come and share your experience, both positive and... less positive.</li> <li>General Project Health -- BoFs are always a good "reality check" and participants are encouraged to bring their feedback with regards to things we could be doing better in our community.</li> </ul>
<p>A space for DevOpsDays and Cloud Native Days conference organizers to share experiences, swap tips and connect with peers building community events. </p> <p>Whether you're experienced or just curious about getting involved, this BoF is a space to connect, collaborate, and support each other.</p> <p>The common thread is working on building building locally rooted conferences, meeting each other and sharing experiences.</p>
<p>Passbolt is an open source credential manager designed for collaboration. This Birds of a Feather session is an opportunity for the Passbolt community to come together in person to openly discuss the future of the project. This BOF is designed as an informal, interactive discussion. </p> <p>The session will focus on three main goals: - Collecting feedback on existing features, workflows, and pain points - Shaping and discussing the Passbolt 2026 roadmap with end users - Creating direct space for technical questions with maintainers</p> <p>Format - Short intro and framing from moderators - Open floor discussion guided by community questions - Notes and key takeaways will be collected to inform future roadmap work</p>
<p>Linux desktop is moving to a new era, ditching complex software spaghetti with years of tech debt with… a protocol? That's it? And you expect some compositor projects replace the almighty X server? Replace just the X server? When the protocol's the limit, we can do far more and far more fun stuff!</p> <p>We'll explore some more-or-less obscure uses for Wayland compositors and an embedded case study how simple task of porting DOOM to a router ended up with making it run basically all modern Linux desktop apps with it for free, with Rust.</p>
<p>In 2026 the KDE project will turn 30, an extraordinary milestone in such a fast-paced ecosystem. </p> <p>In this talk, we'll explore the challenges we have faced over the years and how the KDE community has adapted to stay relevant, continuing to deliver a good experience for people to use on their computers ranging across laptops, mobiles and even gaming consoles.</p> <p>After glancing through our historical context, we'll discuss what's in store for KDE today and how we’re preparing for a bright and sustainable future in the evolving Free Software landscape.</p>
<p>Personal or professional - Linux on the desktop matters! It’s the daily interface between users and digital sovereignty – and it’s often put last. While Linux rules the cloud, servers, and mobile devices, the desktop is where control, compliance, and independence become tangible. This talk explores the current state of Linux on the desktop in Europe, with a focus on two real-world case studies from a leading automotive company and the German government. We’ll examine success stories, roadblocks, and new approaches like immutable Linux, zero-trust models, and EU-level OS initiatives. If we ignore the desktop, we risk leaving the front door of digital sovereignty wide open – or we can start where it matters most: every desk, every user, every day.</p>
<h1>Windows 10 is now end of life!</h1> <h2>... but not dead. Yet.</h2> <h4>The prospect of that alone should be enough to motivate change to Linux desktops - but various governments are providing a lot more reasons to move, such as...</h4> <ul> <li>tariffs (on goods and possibly services)</li> <li>unreliability (in trade and defence partnerships)</li> <li>increased need for data sovereignty ....to name a few.</li> </ul> <p>I've been part of migration projects most of my career, so in this talk I'll present some of the big picture items to consider when you are promoting the idea of migrations to Linux - such as politics, cost and practicality.</p> <p>Thankfully the growing movement to cloud based applications has reduced Windows dependencies, so it is now easier than ever to migrate to a Linux based desktop solution.</p> <p>I'll introduce you to someone called Horace and help you to get him to YES.</p>
<p>Why Office is not as easy as you might hope. Come and hear about office algorithms & data structures, as well as the interesting engineering challenges of interoperability from the Libre / Collabora Office experience.</p> <p>Hear how many decades of accumulated backwards compatibility can make life particularly interesting. See why the temptation to start a new office suite from scratch overwhelms many people from time to time, and get some insights into the compromises that brings.</p> <p>Hear about a code-base that has been loved over decades - through many tech fashions: from Java to component programming; from OS/2 to today's advertising subsidized platform of the future: the Web; from CADT methodology, to CRDT data structures; from bundled python to bundled databases.</p> <p>Hear about the incredible lack of user focus that has plagued decisions and made many things worse.</p> <p>Then hear our vision on driving FLOSS Office to take over the world and progress to date; see a number of pretty pixels to sooth your eyes chosen from the ergonomic beauty that is coming to make open source rock.</p> <p>Finally hear how you can get involved with Collabora Online & LibreOffice.</p>
<p>Libreboot is a coreboot distribution — just as Debian is a Linux distribution — providing fully free (libre) boot firmware for x86 and ARM systems. It replaces proprietary BIOS/UEFI firmware, initializing hardware and starting your operating system. Linux and BSD operating systems are well supported.</p> <p>Coreboot provides essential hardware initialization and then jumps to a payload program that boots your OS. Libreboot provides several payloads including, but not limited to, U-Boot, SeaBIOS and GRUB. Firmware images are provided pre-compiled, for ease of installation.</p> <p>Libreboot began in 2013 and, as of September 2025, is an official Associated Project of Software in the Public Interest (SPI), joining long-established Free Software initiatives such as Debian. This talk will be presented by Leah Rowe, Libreboot’s founder and lead developer.</p> <p>Firmware freedom is more critical than ever as we increasingly depend on computing, for participation in every aspect of civil society. Proprietary firmware endangers privacy, ownership, and repairability. Libreboot ensures that users truly control their hardware — protecting both user freedom and hardware longevity — while promoting a sustainable culture of hardware reuse.</p> <p>Libreboot provides faster boot speeds, better security, and greater flexibility than typical proprietary firmware. Libreboot continues to provide updates — including security updates — long after vendors have dropped official support. The project’s philosophy is simple: you should keep using your hardware until you decide otherwise. Planned obsolescence is only a lack of imagination. Unlike the vendors, we will not try to control the users; our goal is to set you free!</p> <p>This talk will trace Libreboot’s long-term development history, its current progress, and its future roadmap. This talk will also include a live demonstration showing how easy and affordable it is for non-technical users to build and install Libreboot via automation. Libreboot makes free firmware accessible, practical, and even fun, empowering even non-technical users to take back control.</p> <p>At the time of this talk, Libreboot 25.12 (December 2025) also includes a Tianocore UEFI payload and extensive new hardware support — including hundreds of Chromebooks, several Intel Alder Lake platforms, and numerous Kaby Lake and Skylake ThinkPads. These additions, the result of sustained work throughout 2024 and 2025, mark a major expansion of Libreboot’s scope and capability.</p> <p>Libreboot’s main code repositories are hosted at: <a href="https://codeberg.org/libreboot">https://codeberg.org/libreboot</a></p> <p>Libreboot’s SPI association provides fiscal sponsorship, ensuring transparent management and legal protection for the project. Libreboot also receives corporate support from Minifree Ltd, operated by Leah Rowe, which provides computers pre-installed with Libreboot firmware.</p> <p>Libreboot is a community project and we welcome every new contributor. Join us on Libera IRC (<code>#libreboot</code>) or via our SourceHut mailing list to participate.</p>
<p>At Wikimedia Foundation, we run Wikipedia, the world's favourite encyclopædia and one of the top ten websites of the Internet! No unicorns, just hardware, open source, and a small engineering org.</p> <p>This talk pulls back the curtain on the stack that keeps Wikipedia fast, reliable, and resilient at global scale. Caching layers, databases, microservices, and Kubernetes are all stitched together to serve the world.</p> <p>We'll also touch on how we've brought our 25-year-old monolith into the cloud-native era, and discuss the challenges we're navigating as the ongoing ~~rise of the machines~~ surge in LLM traffic changes the game.</p>
<p>In September and October 2025, RubyGems and Bundler, the clients and package registry for the Ruby language, had most of their maintainers removed by RubyCentral, the non-profit foundation that claimed ownership of these repositories. Since then, some of these repositories have been moved into the Ruby organisation and some of the ex-RubyGems maintainers have created an alternative hosting service, gem.coop.</p> <p>I was a neutral party involved with initial mediation between RubyCentral and the maintainers before and during this transition and helped gem.coop bootstrap a governance process.</p> <p>These events have much for non-Ruby projects to learn about non-profits, governance, money and access in open-source and I will share my learnings without taking any particular side in the disputes.</p>
<p>Upgrading high load PostgreSQL databases is a challenge on its own. When having customers around the globe with tight SLAs, the requirement arises to execute these upgrades with minimal or even no downtime at all. This talk shares GitLab's journey from multi-hour maintenance windows to truly zero-downtime upgrades for our PostgreSQL infrastructure. You'll learn the battle-tested techniques we've developed over the last 4 years, like how we execute PostgreSQL major upgrades and OS (glibc) upgrades at the same time, prevent data corruption, as well as always keeping a rollback path via reverse replication. We'll walk through real production examples, the gotchas we discovered, and the tooling we built. Whether you're managing a single HA cluster or a global fleet, you'll leave with actionable strategies to minimize (or eliminate) downtime during your next major upgrade.</p>
<p>1000 years ago in the Package Management devroom at FOSDEM 2018 I gave a talk entitled <a href="https://archive.fosdem.org/2018/schedule/event/how_to_make_package_managers_cry/">"How To Make Package Managers Cry"</a>, where I presented a range of techniques that open source software projects can apply to make the life of package managers utterly miserable.</p> <p>In many ways, the world is a different place since then... Never in my wildest dreams could I have imagined that this was just the tip of the iceberg. Open source enthusiasts have come up with many more and even better ideas!</p> <p>Come and learn about the creative yet tremendously effective ways in which open source software projects (and the broader ecosystem) have taken things to the next level to make package managers scream.</p> <p>You may also get to know a couple of tools that (for some reason) try to counter these best practices, to great dismay of the open source software community.</p> <p>If you too want to make package managers scream, don't miss this talk...</p>
<p>The integration of Open Source Software (OSS) in functionally safe systems represents a critical intersection of innovation and compliance requirements across multiple industries. This talk examines two complementary aspects of this evolving landscape: the current state of OSS in functional safety applications and the persistent barriers hindering wider adoption.</p> <p>2024/2025 have marked significant acceleration in the visibility and adoption of OSS in safety-critical environments, with diverse projects demonstrating varying levels of maturity. Foundation-backed initiatives like the ELISA project within the Linux Foundation are establishing frameworks for Linux in safety applications, while specialized operating systems such as Zephyr and Xen continue to gain traction. The Eclipse Foundation's Safe Open Vehicle Core (S-Core) project represents another significant advancement, aiming to create a common certifiable automotive middleware stack that addresses critical safety requirements. The ecosystem now spans from microkernel solutions like L4Re and seL4 to full-featured platforms, with Linux serving as a prime example of the opportunities and challenges in this space. Infrastructure improvements like the SPDX safety profile address critical aspects of safety documentation in Software Bill of Materials (SBOMs), while safety-certified components like the Ferrocene Rust compiler create new possibilities for language-level safety guarantees.</p> <p>Despite this progress, substantial barriers impede broader OSS adoption in functionally safe systems. A particularly persistent challenge remains the confusion around terminology and approaches - exemplified by the distinctions between "safety Linux" versus "safe Linux" that illustrate broader issues in how safety responsibility is allocated between OSS components and system-level mitigations. By examining architectural concepts currently implemented in production systems or under development, this talk cuts through marketing rhetoric to provide clear distinctions between approaches across various open source technologies.</p> <p>The author will address uncertainty around certification pathways, challenges in establishing sufficient evidence for safety arguments, fragmented governance models, and incomplete understanding of OSS development processes among safety assessors.</p> <p>Attendees will gain practical insights for evaluating safety approaches in OSS-based systems, including key questions to ask when assessing different safety concepts across industries, with particular emphasis on applications where both manufacturers and suppliers are seeking to implement open source software in safety-critical production systems.</p> <p>Links to relevant example projects as part of the talk are available in the resources.</p>
<p>In September 2024, the good name of crates.io was invoked and besmirched by a phishing attack that targeted the owners of many popular crates, much as other language ecosystems had been the target of attacks in the preceding couple of weeks.</p> <p>This talk will go over how this all went down, what we did, and how a worldwide Rust Project <-> Rust Foundation <-> Alpha-Omega collaboration was crucial in its rapid mitigation.</p>
<p>Over the past few years, <a href="https://github.blog/security/supply-chain-security/introducing-npm-package-provenance/">npm</a>, <a href="https://blog.pypi.org/posts/2024-11-14-pypi-now-supports-digital-attestations/">PyPI</a>, <a href="https://github.com/ruby/rubygems/pull/8239">RubyGems</a>, and <a href="https://central.sonatype.org/news/20250128_sigstore_signature_validation_via_portal/">Maven Central</a> have implemented attestations to provide build provenance: linking a package to its exact source code and build instructions. Some of these ecosystems also implemented publish/release attestations detailing exactly what files a specific version of a package should contain. These attestations are distributed as Sigstore bundles, so we'll start out by going over enough <a href="https://www.sigstore.dev/how-it-works">Sigstore</a> to understand how to verify and get the attestation information from these bundles, the APIs to get these attestations for each ecosystem, and discuss the implementation tradeoffs made by each ecosystem, as well as alternatives for non-programming language ecosystems to consider.</p>
<p>Package management systems tackle resolving package dependencies in different ways, which usually involves associating a package a name and version at least. In this talk I am doing a bit of an exploration of the solution space, including how dependencies are resolved in: - a language specific package manager with a lock file (example: cargo https://doc.rust-lang.org/cargo/) - by a typical distribution (example: Debian https://www.debian.org/ ) - by Nix(https://nixos.org/) and Guix(https://guix.gnu.org/) (example: Guix) Then I will reflect on these solutions from the perspective of reproducible builds(https://reproducible-builds.org/).</p>
<p>Package managers are legion. Every language and operating system has its own solution, each with subtly different semantics for dependency resolution. This fragmentation prevents multi-lingual projects expressing precise dependencies across language ecosystems, means external system and hardware dependencies are implicit and unversioned, and obscures security vulnerabilities that lie in the full dependency graph. We present the Package Calculus, a formalism for dependency resolution that unifies the core semantics of diverse package managers. Through a series of formal reductions, we show how real-world package manager features reduce to our core calculus. We define the language Pac to translate between distinct package managers and show we can perform dependency resolution across ecosystems.</p> <p>Get in touch at https://ryan.freumh.org/about.html</p> <p>See the slides at https://ryan.freumh.org/talks/slides/2026-fosdem-pac.html</p>
<p>While reproducible builds provide a gold standard for artifact integrity, they often treat the build process itself as a black box: either it matches or it doesn't. But in an era of sophisticated supply chain attacks like the XZ backdoor and Shai Hulud, understanding why a build behaves the way it does is just as critical as the final output. To secure the open-source package ecosystem, we needed to look inside this black box. In this talk, we explore how OSS Rebuild instruments the build environment to detect "badness" in real-time. We detail our open-source observability suite, featuring a transparent network proxy for uncovering hidden remote dependencies and an eBPF-based system analyzer for examining build behavior in fine detail.</p>
<p>At FOSDEM 2018, we introduced Package-URL (PURL: https://github.com/package-url/purl-spec), a "mostly" universal URL to identify and locate software packages: https://archive.fosdem.org/2018/schedule/event/purl/</p> <p>Now, PURL is an international standard to accurately and consistently reference packages across ecosystems, regardless of whether you're working with language-specific managers, OS distributions, or containerized environments.</p> <p>This talk highlights the journey of PURL, from its first presentation to Ecma standard and planned ISO standard. We'll share how PURLs enable accurate package tracking across ecosystems for vulnerability management (PURL is now part of CVE format), tool interoperability (already adopted by security tools, SCA platforms, and package registries), and compliance and security workflows (generating accurate and actionable SBOMs and VEXs).</p> <p>Whether you maintain a package manager, build supply chain security tools, query packages or vulnerability databases, or just want better visibility into your polyglot dependencies, you'll learn how this lightweight standard is the essential infrastructure for modern software ecosystems.</p>
<p>Package manifests record source-level dependencies: <em>pandas</em> depends on <em>numpy</em>'s code. The story is different for binary dependencies: <em>numpy</em> depends on <em>OpenBLAS</em>'s binaries, but package managers can't easily see this. We must map the OSS ecosystem's binary dependency relationships to reliably (1) identify upstream security vulnerabilities and (2) properly credit and financially support maintainers. I propose solving this problem by creating a global index of binary dependencies, using a <em>global linker</em> that tracks binaries' symbols across the entire Open Source ecosystem, combined with auxiliary strategies like statically analysing build recipes. (<a href="https://hackmd.io/@vladh/binary-dependencies">read more</a>)</p>
<p>Package registries are critical infrastructure used by almost all software. As they scale, package registries become critical points of supply chain security. They also become leveraged points of attack. Most registries operate on dwindling funding from grants, donations, and in-kind resources while facing increased costs across every facet of their operation and development. Something has to change.</p> <p>The Alpha-Omega project has been raising the alarm, funding security improvements, and exploring a revenue-generating options with the major package registries. This is a hard problem with multiple players and tradeoffs. </p> <p>This talk will go over the economic models underlying package registries, the security risks and expectations, and look at some of the revenue experiments happening today.</p>
<p>Homebrew released v5.0.0 in November 2025. I'll walk through some of the major changes that landed in that Homebrew version, what expectations we're aiming to improve based on other package managers and things other package managers could learn from Homebrew's approach.</p>
<p>The gaming industry, outside of console and mobile games, is mainly focused on three operating systems: Windows, GNU/Linux, and macOS. This leaves FreeBSD with a library mostly restricted to open-source native games. These restrictions may decrease the interest of new and current gaming users for FreeBSD as their main OS as they are accustomed to having access to a wider variety of games (as is the case for GNU/Linux ). Today, thanks to a handful of contributors and through the use of Linuxulator or Wine FreeBSD users have the necessary tools to enjoy gaming :) Firstly, the port of Steam, which allows us to run both GNU/Linux games on FreeBSD under a chroot, and the multiple ports of wine, wine-devel, and wine-proton, which will enable us to play Windows games under FreeBSD. Secondly In addition to these ports, the upstreaming first approach with Wine allowed us to quickly update the Wine version available after a release. This talk will shed a light on the available compatibility tools and how we can leverage these tools to improve the gaming experience on FreeBSD.</p> <p>Links to the mentioned project: https://docs.freebsd.org/en/articles/linux-emulation/ https://www.winehq.org/ https://github.com/shkhln/linuxulator-steam-utils https://github.com/ValveSoftware/wine https://github.com/shkhln/libc6-shim</p>
<p>FreeBSD has first tier level support in Valgrind. Valgrind on illumos works fairly well. They are both supported "out of the box" in upstream Valgrind.</p> <p>The other BSDs are not in the picture, which is a shame since there aren't too many fundamental differences between the BSDs.</p> <p>This talk will be about what needs to be done in order to be able to get Valgrind up and running on DragonFly/Net/Open BSD. I'd like it to be both a source of information for anyone that would like to work on Valgrind and also a source of motivation.</p> <p>This isn't a promise that I will have the time to do this development work!</p> <p>Talk that I gave at Fosdem 2022 (video only, during Covid) https://archive.fosdem.org/2022/schedule/event/valgrind_freebsd/</p> <p>Here is the upstream Valgrind web site https://valgrind.org/</p> <p>And the upstream git repo https://sourceware.org/git/valgrind.git</p> <p>Here is a repo that I used when I was adding arm64 support to FreeBSD Valgrind https://github.com/paulfloyd/freebsdarm64_valgrind</p>
<p>NetBSD 11 introduces a new MICROVM kernel that can boot in QEMU in about 10 ms, thanks to PVH support, MMIO VirtIO devices, and various low-level optimisations. Building on this foundation, we created <a href="https://smolBSD.org">smolBSD</a>, a meta-OS and microVM generator that assembles tiny, versatile and fully isolated services using the MICROVM kernel plus selected pieces from NetBSD and pkgsrc. Recent work by Pierre “khorben” Pronchery enables even faster startup by embedding the root filesystem as an initrd-style RAMdisk. This talk presents <a href="https://smolBSD.org">smolBSD</a>’s design, capabilities, and how it enables ultra-fast, minimal, and reproducible micro-services.</p>
<p>The OpenSolaris Operatingsystem came with one Component that always fascinated me and I am using extensively to package the OpenIndiana Operating System. This talk shows IPS History (why it was created and how) What it currently can do. The Concepts used (Repositories, Packages, FMRI, Facets, Variants, and Manifests, History) and what you can do with them and what IPS does with them. And why Self-Assembly is a major factor in that. As last section I will also talk about porting IPS to rust and Improvements we can make thanks to 10 years of technology advancement since it's Original creation. https://github.com/openindiana/ https://github.com/OpenIndiana/pkg5</p>
<p>Swift is a general-purpose programming language often associated with app development for the Apple ecosystem. Over the years, Swift has extended its reach and is now a cross-platform language with support for Linux, Windows, and more recently, Android. Now, we are bringing Swift to FreeBSD and there are truly devils in the details. How do you start porting a language to a new environment? How do you debug issues before you have a working debugger? This is the story of how we overcame challenges like these while porting Swift to FreeBSD.</p>
<p>It is no secret that certain applications, such as firewalls, routers, and hardened web services, perform best on BSD systems. Yet Linux dominates cloud infrastructure, forcing users to either port these applications or run them as full BSD virtual machines, each requiring special handling and management. This talk presents <code>urunc</code>, a container runtime for unikernels and single-application kernels that enables BSD workloads to run efficiently in Linux environments. <code>urunc</code> executes BSD applications in tiny microVMs and software-based sandboxes while integrating them seamlessly with existing Linux container platforms. This allows Kubernetes and similar systems to manage BSD workloads alongside Linux containers without extra effort or special handling. A live demo will walk through building, packaging, and deploying BSD applications with urunc, with initial performance metrics on startup time and network throughput, showing that BSD applications remain practical even in BSD-“hostile” environments.</p>
<p>In this talk I will: * introduce the unusual I/O needs of databases and PostgreSQL's new I/O architecture and direction * show how PostgreSQL works on FreeBSD, NetBSD, OpenBSD and illumos today * compare those systems' available support for native asynchronous I/O with Windows and Linux * speculate on the pathways that need to be drilled through their kernels to achieve the state of the art * speculate on the API design constraints and options I see * discuss OpenZFS's exciting new direct I/O and block cloning features and their relevance to PostgreSQL * show-and-tell some experimental patches for full-featured direct I/O on FreeBSD's UFS * show-and-tell some experimental patches for PostgreSQL with FreeBSD's native AIO and <code>kqueue</code></p> <p>My goal is to provide a database hacker's take on the I/O concerns that "go together" and explain how and why they are linked. It is written for a cross-project kernel and file system hacker audience, a rare opportunity provided by this FOSDEM devroom. The presentation begins with a high-level problem space overview, before diving down to user space, VFS and device levels to discuss the options as I see them. It includes some exploratory patches developed over the past few years of working full time on PostgreSQL I/O, porting and testing on ~10 operating systems, and hacking on FreeBSD for fun and education.</p> <p>It is a 25 minute talk, broken up into 5 subtopics consisting of 5 one-minute slides, and the pace will be fast:</p> <ul> <li>What databases want and why, a 30,000 foot overview </li> <li>User space programming interfaces for asynchronous I/O</li> <li>Kernel interfaces for asynchronous I/O</li> <li>PostgreSQL on FreeBSD/ZFS</li> <li>Using FreeBSD/UFS as a starting point for database/kernel interface exploration</li> </ul>
<p>gotwebd is the web interface for browsing Git repositories provided as part of Game of Trees—a project grown out of the OpenBSD community whose goal is to develop a new version control system that relies on prior art, takes what makes Git's design great, leaves out the parts that make Git hard for us to use, and invents new parts for an end result that serves our needs.</p> <p>Other than the most obvious features, such as browsing repositories, reading commit logs, and inspecting diffs, gotwebd has a few unique features.</p> <p>First, the privsep design and the use of sandboxing techniques on different operating systems; then the built-in SSH "web" authentication for access control, which also serves as protection against relentless AI scraping; and finally, the ability to directly serve static web content from a Git repository without the need for CI or external hosting.</p> <p>In this talk, we'll walk through the design of gotwebd, its evolution over time, and present its unique features in detail.</p>
<p>We live in an age where internet is a requirement for our own leisure, whether it is to work from home, keep in contact with our family or our own leisure. It is common to hear about how some company we trusted with our data has been hacked, and all our data is now floating around the internet. Many of us take steps to increase the security of our laptops, and our mobile phones. Some of us reject the use of SaaS products (such as Google Drive, Dropbox, Discord etc) and host our own, either on our own hardware or hardware rented in the cloud.</p> <p>Unfortunately, this often leads us to assume that our local network is secure, thinking only about the security of our services and not the connectivity to them. Many routers issued to consumers by an ISP or bought often miss security patches and reach EOL within a very short lifespan. It is also not uncommon for these routers to have their own custom configuration format, which is device specific, making migration to new hardware more difficult.</p> <p>Introducing OpenBSD, "free, functional and secure"! Any old hardware could become a router, that Raspberry Pi you have lying around? That old desktop you do not use anymore? OpenBSD comes with all the software you need for a router (and more!) within the base system.</p> <p>Join me, and lets discuss how to keep your network secure, and give you more control over your network.</p>
<p>CryptPad is a collaborative office-suite that is end-to-end encrypted and fully open-source. The project has been operating for over 10 years and is used to collaborate on millions of documents each month on the flagship instance cryptpad.fr. In this talk we will introduce the product and its suite of applications. We will highlight some recent achievements from the last year including</p> <ul> <li>an updated look and feel;</li> <li>a re-write of our server;</li> <li>improvements to office applications;</li> <li>and a new CryptPad embedding API.</li> </ul> <p>We will also recap the financial situation of the project, and our plans looking ahead towards sustainability.</p>
<p>2025 has been a crazy year for open source, self hosted collaboration. As in, everyone has woken up to the risks of having an entire economy depend on 3-4 big American tech firms. Well, we at Nextcloud have been working to solve that since we started in 2016 and the large roll-outs recently, of millions of users at various public sector organizations across Europe. And now suddenly everyone else starts talking about it?</p> <p>Well, we’re at FOSDEM, so all we care about is… features. That, and self hosting of course. It is more fun. And who doesn’t want to stay in control?</p> <p>So, like every year, I will go over everything we did in Nextcloud in the last year. Is it feasible to do that in a single talk? Of course not, but I’ll try anyway, and you can judge me.</p> <p>See you in Brussels!</p>
<p>“Privacy-invasive cloud services,” “isolated users” and “small, disconnected instances” are what comes to mind when we think of self-hosting. It gives users control, but it also isolates them, with each server becoming a separate island.</p> <p><a href="https://cloudillo.org/">Cloudillo</a> changes this. It is a self-hosted application platform that makes collaboration extensible, privacy-preserving, and organic — letting groups and organizations collaborate freely across different installations without relying on any centralizing infrastructure, while keeping their data private and under their control.</p> <p>At its core, Cloudillo provides all the building blocks of a modern collaboration suite: file storage, real-time database, live editing, social interactions, and user identity.</p> <p>But what’s the kicker with Cloudillo? It is that these are not closed features, but open APIs developers can use to build new applications that integrate seamlessly into the platform. A built-in DNS + PKI-based identity layer enables people and organizations to connect securely, exchange data, and seamlessly share both content and applications across independently hosted Cloudillo instances — without any third-party coordination service.</p> <p>Cloudillo’s entire backend is delivered as a single 30MB Rust binary, with no external dependencies. It emphasizes simplicity, performance, and security. Developers can deploy it in minutes, extend it in Rust, or build applications in TypeScript, then immediately gain access to a global framework for distributed collaboration.</p> <p>This short talk introduces the concept behind Cloudillo, explains its technical foundations, and demonstrates how developers can create their own apps — apps that reach beyond a single server, thanks to Cloudillo — the platform that aims to make privacy-first collaboration not just possible, but convenient and open for innovation.</p>
<p>Taiga is a Spanish open-source project management software that was created in 2014. After achieving success with over 20 million users, a rewrite is started in 2021 in order to modernise the application. However, this soon came to a halt: the original team is no longer able to continue the project. So, after 10 years of development and with many users eagerly awaiting this sequel, is this the end?</p> <p>Thanks to the magic of open source, the story continues. A French cooperative that was also working on Taiga, took the project under its wing, ready to start afresh.</p> <p>Join us to discover the origins of Tenzu (formerly Taiga-Next), find out where we are now, and learn about our future plans.</p>
<p>Join me for a fast-paced tour of OpenProject’s most impactful updates over the past year—from powerful portfolio management enhancements to much requested service management features, such as internal work package notes.</p> <p>This session will also spotlight our long-term tech strategy to bring real-time text collaboration to every corner of the platform, enabling teams to co-create work packages, meeting notes, and other project management artifacts with ease. Discover how we’re leveraging and extending BlockNote, the rich-text editor already powering applications like openDesk’s Notes and Mijn Bureau’s Docs, to bridge the gap between quick te sketches and fully-fledged project plans. We’ll also invite developers to explore our BlockNote extensions, making it easier than ever to integrate work and task management into their own platforms.</p> <p>Further, I will give an outlook on our strategy to help project teams to migration from Jira Data Center and Confluence to OpenProject and XWiki respectively.</p> <p>Whether you’re a user, contributor, or developer, this talk will inspire you to reimagine collaboration in open-source project management.</p>
<p>During their most recent “100-Day-Challenges”, teams from France, the Netherlands, and Germany collaborated to co-develop sovereign public sector IT. The Netherlands is using components from La Suite Numérique and openDesk to build MijnBureau, while French and German teams continue to work together on their workspace solutions. This session explores how these cross-border collaborations tackle technical and organisational challenges and enable interoperability between different national workspaces. By sharing experiences and lessons learned, we highlight the potential of coordinated European initiatives to strengthen digital sovereignty and co-develop resilient, citizen-focused public sector software across borders.</p>
<p>It is hard to sustainably support #OpenSource as government - after all, the public sector's subsidy programs tend to be short term focused, fragmented. They are sadly doing little to shift the billions now spent on proprietary US SaaS solutions towards sovereign open source, and have little staying power and permanence.</p> <p>I'd argue the public sector should work with existing communities that have managed a sustainable financial model, commit to deploy these & shift real procurement money rather than be distracted by subsidies.</p> <p>I will keep my argument short - and leave the time for discussion!</p>
<p>In this talk, we will highlight the latest updates to BlockNote. BlockNote is a rich text editor that focuses on a modern (block-based, Notion-style) User Experience and an easy DX (Developer Experience). BlockNote is used in open source projects like Docs (La Suite / ZenDiS), OpenProject and XWiki.</p> <p>In this talk we'll give an introduction to how it works and highlight the latest developments and upcoming features, such as:</p> <ul> <li>Features for Async Collaboration: Versioning, Track Changes and Comments</li> <li>The renewed Extension system</li> <li>AI Integration</li> </ul>
<p>Cristal is a modular, extensible, and embeddable Wiki User Interface built with Vue and TypeScript. It offers a modern, polished interface using VueJS and supports offline and real-time editing. Built to be data storage agnostic, it is embeddable in several existing collaboration and knowledge management solutions (e.g., XWiki, a local file system, a Nextcloud storage, or a GitHub repository).</p> <p>In this talk, I will showcase how Cristal can be embedded seamlessly as a Nextcloud application, allowing Nextcloud administrators to provide knowledge management to their users in a few clicks. In particular, I'll highlight how past design choices helped embed Cristal in Nextcloud. But also present a return of experience of the unexpected issues faced in the process. I will also present other features developed this year (integration of the BlockNote editor, support for macros) and how they will benefit current and future Cristal users.</p>
<p>This talk is presented by Stephan Meijer (NL government, NLdoc/La Suite Docs) and Albert Krewinkel, maintainer of <a href="https://github.com/jgm/pandoc">Pandoc</a>.</p> <p>Public administrations hold millions of documents trapped in formats that are hard to reuse and often fail WCAG requirements: PDFs, legacy Word templates, ad-hoc styles. At Logius, with the NLdoc project, we were tasked with turning those documents into accessible, reusable HTML and other open formats. Our first instinct was the obvious one: use Pandoc and wrap it with some pre- and post-processing. It worked… until it didn’t. Every new edge case, every new target editor, every new accessibility rule meant more custom glue code and brittle filters.</p> <p>So we flipped the problem: instead of chaining converters, we designed a JSON-based document Abstract Syntax Tree (AST) with an OpenAPI specification and built dedicated conversion services around it. That AST now sits at the centre of a small ecosystem: PDFs and DOCX files are converted into the AST, and from there into editors such as Tiptap and BlockNote, or directly into formats such as HTML. Support for ODT, Markdown and EPUB is on the way.</p> <p>The same AST also powers the NLdoc Tiptap-based editor, where authors get real-time accessibility validation and can export to accessible formats. It also powers the import functionality in La Suite (Docs), the FR–DE–NL sovereign collaboration stack.</p> <p>In this talk we’ll walk through that journey: why "just use Pandoc" wasn’t enough, what our AST looks like, how we wired it into a queue-based microservice architecture, and how this approach turns document conversion from a one-off migration hack into an interoperability layer for accessible, sovereign collaboration tools.</p> <p>Recent versions of the document specification are available at <a href="https://gitlab.com/logius/nldoc/spec/document/-/releases">the Releases page of its repository</a>.</p> <ul> <li>The Elixir poject is available on <a href="https://github.com/docspec/docspec-ex">github.com/docspec/docspec-ex</a></li> <li>The import API for La Suite Docs is published at <a href="https://github.com/docspecio/api">github.com/docspecio/api</a>.</li> <li>The La Suite Docs application itself is available at <a href="https://github.com/suitenumerique/docs">github.com/suitenumerique/docs</a>.</li> <li>The <a href="https://pandoc.org/">Pandoc website (pandoc.org)</a>.</li> <li>The <a href="https://github.com/jgm/pandoc">Pandoc repository (github.com/jgm/pandoc)</a>.</li> </ul>
<p>The new Collabora Office brings a beautiful, ergonomic suite, based on LibreOffice to the desktop. Come hear why, in 2026 we're creating a native local application. Hear about the limitations of Web APIs, and checkout some of the metrics we have gathered around how people collaborate on-line, and the engineering decisions that flow from that. Hear about our new approaches to handle collaboration, off-line, conflicts, and forthcoming protocol to negotiate transitions between co-editing, sharing, on-line and off-line. Finally catch up with the latest in UX research, interoperabiltiy and feature improvements as well as seeing how to get involved with the project.</p>
<p>Collabora Online introduced a new feature that lets users start a slideshow for everyone who has joined the presentation. This feature can be used during meetings where, instead of sharing the screen to present something, the user can now just start the slideshow inside the presentation document.</p>
<p>Four years ago, the We4Authors initiative united several content management tools (mostly open source) to identify and document accessibility best practices in preparation for the European Accessibility Act. It was the most coordinated effort to help content authors produce accessible digital content at scale. Yet, despite the groundwork, only the recommendations have not been widely adopted. The Web Almanac confirms what many suspected: web accessibility has not meaningfully improved in preparation for the Act’s introduction. https://events.drupal.org/europe2020/sessions/top-cms-tools-are-working-together-build-more-inclusive-world.html</p> <p>Much of this was built on or extending ideas in Authoring Tool Accessibility Guidelines (ATAG) 2.0. https://www.w3.org/TR/ATAG20/</p> <p>Today, the context has changed.</p> <p>Artificial Intelligence—especially small, local language models—offers a new opportunity to deliver accessibility guidance where it’s needed most: at the moment of authoring. CMSs can leverage open source AI to suggest accessible alternatives, improve media descriptions, and identify structural issues in real time—without sending user data to third parties or compromising privacy.</p> <p>This talk will explore how we can: • Revisit the ATAG 2.0 & We4Authors guidance and align it with today’s AI capabilities. https://www.w3.org/WAI/standards-guidelines/atag/ • Integrate small language models within CMS authoring environments. • Collaborate across open source communities building on the Open Web Alliance • Build shared datasets, APIs, and modules to improve author support and accessible defaults.</p> <p>Accessibility progress requires shared effort, not just compliance checklists. Let’s use open collaboration and new tools to help every author publish content that works for everyone.</p>
<p>Digital Workplaces increasingly consolidate collaborative tools, yet telephony often remains isolated and difficult to integrate. User needs show that a unified interface, including VoIP, simplifies the user experience while reducing vendors and costs. Once treated as a silo, telephony is now starting to become a central component of collaborative platforms.</p> <p>This presentation will cover the key technical integration points for adding a a softphone application and a VoIP calling service to a Digital Workplace: embedding a web-based calling client into an existing interface, managing SSO and account provisioning, unifying call histories and presence information, ensuring interoperability between system notifications and platform notifications, and adapting the user interface.</p> <p>We will illustrate these points with a concrete example using the SIP client Linphone and the SIP server Flexisip, demonstrating how an open source VoIP solution can be technically integrated into a collaborative platform: adapting WebRTC to SIP, handling push notifications for incoming calls, retrieving call logs via an API, and more.</p> <p>The goal is to show how telephony can become a modular building block for collaboration rather than an isolated tool, and why this approach is essential for open source Digital Workplaces like Nextcloud, OpenDesk, or eXo Platform to offer a complete solution. It is only by combining the strengths of different specialized open-source software editors that it may be possible to compete with major players in the collaborative-software market, such as Microsoft 365.</p>
<p>In a world where custom JSON and binary formats thrive, HTML and XML continue to provide an open and universal system for sharing structured information. But these languages are plagued by decades of insufficient tooling which makes working with them tenuous at best. The HTML API in WordPress has introduced a safe, reliable, and convenient interface for parsing HTML to address a number of these issues; in the process it unlocks new worlds of interoperability and translation for human-authored content.</p> <p>This talk will discuss the streaming interface of this new processing pipeline and how it can be replicated in other languages and platforms. It will highlight how re-embracing HTML and other markup languages can improve interoperability between platforms and how better tooling can make working with these legacy formats less painful.</p> <p>Having a spec-compliant DOM parser is useful, but a spec-compliant and minimally-allocating streaming parser can be a game-changer in high-demand and low-latency applications. Come hear the fascinating war stories from developing such a system, how design played a key role, and ways it has already unlocked novel and high-quality features.</p> <ul> <li>https://make.wordpress.org/core/tag/html-api/</li> <li>https://developer.wordpress.org/reference/classes/wp_html_processor/</li> <li>https://developer.wordpress.org/reference/classes/wp_html_tag_processor/</li> </ul>
<p>With a live demo I will show how I distribute my (mostly long-form) content (POSSE) from Drupal (CMS) to multiple Nostr relays. After this demo I will explain the technicals details how this works (using the Nostr-PHP library https://nostr-php.dev and used Drupal modules, https://www.drupal.org/project/nostr_content_nip23, which I maintain).</p>
<p>In the last few years, we've revived the idea of a student wiki at MFF CUNI, where the last attempt had languished for years. We'll talk about the technical side – choosing a platform, the problems we encountered, and our extensive modifications – as well as the organisational side, from getting institutional backing for our project to actually getting student contributions.</p> <p>Through a combination of automated migrations and follow-up manual edits, we've consolidated a number of older, semi-abandoned platforms at the faculty to the new wiki. The entire software stack is FLOSS while also allowing integration with other university systems.</p> <p>You can see the current state of the wiki at <a href="https://wiki.matfyz.cz">https://wiki.matfyz.cz</a>, and our source code at <a href="https://gitlab.mff.cuni.cz/matfyzak/wiki/">https://gitlab.mff.cuni.cz/matfyzak/wiki/</a></p>
<p>Collaboration in the physical world can learn from the tools software developers use. Forgejo is an excellent code forge that can be repurposed for collaborative project management or a simple TODO app. This presentation explains how a PWA can be built on top of Forgejo by generating a binding for a mobile app from the api description.</p> <p>By reusing Forgejo as a backend, development time on a backend is saved and a fallback frontend exists too. The advantage lies in the ability to create a dedicated frontend for particular workflows while retaining the proven parts.</p>
<p>This talk introduces ElemRV, a lightweight open-source RISC-V microcontroller designed for accessibility and adaptability. We'll trace the project's origins and its first tape-outs using IHP's Open PDK, demonstrating how open-source silicon can move from concept to fabrication. The presentation covers ElemRV's architecture and key components, highlighting the design choices that shaped the microcontroller. We'll walk through the complete ASIC flow - from RTL source code to tape-out-ready GDSII files - demystifying the process of creating custom silicon with open-source tools. The session concludes with the roadmap for future tape-outs and planned enhancements, inviting community collaboration on this libre hardware project.</p>
<p>The f8 is an architecture for small embedded systems optimized for memory efficiency - regarding both code and data memory. We present the current state of the architecture (including the f8l variant for reduced core area), reference implementation, and the toolchain, which is based on the Small Device C Compiler (SDCC). https://github.com/f8-arch https://sdcc.sourceforge.net/</p>
<p>I have been working hands-on with FPGAs for open-source projects in distributed storage and networking. More recently, I have been interested to FPGA applications in finance and ultra–low-latency systems. Along the way, I found out that several open-source projects were immensely helpful, which made me realize that engineers and developers who want to get started could benefit from the same resources. This talk will cover the fundamentals of how, why, and where FPGAs are used in financial applications. Naturally, this talk will also highlight key open-source projects that can help the community build FPGA-based projects in this domain.</p>
<p>We will explore version 2.0 of the FABulous embedded FPGA (eFPGA) Framework and show how to design, implement, and simulate an embedded FPGA fabric. Starting from a high-level specification, we work towards a tiled and optimised, tapeout-ready physical layout (GDSII), in just a few steps.</p> <p>FABulous is an easy-to-use, free and open-source eFPGA framework covering all aspects of what an FPGA ecosystem requires, from high-level design and layout to simulation and CAD tool integration. Version 2.0 introduces the ability to automatically generate a tiled and optimised physical layout, simplifying chip-level integration significantly.</p> <p>The framework supports extensive customisation, including user-defined primitives, I/O cells, and integrating complex blocks such as CPU cores or ADCs. It has demonstrated superior area density in both standard-cell and custom-cell-based flows and has been validated across more than 15 manufactured chips, spanning 28 nm to 180 nm, including open (SKY130, IHP130, GF180) and industry (TSMC 180, 130, 28) PDKs. This demonstrates its practicality and adaptability across a wide range of design contexts.</p> <p>GitHub: https://github.com/FPGA-Research/FABulous Docs: https://fabulous.readthedocs.io/en/latest/</p>
<p>The use of programmable logic devices, such as FPGAs, requires a range of software tools, from editors for HDL design to the place and route software that maps the design to the physical device and the software that handles the actual configuration process. These are often combined into a coherent IDE to improve efficiency and ease the learning process by offering smooth transitions between the different stages of development, from writing HDL via synthesis, simulation and implementation to the configuration of the device. In the world of FPGAs, these IDEs are mostly proprietary software, developed and owned by the few big FPGA vendors, that only support their own hardware. This means that once design flows are established around one vendor’s software suite, switching to a different vendor’s hardware becomes a tedious or even entirely unworkable task. For years now, pioneers in the open-source community have been steadily working to bridge the gap between commercial and open design tools, to the point that competitive solutions now exist for many aspects of FPGA design. With all the building blocks now available we in the FEntwumS project are now working to integrate a whole range of these tools into one coherent IDE that is as vendor-agnostic as possible and, most importantly, free and open-source. As a representative case study to validate and benchmark this platform, we integrate OpenEye, an open-source and fully FPGA-compatible neural network accelerator developed within the consortium. Its scalable architecture enables us to evaluate the robustness of the toolchain across different device classes and design configurations, testing synthesis behavior, implementation quality and runtime characteristics. By using OpenEye as a practical test vehicle, we ensure transparent evaluation, reproducibility and alignment with the open-source philosophy that underpins the entire project. In this talk, we will present our approach, our current progress, issues we have encountered and our future plans.</p>
<p>The organizing team of the Devroom welcomes you to the Railways and Open Transport room. Exciting content lies ahead.</p>
<p>The public transport sector is mostly a traditional sector with an oligopolistic market situation for system solutions for travel planning and ticketing. The lock-in and dependency to few system vendors in Europe stifles innovation and impedes initiatives to make public transport more attractive. But in the Nordic countries, public transport agencies (PTA) choose an alternative path to overcome system vendor dependency through open source and by engaging in community development. Our qualitative study interviewed 13 persons from 5 different PTAs in the Nordics entails an alternative pathway where they digitally disrupted the regional or national public transport market. They choose to utilise open source for central components and engage in community development to achieve political ambitions to make public transportation an attractive alternative to car travelling.</p> <p>Our study presents a model on how organisations can co-evolve with the open source community through long-term engagement to access state-of-the-art digital technology and foster innovation. The model depicts a cumulative process that yields better opportunities the longer and deeper the engagement becomes. This enables digital transformation outcomes such as access to a global pool of knowledge, agile and adaptive value-creation, open innovations processes, partnership and synergy opportunities. The talk will present the findings from the study and how the model can be used as a tool to better understand and depicts the organisational alignment process, the inner mechanism and the possible transformative outcome of engaging in open source community development. Our findings demonstrate that also large traditional organisation within the transport sector can partially foster digital transformation capabilities through departmental engagement in community development which can radiate to other parts of the organisation. This entails alternative pathways for traditional organisation that are under demand to digitally transform. But this requires sustained resource investment and loyalty to community objectives to gain influence and trust, to access deeper collaboration and innovation opportunities. The talk will discuss both obstacles, possibilities and strategies that organisations can adopt when engaging in open source community development.</p>
<p>2025 marks a turning point for European mobility data. A significant update to the Multimodal Travel Information Services (MMTIS) regulation takes effect in March 2025. In parallel, ERA and DG MOVE have initiated a coordinated overhaul of all Transmodel-based standards, and a newly agreed TSI Telematics revision (November 2025) sets the direction for railway digitalisation from 2026 onward.</p> <p>This talk brings together Yann Seimandi (DG MOVE) and Stefan Jugelt (ERA) to give developers and open-source contributors a clear picture of the new regulatory and technical landscape. We will cover:</p> <p>What’s new in MMTIS 2.0 - How NAPCORE supports harmonised, cross-border mobility data - Upgrading Transmodel-based standards to European Norms - Specification of EUDIT, the new Transmodel-based Booking API - Development of EFIP, a unified European NeTEx Fares Profile - Alignment of TSI Telematics with the broader multimodal ecosystem</p> <p>Participants will gain insight into the impact on APIs and data models and how open-source communities can contribute to Europe’s mobility infrastructure.</p>
<p>European transport systems are adopting standards such as DATEX II, NeTEx and SIRI, but developers struggle to discover existing tools, validators, converters, and libraries. We're launching Awesome NAPCORE Tools (awesome.napcore.eu) - a community-curated registry of open source tools for European mobility data. This talk introduces the platform and invites the open source community to contribute. We'll cover:</p> <ul> <li>The European mobility data landscape and key standards</li> <li>Current challenges in tool discovery</li> <li>How the registry works and the contribution process</li> <li>Inclusion criteria and governance approach</li> <li>Vision for community ownership</li> </ul> <p>Whether you maintain a DATEX II validator, a NeTEx library, or build transport applications, we want to showcase your work and connect you with users and fellow developers.</p>
<p>We deserve open-source transit technology that is both beautifully designed and easy to use. The Mobility Database is a free, open-source platform for global transit data in the General Transit Feed Specification (GTFS) and General Bikeshare Feed Specification (GBFS) formats. These global specifications make it easier for public transport agencies, operators, and shared mobility providers (bike-share, scooter-share, car-share) to publish accurate, high-quality transit data, enabling them to share their services efficiently with the public.</p> <p>Why are we building this at MobilityData? 1️⃣ Easy access & maximum reuse of open data: Because open data should not feel like a scavenger hunt, we make it easy to find and access global mobility data for free, and with a barrier-free API.</p> <p>2️⃣ High quality of open data: We provide simple quality evaluation reports that can guide precious resources of the industry where they matter most, guaranteeing that hard work translates into the high-quality, reliable information public transport riders deserve.</p> <p>3️⃣ Strengthen the open data community by boosting the international visibility of feeds. This turns the platform into the trusted meeting ground where analysts can easily cross-reference global best practices and collaborate worldwide.</p> <p>We recently released map visualizations, the ultimate tool for the data detective 🕵: on the platform, we can now instantly see the modes, routes, stops, and coverage of any data source, making it simple to spot a rogue stop or understand a feed's architecture at a glance.</p> <p>In Europe, the Mobility Database relies on the National Access Points (NAPs) across multiple countries (France, Norway, Switzerland, Spain, Denmark, Sweden, Finland, and more). And because good open source is a two-way street we also contribute back by providing free open-source tools for our partners and making sure producers coming our way find their way to their local National Access Point (NAP). This way, no stakeholder will have to browse the entire digital continent just to get comprehensive data from their region of choice. </p> <p>This talk will explore how the Mobility Database fosters a vibrant open-source ecosystem, gives transit data the attention it deserves, and supports sustainable transport.</p>
<p>Despite EU-level initiatives, the availability and quality of open data on public transport differs wildly between member states. I'll talk about the situation in the Czech Republic from the perspective of someone who's been fighting for data availability for the last 5 years.</p> <p>We'll focus mostly on timetables, briefly covering the history of the Czech Republic's centralised system, the current state of affairs after multiple lawsuits, and the (hopefully) rosy future. I'll also talk about other datasets, like real-time positions and train composition, and also about my experience trying to fit Czech data into existing open standards and software.</p>
<p>In this talk, I will present why and how I started writing Bimba, a public transport application for my city back in 2017. The talk will show major turning points in the journey: when the city started providing open data, when Bimba no longer worked in single place, when Transitous was integrated enabling not only global coverage but also global routing, and meeting people and ideas during last year's RaOT track at FOSDEM and the first Open Transport unconference. I will also present how—with crowdsourcing—Bimba is now also a part of the community and finally, I will hint to what may come in the future.</p>
<p>Not every public transport agency publishes real-time delay information, and some do not even have it. Some of the proprietary transit apps have used user-submitted data to bridge this gap for some time now.</p> <p>This talk explores how we can do the same in open-source apps, based on <a href="https://transitous.org/">Transitous</a>. It covers the steps from collecting the vehicle positions from people's phones in an ethical way, to deriving the delay and to integrating the results with existing routing services and apps.</p> <p>In addition to allowing for the independent collection of real-time information, the components written for this project (<a href="https://codeberg.org/jbb/transitous-gps-collector/">gps-collector</a> and <a href="https://codeberg.org/jbb/gtfs-delay-tracker">gtfs-delay-tracker</a>) could potentially be useful for community buses, heritage railways and smaller public transport agencies with limited budgets.</p>
<p>In late 2025, <a href="https://dbinfrago.com">DB InfraGO</a> - Germany's state owned operator of railway infrastructure - released its <a href="https://github.com/dbinfrago/openstation-docs">“OpenStation“ API</a>, the new single source of truth for train station data. The API (or as some users have put it: "glorified collection of XML files") is based on the european <a href="https://netex-cen.eu">NeTEx</a> and <a href="https://siri-cen.eu">SIRI</a> standards, and its contents are released as CC0 (public domain), a first for Deutsche Bahn.</p> <p>In this talk, we want to share our experiences with NeTEx and SIRI from a data producer's perspective, highlight some benefits and challenges of our new API, explain its intended role within the transport data ecosystem, and discuss our future plans for OpenStation. Last but not least, we would like to hear your thoughts and feedback on our new API.</p>
<p>OpenTripPlanner is a mature, open-source engine for multimodal journey planning across public transport, walking, cycling, micromobility, and driving/park and ride.</p> <p>It supports datasources on multiple different format (NeTEx, GTFS), consumes hundreds of realtime updates per second to timetable data while delivering fast response times.</p> <p>With all these capabilities it is important to map real world as accurate as possible. </p> <p>How do you manage time-traveling trains, ghost buses, levitating trains, and how long is a staircase?</p> <p>Inconsistent data, outliers and quirky rules go head to head with configuration and algorithms in a battle to answer the questions, what is the best journey from A to B.</p>
<p>With a smartphone, users nowadays can plan public transport journeys spontaneously and react to incidents in real-time by changing itineraries on the fly, even proactively. Algorithms and UIs however are still clinging to the notion of an upfront query and journey plan that the user is blindly following as long as is physically possible.</p> <p>Similar to turn-by-turn directions for car drivers, we propose to focus on showing the user only the next best step they should take according to the real-time situation in order to eventually get to their destination, and not an entire, fixed journey plan. Instead of just the destination arrival time, we compute the probability distribution of destination arrival of the user, taking into account reliability of transfers and alternative continuations. Simulations show that on average, a user will arrive earlier than when following a classical journey planner, not only in the case of delays.</p> <p>A prototype can be used at <a href="https://tespace.traines.eu/">https://tespace.traines.eu/</a> with source code available at <a href="https://github.com/traines-source/time-space-train-planner">https://github.com/traines-source/time-space-train-planner</a>. TeSpace relies on <a href="https://transitous.org/">https://transitous.org/</a> and the <a href="https://github.com/motis-project/motis">https://github.com/motis-project/motis</a> API for global public transport timetable coverage (where available). Let's also talk about how to advance these two beyond classical pareto-optimal journeys!</p>
<p>Long ago I wanted to build an app for the local bike sharing system in my city, only to realize open data was not publicly available. Out of frustration, I built a free and open API for others to create applications, visualizations and research using bike sharing data.</p> <p>Fast forward today and thanks to the community, the <a href="https://citybik.es">CityBikes project</a> supports more than 800 cities all around the world and our API powers bike sharing transportation apps across all platforms.</p> <h3>"open" data</h3> <p>Even with the introduction of open data standards like GBFS (at this time, approx 60% of our feeds) there's a fair amount of systems that are not accessible outside of their apps. The reality of open data shatters once you look too close into it: cursed APIs, broken feeds and HTML tables.</p> <p>Our mission is to change that by providing developers, researchers and organizations the tools and resources to bridge this gap.</p> <p>In this talk, I’ll share the motivations behind the project, what it’s like to maintain it after more than a decade, and dive into the new tools and historical data systems we’re building.</p>
<p>Visualizing origin-destination (OD) mobility data—commuter flows, transit ridership, freight traffic—is essential for transport planning, but datasets can contain millions of flows that overwhelm traditional mapping approaches. In this talk, I'll present open-source tools for preparing and visualizing large-scale OD data interactively in the browser.</p> <p>I'll introduce <a href="https://flowmap.gl">flowmap.gl</a>, a WebGL-based flow map layer for <a href="https://deck.gl">deck.gl</a> that renders geographic movements with adaptive clustering and filtering. To handle large datasets, I'll demonstrate <a href="https://pypi.org/project/sqlrooms-flowmap/">sqlrooms-flowmap</a>, a Python tool that uses <a href="https://duckdb.org">DuckDB</a> with spatial extensions to prepare OD data for tiled serving:</p> <ul> <li><strong>Hierarchical clustering</strong>: locations are grouped at each zoom level using pixel-radius clustering, creating a hierarchy where clusters merge as users zoom out</li> <li><strong>Nested Hilbert indexing</strong>: OD pairs are indexed using a space-filling curve that preserves locality, enabling efficient range queries for tile-based serving</li> <li><strong>Spatio-temporal aggregation</strong>: flows are aggregated to match zoom-based clustering, with optional temporal bucketing by hour/day/week</li> </ul> <p>The prepared data can be visualized using a demo app built with <a href="https://sqlrooms.org">SQLRooms</a>, a browser-based analytics framework powered by DuckDB, where users can query and explore flows using SQL alongside interactive maps.</p> <p>I'll show a live demo using Switzerland's <a href="https://www.are.admin.ch/are/en/home/transport-and-infrastructure/data/npvm.html">National Passenger Transport Model (NPVM)</a>—an open dataset of passenger flows across the Swiss transport network—demonstrating the full pipeline from raw data to interactive visualization, all using open-source tools that can run locally without cloud dependencies.</p>
<p>In the past two years the Open Source Railway Designer (OSRD) has been presented at FOSDEM. The integrations shown there sparked our interest in testing OSRD ourselves in a practical context. In initial studies we used OSRD to evaluate capacity effects on highly congested corridors, including a scenario with a speed increase in rail freight transport. These studies show that OSRD provides a solid basis for open, reproducible capacity studies.</p> <p>However, the next crucial step in the planning process is microscopic operational simulation, which can be used to evaluate the effect of timetables and operating procedures over time and during disrupted operations. This component is not yet part of the OSRD workflow. To address precisely this gap, we have investigated how the agent-based tool SUMO (Simulation of Urban MObility) can be applied for railway operational issues. SUMO enables a detailed representation of vehicle movements along an infrastructure under a given timetable and allows delays and different operating modes to be modelled.</p> <p>In a case study on the Frankfurt underground, we used SUMO to analyse various operational concepts. This included simulations in fixed-block and moving-block operation as well as the modelling of a driverless shunting. The results show that SUMO delivers precise insights into the dynamic system behaviour and provides relevant key figures for operational evaluation - while also exposing the framework conditions and limitations of the current approach.</p> <p>Finally, we discuss the potential of linking OSRD and SUMO: from open infrastructure modelling and timetable mapping to microscopic operational simulation. We would like to outline how a consistent open source workflow for railway and light rail systems could be created and invite the community to develop it further together.</p> <p>Open Source Railway Designe (OSRD) https://osrd.fr/en/ Simulation of Urban MObility (SUMO) https://eclipse.dev/sumo/</p>
<p>You're a railway infrastructure manager. A train operator calls up, and would like to fit a new train in the existing schedule. It should leave at 10am, and it's 8am. How do you make sure this new train won't cause any traffic jams?</p> <p>Three years ago, we made a proof of concept for this complex problem (<a href="https://archive.fosdem.org/2023/schedule/event/rot_osrd/">I've already talked about it in this track</a>). Since then, we've successfully made it production-ready, and we've had users for a year now.</p> <p>We have faced new challenges, both expected and unexpected. We have made some mistakes and learned from them. We have stories to tell.</p> <p><a href="https://osrd.fr/en/">OSRD website</a> <a href="https://github.com/OpenRailAssociation/osrd">GitHub</a></p>
<p>After a successful beta run, the HackerTrain to FOSDEM is back! This time we are going distributed.</p> <p>In this talk we will present:</p> <ul> <li>how we organized a train trip for an unknown number of groups of unknown people that travel on different dates and on different routes to the same event</li> <li>lessons learnt on how to manage such chaos on a zero budget</li> <li>how the actual train rides went (hopefully with pictures!) – we expect several lines from all corners of Europe</li> <li>lessons learnt on those routes</li> <li>what are the next steps and the long-term goals for the HackerTrain</li> </ul> <p>Through this beta run of the HackerTrain to FOSDEM we hope to uncover also the potential for (massive) group travel to (FOSS) events, as well as the hurdles that we still need to overcome to make affordable, easy, comfortable and engaging cross-border public travel possible.</p>
<p>Introduction to the Modern Email DevRoom</p>
<p>There are almost half a dozen new opensource webmail systems that you can host yourself now, after a decade of little development. One of them is so good that after testing it for my work, I've grown to use it almost every day privately. Several of their developers attend FOSDEM this year and may talk about their software in depth, this talk covers them as a group. It's mostly for an audience that (may) want to self-host (again).</p> <p>What sets the new webmail systems apart from the old ones, how do they compare to Google's and Microsoft's polished offerings, how do they compare to each other? I'll talk about all of that, and since I am a standards wonk there is a risk that I may digress into how well or badly they use the standards.</p> <p>I'll mostly talk about Snappymail¸Alps, Kurrier and Mox.</p>
<p><a href="https://opencloud.eu/en">OpenCloud</a> is a production-ready Open Source "Drive" solution for storing and sharing files, and we are adding a Groupware stack to all that.</p> <p>We'd like to present our concept (especially regarding the integration of the other services in our stack, namely OpenCloud Drive and <a href="https://opentalk.eu/en">OpenTalk</a>) as well as what we have so far in terms of our implementation, which extensively uses JMAP in its middleware, in combination with a <a href="https://stalw.art/">Stalwart</a> backend that does a lot of the heavy lifting.</p> <p>The whole stack is <a href="https://github.com/opencloud-eu/">Open Source</a>, implemented in Go and TypeScript.</p>
<p>Parula: Updates on the progress</p> <h3>Apps</h3> <ul> <li>Calendar and invitations</li> <li>WebApps</li> </ul> <h3>Protocols</h3> <ul> <li>SML: Poll, Meeting time poll, Book me</li> <li>JMAP Contacts - First app to support this new RFC standard</li> <li>JMAP Calendar (soon)</li> </ul> <h3>Platforms</h3> <ul> <li>Mobile apps for Android and iOS app (alpha)</li> </ul> <h3>Links</h3> <ul> <li><a href="https://parula.app">Website</a></li> <li><a href="https://github.com/mustang-im/mustang/">Source code</a></li> <li><a href="https://archive.fosdem.org/2025/schedule/event/fosdem-2025-4887-parula-presenting-the-new-email-client/">Last year's talk - intro to Parula</a></li> </ul>
<p>In 2025, Thunderbird did something it hasn't done in over 20 years, since before even its first stable release in 2004: it grew built-in support for a new email platform. This new platform is Microsoft Exchange, the backbone of some of Microsoft's biggest communications and productivity tools.</p> <p>This talk will briefly go over the step we took to try to define how to support new platforms and protocols in an old code base, and the challenges we encountered as we worked our way towards full email support for Exchange in Thunderbird.</p>
<p>An update to my 2018 KDE Kontact / E-Mail talk showing the status and problems of an enterprise user of Kmail and Co. This was eight years ago, let's check what has changed and where we need to do better:</p> <p>https://www.youtube.com/watch?v=H8SVe6wISmY "Having been a KDE user almost from the start, over the years I have learnt lots of troubleshooting, hacking and optimizing settings in Kmail, Kontact, KDE and Akonadi. And I would like to share and learn more :-)</p> <p>I am using Kontact on a daily basis, in an environment with lots of E-Mails and Gigabytes of data and e.g. a variety of calendars. Three mail accounts, three different IMAP-Servers, five+ desktops to take care of, archiving, filtering, calendaring, using Kontact keyboard-only (almost), in mailing lists, searching, per-folder settings, import/export of data,</p> <p>I want to share my insights and get a discussion going - hopefully with the audience - that this presentation might spark with the goal of making Kontact(Kde-PIM) better. There's no other working Enterprise level Mail/Groupware Client for Linux with so many great features.</p> <p>I learnt a lot about debugging Kontact and Kmail for my needs, and even fixing with some akonaditools. I would love to present my findings and I hope to get a discussion going - with some developers? - how to:</p> <pre><code>use troubleshoot quick setup copy revert/purge </code></pre> <p>Akonadi directories, Kontact, KDE and Kmail settings and files. Akonadictl, Akonadiconsole, Baloo, ...</p>
<p>A fast-forward dialog about the state of email and security.</p> <p>In our talk we will point out real examples and funny stories as well as some interesting tools and how to combine them into a holistic mail security concept.</p> <p>We will cover famous things like the need of unencrypted Pop3, FOME - the fear of missing email, postmasters nightmare with dmarc, dkim, spf in between security and comfort focused users, arc - the layered chain of postmasters of trust - and many more. Yes, something with AI.</p> <p>It's not as bad as it maybe sounds.</p> <p>Additionally we will talk about the perfect Ratatouille for mail infrastructures - covering various established and exciting new flavors and spices. In other words, how to tie up open source components for a perfect mail security infrastructure.</p>
<p>Even Signal took years to get it right, and Matrix is not quite there yet: Implementing a multi-device chat system that supports not only reliable encryption, but also reliable deletion of messages also known as "Forward Secrecy". </p> <p>In this talk we'll present a new "Autocrypt 2 certificate" specification draft, that originated from the <a href="https://chatmail.at">chatmail</a> community and its supporters. The draft is built upon <a href="https://www.rfc-editor.org/rfc/rfc9580.html">the modern RFC9850 OpenPGP standard</a> and aims to to supports encryption that is safe against attackers that collect all in-transit traffic and then </p> <ul> <li> <p>try to use a prospective future Quantum computer to decrypt all collected messages, or </p> </li> <li> <p>try to recover deleted messages after they get hold of a device/private key. </p> </li> </ul> <p>The draft Autocrypt2 certificate specification is designed to be usable by any Internet Messaging system and is intended for submission to IETF early 2026.</p>
<p>This talk covers Rspamd development from March to December 2025, focusing on four major areas. First, HTML fuzzy hashing - a new algorithm that generates structural fingerprints from DOM trees, enabling detection of phishing emails that reuse legitimate templates with modified links. Second, multi-class Bayesian classification that extends the traditional spam/ham model to support up to 20 categories (newsletters, transactional mail, promotions) with single-call Redis lookups. Third, protocol improvements including TCP transport for fuzzy queries and encrypted ZIP archive handling via libarchive. Fourth, neural network refactoring into a provider-based architecture for combining multiple feature sources. We'll also discuss practical experience using LLM tools for code generation, documentation, and PR review during this development cycle - what worked, what didn't, and where human judgment remains essential.</p>
<p>Cascading Style Sheets (CSS) enable visual customization of HTML emails. However, this flexibility comes at a cost: in this talk, we reveal how CSS creates serious privacy and security vulnerabilities. We demonstrate that CSS facilitates fingerprinting and tracking in HTML emails, even undermining the privacy protections offered by email clients that use proxy services to access remote resources. These tracking capabilities enable targeted phishing and spam campaigns.</p> <p>More critically, we present a novel scriptless attack that exploits container queries, lazy-loading fonts, and adaptive ligatures to exfiltrate arbitrary plaintext from PGP-encrypted emails. The attack targets mixed-context scenarios—cases where email clients render both trusted (encrypted) and untrusted (attacker-controlled) HTML content within the same message view. We successfully demonstrate end-to-end exfiltration of PGP-encrypted text from Thunderbird, along with two other major email clients that permit such content mixing.</p> <p>These findings expose fundamental gaps in current isolation mechanisms, demonstrating that post-Efail mitigations remain insufficient against CSS-based attacks.</p>
<p>Email service is at the core of a collaborative suite. And, good news, FOSS solutions for all collaborative uses have an unprecedented maturity. But Europe still faces a critical dependence on Office 365, with strategic and financial costs that are now undeniable.</p> <p>The challenge is no longer functional, <strong>FOSS solutions suffer from an architectural limitation : a simple SSO does not create a platform</strong>. To offer a true Smart Platform Experience around the mail, we must go beyond silos solutions and build deep, consistent, cross-functional integration between independent services.</p> <p><strong>Based on the integration of DINUM's LaSuite into Twake.AI</strong>, we will analyze what is missing to offer a “Smart Platform Experience”: a standardized cross-functional layer that brings together independent services.</p> <p><strong>Samuel Paccoud, director of lasuite.numerique.gouv.fr</strong>, will comment this integration and the perspectives he identifies.</p> <p>We will see how such a standard can enable a modular ecosystem, where each application remains independent but can interoperate deeply, forming a credible and sustainable sovereign workplace. This is the mission of the Open Buro consortium: to <strong>create an open foundation where architecture becomes a political act</strong>.</p>
<p><a href="https://github.com/suitenumerique/messages">Messages</a> is a project from <a href="https://anct.gouv.fr/">ANCT</a>, a French government agency that aims to bring secure and modern tools to small rural towns.</p> <p>In this talk we'll introduce the MIT-licensed project and explain how the specific requirements of public servant inboxes led to a unique design, breaking free to legacy protocols like IMAP.</p>
<p>If you're following along with email standards, you know about JMAP: it replaces both IMAP and SMTP-for-sending, eliminating a lot of weird and dated protocol design with HTTP and JSON. It makes easy things easy, and also enables fast, efficient offline synchronization. It's not a new email system, just a new access protocol.</p> <p>But did you know that JMAP can also handle your calendars, your address book, your files, and plenty more things to come? This talk will describe JMAP extensions for those systems: what they are, how they work, and why you should be excited.</p>
<p>Ever wondered how Gmail, Yahoo, and Apple iCloud manage to host hundreds of millions of email accounts reliably? How do they store petabytes of messages, survive hardware failures without losing data, and keep spam at bay across billions of daily deliveries?</p> <p>This talk explores how to design and operate a large-scale email system using Stalwart, an open-source mail server built from the ground up for distributed deployments. Using a 1,024-node cluster as a concrete example, we will examine the architectural patterns that make planet-scale email possible, and how similar approaches are used by providers such as Apple iCloud.</p> <p>The session covers the full stack of distributed email challenges: storing and indexing messages across a cluster, running spam and phishing filtering at scale without becoming a bottleneck, managing distributed MTA queues for reliable delivery, and load balancing IMAP, JMAP, and SMTP traffic across nodes. We will also look at how Stalwart handles cluster coordination, orchestration, and autoscaling, how to reason about failure scenarios before they occur, and how to adapt a deployment to fluctuating load in dynamic environments.</p> <p>Attendees will leave with a practical understanding of how modern distributed email systems are built and operated, and how to apply these principles using open-source technology.</p>
<p>Traditional email servers were designed for a different era. They work great for small deployments but struggle at scale: Maildir breaks at 100k+ users, configuration changes require service reloads, and a single blacklisted IP blocks everyone on the server.</p> <p><a href="https://wildduck.email/">WildDuck</a> takes a different approach. Built on MongoDB and Node.js, it treats email as a modern distributed systems problem. This talk explores the architectural decisions behind WildDuck and the lessons learned running it in production with 100,000+ accounts.</p>
<p>Dovecot 2.4 removed one of the mail server's most outstanding features: being able to replicate between two servers, even in an active-active scenario if desired. The actual sync code stays in place, but the replication orchestrator was removed.</p> <p>On the other hand, the same release introduces improvements to two APIs: the event API now allows reacting to pretty much anything happening in Dovecot using an HTTP server, while the doveadm HTTP allows to trigger synchronization with another server.</p> <p>We'll have a look on Dovecot 2.3's implementation of replication, checking out alternative solutions to replication to finally look into a Golang-based solution that does not require forking the mail server codebase.</p>
<p>Gatling is a framework for performance testing and Apache James contributors had been providing a DSL (Domain Specific Language) for easily writing IMAP performance tests. We also wrote JMAP benchmarks using Gatling.</p> <p>This talk will cover the inner working of Gatling, the architecture of the IMAP DSL, key contributions to Yahoo's imapnio library, the toolbox for performance testing Apache James (including provisionning data), and present related results. </p> <p>We will also present how it completes other performance-related tools of the Apache James eco-system: Grafana metrics, async-profiler flame graphs (and contributions to the FOSS eco-system it did lead to!), JMH (Java Micro-benchmark Harness) tests for MIME4J...</p>
<p>This talk I will go over some FOS (online) tooling to check your mail config. Some common misconfigurations in DNS. Why you should probably want to avoid <code>www CNAME @</code>, and how to config other observations from the <a href="https://www.forumstandaardisatie.nl/metingen/informatieveiligheidstandaarden">biannual measurements</a> of scanning more than 10.000 governmental host names in The Netherlands. After this talk you'll know at least one DNS or security improvement for your own or organization domain, or something to monitor for your email.</p> <p>Online tools: - <a href="https://github.com/internetstandards/Internet.nl/">the free open source</a> <a href="https://internet.nl">Internet.nl</a> (in the project team) [IPv6, DNSSEC, SPF, DMARC, DKIM, STARTTLS, DANE inbound] - <a href="https://github.com/internetstandards/havedane/">the free open source</a> <a href="https://havedane.net/">haveDANE.net</a> (adopted/hosted by platform behind internet.nl) [interactive DANE outbound] - <a href="https://github.com/zonemaster/zonemaster/">the free open source</a> <a href="https://www.zonemaster.net/">zonemaster.net</a> [DNS] - <a href="https://github.com/dnsviz/dnsviz/">the free open source</a> <a href="https://dnsviz.net/">DNSViz.net</a> [DNS]</p> <p>Run yourself: - <a href="https://codeberg.org/glts/spftrace">the free open source</a> <a href="https://docs.rs/crate/spftrace/latest">spftrace</a> [SPF] - <a href="https://github.com/testssl/testssl.sh">the free open source</a> <a href="https://testssl.sh/">testssl.sh</a> [STARTTLS]</p> <p>And a split second for some links to non FOS tooling that is useful, and maybe be made open source (there is no sell of a product nor ads), or should be re-created: - https://www.email-security-scans.org - https://www.huque.com/bin/danecheck-smtp - https://dane.sys4.de</p> <p>(Free but commercial that needs a FOS alternative: https://www.mail-tester.com & https://emailspooftest.com)</p> <hr /> <p>In 2025 I gave a 45 minute talk on WHY2025 <a href="https://media.ccc.de/v/why2025-258-how-not-to-configure-your-domainname-internet-nl">How (not) to configure your domainname [internet.nl] (recording)</a> about internet standards / misconfigurations in both website and email space. In this talk I want to focus on the mail part and (online) free open source tooling to check your mail config.</p> <p>This presentation will touch on: - DNSSEC (<a href="https://datatracker.ietf.org/doc/html/rfc4033">RFC 4033</a> and many more), some common failures (e.g. CNAME's) - why not CNAME to your apex domain (if you have an Mx record) - use Null MX (<a href="https://datatracker.ietf.org/doc/html/rfc7505">RFC 7505</a>) (if you don't use mail on a hostname) - why configuration SPF (<a href="https://datatracker.ietf.org/doc/html/rfc7208">RFC 7208</a>) on all hostnames - why there are more reasons to avoid CNAME's - why enable DANE (<a href="https://datatracker.ietf.org/doc/html/rfc6698">RFC 6698</a>) and TLSRPT (<a href="https://datatracker.ietf.org/doc/html/rfc8460">RFC 8460</a>) and why it's superior to MTA-STA (<a href="https://datatracker.ietf.org/doc/html/rfc8461">RFC 8461</a>), how to rotate DANE - why monitoring matters (IPv6, DANE, SPF, etc.)</p>
<p>I'm the maintainer of a very popular email client library, <a href="https://github.com/PHPMailer/PHPMailer">PHPMailer</a>, and have found that it's difficult to test reliably because mocks get overcomplicated and unrepresentative, and it's difficult to configure mail servers to produce specific errors, for example to test what happens in your client if the server rejects a message with an unknown user, greylisting, spam filter, or authentication failure response. To this end I have created <a href="https://badsmtp.com">BadSMTP</a>, a mail server written in Go that produces specific errors on demand, easily driven by client configuration alone. It's a single, standalone binary, designed to run in CI systems, or as part of a larger system along the lines of mailhog. Essentially I want to do for SMTP what badssl.com does for TLS. This talk is a simple overview of the project, why it was needed, and how to use it.</p>
<p>The OpenEmbedded/Yocto Project is a powerful open-source collaboration that provides a framework for creating custom embedded Linux distributions. It has become a key tool for developers building highly tailored, minimal, and efficient Linux systems across a wide range of devices, from IoT to automotive, robotics, and beyond.</p> <p>Join us for this Birds of a Feather (BoF) session where OE/Yocto users, developers, and maintainers can gather to share their experiences, challenges, and best practices. Whether you’re a seasoned user or just starting to explore its capabilities, this session will provide an opportunity for lively discussion, collaboration, and networking.</p>
<p>This BOF will present the topics open for applicants in Horizon Europe Work Programme in relation to the Open Internet Stack successor programme to Next Generation Internet (NGI) for a total of 41.3M€. The agenda covers the results from the 2025 calls, the 3 new topics involved as well as Q/A and free interactions with Commission staff.</p>
<p>The NGI Zero consortium offers funding and support services to projects that help fix the internet through open software, open hardware and open standards. This gathering is a meet-and-greet for people who are part of, or interested in the NGI Zero ecosystem. Feel free to join! https://nlnet.nl/NGI0/</p>
<p>Reproducible builds are a set of software development practices that create an independently-verifiable path from source to binary code.</p> <p>There will be a Q&A session with members of the Reproducible builds team & community.</p>
<p>The vulnerability management world is in a bit of turmoil. With the DoS-type attack AI slop is putting on Open Source projects at the same time as the funding of core systems is unsure, we need to agree on requirements for the future, ways of working and how we can handle the shift forced by the Cyber Resilience Act. Let's spend an hour talking about this and discuss ways forward.</p> <p>The Global Vulnerability Intelligence Platform is a project that aims at working on a long term solution, a cooperation between OWASP, OpenSSF, Eclipse/ORCWG, OpenForum Europe and with support from the Sovereign Tech Resilience project.</p> <p>https://www.gvip-project.org</p>
<p>What's going on in the Perl, CPAN, Raku and Raku.land communities and ecosystems?</p> <p>Come, get to know some of the people, and learn (or share!) what's going on. We might have news from different Perl Mongers, upcoming events, CPAN Security Group, the Perl Foundation, the Raku Foundation, and more! It depends on who shows up.</p> <p>And if you are new and unfamiliar with these communities, then come and ask questions! Lots of helpful people around.</p> <p>Hope to see you there!</p>
<p>Special-Purpose Operating Systems are purpose-built Linux distributions for fufilling one specific function. We are a collaborative initiative, bringing together developers, maintainers, and adopters focused on operating systems designed for specific workloads—cloud-native, edge, embedded systems.</p> <p>In this Birds of a Feather (BoF) session, we aim to connect in person for the third time at FOSDEM, a pivotal event for the open-source operating system community. This meetup will provide a space for SPOS enthusiasts, contributors, and representatives from major Linux distributions to exchange insights, share experiences, and discuss the future direction of specialized operating systems.</p>
<p>Recent Rockchip SoCs (namely, those of the RK35 generation) integrate dedicated IP blocks for video capture and image signal processing. Yet support for these blocks in upstream Linux remains one of the last missing pieces in an otherwise well-supported SoC lineup.</p> <p>This talk will begin with an overview of the contributions that have already landed in mainline, provide an update on the change sets that are currently in flight, and outline the remaining work needed to fully enable video capture and camera functionality on RK35xy SoCs.</p>
<p>This talk describes our in-race-car video camera hardware and the open-source software that underpins our sub 200ms Glass to Glass streaming. </p> <p>We will discuss interfacing to V4l2 (in various modes) from memory safe languages (that <em>aren’t</em> C) and also the problems and advantages of accessing a chip specific encoder API. I will have a solid grumble about the increasing complexity and opacity of the linux media APIs and a moan about how much I miss Plan9 style thinking.</p> <p>We will use examples from the following open source projects (among others) https://github.com/pipe/whipi https://github.com/pipe/v4l2Reader https://github.com/steely-glint/PhonoSDK</p>
<p>The WebKit <a href="https://wpewebkit.org/">WPE</a> and <a href="https://webkitgtk.org/">GTK</a> ports are aiming to leverage GstWebRTC as their WebRTC backend. Over the years we have made progress towards this goal both in WebKit and in <a href="https://gstreamer.freedesktop.org/">GStreamer</a>. During this talk we will present the current integration status of GstWebRTC in WebKit, the achievements recently accomplished and the plans for the coming months.</p>
<p>This talk will present a range of unusual programming techniques that were used in the development of a state-of-the-art H.264 software decoder (https://github.com/tvlabs/edge264), to drastically reduce code and binary size and improve speed. The techniques are applicable to other audio/video codecs, and will be presented as HOWTOs to help participants use them in their projects. It complements my talks from the last 2 years at FOSDEM, and will focus this time on (i) using YAML output as a cornerstone for bug-hunting and data-analysis, and (ii) optimizing the infamous CABAC serial arithmetic decoder.</p>
<p>The global software ecosystem has moved to richer and richer web experience. With the addition of A/V APIs, webgl acceleration, rich media APIs, RTC and, more recently, the wide open field of web assembly-supported features, more or and more of the typical user interaction and applications happens within the browser.</p> <p>However, not all processing is meant to happen browser-side. In particular, when dealing with media with potentially large resolutions, exotic formats or complex compute-heavy effects, to provide a full user experience, it might be required to move back and forth between the browser and a backend server processing.</p> <p>But this comes with its own sets of challenges: what kind of processing is well suited in the browser? How to best interface a browser-based API with a backend-end based one? How is it possible to transpose a user experience that is built on javascript APIs available in the browser to a backend-based processing where these APIs typically have no bearing.</p> <p>In this talk, which is based on some of the challenges faced when building Descript, a feature-rich web-based video editor, we will review some of the technologies that are available to help interfacing web and backend processing, illustrate some of the challenges that these pose and also solve and explore potential future solutions using recent or prospective technologies.</p>
<p>In this talk, I will pass in review about what happened in the VideoLAN and FFmpeg communities about VLC, FFmpeg, x264, dav1d, dav2d, checkasm, libplacebo and libspatialaudio.</p> <p>And a bit of Kyber :)</p> <p>All in one short talk :)</p>
<p>Streamplace (https://stream.place) has been spending the last two years developing a novel form of decentralized public broadcast to facilitate a live video layer for Bluesky's AT Protocol. The basis of this system are C2PA-signed one-second MP4 files that can be deterministically muxed together into larger segments for archival. This talk will give a technical overview of how all the pieces fit together and show off how our freely-licensed media server facilitates cooperative livestreaming infrastructure.</p>
<p>This joint talk by DeepComputing and contributors from the VLC project showcases how intelligent media playback and real-time audio processing are becoming a reality on open RISC-V hardware. We demonstrate VLC running Whisper (speech-to-text) and Qwen (text-to-text LLM) on ESWIN’s EIC7702 SoC with a 40-TOPS NPU, achieving practical AI-enhanced multimedia performance entirely on RISC-V. We will walk through the porting process, performance tuning across CPU/NPU, audio pipeline integration, and the technical challenges of enabling real-time inference on today’s RISC-V AI PCs. The session will also preview our upcoming 16-core RISC-V platform and discuss how VLC’s evolving AI support roadmap aligns with this next generation of RISC-V hardware. Together, we outline the upstreaming efforts required to bring AI-accelerated playback, real-time captioning, translation, and other intelligent media features to the broader open-source community.</p>
<p>Machine learning in GStreamer is evolving rapidly, with major recent advances such as a dedicated analytics framework in the core library and new elements for integrating popular ML runtimes. These improvements further solidify GStreamer’s position as a leading open source multimedia framework for building robust, cross-platform media analytics pipelines. In this talk, we’ll explore the latest developments, including the GStAnalytics library, ONNX support, Python integration via gst-python-ml, new Tensor negotiation capabilities, and more.</p>
<p>After spending the past 10 years (and more!) working with WebRTC, and even more than that with SIP/RTP, I decided to have a look at the efforts happening within the standardization community on how to leverage QUIC for real-time media. This led me to studying not only QUIC itself, but also RTP Over QUIC (RoQ) and Media Over QUIC (MoQT).</p> <p>As part of my learning process, I started writing a QUIC library, called imquic. While it can (mostly) be used as a generic QUIC/WebTransport library, I also implemented native support within the library for both RoQ and MoQT, as a testbed to use for prototyping the new protocols in an experimental way. This presentation will introduce these new protocols and the imquic library implementing them, talking a bit about the existing demos and the proof-of-concept integration in the Janus WebRTC Server for QUIC-to-WebRTC translation.</p>
<p>As of the 3.10 release, the public domain (Unlicense) media server MistServer (https://mistserver.org) gained a new feature: the ability to mix raw (UYVY pixel format only, for now) video streams, raw audio streams (PCM) and PNG images with resizing, overlapping, aspect ratio keeping and support for non-uniform frame rates between sources. Not only that - but it's even possible to control the configuration in real time without any downtime. This talk shows off what is possible, and explains how we did it in technical detail.</p> <p>Covered topics:</p> <ul> <li>How to efficiently store a multi-frame raw video buffer in shared memory</li> <li>Synchronization handling between multiple sources</li> <li>Handling sources being added or removed without interruptions</li> <li>How we implemented decoding and encoding between raw and encoded formats</li> <li>The user interface that was built to control the mixing in a user-friendly way (though "raw" control through JSON is also possible)</li> </ul>
<p>Nextflow is a workflow manager that enables scalable and reproducible workflows. Nextflow is complemented by the nf-core community effort that aims at developing and supporting a curated collection of Nextflow pipelines, developed according to a well-defined standard, and their components. Since its inception, nf-core has set rigorous standards for documentation, testing, versioning and packaging of workflows, ensuring that pipelines can be "run anywhere" with confidence.</p> <p>In order to help adhere to the standards, nf-core comes along with <a href="https://github.com/nf-core/tools">nf-core/tools</a>, an open-source toolkit designed to support the Nextflow pipeline ecosystem. These include tools for the creation, testing, and sharing of Nextflow workflows and components. The nf-core tooling is central to all <a href="https://nf-co.re/">nf-core</a> pipelines, but it can also be used to develop pipelines outside the nf-core community.</p> <p>The pipelines and the tooling are actively maintained by the nf-core contributors and by the nf-core infrastructure team (supported by the CRG, SciLifeLabs, QBIC, and Seqera). This infrastructure provides everything: from pipeline templates to management of nf-core components, ensuring consistency and high quality across projects.</p> <p>In this talk, we’ll give a short introduction to nf-core and how nf-core/tools supports both pipeline developers and end users, helping the community build reliable and reusable workflows.</p>
<p>Modern research workflows are often fragmented, requiring scientists to navigate a complex path from the lab bench to computational analysis. The journey typically involves documenting experiments in an electronic lab notebook and then manually transferring data to a separate computational platform for analysis. This process creates inefficiencies, introduces errors, and complicates provenance tracking. To address this challenge, we have developed a tight, two-way integration between two open-source solutions: RSpace, a research data management platform and ELN, and Galaxy, a web-based platform for accessible, reproducible computational analysis. By connecting two open-source platforms, we're building truly open research infrastructure that institutions can adapt to their specific needs while maintaining full control over their research data. </p> <p>The integration's foundational step makes RSpace a native repository within Galaxy, enabling researchers to browse their RSpace Gallery and import data directly into Galaxy histories. This connection is bidirectional; not only can data be pulled into Galaxy but also selected outputs or even entire histories can be exported back to RSpace. This creates a seamless FAIR data flow that preserves the critical link between experimental results and their computational context. </p> <p>Building on this foundation, the integration has been further extended to allow researchers to initiate analysis directly from RSpace. By selecting data attached to a document and clicking a Galaxy icon, users upload it into a fresh, systematically-annotated Galaxy history that traces the data to its experimental source. This allows to document field work, launch a complex analysis, monitor its progress, and import the results, all while maintaining a clear and auditable link between the initial data and documentation and the outputs of the final computational analysis. </p> <p>This partnership between two open-source platforms represents a significant stride towards more open, integrated, cohesive research infrastructure that institutions can build upon, reducing friction so scientists can focus on discovery rather than data logistics. Future developments will focus on improving the native repository integration, automated reporting of results back to RSpace, enhanced RO-Crate support for standardized metadata exchange, and improved templating in RSpace for sharing and reusing specific workflow configurations.</p> <ul> <li>https://galaxyproject.org/</li> <li>https://www.researchspace.com/</li> <li>https://galaxyproject.org/news/2025-02-27-rspace-talk/</li> <li>https://galaxyproject.org/news/2025-06-23-rspace-integration/</li> <li>https://www.researchspace.com/blog/rspace-galaxy-filesource-integration</li> <li>https://www.researchspace.com/blog/rspace-adds-galaxy-integration</li> <li>https://documentation.researchspace.com/article/zzsl46jo5y-galaxy</li> </ul>
<p>I will share how adopting <a href="https://nixos.org/">Nix</a> transformed my bioinformatics practice, turning fragile, environment‑dependent pipelines into reliable, reproducible workflows. I will walk the audience through the practical challenges of traditional Docker‑centric setups, introduce the core concepts of Nix and its package collection (nixpkgs), and explain how tools such as <a href="https://docs.ropensci.org/rix/">rix</a> and <a href="https://docs.ropensci.org/rixpress/">rixpress</a> or <a href="https://github.com/PapenfussLab/bionix">bionix</a> simplify data analysis workflows. Attendees will leave with concrete strategies for managing development environments, rapid prototyping, and generating Docker images directly from Nix expressions—complete with tips, tricks, and curated resources to lower the barrier to adoption. Whether you’re unfamiliar with Nix or have found it intimidating, this session aims to inspire a shift toward reproducible, maintainable bioinformatics pipelines.</p>
<p>The release of AlphaFold2 paved the way for a new generation of prediction tools for studying unknown proteomes. These tools enable highly accurate protein structure predictions by leveraging advances in deep learning. However, their implementation can pose technical challenges for users, who must navigate a complex landscape of dependencies and large reference databases. Providing the community with a standardized workflow framework to run these tools could ease adoption.</p> <p>Thanks to its adherence to nf-core guidelines, the nf-core/proteinfold pipeline simplifies the application of state-of-the-art protein structure modeling techniques by taking advantage of the optimized execution Nextflow’s capabilities on both cloud providers and HPC infrastructures. The pipeline integrates several popular methods, namely AlphaFold 2 and 3, Boltz 1 and 2, ColabFold, ESMFold, HelixFold, RosettaFoldAA, and RosettaFold2NA. Following structure prediction, nf-core/proteinfold generates an interactive report that allows users to explore and compare predicted models together with standardized confidence metrics, harmonized across methods for consistent interpretation. The workflow also integrates Foldseek-based structural search, enabling the identification of known protein structures similar to the predicted models.</p> <p>The pipeline is developed through an international collaboration that includes Australian BioCommons, the Centre for Genomic Regulation, Pompeu Fabra University, and the European Bioinformatics Institute, and it already serves as a central resource for structure prediction at several of these organisations and others. This broad adoption demonstrates how nf-core/proteinfold, through its open-source and community-driven development model, is lowering the barrier to using deep learning based approaches for protein structure prediction in everyday research.</p> <p>Interestingly, nf core proteinfold represents a new generation of Nextflow workflows designed to place multiple alternative methods for the same task within one coherent framework. This design makes it possible to compare the different procedures, providing a basis for developing combined approaches that may mature into meta-methods.</p> <h3>More info</h3> <p><a href="https://nf-co.re/">nf-core project</a></p> <p><a href="https://nf-co.re/proteinfold">nf-core/proteinfold pipeline</a></p> <p><a href="https://github.com/nf-core/proteinfold">nf-core/proteinfold GitHub repository</a></p> <p><a href="https://nf-co.re/join">Join nf-core</a></p> <p><a href="https://bsky.app/profile/josesca.bsky.social">My bluesky</a></p>
<p><strong>ProtVista</strong> is an open-source protein feature visualisation tool used by UniProt, the high-quality, comprehensive, and freely accessible resource of protein sequence and functional information. It is built upon the suite of modular <strong>standard and reusable web components</strong> called Nightingale, a <strong>collaborative open-source</strong> library. It enables integration of protein sequence features, variants, and structural data in a unified viewer. These components are shared across resources, for example Nightingale components also power feature visualisations in InterPro or PDBe, and the turnkey ProtVista library is used by Open Targets or Pharos.</p> <p>ProtVista is undergoing major <strong>technical upgrades</strong>, to expand its reach, cover broader use cases, and also be able to handle ever-growing quantities of data. We are transitioning <strong>from SVG graphics to Canvas/WebGL rendering</strong> to improve performance for large datasets and on low-spec devices. We are refactoring the tool’s core to allow <strong>custom data inputs</strong> via a configurable API, letting developers plug in their own protein annotation data sources. Additionally, a new track configuration UI will let end-users <strong>toggle and rearrange feature tracks</strong> for a more flexible, tailored view. This talk will introduce ProtVista’s open-source design based on <strong>standards</strong> and demonstrate how these upcoming enhancements make it easier and faster to build <strong>interactive protein feature visualisations</strong>.</p> <p>Relevant links: - ProtVista codebase: <a href="https://github.com/ebi-webcomponents/protvista-uniprot">https://github.com/ebi-webcomponents/protvista-uniprot</a> - Nightingale codebase: <a href="https://github.com/ebi-webcomponents/nightingale">https://github.com/ebi-webcomponents/nightingale</a> - Publication “Nightingale: web components for protein feature visualization”, 2023 <a href="https://academic.oup.com/bioinformaticsadvances/article/3/1/vbad064/7178007">https://academic.oup.com/bioinformaticsadvances/article/3/1/vbad064/7178007</a> - Publication “ProtVista: visualization of protein sequence annotations”, 2017 <a href="https://academic.oup.com/bioinformatics/article/33/13/2040/3063132">https://academic.oup.com/bioinformatics/article/33/13/2040/3063132</a></p>
<p>As our tools evolve from scripts and pipelines to intelligent, context-aware systems, the interfaces we use to interact with data are being reimagined.</p> <p>This talk will explore how accelerated and integrated compute is reshaping the landscape of biobank-scale datasets, weaving together genomics, imaging, and phenotypic data with and feeding validatable models. Expect a whirlwind tour through: · Ultra-fast sequence alignment and real-time discretization · Estimating cis/trans effects on variant penetrance via haploblock architecture · Biobank scale data federation · Knowledge graphs as dynamic memory systems (GNNs - LLM co-embedding)</p> <p>We'll close by tackling the unglamorous but essential bits: validation, contextualization, and the digital hygiene required to keep model-generated data from becoming biomedical junk DNA. Think of it as a roadmap toward smarter, faster, and more trustworthy data-driven healthcare.</p>
<p>Advances in DNA sequencing and synthesis have made reading and writing genetic code faster and cheaper than ever. Yet most labs run experiments at the same scale they did a decade ago, not because the biology is limiting, but because the software hasn't caught up.</p> <p>The conventional digital representation of a genome is a string of nucleotides. This works well enough for simple projects, but the model breaks down as complexity grows. Sequences aren't constant: they evolve, mutate, and are iterated on. Unlike software, there's no instant feedback loop to tell you if an edit worked; wetlab experiments take time. You gain some of that time back by working with multiple sequences in parallel. But keeping track of thousands of sequences and coordinate frames is tricky at best when a researcher is working solo, and far harder when collaborating with other people or agents on the same genetic codebase.</p> <p>Gen is a version control system built specifically for biological sequences (http://github.com/genhub-bio/gen). It models genomic data as a graph rather than flat text, preserving the full structure of variation, editing history, and experimental lineage. On top of this, projects are organized into repositories with branching, diffing, and merging, just like git. Git was first released 20 years ago and transformed how software teams collaborate on shared codebases. Gen brings that same workflow to biology.</p> <p>This talk will introduce Gen's design philosophy and walk through a real-world use case. Gen is open source under the Apache 2.0 license, implemented in Rust with a terminal interface and Python bindings, and designed to integrate with existing bioinformatics pipelines.</p>
<p>dingo is a Python package that brings advanced scientific-computing techniques into the hands of developers and researchers. It focuses on modelling metabolic networks — complex systems describing how cells process nutrients and energy — by simulating the full range of possible biochemical flux states. Historically, exploring these possibilities in large-scale networks has been computationally prohibitive. dingo introduces state-of-the-art Monte Carlo sampling algorithms that dramatically speed up these simulations, enabling the analysis of very large models such as Recon3D on a regular personal computer in under a day. With its easy-to-use Python interface and integration within the broader scientific Python ecosystem (e.g. NumPy, Matplotlib), dingo lowers the barrier to entry for studying complex biological systems. This talk will walk the audience through the computational challenges of metabolic modelling, show how dingo leverages Python and efficient sampling to overcome them, and highlight how Python developers and computational biologists alike can contribute to or extend this open-source project. Whether you’re interested in open-source scientific software, computational biology, or high-performance Monte Carlo methods in Python, this talk aims to inspire and provide actionable insight into using and contributing to dingo.</p>
<p>AI is gaining importance in bioinformatics with new methods and tools popping every day. While applications of AI in bioinformatics inherited a lot of technological solutions from other AI-driven fields, such as image recognition or natural language processing, this particular domain has its own challenges. An alarming example is a study showing that most AI models for detecting COVID from radiographs do not rely on medically relevant pathological signals, but rather in shortcuts such as text tokens on the images (DeGrave et al., Nat Mach Intell, 2021, doi: 10.1038/s42256-021-00338-7), stressing the importance of the data, on which the AI models were trained. Equally special is the data used for training biological language models: first, it is not that large compared to natural languages (e.g. one of the most successful protein language models ESM-2 has been trained on only 250M sequences), and second, it is highly structured by evolution and natural selection, and thus has a relatively low intrinsic dimension.</p> <p>In my talk, I will speak about consequences of this underlying structure of the data for performance of models that are trained with it -- spoiler alert! it is terribly overestimated. The reason for this is information or data leakage: the model remembers irrelevant features highly correlated with the target variable and does not learn any biologically meaningful properties that can be transferred to out-of-distribution data. I will present our own check list (see our paper Bernett et al., Nat Methods, 2024, doi: 10.1038/s41592-024-02362-y) and a solution (https://github.com/kalininalab/DataSAIL, Joeres et al., Nat Comm, 2025, doi: 10.1038/s41467-025-58606-8) for avoiding the information leakage pitfall. I will discuss examples and applications from protein function prediction and drug discovery.</p>
<p>The study of animal behaviour has been transformed by the increasing use of machine learning-based tools, such as DeepLabCut and SLEAP, which can track the positions of animals and their body parts from video footage. However, there is currently no user-friendly, general-purpose solution for processing and analysing the motion tracks generated by these tools. To address this gap, we are developing movement, an open-source Python package that provides a unified interface for analysing motion tracking data from multiple formats. Initially, movement prioritised implementing methods for data cleaning and kinematic analysis. We are now focusing on expanding its data visualization capabilities and on developing metrics to analyze how animals interact with each other and with their environment. Future plans include adding modules for specialised applications such as pupillometry and collective behaviour, as well as supporting integration with neurophysiological data analysis tools. Importantly, movement is designed to cater to researchers with varying levels of coding expertise and computational resources, featuring an intuitive graphical user interface. Furthermore, the project is committed to transparency, with dedicated engineers collaborating with a global community of contributors to ensure its long-term sustainability. We invite feedback from the community to help shape movement's future as a comprehensive toolbox for analysing animal behaviour. For more information, please visit <a href="https://movement.neuroinformatics.dev/latest/index.html">movement.neuroinformatics.dev</a>.</p>
<p>The electrochemical-level simulation of neurons brings together many different challenges in the realms of biophysical modelling, numerical analysis, HPC, neuromorphic hardware and software design. To approach these challenges, we recently developed a modular platform, EDEN (https://eden-simulator.org). EDEN offers both a <code>pip install</code>able simulation package for neuroscientists, and a modular <em>construction kit</em> for neuro-simulator programmers to rapidly develop and evaluate new computational methods. It leverages the community standard NeuroML (https://neuroml.org) to integrate with the existing open-source stack of modelling and analysis tools, and minimise the barrier to entry for technical innovations in neural simulation.</p> <p>Further reading: - the <a href="https://doi.org/10.3389/fninf.2022.724336">2022 paper</a> for the high-level design - the <a href="https://doi.org/10.3389/fninf.2025.1572782">2025 paper</a> for the plug-in architecture</p>
<p>Back in 2020, the COVID-19 pandemic unexpectedly gave the Debian Med project a strong boost. New contributors joined, collaboration intensified, and Debian’s role in supporting biomedical research and infrastructure became more visible.</p> <p>Almost five years later, Debian Med continues to benefit from this momentum. The project still shows higher activity levels than before the pandemic, with lasting improvements in package quality, continuous integration coverage, and cooperation with other Debian teams.</p> <p>This talk will present how the Debian Med team has evolved since the pandemic, which effects have lasted, and where new challenges have emerged as both the world — and Debian — have settled into a new normal.</p> <p>You can learn more about Debian Med at https://www.debian.org/devel/debian-med/</p>
<p>Tabular data, often scattered across multiple tables, is the primary output of data analyses in virtually all scientific fields. Exchange and communication of tabular data is therefore a central challenge. With Datavzrd, we present a tool for creating portable, visually rich, interactive reports from tabular data in any kind of scientific discipline. Datavzrd unifies the strengths of currently common generic approaches for interactive visualization like R Shiny with the portability, ease of use and sustainability of plain spreadsheets. The generated reports do not require the maintenance of a web server nor the installation of specialized software for viewing and can simply be attached to emails, shared via cloud services, or serve as manuscript supplements. They can be specified without requiring imperative programming, thereby enabling rapid development and offering accessibility for non-computational scientists, unlocking the look and feel of dedicated manually crafted web applications without the maintenance and development burden. Datavzrd reports scale from small tables to thousands or millions of rows and offer the ability to link multiple related tables, allowing to jump between corresponding rows or hierarchically explore growing levels of detail. We will demonstrate Datavzrd on real-world bioinformatics examples from tools such as Orthanq and Varlociraptor, highlighting how it can turn complex analytical outputs into interactive, shareable reports.</p> <p>Software: https://github.com/datavzrd/datavzrd General Website: https://datavzrd.github.io</p>
<p>We wanted to showcase a lot of different contributions and the beautiful heterogeneity of bioinformatics ending with a lighting talk session! Here's the list of the 3' presentations:</p> <ul> <li>Guixifying workflow management system: past, present, maybe future? by Simon Tournier </li> <li>VTX, High Performance Visualization of Molecular Structure and Trajectories by valentin</li> <li>Multimodal Tumor Evolution Analysis: Interactive 4D CT and Time-Aligned Clinical Data in a Hospital Web Platform by Fabian Fulga</li> <li>DNA storage and open-source projects by Babar Khan</li> <li>From Binary to Granular: Automating Multi-Threshold Survival Analysis with OptSurvCutR by Payton Yau</li> </ul> <hr /> <p><strong>Guixifying workflow management system: past, present, maybe future?</strong> Bioinformatics and Computational Biology face a twofold challenge. On one hand, the number of steps required to process the amounts of data is becoming larger and larger. And each step implies software involving more and more dependencies. On the other hand, Reproducible Research requires the ability to deeply verify and scrutinize all the processes. And Open Science asks about the ability to reuse, modify or extend.</p> <p>Workflow might be transparent and reproducible if and only if it’s built on the top of package managers that allow, with the passing of time, to finely control both the set of dependencies and the ability to scrutinize or adapt.</p> <p>The first story is <a href="https://hpc.guix.info/">Guix</a> Workflow Language (<a href="https://guixwl.org/">GWL</a>): a promise that has not reached its potential. The second story is Concise Common Workflow Language (<a href="https://ccwl.systemreboot.net/">CCWL</a>): compiling Guile/Scheme workflow descriptions to CWL inputs. The third story is <a href="https://forge.systemreboot.net/ravanan/">Ravanan</a>: a CWL implementation powered by <a href="https://hpc.guix.info/">Guix</a> – a transparent and reproducible package manager.</p> <p>This talk is a threefold short story that makes one: long-term, transparent and reproducible workflow needs first package managers.</p> <hr /> <p><strong>VTX, High Performance Visualization of Molecular Structure and Trajectories</strong> VTX is a molecular visualization software capable to handle most molecular structures and dynamics trajectories file formats. It features a real-time high-performance molecular graphics engine, based on modern OpenGL, optimized for the visualization of massive molecular systems and molecular dynamics trajectories. VTX includes multiple interactive camera and user interaction features, notably free-fly navigation and a fully modular graphical user interface designed for increased usability. It allows the production of high-resolution images for presentations and posters with custom background. VTX design is focused on performance and usability for research, teaching, and educative purposes. Please visit our website at https://vtx.drugdesign.fr/ and/or our github at https://github.com/VTX-Molecular-Visualization for more.</p> <hr /> <p><strong>Multimodal Tumor Evolution Analysis: Interactive 4D CT and Time-Aligned Clinical Data in a Hospital Web Platform</strong> Modern oncology practice relies on understanding how tumors evolve across multiple imaging studies and how these changes correlate with clinical events. This talk presents a hospital-oriented web platform for multimodal tumor evolution analysis, integrating interactive 4D CT visualization with time-aligned clinical data, including PDF clinical documents, lab results and treatment milestones.</p> <p>The system combines a Node.js front end with a Flask-based visualization backend that handles CT preprocessing, metadata extraction, and generation of time-synchronized 4D volumes. Clinicians can navigate volumetric CT scans across multiple time points, compare tumor morphology longitudinally, and immediately access the corresponding clinical context within the same interface. The platform displays radiology reports, pathology documents, and other PDF-based data side-by-side with imaging, creating a unified temporal view of patient evolution.</p> <p>We describe the architecture, including the ingestion pipeline for DICOM and document data, the design of the multimodal synchronization layer, rendering strategies for large 4D CT volumes, and the integration of document viewers and time-series dashboards.</p> <p>Web platform: https://github.com/owtlaw6/Licenta Flask App (CT Scan related scripts): https://github.com/fabi200123/4D_CT_Scan</p> <hr /> <p><strong>DNA storage and open-source projects</strong> The magnetic recording field goes back to the pioneering work of Oberlin Smith, who conceptualized a magnetic recording apparatus in 1878. Fast forward, in 1947, engineers invented the first high-speed, cathode ray tube based fully electronic memory. In 1950, engineers developed magnetic drum memory. In 1951, the first tape storage device was invented. By 1953, engineers had developed magnetic core memory. The first hard disk drive RAMAC was developed in 1957. Since then, HDDs have dominated the storage for several decades and continue to do so because of its low cost-per-gigabyte and low bit-error-rate. Based on some estimates, in 2023, approximately 330 million terabytes of data were created each day. By 2024, HDDs dominated over half of the world’s data storage. As of 2025, approximately 0.4 zettabytes of new data are being generated each day, which equals about 402.74 million terabytes. What does it indicate? Data is growing and there is a need of solutions in term of longevity, low power consumption, and high capacity. Deoxyribonucleic acid (DNA) based storage is being considered as one of the solutions. This talk is about current status of DNA storage and open-source projects that exist in this domain so far.</p> <hr /> <p><strong>From Binary to Granular: Automating Multi-Threshold Survival Analysis with OptSurvCutR</strong> In risk modelling, categorising continuous variables—such as biomarker levels or credit scores—is essential for creating distinct risk groups. While existing tools can optimize a single threshold (creating "High" vs "Low" groups), they lack a systematic framework for identifying multiple cut-points. This limitation forces analysts to rely on simple binary splits, which often mask the actual shape of the data. This approach fails to detect complex biological realities, such as U-shaped risk profiles or multi-step risk stratification involving 3, 4, or even 5+ distinct groups.</p> <p>In this lightning talk, I will introduce OptSurvCutR, an R package designed to bridge this gap using a reproducible workflow. Currently under peer review at rOpenSci, the package automates the search for optimal thresholds in time-to-event data.</p> <p>I will demonstrate how the package: - <strong>Goes Beyond Binary Splits</strong>: Unlike standard tools restricted to a single cut-off, <em>OptSurvCutR</em> uses systematic searches to identify multiple thresholds, automatically defining granular risk strata (e.g., Low, Moderate, High, Severe).</p> <ul> <li> <p><strong>Prevents False Positives</strong>: It integrates statistical corrections (MSRS) to ensure that the differences between these multiple curves are real, not just random chance.</p> </li> <li> <p><strong>Quantifies Uncertainty</strong>: It uses bootstrap validation to measure the stability of the thresholds, ensuring that your multi-level risk model is robust.</p> </li> </ul> <p>Project Links: - <strong>Source Code (GitHub)</strong>: https://github.com/paytonyau/OptSurvCutR - <strong>rOpenSci Review Process</strong>: https://github.com/ropensci/software-review/issues/731 - <strong>Preprint</strong>: https://doi.org/10.1101/2025.10.08.681246</p>
<p>Opening remarks and housekeeping.</p>
<p>Deutsche Bahn, with its 230,000 employees and hundreds of subsidiaries, is far from an average organization. Yet it faces the same challenges under the CRA as many others. In this session, we will show how we connected the concrete requirements of CRA compliance with our broader effort to bring transparency to our software supply chains. This forms the basis for security and license compliance processes, as well as for proactively shaping the ecosystems we depend on.</p> <p>We will outline our strategy for addressing the expectations tied to the different roles we take on -- customer, manufacturer, and indirectly even steward -- from both organizational and technical angles. Given the diversity and scale of Deutsche Bahn, we rely on modular FOSS tools that offer the flexibility to adapt to varying stakeholder needs and evolving regulation. This flexibility is a core element of our approach. Join this session to learn how we align strategy and technology to make this work.</p> <p><em>Note: This talk will be enriched by the session <a href="https://fosdem.org/2026/schedule/event/7EYTRJ-deutsche-bahn-large-scale-sbom-approach/">Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use </a> that puts an emphasis on the tooling aspects and the implementation in DevOps processes.</em></p>
<p>EV charging stations expose a uniquely difficult CRA landscape: A single physical device can be accessed through very different user paths: ISO 15118 (Plug&Charge), RFID cards, mobile apps, credit-card terminals, and OEM-backends. Between the end user and the actual product manufacturer sit multiple intermediaries (CSMS, OEM cloud, roaming hubs, payment processors), each with partial control over configuration, telemetry, and security posture. How to deliver all the CRA obligations across this complex eco system? At the same time a typical Charging Station Operator (CPO) has to manage over 300 different manufactures, models, firmware images and cyber security might differ from monitored private charging stations up to high-power public charging stations.</p> <p>Rather on relying on "out-of-band" CRA management, a better approach might be to integrate all CRA cyber security obligations and especially the vulnerability management deeply into the commonly used management protocols like the Open Charge Point Protocol (OCPP). This removes the disconnect between CRA compliance work and operational reality.</p> <p>Work in the Open Charge Alliance (notably the Cyber Security Task Group), CyberStand.eu’s CRA alignment efforts, and the newly NLnet NGI Zero Commons–funded <strong>EVQI</strong> project is already pushing concrete interfaces in this direction: Device-model variables for CRA readiness, structured vulnerability and lifecycle metadata, cross-vendor health monitoring, and standardized audit-trail exports suitable for CRA Article 10-15 reporting.</p> <p>This session outlines how CRA obligations can be realized in a heterogeneous, multi-vendor charging ecosystem with an emphasis on operators managing 50000+ of devices. It shows which processes must be automated, which artefacts need to be transported over OCPP, and how deep protocol-level integration enables consistent, scalable CRA compliance across an extremely diverse EV-charging landscape.</p>
<p><a href="https://github.com/erlang/otp">Erlang/OTP</a> is an open source programming language designed for the development of concurrent and distributed systems. Created 40 years ago and open sourced in 1998, Erlang is used by <a href="https://www.ericsson.com/en">Ericsson</a>, <a href="https://www.cisco.com/">Cisco</a>, <a href="https://www.whatsapp.com/">WhatsApp</a>, <a href="https://discord.com/">Discord</a>, and <a href="https://www.klarna.com/se/">Klarna</a> for mission critical applications as well as loved by a broad community of open source developers. With the advent of the Cyber Resilience Act (CRA), the Erlang/OTP team, jointly with the <a href="https://erlef.org/">Erlang Ecosystem Foundation</a> (EEF), began to prepare the project to meet CRA requirements. In this presentation, Kiko will describe and dive into the various supply chain best practices implemented by the Erlang/OTP project: the creation of Source Software Bill-of-Materials (Source SBOMs), automated vulnerability scanning of dependencies using <a href="https://osv.dev/">OSV</a>, creation of <a href="https://github.com/openvex/spec">OpenVEX statements</a>, vulnerability handling in collaboration with the <a href="https://cna.erlef.org/">EEF as CNA</a>, and contributions to towards other open source projects [[1],[2],[3]] to improve the security posture of the ecosystem. Moreover, Kiko will provide an insight into the lessons learned from implementing these measures in an open source project.</p>
<p>Embedded products are at the core of the Cyber Resilience Act, yet they face unique compliance challenges. Hardware vendors ship heavily patched BSPs, software modules often diverge from upstream, and reliable identification of modified components is still far from solved. For teams building products on top of these layers, translating CRA requirements into daily engineering practice is not straightforward.</p> <p>This talk provides a practical overview of where CRA compliance currently stands for embedded devices, using Yocto Project–based workflows as a representative example. We will explore what is already achievable today with existing tooling (SBOM generation, vulnerability scanning, provenance capture), and highlight the gaps that still require industry-wide definitions - from consistent software identification to handling vendor modifications and long-tail dependencies.</p> <p>Participants will gain a grounded, realistic understanding of how CRA obligations map to actual embedded development, what can be implemented now, and where the ecosystem still needs collective work to reach a "working" state.</p>
<p>The Cyber Resilience Act (CRA) is reshaping expectations around open source software, introducing new requirements for security, traceability, and documentation. While maintainers are responsible for technical compliance, community managers play a critical but often overlooked role in helping projects adapt. This session is designed for community managers, project maintainers, stewards, and open source contributors interested in practical CRA readiness. The focus is on practical enablement by Community Managers, exploring how they can support compliance without assuming legal liability. </p> <p>We’ll show how Community Managers can: - Communicate CRA-relevant processes to contributors, downstream adopters, and vendors - Structure documentation, governance pages, and onboarding materials for clarity and discoverability - Protect newcomers from unnecessary compliance burden, keeping contribution welcoming and accessible - Support maintainers, triaging non-technical questions, coordinating workflows, and preventing burnout Facilitate cross-project collaboration, shared tooling, and evidence collection practices - Manage vulnerability communication to maintain trust and transparency</p> <p>The objective is for attendees to leave with practical strategies, templates, and examples that make CRA compliance manageable while keeping open source communities healthy and contributor-friendly. This session is ideal for community managers, project stewards, maintainers, and anyone interested in the human side of CRA readiness in FOSS projects. Attendees will leave with key takeaways: - Understand CRA’s indirect impact on community management and a checklist of how tos - Learn concrete ways to keep projects welcoming despite increased compliance expectations - Explore templates and workflow ideas that reduce friction for contributors and maintainers alike - See examples of cross-project coordination and documentation practices that support CRA readiness</p> <p>This session emphasizes practical, community-driven solutions focusing on doing and not debating legal strategy making CRA compliance achievable and sustainable for FOSS communities.</p>
<p>This panel brings together experts to discuss the practical realities of implementing the CRA steward role, as defined by the regulation, and how organisations are approaching its execution. Panelists will explore how the concept of CRA stewards is being interpreted, what responsibilities are emerging in practice, and the challenges organisations face in preparing for this new function. They will also highlight which elements remain unclear, what support or guidance is still needed, and how future work at the level of EC and broader ecosystem can help refine and operationalise the steward role effectively. The panel aims to offer concrete insights for organisations navigating this evolving responsibility.</p>
<p>Security teams are currently drowning in vulnerability data, but the Vulnerability Exploitability eXchange (VEX) offers a solution by providing machine-readable clarity on which exploits actually matter. This technology is rapidly evolving from a "nice-to-have" efficiency tool into a critical compliance enabler for the EU Cyber Resilience Act (CRA), which mandates effective vulnerability handling for the European market.</p> <p>In this session, Georg and Rao present the findings from the VEX Industry Collaboration Working Group, a group of industry leaders driving the development and application of VEX. The group identified a set of challenges and gaps hampering adoption, ranging from the different evolving technical directions in VEX formats to practical barriers such as discovery and distribution of VEX documents, immature tooling, and education. Rao and Georg will outline a shared path forward, advocating for the creation of a common distribution system, development of necessary tooling, and establishing a forum for collaboration between industry partners and open source projects to drive adoption and education.</p>
<p>The Cyber Resilience Act (CRA) requires a risk-based approach when developing and supporting products, even those that are only software. The most important part of this is the cybersecurity risk assessment. This document is the main thing that decides which essential cybersecurity requirements you must follow for your product and which ones you don't need to implement. If you don't have this cybersecurity risk assessment, your product will be seen as not compliant in the EU market, no matter how good it is overall. You are in charge of creating this risk assessment.</p> <p>In this session, we will learn the steps of this formal and documented process to set up a compliant and reliable way to manage cybersecurity risks for your products with digital elements.</p> <p>We will draw inspiration from standard industry practices for information security risk management and the recently released EN 40000-1-2 draft from the European Committee for Electrotechnical Standardization.</p> <p>We will start by defining the product's context and defining risk acceptance criteria. Then, we will move to the risk assessment itself. This involves finding and documenting the product's assets and objectives, identifying threats, estimating how big the risks are, and then evaluating the risks to process them further. </p> <p>To close the risk management loop, we will discuss how to treat risks, how we need to communicate risks to our users and how to monitor and review those identified risks.</p>
<p>The implementation of the EU Cyber Resilience Act is currently shaped by two flawed assumptions: that most open source projects have a steward, and that stewards are synonymous with foundations. Data from the JavaScript and Rust ecosystems shows the opposite—hundreds of thousands of widely used packages exist outside any stewardship structure, while foundations oversee only a tiny fraction. The CRA anticipated this reality and introduced a separate mechanism to help manufacturers meet due-diligence requirements: a security attestation program intended to function as an open-source analogue to CE marking. Done well, attestations can dramatically simplify compliance while improving security and sustainability across the ecosystem.</p> <p>Current proposals, however, lean toward lightweight models that offer limited value to manufacturers and little support for the maintainers who produce the software those manufacturers rely on. This talk proposes a more effective middle path: an attestation approach that leverages maintainer expertise, delivers clear and actionable assurances to manufacturers, and creates sustainable revenue channels for projects.</p> <p>Using the OpenJS Foundation’s Ecosystem Sustainability Program (ESP) as a concrete example, we will illustrate how project-approved commercial support, revenue sharing, and clear integration points can produce benefits for both manufacturers and maintainers. ESP demonstrates how a structured program can help fund essential security and maintenance work without requiring projects to become foundation-stewarded. By connecting these lessons to the CRA’s attestation framework, the session outlines what a truly useful attestation system could deliver: practical compliance for manufacturers, meaningful support for maintainers, and a healthier, more resilient open source ecosystem.</p>
<p>Everyone's building CRA compliance tooling: SBOM generators, vulnerability scanners, security scorecards, automated due diligence checks. But, CRA readiness isn't just about tooling. It's about ensuring the data feeding those tools is actually accurate and trusted. The project activity, package metadata, licensing information, and vulnerability data these tools depend on is systematically unreliable, and we need to fix it at the source.</p> <p>This talk demonstrates why data accuracy is the blocking issue for practical CRA readiness. We'll show real-world examples from major package ecosystems: Python packages with wrong license declarations, Java JARs with embedded vulnerable dependencies that scanners miss, Rust crates with incomplete origin metadata. When demonstrating due diligence or attempting automated vulnerability reporting, the underlying data failures make compliance impossible, no matter how good your tools are.</p> <p>The good news is that this is solvable, and the FOSS community is already working on it! </p> <p>We'll present concrete approaches being deployed across ecosystems: systematic metadata curation projects that scan and fix package data at scale, validation tooling that catches errors before publication, and community infrastructure that makes accurate software metadata freely available. You'll see how projects like Maven Heaven, T-Rust, and Nixpkgs Clarity are cleaning up metadata for the most popular packages, releasing curated data under open licenses, and providing author-facing tools to prevent bad data from entering registries. And we'll discuss how reliable project health data provides critical insights for proactive CRA due diligence and risk management.</p> <p>This session gives you practical next steps: how to audit data quality in your dependencies, contribute to metadata curation efforts, integrate validation into your publishing workflow, and leverage community-curated data for more reliable compliance automation.</p>
<p>For FOSS maintainers, many of whom contribute voluntarily and without formal organizational backing, the CRA raises urgent questions: What exactly changes for my project? What responsibilities - if any - apply to me? And how can I prepare without being overwhelmed? This panel puts FOSS maintainers at the center of the conversation. Joined by industry practitioners for complementary perspectives, maintainers will discuss what the CRA means for day-to-day project work, long-term sustainability, and collaborative development practices. Key topics include: Which CRA obligations might touch volunteer-driven FOSS projects - and which clearly do not What are those tools you use right now or plan using to get closer to the CRA readiness and what you’re missing How maintainers can proactively position their projects without needing formal compliance How industry stakeholders can step up to support the FOSS components they rely on Practical guidance on documentation, secure development practices, and project governance How the CRA could catalyze a healthier relationship between FOSS communities and commercial users</p>
<p>People want to run Java workloads in Linux containers and they want that to work well. Historically, Java has tended to prefer to manage things itself, and without tuning, there have been challenges getting OpenJDK payloads to excel alongside other workloads in container workloads. But that has been changing.</p> <p>This talk will give a high-level overview of the journey that OpenJDK has taken to play nicely with others in a container context (Kubernetes or otherwise), the current state-of-play, and where we might be going in the future.</p> <p>No deep Java knowledge necessary.</p> <p>The author works on OpenJDK and containers, both in the upstream OpenJDK project and downstream, initially at Red Hat, and now at IBM.</p> <p>https://openjdk.org https://rh-openjdk.github.io/redhat-openjdk-containers/</p>
<p>In early 2025 we started the process to create the Kubernetes Checkpoint Restore Working Group. In December the working group had its first meeting and in this short presentation I want give an overview why we think it is important to continue the checkpoint restore related work from the last five years in this working group. In addition I want to present the topics the working group hopes to solve in the context of Kubernetes.</p>
<p>Reducing container image size improves security, speeds up cold starts, and cuts network transfer costs. Yet in development workflows, it’s easy to inherit bloated base images or copy templates full of unused tools. To build minimal, production-ready OCI images, we need visibility into what a container actually uses at runtime</p> <p>This talk presents a lightweight method for profiling file access inside containers using <a href="https://docs.ebpf.io/">eBPF</a>, <a href="https://podman.io/">Podman</a>, and <a href="https://specs.opencontainers.org/runtime-spec/runtime/#lifecycle">OCI lifecycle hooks</a>. By leveraging the prestart hook, we can gain access to the container’s initial PID, allowing an eBPF program to trace all file opens. Tracepoint and LSM (Linux Security Module) eBPF programs are combined to capture the absolute path of each opened file.</p> <p>In this presentation, we will show how this approach can allow us to distinguish required files from bloat, validate dependencies, and reduce container image size, resulting in smaller, faster, and more secure OCI images.</p>
<p>We usually think about successful open source in terms of user adoption, level of community contributions, or even vanity metrics like GitHub stars. But what if the success of many of the most popular open source projects in the cloud native ecosystem lies in the ability of external consumers to extend the project in ways the creators didn’t even envision?</p> <p>In this talk we’ll look at the containerd project and its intentionally designed extensibility. These extensible capabilities have become key launching points for innovation created and even maintained outside of the core project. We’ll look at the details of our snapshotter and shim interfaces, two popular ways to extend containerd that have many examples after 10 years of project development. New features will be demonstrated that utilize these interfaces such as native macOS support that uses the brand new "nerdbox" shim and the erofs snapshotter.</p> <p>We'll detail the concrete value provided by extensibility and invite other project creators and maintainers to consider how they are designing for extensibility to enable innovation.</p>
<p>Reproducing a container image would ideally be just a matter of setting <code>SOURCE_DATE_EPOCH</code> in your build commands or containerfiles. Like most reproducible builds though, that’s just one part of the story. And unfortunately, the other part is <em>not</em> the rest of the sources of non-determinism (and yes, there are quite a few). The most critical part of the story is <em>guaranteeing</em> that anyone can reproduce your container image <em>bit-for-bit</em>, regardless of the date, location, device architecture, or container runtime they are using. Who’s doing this though?</p> <p>In this talk we’ll explain why one should care about reproducible images, why are we reproducibly building <code>sha256:b0088ba0110c2acfe757eaf41967ac09fe16e96a8775b998577f86d90b3dbe53</code> for about a year now, and how you can easily leverage some of the stuff we learned along the way.</p>
<p>Containers are everywhere, whether you run them locally for testing or on a production server, there is always a need to find its logs, metrics to know how much resources are being consumed and whether it is stable or not.</p> <p>In this talk, we will demonstrate an example of how to monitor your Docker Containers using Prometheus and cAdvisor and view the metrics in Grafana to get better observability.</p> <p>It will be an introduction Open Source tools, integration and also an excellent opportunity to learn more about the advanced features, including troubleshooting & debugging.</p> <p>join us to learn more about Grafana, community contributions and share your feedback and suggestions!</p>
<p>Last year we open sourced a Containerization framework and container CLI tooling to enable developers to create and run Linux container images directly on their Mac in a way that focuses on security and privacy. In this talk, we'll dive into the Containerization framework, describing its foundational role in creating the container CLI which enables users to build, run and deploy Linux containers on Mac. We’ll walk through the architecture, highlight key APIs and discuss why we wrote it in Swift. We’ll then discuss some of our future roadmap for feature development and integration opportunities and challenges in the existing open source ecosystem.</p>
<p>OCI is many things, and soon it's a format systemd is going to understand somewhat natively. In this talk I want to explain the how, the why, and where we are going with this.</p>
<p>Over the past decade (or three) of container runtimes on Linux, the attacks against container runtimes with the most bang-for-your-buck have generally been filesystem related — often in the form of a confused-deputy style attack. This is aided in part by the sheer number of juicy targets accessible through filesystem APIs such as <code>/proc</code>.</p> <p>In particular, the past few years have seen quite a few security issues of this form in <a href="https://github.com/opencontainers/runc">runc</a> and other container runtimes — most recently in a set of CVEs published in November 2025 (<a href="https://github.com/opencontainers/runc/security/advisories/GHSA-9493-h29p-rfm2">CVE-2025-31133</a>, <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-qw9x-cqr3-wc7r">CVE-2025-52565</a>, and <a href="https://github.com/opencontainers/runc/security/advisories/GHSA-cgrx-mc8f-2prm">CVE-2025-52881</a>). However, this is far from a container-specific issue. Many Unix programs have historically suffered from similar issues, and the various attempts at resolving it have not really measured up.</p> <p>This talk will go through the myriad of issues necessary to protect user space programs against these kinds of attacks, completed and ongoing kernel work to try to make these problems easier to resolve, and our experience migrating a container runtime's codebase to a design which emphasises path-safety. In addition, this talk will also include an update on <a href="https://github.com/cyphar/libpathrs">libpathrs</a> (a library intended to make mitigating these attacks much easier for most Linux programs).</p>
<p>This talk is aimed to give an overview on a problem of system resource reporting in LXC-based containers.</p> <p>We will cover: - LXCFS - syscall interception (sysinfo) - what is still missing in kernel API</p>
<p>I run my 3D in Kubernetes, as-code and git versioned, and you can too! Say goodbye to your Raspberry Pets, lost configs, clunky updates, <code>apt upgrade</code> breaking your setup, and always out-of-date backups. Say hi to everything is versioned and tracked in git, one <code>git revert</code> away from mistakes.</p> <p>In this session I will showcase <a href="https://github.com/nadiamoe/kubeklipper/">kubeklipper</a>, a helm chart to run <a href="https://www.klipper3d.org/">Klipper</a>, <a href="https://github.com/Arksine/moonraker">Moonraker</a>, a web frontend (<a href="https://docs.mainsail.xyz/">Mainsail</a> or <a href="https://docs.fluidd.xyz/">Fluidd</a>) and even a slicer all in your Kubernetes cluster.</p>
<p>In 2025 we rebuilt www.epfl.ch from the ground up: a fleet of 650 WordPresses, masquerading as one Web site. By applying Kubernetes and nginx (instead of Apache previously) to the best of their abilities, we achieved a 10-fold reduction of our footprint, from 20 Kubernetes pods to 2. Our contribution consists of two dozen plug-ins for WordPress, and extensive configuration-as-code including an OpenShift (OLM)-compatible WordPress operator. You can use it in whole or in part for your organization today, and we'll show you where to start.</p> <h1>Starting Points</h1> <ul> <li><a href="https://github.com/epfl-si/wp-ops">wp-ops</a>: the main thing, w/ Dockerfiles and Ansible configuration-as-code. In turn, these pull together a whole lot of open-source code, and a number of other GitHub repositories from below https://github.com/epfl-si , all open-source; including:</li> <li><a href="https://github.com/epfl-si/wp-theme-2018/">wp-theme-2018</a>, showing the EPFL colors,</li> <li><a href="https://github.com/epfl-si/wp-menu-api">wp-menu-api</a>, a Node microservice to stitch all menus together,</li> <li><a href="https://github.com/epfl-si/wp-operator">wp-operator</a>, the OLM-conformant Kubernetes operator and Custom Resource Definition (CRD),</li> <li>various WordPress plugins, some generic like <a href="https://github.com/epfl-si/wp-plugin-pushgateway">wp-plugin-pushgateway</a> to push your wp-cron results into Prometheus, some very specific like <a href="https://github.com/epfl-si/wp-plugin-epfl-restauration">wp-plugin-epfl-restauration</a> which shows what's for lunch today;</li> <li><a href="https://github.com/epfl-si/wp-veritas">wp-veritas</a>, our backoffice GUI to create, update and delete WordPresses in the tree (written in Next.js);</li> <li>and <a href="https://github.com/epfl-si?q=wordpress&type=all&language=&sort=">many more</a>.</li> <li><a href="https://github.com/epfl-si/wp-dev">wp-dev</a>: to get the whole shebang (or most of it) up and running on your workstation — ready for hacking, committing, forking, and contributing.</li> </ul>
<p>devroom opening</p>
<p>Nixpkgs is massive with the largest, most up-to-date collection of Nix packages, powering reproducible systems and forming the backbone of many projects. But there's a problem: Nix packages' license metadata is a mess. </p> <p>Nix's license tracking uses a custom license ID system that doesn't match the best practice of using SPDX license expressions standards, inconsistently referencing SPDX or ScanCode LicenseDB. The metadata often falls out of sync with the actual code or misrepresents what's really licensed, and packagers typically only check the top-level declared license and skip the file-level details where the real complexity hides. For an ecosystem built on correctness and reproducibility, this is a gap we need to close.</p> <p>Nixpkgs Clarity fixes this with state-of-the-art automated license detection. We're correcting and standardizing license metadata across the entire Nixpkgs collection, aligning with SPDX best practices, and making sure what we declare actually matches what's in the code. This matters because accurate license data is critical for software supply chain security, CRA compliance, and anyone who needs to responsibly reuse Nixpkgs packages in production.</p> <p>This talk shows how we're detecting and correcting license metadata across Nixpkgs, and what changes when you finally have accurate license data. We'll share how we are tackling the unique challenges of Nixpkgs at scale, with tens of thousands of packages, Nix's functional approach to package definitions, and automated detection in a way that maintainers can trust and verify. </p> <p>If you care about making Nixpkgs even more reliable and supply chain ready, come see how we're bringing Nix's correctness principles to Nix packages' license metadata.</p>
<p>Since 2015, IndieHosters has specialized in hosting and making accessible free software as a service, from blogs and forums to wikis and online collaboration tools, with a core mission to enable people and organizations to always keep control over their data and privacy in order to achieve data sovereignty.</p> <p>To support this mission, we created libre.sh, a framework of tools that enables us to host free software at scale. It has evolved quite a bit since our initial talk at FOSDEM 2017. We progressively changed many of the tools and software we have been using, for instance, transitionning from Docker Compose to kubernetes. In more recent time, we are progressively using Nix and NixOS in various part of our work. In this talk, we wish to show what this change actually looks like in our processes.</p> <p>As a demonstration, we are gonna deploy an instance of LaSuite.coop, a fully-fledged application suite, starting from a fresh environment. Along the way we'll cover how our provisionning is done with nixos-anywhere and disko, how declarative Nix environments impacted our workflow, how we build reproducible container images using Nix, and more. Basically, if it uses Nix at IndieHosters, we will discuss it! We can't wait to discuss, share our experiences with the Nix community and receive valuable feedback from you!</p> <ul> <li><a href="https://k8s.libre.sh/">https://k8s.libre.sh</a></li> <li>https://LaSuite.coop is a cooperative of various french cooperatives, hosting free software mainly developped by https://lasuite.numerique.gouv.fr/en</li> <li><a href="https://archive.fosdem.org/2017/schedule/event/libre_sh/">Our 2017 FOSDEM Talk</a></li> </ul>
<p>Our digital lives are increasingly fragmented across numerous centralised online services. This model concentrates power, leaving us with minimal technical control over our personal data and online identities. The long-term permanence of these platforms is uncertain, and their commercial incentives are often misaligned with user interests. We propose inverting this model: instead of centralising our data in proprietary silos, let’s centralise our presence under our own control using open, federated services. We introduce the concept of ‘digital islands’, or Eileans – self-hosted hubs for an individual’s or community’s online presence. By hosting services ourselves, we regain autonomy and control. Eilean is a project designed to simplify the creation and management of these digital islands. The core idea is to parameterise a complete operating system deployment by a domain name and a desired set of services. This allows users to easily deploy their own instances of federated services like Matrix, Mastodon, and E-Mail. We utilise NixOS to enable declarative, reproducible configuration and deployment of these services. This provides strong guarantees about the system’s state.</p> <p>See the code at https://github.com/RyanGibb/eilean-nix</p> <p>Get in touch at https://ryan.freumh.org/about.html</p> <p>See the slides at https://ryan.freumh.org/talks/slides/2026-fosdem-eilean.html</p>
<p>With TAPPaaS we are building a small, composable private cloud for homes, communities and small organisations. It should feel like an enterprise‑grade packaged solution, but be built fully with FOSS and declarative Nix/NixOS tooling. Our current design is a 2‑node cluster with a third backup node, using Proxmox as cluster manager, NixOS and flakes for all VMs running platform services. All changes go through GitOps workflows, and services are packaged as NixOS modules that share central identity, secrets, backup and monitoring. We will show the architecture, NixOS/Flake deployment structure and CI/CD pipeline, and how declarative configuration helps with upgrades, failures and restores. This talk is for Nix/NixOS users and operators who want to turn homelab ideas into robust platforms for real organisations. We will share what works and where we struggle, and invite experienced nixers to challenge our choices and point us to patterns and tools we should adopt.</p>
<p>Reproducibility remains one of the largest challenges in benchmarking distributed systems, especially when hardware, kernel settings, and dependency versions vary between tests. This talk presents a NixOS-based approach for constructing deterministic, portable benchmark environments for large-scale data infrastructure. We show how Nix’s declarative system configuration, content-addressed builds, and reproducible packaging model allow engineers to isolate performance variables and eliminate configuration drift entirely. Using Apache Cassandra as the primary case study, the talk demonstrates how NixOS can define and reproduce complete cluster environments—from OS images to JVM parameters and custom benchmarking tools—across both cloud and on-prem setups. Attendees will learn practical patterns for packaging workloads, pinning dependencies, and generating ephemeral benchmark nodes. The session concludes with a discussion of how Nix abstractions can support multi-architecture testing.</p>
<p>NixOS reproducibility monitoring has historically been limited to the ISO images we ship, because they are a package set small enough to be rebuilt on a single machine. In this talk, we introduce <a href="https://github.com/nix-community/lila">LILA</a>, a decentralized reproducibility monitoring infrastructure for the NixOS community, aimed at removing this limit and allowing a collaborative monitoring of the entirety of nixpkgs!</p>
<p>The OCaml language package manager, Opam, has support for interfacing with system package mangers to provide dependencies external to the language. Supporting Nix required re-thinking the abstractions used to interface with traditional package managers, but enables using Opam for development easy whilst benefitting from Nix's reproducible system dependencies. This provides one example of how Nix interfaces with other software development and deployment technologies.</p> <p>Read more at https://ryan.freumh.org/opam-nix.html</p> <p>Get in touch at https://ryan.freumh.org/about.html</p> <p>See the slides at https://ryan.freumh.org/talks/slides/2026-fosdem-opam-nix.html</p>
<p>All the big cloud providers provide your machines with a unique cryptographic identity that can be used to talk to their cloud services securely without having to manage or rotate any cryptographic secrets yourself. For example GCP has Service accounts and AWS has IAM roles. This ubiquity of cloud identity and the seamless integration with all the the services of these cloud providers is one of the reasons why they are so successful.</p> <p>SPIFFE (Secure Production Identity Framework For Everyone) tries to unify these concepts of workload identity in a vendor neutral framework. But how do we bootstrap our cryptographic identity securely when we are running things on our own hardware as opposed to on cloud? What is our bottom turtle?</p> <p>In this talk, I will show how I use Nix OSin combination with the swiss-army knife of tools provided by systemd (ukify, systemd-measure, systemd-repart, systemd-veritysetup-generator) to create reproducible images for which we can predict TPM measurements.</p> <p>Paired with a custom attestation plugin for SPIRE (the reference CA server for SPIFFE) that uses TPM remote attestation I can give each of my servers a unique identity encoded in a TLS certificate if and only if they were booted up with the software that I intended them to boot up with.</p> <p>This then allows me to have workloads talk to each other with mutual TLS without having to manage any keys or certificates myself.</p>
<p>Have you ever felt the need for a virtual machine in your NixOS server environment? Maybe the functionality you want is not available in NixOS? Maybe there’s a custom OS image for a service you want to provide? Maybe you just want to securely isolate your workload? NixOS promises reproducible and declarative systems, but for VMs it just wasn’t there yet. To close this gap we built the <code>ctrl-os.vms</code> NixOS module, a solution to define generic virtual machines directly in your NixOS configuration. It works just like <code>virtualisation.oci-containers</code>, but for VMs instead of containers. 20 lines of Nix make it possible to run any Linux distribution you want as a VM on your NixOS host. To put a cherry on top you can use <code>cloud-init</code>, from our NixOS configuration to configure your guests declaratively, too! <code>ctrl-os.vms</code> is part of the <a href="https://github.com/cyberus-ctrl-os/ctrl-os-modules">ctrl-os-modules</a> repository.</p>
<p>I'll present my story of building a machine-readable inventory of computing equipment of my employer. It collects information such as: “<em>This <strong>computer</strong> is located in this <strong>room</strong> with this <strong>network configuration</strong>, these <strong>software requirements</strong> and is connected to this <strong>port</strong> of this <strong>switch</strong></em>” so that I can easily develop scripts that configure the machine, the switch, monitoring of both and many other things including a physical map.</p> <p>I went through many iterations of this project–codenamed <em>AR</em>–and settled on NixOS modules for their balance between how easy it is to write new records and how easy it is to use them. Let me share the joy it brought to my job and present curated code snippets so you can build your own inventory with ease.</p>
<p>Nix and Nixpkgs are gaining ever-broader adoption at the same time that SBOMs (Software Bills of Materials) are emerging as a standard format for demonstrating provenance. This talk will argue that bridging the gap is imperative for the Nix ecosystem, illustrate a fleshed-out approach to SBOM generation. This will suggest some improvements to Nixpkgs that I believe could unlock further progress.</p>
<p><a href="https://codeberg.org/xlambein/nixss">Nixss</a> (pronounced "nix" like you're a snake) is a Nix library for making static sites. It's not a static site generator, rather, it provides tools to build your own. Nixss comes with several pre-processors and combinators that will turn whatever files you throw at it into a tree of Nix derivations, which builds into a static site. It also has its own Nix-based templating system, if you'd rather not use more conventional ones.</p>
<p>NixOS, with its ability to centrally manage multiple devices, is an ideal way to maintain a network infrastructure that consists of multiple devices (routers, switches, access points). This presentation will provide an overview of how NixOS can be utilized on routers. This will include configuration based on systemd-networkd for routing and switching, as well as hostapd for Wi-Fi. It aims to provide you with tips on setting up your network infrastructure on NixOS itself.</p> <p>My personal NixOS configuration with three different home networks backed by NixOS: https://gitlab.com/Cynerd/nixos-personal/</p> <p>Project providing support for running NixOS on Turris routers: https://gitlab.com/Cynerd/nixturris/</p>
<p>Introducing <a href="https://github.com/minijackson/sphinxcontrib-nixdomain/"><code>sphinxcontrib-nixdomain</code></a>! A plugin for the <a href="https://www.sphinx-doc.org/">Sphinx</a> documentation generator that takes your Nix code and generates documentation for NixOS options, Nix packages, and Nix functions.</p> <p>This talk shows how to set up <code>sphinxcontrib-nixdomain</code> for your project, how to generate documentation for Nix objects, and how to add cross-references to those Nix objects.</p> <p>We'll also go over the benefits the Sphinx documentation system provides when used with this plugin.</p> <p>Resources:</p> <ul> <li><a href="https://sphinxcontrib-nixdomain.readthedocs.io/"><code>sphinxcontrib-nixdomain</code> documentation</a></li> <li><a href="https://github.com/minijackson/sphinxcontrib-nixdomain/"><code>sphinxcontrib-nixdomain</code> source code</a></li> <li><a href="https://www.sphinx-doc.org/">Sphinx documentation</a></li> <li><a href="https://epics-extensions.github.io/EPNix/">EPNix documentation</a>, my work project that extensively uses <code>sphinxcontrib-nixdomain</code></li> </ul>
<p><a href="https://github.com/hoh/nix-manipulator">Nima</a>, the Nix Manipulator, is a new Python library and collection of tools for <strong>parsing, manipulating and reconstructing</strong> Nix source code.</p> <p>This presentation will introduce the project, its original goals, key features, and practical applications. It will explore the tradeoffs and decisions made during development and demonstrate how to use its various features.</p> <h3>Context</h3> <p>Started during <a href="https://saltsprint.org/">SaltSprint</a> 2025, Nima aims to fill the absence of tools for easily updating and editing Nix code. Popular tools such as <a href="https://github.com/Mic92/nix-update">nix-update</a> rely on <a href="https://github.com/Mic92/nix-update/blob/fbb35af0ed032ab634c7ef9018320d2370ecfeb1/nix_update/update.py#L26">simple string replacement</a> or regular expressions for updating Nix code.</p> <h3>Goals</h3> <ul> <li>Ease of use.</li> <li>High-level abstractions make manipulating expressions easy.</li> <li>Preserving formatting and comments in code that respects RFC-166.</li> </ul> <p>Eccentric formatting that does not respect RFC-166 and would add unnecessary complexity may not be preserved.</p> <h3>Targeted applications</h3> <ul> <li>Updating values in Nix code by hand, scripts, pipelines, and frameworks.</li> <li>Writing refactoring tools.</li> <li>Interactive modifications from a REPL.</li> </ul> <h3>Foundations</h3> <p>Nima builds on <strong>tree‑sitter</strong>, a multilingual concrete‑syntax AST, with the <a href="https://github.com/nix-community/tree-sitter-nix">tree‑sitter‑nix</a> grammar providing lossless parsing of Nix files.</p> <h3>Project status</h3> <p>The project is still in <strong>early‑stage</strong>:</p> <ul> <li>Most Nix syntax is supported, but not all everything yet.</li> <li>Test-driven approach prevents regressions.</li> <li>CLI and API stability is still evolving.</li> </ul> <h3>Links</h3> <p>Source: https://github.com/hoh/nix-manipulator Announcement: https://discourse.nixos.org/t/announcing-nix-manipulator-nima-structured-edits-for-nix-that-keep-formatting/68513/11</p>
<p>Nix Forge is an attempt to lower the barrier and learning curve required for packaging and deploying software with Nix, enforce best practices and unlock the superpowers of Nix.</p> <p>By providing a human-readable packaging recipe format (inspired by conda-forge), Nix Forge abstracts away the need for advanced Nix packaging knowledge and experience without sacrificing its powers. Users can define packages and multi-component applications running in shell environments, containers, or inside a NixOS system using simple declarative configurations instead of writing Nix expressions. The NixOS-style module system guides users through the packaging process, enforces best practices, and provides type checking for recipes—ensuring quality and correctness from the start. On the other hand, the web user interface provides an attractive catalog of packages and applications with copy-paste instructions for end users.</p> <p>This presentation will demonstrate how this approach significantly benefits developers in the era of LLMs. With its simplified, structured format, LLMs can now effectively help users create and modify Nix packages—a task that previously required deep Nix expertise. The human-readable recipes allow developers to easily verify LLM-generated configurations, while built-in type checking enforces correctness automatically.</p> <p>Source code - https://github.com/imincik/nix-forge Web UI - https://imincik.github.io/nix-forge</p>
<p>This talk details our personal journey of creating a setup for video streaming at conferences, called <a href="https://github.com/OpenFest/mixos">mixos</a>. We explain the challenges we faced and how Nix and NixOS helped us get the work done in a robust and efficient way. We do not consider ourselves extremely proficient in Nix, so any feedback from the community would be greatly appreciated.</p> <p>In addition, we (as part of the FOSDEM video team) demonstrate how the same Nix-based setup can run on a <a href="https://github.com/fosdem/video">FOSDEM video box</a>.</p>
<p>Debugging Nix can be frustrating: poor error reporting, non-incremental builds, and cryptic stack traces make fixing a derivation a pain. This talk presents practical tools and techniques to make working with Nix expressions and builds more fun. A significant portion of this talk is a live coding demo, targeted at somewhat beginner-intermediate Nix users.</p>
<p>Discover how PEP 810's explicit lazy imports can dramatically improve Python application startup times. Using a real CLI tool as a case study, that we totally use in our real business, this talk demonstrates practical techniques to optimize import performance while maintaining code clarity and safety.</p>
<p>Python’s Global Interpreter Lock has shaped the way developers build concurrent applications for nearly three decades. While the GIL simplified the CPython ecosystem, it also imposed well-known limits on CPU-bound work and multithreaded scalability. With the introduction of free-threaded Python (3.14t), that is about to change.</p> <p>This talk explores the history and purpose of the GIL, why it existed for so long, and the innovations that finally made its removal viable. We’ll look at how free-threading affects real workloads through concrete benchmarks. We'll investigate the often overlooked effect of freethreading on webservers. You’ll see how modern servers like Granian, ASGI frameworks, and WSGI stacks behave when threads are no longer serialized by the interpreter.</p> <p>By the end, you’ll understand not only what the GIL is, but what its disappearance means for scaling Python applications in production. Whether you're building high-throughput APIs, tuning async code, or planning future architecture, free-threaded Python opens the door to new performance ceilings - along with new tradeoffs every developer should know.</p>
<p>Apache Airflow is the most popular Data Workflow Orchestrator - developed under the Apache Software Foundation umbrella. We have 120+ Python distributions in our rep, and we often release ~ 100 of them every two week. </p> <p>All those distributions are built from a single monorepo. </p> <p><code>[jarekpotiuk:~/code/airflow] find . -name 'pyproject.toml' | wc 120 120 4248</code></p> <p>This had always posed a lot of challenges and we had a lot of tooling to make it possible, however with the recent development of Python Packaging tools, multipel Packaging PEPs implemented, and with new wave of tools such as <code>uv</code> and <code>prek</code>, our setup is finally manageable and we removed 1000s of line of custom code we wrote before after we applied <code>uv</code> workspaces, switched to <code>prek</code>, started using inline script metadata.</p> <p>It's a breeze to have monorepo now. This talk explains how.</p> <p>Bonus content. If you know the differences between dynamically and statically linked libraries in C and other languages, or used NPM - you might recognise the need of being able to use different versions of the same library in the same system. It's not possible in Python. Or is it? </p> <p>We've figured out a way to eat cake and have it too - and we have "statically linked" libraries in Python. How did we do it? </p> <p>You will find out how from the talk.</p>
<p>Remember when we said "Infrastructure as Code"? Somehow, the industry heard "Infrastructure as YAML" and ran with it. Now we're drowning in a sea of indentation-sensitive, template-riddled, Jinja2-abused configuration files that make even the most battle-hardened sysadmins weep into their mechanical keyboards.</p> <p>Enter <strong>PyInfra</strong>—where your infrastructure is <em>actually</em> code. Real Python. With loops that don’t require learning a DSL. With functions that are... wait for it... actual functions. With error handling that doesn’t involve praying to the YAML gods and sacrificing a virgin bracket.</p> <p>In this talk, you’ll see how to: - Write infrastructure automation that your IDE actually understands - Debug with real stack traces instead of <code>"ERROR: The task includes an option with an undefined variable"</code> - Use actual Python conditionals instead of <code>when: ansible_os_family == "Debian" and not (ansible_distribution == "Ubuntu" and ansible_distribution_version is version('20.04', '>='))</code> - Import and reuse code like a civilized developer, not copy-paste playbooks like it’s 1999 - Test your infrastructure code with <code>pytest</code>, not <em>"let’s run it in staging and see what breaks"</em></p> <p>We’ll explore how a typical Ansible playbook can be transformed into clean, maintainable Python with PyInfra, shrinking from 500 lines of YAML to 50 lines of readable code. You’ll discover the joy of list comprehensions over <code>with_items</code>, and the power of deployment logic that can actually <em>think</em>.</p> <p>Stop treating your infrastructure like a configuration file. It’s 2026—your servers deserve better than YAML. They deserve Python.</p> <p><strong>Warning:</strong> This talk may cause uncontrollable urges to refactor all your Ansible playbooks. Side effects include increased productivity, better sleep, and colleagues actually understanding your infrastructure code.</p> <p>Link to the marp: https://marp.kalvad.com/fosdem_2026 (gifs are not working in pdf)</p>
<p><em>Summary:</em></p> <p>ETL stands for "extract, transform, load" and is a synonym for moving data around. This has traditionally often required managing complex systems in the cloud or large data centers. The talk will demonstrate how all this can be greatly simplified by applying modern tools for the task: Python and DuckDB, both open source and readily available to run on most systems - even your notebook.</p> <p><em>Description:</em></p> <p><strong>ETL</strong> stands for "extract, transform, load" and is a synonym for moving data from one system to another. </p> <p>Traditionally, ETL was done in exactly that order: first you extract the data you want to process, then you transform it and then you load it into the target system. More modern approaches based on data lakes, swap the T and L, since transformation is more efficiently done in a database system, especially when it comes to large volumes of data.</p> <p>In order to make all this work, the usual approach is to have a workflow system, taking care of managing all the intermediate steps, a large data lake database and distributed storage systems. This results in lots of complexity, need for system/cluster administration and maintenance.</p> <p>Now, with today's computers, most data sizes used in ETL no longer need all this complexity. Even notebooks or single VMs can handle the load, when used with external object storage, so all you really just need is the right software stack to manage your ETL - without all the overhead:</p> <ul> <li> <p><strong>Python</strong> has grown to be the number one programming language on the planet and is especially well suited for integration work due to its many readily available connectors to plenty of backend systems. It often comes preinstalled on Linux machines and is easy to install on most other systems.</p> </li> <li> <p><strong>DuckDB</strong> has emerged as one of the most capable embedded OLAP database systems and supports data lakes with the DuckLake extension, right out of the box. Installation is just a <code>uv add duckdb</code> away.</p> </li> </ul> <p>Both can be run on the same machine and are very resource friendly.</p> <p>The talk will give an overview of the typical steps involved in ETL processes, give a short intro to DuckDB and showcase how DuckDB can be put to good use when implementing ETL processes. If time permits, I can also cover a few advanced topics addressing optimization strategies.</p> <p><em>Resources:</em></p> <ul> <li> <p><a href="https://www.python.org/">Python.org</a></p> </li> <li> <p><a href="https://duckdb.org/">DuckDB – An in-process SQL OLAP database management system</a></p> </li> </ul>
<p><a href="https://www.djangoproject.com">Django</a>'s built-in admin is powerful, but it's essentially a separate framework within Django and it's 20 years old.</p> <p>Wouldn't it be nice to be able to work with an admin interface that works like the rest of Django, built on generic CBVs, plugins, and view factories? <a href="https://github.com/jazzband/django-admin2">Django-Admin2</a>, was an attempt at doing just that and it was a fairly successful ptoject.</p> <p>10 years later, after looking at reviving that project, I realized we needed a fresh approach: Meet <a href="https://codeberg.org/emmaDelescolle/django-admin-deux">Django-Admin-Deux</a>: a proof-of-concept Django admin replacement where CRUD operations are just actions, knowledge transfers both ways, and everything feels like Django.</p> <p>Let's have a look at what python features and architecture makes this possible</p>
<p>The French digital agency (DINUM) has undertaken to develop an open-source collaborative digital workplace to make the work of public servants simpler and more effective.</p> <p>This collaborative digital workplace is distributed under an open-source license to allow anyone who wishes to take its applications and integrate them into their preferred tools.</p> <p>By participating in existing open-source communities, the digital workplace enables the emergence of digital commons that facilitate independence for those who wish to deploy and use them.</p> <p>Designed with a modular approach, it can be partially or progressively adopted or complement an existing offer.</p> <p>I propose to present two applications, both technically and functionally, that are integrated into this collaborative suite:</p> <ul> <li> <p>Collaborative editing and documentation: The Suite <a href="https://github.com/suitenumerique/docs">Docs</a>, based on Prosemirror and Blocknotejs. Developed jointly with Germany and the Netherlands.</p> </li> <li> <p>File sharing: <a href="https://github.com/suitenumerique/drive">Drive</a></p> </li> </ul> <p>These applications share the same technical stack, which relies on Python and the Django framework, Django Rest Framework, and PostgreSQL.</p> <p>Beyond a list of libraries used, I will present the quality processes we have implemented, the complete workflow from the idea of a new feature to its implementation and deployment. I will share our dev handbook (also under an open-source license) that compiles our best practices.</p> <p>How what could be qualified as a "Boring Stack" (meaning proven and battle-tested) allows us to focus on solving complex problems.</p>
<p>After the success of last year's impromptu lightning talks session, we will have an official one in the Python Devroom for 2026.</p> <p>Please submit your talks using this form:</p> <ul> <li> <p><a href="https://docs.google.com/forms/d/e/1FAIpQLSfh1zpbP6KgMmexQeT6jlcX1_o8W26zovBUVVudxopBMfjGsg/viewform?usp=header">Lightning Talk Submission Form</a></p> </li> <li> <p>The form will be opened for submissions at around 14:00 CET on Saturday, Jan 31, 2026.</p> </li> </ul> <p>Lightning Talks are at most 5 minutes and should be Python related.</p> <p>Note: All presentations in this slot will be recorded and made available under a CC-BY license.</p> <p>Thank you, Python Devroom Organizers</p>
<p>Join the Ariel OS community for an informal BoF session where maintainers, contributors, and anyone interested in hearing more about Ariel OS will be discussing the latest. - Feedback: What works for you and what does not. Where can we do better. - Roadmap: Where do we go from here - Challenges: Where do you see issues and challenges along the way.</p>
<p>A meetup for people interested in FOSS solutions for processing the videos from the raw data captured by the camera sensors (in formats such as Magic Lantern Video, CinemaDNG, CanonRaw).</p>
<p><a href="https://github.com/dracut-ng/dracut-ng">Dracut</a> is an event driven initrd infrastructure. It is used as default initrd generator in many Linux distributions. Ubuntu and Debian will make it the default as well.</p> <p>This is a BoF for all people interested in talking about Dracut. Come to this BoF in case you want to talk to the upstream/downstream maintainer(s) of Dracut in person.</p>
<p>Are you building something cool with a friendly functional programming language? Bring your projects for a laid-back show and tell session! We'll look at real-world code in languages like Gleam, OCaml, Elm, Kotlin, and other functional languages that emphasize type safety without unnecessary complexity.</p> <p>Share a piece of code you're proud of, a thorny problem you solved elegantly, or simply come to see how others are using functional programming to build practical things. We'll explore patterns that work well across different languages and discuss how type systems and functional features help us write more reliable software.</p> <p>Whether you're a functional programming enthusiast or just curious about these languages, join us for an interactive session focused on real projects and practical experiences. No deep theory required - just genuine examples and friendly discussion about building things that work.</p> <p>This is a participatory session - if you have a project to share, great! If not, come with your questions and curiosity. We're happy to meet you!</p>
<p>Join us for the NetworkManager meetup at FOSDEM 2026 to share your ideas, provide feedback or simply meet other users. There is no fixed agenda, so please bring your own topics.</p> <p>https://networkmanager.dev/</p>
<p>Welcome session.</p>
<p>Robot Vacuums are a pretty common item in many households around the world. They've also become a fairly standard item for robot hobbyists to hack on and use as cheap, open platforms for experiments in mobile bases. The classic "Turtlebot" platform has seen many incarnations, as the iRobot Create series, the Kobuki base, the Neato BotVac and now lives on in the "Hackerbot" from HackerBot Industries(https://www.hackerbot.co/). It has an open command set, options for an arm, animated head and SDK to support the development of character-like human-robot interactions. It does autonomous mapping of whatever space it was in at the push of a button. Unfortunately, the map is stored in an internal proprietary format, accessible through an app you download onto your phone.</p> <p>I have a number of robots at home and in my lab, all of which run ROS. Surely there must be some way to hack out the map and convert it into a ROS-compatible format that my other robots could use! My talk would be discussing the steps I took to make this happen, the FOSS packages I used and the resulting tool. </p> <p>This is not my first excursion into hacking robot mapping and sensors, so I'll also present some tips and tricks I've learned over the years to make seemingly proprietary robot subsystems more open and generally usable. </p> <p>Mapping tool GitHub: https://github.com/jetdillo/hackerbot-maptools</p> <p>Hackerbot Base: https://www.hackerbot.co/</p> <p>My robot consulting business: https://www.familiarrobotics.com</p>
<p>When building a robot you want to make sure your set up is perfect. This means good calibration for your sensors, good configurations for your sensors, good synchronization between sensors, good data logging practices and much much more! </p> <p>In this talk Roland and Sam will talk about their experiences with poorly configured robots, the importance of visualisation and the (open source) tools they use to solve their problems.</p>
<p>As robotics systems grow more complex, bringing together all types of specialties from algorithm/ML developers, control engineers, to safety engineers, has become increasingly painful, especially when working with large, brittle stacks like C++ and ROS.</p> <p>This talk shares the journey of building Copper-rs, a Rust first robot runtime to make robotics development simpler, safer, and more predictable. Rust’s mix of performance, memory safety, and fearless concurrency offers a foundation for systems that don’t collapse under their own complexity.</p> <p>Built entirely in the open, Copper-rs has grown out of the Rust for Robotics community and explores how we can take the openness and collaboration that made ROS successful and bring those values into a new generation of deterministic, Rust-based robotics systems.</p> <p>The copper-rs project is an Apache v2 project available at https://github.com/copper-project/copper-rs</p>
<p>ROS 2 is tied to specific Ubuntu versions, which limits platform choice and can introduce additional configuration complexity. In this talk, I will explain how to run ROS 2 on non-standard platforms using Apptainer, a practical alternative to Docker. I explain why Apptainer works well for robotics: it enables easy access to USB and serial devices, supports GPUs, and runs GUI programs like rviz without configuration. The talk ends with a short look at when the package manager Pixi might even let you avoid containers altogether. Being less tied to a specific Ubuntu release makes robot development more flexible.</p>
<p>Just1 is an open-source robotics platform built for learning and rapid experimentation. It supports manual and autonomous navigation, path following, and obstacle avoidance. With a bill of materials around $250, it offers an affordable way to explore robotics, ROS 2, and autonomous behaviors.</p> <p>The hardware includes a Raspberry Pi 4, mecanum wheels, TT motors, a 2D LiDAR, Raspberry Pi camera, and an IMU. The software stack is based on ROS 2 Jazzy, with RTAB-Map for SLAM, Nav2, and Foxglove integration.</p> <p>I created Just1 as a simple, low-cost platform to experiment and to share with the community. Upcoming work focuses on simulation support (Gazebo / NVIDIA Isaac).</p> <p><a href="https://github.com/NRdrgz/Just1">Github Repo</a> </p> <p><a href="https://nrdrgz.github.io/2025/10/21/building-just1-autonomous-robot/">Blog Article</a></p>
<p>The learning curve for ROS2 can be steep, often requiring the installation and resolution of diverse software dependencies across operating systems, sensors, network configurations and robotic platforms. By combining virtual machines (VMs), with their off-the-shelf, ready-to-use environments resources and modern container registry workflows, we can reduce this complexity and enables learners to focus more directly on developing ROS2 skills. This approach also offers a smoother onboarding process for participants with varying levels of technical experience. In this talk, we share hands-on insights from our hackathon, which explored a distributed setup involving two servers located in different University College London (UCL) departments --Advanced Research Computing (ARC) and Civil, Environmental and Geomatic Engineering (CEGE)-- connected via a Zero Overhead Network Protocol (Zenoh) router with 10 GbE connectivity. One server from CEGE was connected to physical sensors --laser scanners, Inertial Measurement Units, and cameras-- with data streamed through the ROSBridge suite and Zenoh. On the ARC server and platforms (unified-AI and condenser), participants worked with off-the-shelf VMs and within containerised environments running ROS 2 Humble on Ubuntu 22.04. Five to ten participants accessed live sensor data via the ROSBridge Suite to visualise streams, perform object recognition and segmentation, and analyse outputs. They experimented with network constraints by varying sample rates, data types, and file sizes, and explored the trade-off between CPU usage for core ROS 2 packages and GPU demands for intensive tasks. Lessons on containerisation for virtual machines, managing dependencies, understanding latency and bandwidth, balancing resources, and cost considerations were shared, alongside next steps and a call for collaboration to advance ROS 2 skills and infrastructure in academia. </p> <h4>References</h4> <ul> <li>The slides are available <a href="https://ucl-cyberphysicalsystems.github.io/fosdem2026/">here</a>.</li> <li>See our <a href="https://github.com/UCL-CyberPhysicalSystems/hackathon-01">hackathon github repo</a> for further details, the discussion forum, and ways to get involved.</li> </ul>
<p>Building localization and navigation systems requires a lot of time, effort and statistical analysis over multiple scenarios. There are multiple sparse tools out there to create specific KPIs around datasets but almost none that provide end to end integration test scenarios, KPIs and automatic report generation for localization systems. Last year, at FOSDEM, we presented beluga - https://github.com/Ekumen-OS/beluga - a Monte Carlo Localization Framework for robotics. This year, we would like to present one of the tools we built for this project, Lambkin, the Localization and Mapping BenchmarKINg system that allows to orchestrate test runs of your code, data, KPIs and report generation all in one platform. You can find the code here: https://github.com/Ekumen-OS/lambkin</p>
<p>ROS2’s interface generation can be a major bottleneck in the build process, especially for large projects. The rosidl toolchain, while reliable, is slow due to its Python-based code generation and inefficient use of CPU resources. rosidlcpp (https://github.com/TonyWelte/rosidlcpp) tackles these challenges by reimplementing the rosidl generators in C++. However, switching to C++ is only one of the ways rosidlcpp achieves faster builds. This talk will walk through the optimization journey behind rosidlcpp. We’ll cover how the build inefficiencies were diagnosed and the techniques used to address them.</p>
<p>More than two decades have passed since the first steps of the Gazebo simulator, one of the early attempts to provide a fully-featured 3D environment for robotics simulation. Rewritten into modular libraries, the new Gazebo preserved most of the internals from the previous era even if new features have been added continuously.</p> <p>Meantime, especially in the last 5 years, the field of robotics simulation has experienced a rapid transformation. A new generation of simulators has emerged (Isaac Sim, O3DE, Carla, etc.) showing powerful rendering capabilities and advanced physics engines, supported by GPU acceleration to enhance realism and performance. These developments have not only changed the landscape of simulation, but have also created new opportunities for integrating AI, machine learning, and robotics in more complex and scalable virtual environments.</p> <p>Are there any plans to push Gazebo into the modern features? The talk will provide information directly from one of the members of the Gazebo core team about existing roadmaps, funded projects, proof of concepts and any internal discussions on what could come for Gazebo in the future.</p>
<p>Rust offers many advantages for robotics. One key benefit is its memory safety, which helps prevent critical bugs in complex systems. Additionally, its high performance is essential for real-time applications, while safe concurrency allows for efficient parallel processing, crucial for multi-core robotic systems.</p> <p>This talk will present rclrs (https://github.com/ros2-rust/ros2_rust), the Rust client library for ROS 2, and its accompanying tooling. rclrs is being developed in the open by a community of Rust and ROS enthusiasts. Support for Rust is now part of ROS 2 rolling and will be shipped in the next ROS 2 releases.</p>
<p>In this talk, we will discuss the open hardware and open-source software available today for creating open-source robots, taking the Upkie wheeled bipeds as our working example:</p> <ul> <li>Project page: https://hackaday.io/project/185729-upkie-wheeled-biped-robots</li> <li>Robot software: https://github.com/upkie/upkie/</li> <li>Robot hardware: https://github.com/upkie/upkie_parts</li> </ul> <p>On the software side, we will go through the core robotics libraries used by the robots: Gymnasium, moteus, and PyBullet, as well as libraries for developing robot behaviors, such as Stable-Baselines3 for reinforcement learning and qpmpc for model predictive control. We will compare model-based and AI-driven approaches to implement new behaviors on Upkies, discussing what has worked and not worked so far, as well as future plans for the project like integrating vision for perceptive locomotion.</p> <p>On the hardware side, we will describe how Upkies use mjbots actuators and PCB cards, which are fully open source (down to motor-driver firmware and KiCad electronics files!). Upkies can be built from off-the-shelf components for around $3,000, making experimentation with bipedal robots more accessible to hobbyists and educators. We will finally conclude by releasing version 2 of the robot hardware with an on-stage demonstration.</p>
<p>Building robots, whether industrial arms or autonomous vehicles, often comes with middleware pain that drains valuable engineering time. Issues like communication delays, execution inconsistencies, poor scalability, and nondeterministic behavior are common and frustrating. Most developers want to focus on their application, not on becoming middleware experts.</p> <p>This talk introduces <a href="https://github.com/eclipse-iceoryx/iceoryx2">iceoryx2</a>, the next generation of the widely used zero-copy middleware Eclipse iceoryx. It is written in Rust, with additional bindings for C, C++, Python, and C#, and runs on a variety of operating systems. iceoryx2 is already used in robotics, automotive, medical, finance, and other domains where high-throughput and low-latency communication are critical.</p> <p>We will walk through common middleware pain points in robotic systems and show how iceoryx2’s architecture and feature set help eliminate or significantly reduce them.</p>
<p>Many ROS developers know PX4 exists but never get the chance to actually poke at it. This talk gives you that chance. We walk through a complete precision landing pipeline using PX4, ROS 2, OpenCV, Aruco markers, and Gazebo, built the same way we teach it in our hands on workshops.</p> <p>We start with the pieces of the PX4 architecture that matter to you as a ROS developer, then show how the PX4 ROS 2 interface works, including the PX4 ROS 2 Library by Auterion that makes message handling feel familiar instead of foreign. From there we jump into simulation with Gazebo, run OpenCV based Aruco detection, and wire it all into a precision landing controller.</p> <p>The heart of the session is practical. We take the tag pose produced by OpenCV in the camera optical frame, transform it into the body frame and world frame, and use it to run an approach phase with PI velocity control. We cover the spiral search pattern for when the tag is not visible, and the land detection feedback that lets the system finish the job safely.</p> <p>To make it easy to try everything at home, we will provide a Docker container and an open repository with all the source code and configuration you need to reproduce the pipeline on your own machine.</p> <p>If you have ever thought about connecting your ROS and OpenCV skills to PX4 but did not know where to start, this talk will get you there with a smile and a working example you can take home.</p>
<p>Have you ever wanted to build your own robot but felt overwhelmed by the complexity of dependencies, compilers, and unstable C++ code? Then why not use Rust? In this talk, we aim to convince you that ROS 2-Rust allows the creation of a state-of-the-art stack that is simple, safe, robust, memory-safe, and highly-performant, drastically reducing the time spent debugging runtime crashes. We will also show how to take advantage of Cargo, the Rust package manager, to ease dependency management.</p> <p>In order to demonstrate our postulate, we have open-sourced a repository that allows everyone to create a minimal, teleoperable rover from scratch. This shows how ROS 2-Rust can further reduce the barrier to entry in the world of robotics.</p> <p>This project also displays how we used Pixi to simplify the entire development workflow, allowing any developer to clone our open-source repository and achieve a fully working, cross-platform ROS 2 and Rust environment with just a single Pixi install command.</p> <p>Join us to see how this modern toolchain transforms complex robotics projects into an accessible and enjoyable open-source experience. We aim to inspire you to start your own rover project and show that building your first robot is now as simple as that.</p>
<p>Simulation has evolved to be a key part of robotics development. Nevertheless, existing simulators such as Gazebo and O3DE tend to be time consuming to set up, computationally heavy and out of the box often simulate systems too idealistically, leading to systems that work in simulation but fail in the real world.</p> <p>The new ROS 2 package <code>vehicle_dynamics_sim</code> aims to resolve this situation for the specific case of mobile platforms by providing an easy to configure and lightweight vehicle dynamics simulator focused on realistic actuator dynamics. It by default simulates real world imperfections such as dead time and acceleration limits, comes with six vehicle types (four bicycle/Ackermann + differential + omni/mecanum) and is fully configured through a minimum of ROS parameters. The two main use cases are trajectory following controller development and automated validation (CI).</p> <p><a href="https://github.com/abaeyens/vehicle_dynamics_sim">vehicle_dynamics_sim code and documentation</a></p>
<p><a href="https://www.ros.org/">ROS</a> is a popular and widely used middleware, ecosystem, and environment for robotics development. It's become quite popular in research environments and for early prototyping, but it's not as common to see it in production environments. Why is that?</p> <p>In this talk, I'll go over my experience productionising ROS in professional settings, what gaps ROS has, and how you all can avoid the pitfalls, issues, and hellholes I've dug myself into multiple times through my career. This will include ROS message serialisation and how to mesh it with other serialisation formats, how you can leverage <a href="https://bazel.build/">Bazel</a> to generate real ROS build artifacts with <a href="https://github.com/mvukov/rules_ros2">rules_ros2</a>, and how to integrate all the above into a real robot in production with OTA updates.</p> <p>You can find the examples for this talk at <a href="https://github.com/rdelfin/ros2_bazel_examples">https://github.com/rdelfin/ros2_bazel_examples</a></p>
<p>ArduPilot is a trusted, versatile, and open source autopilot system supporting many vehicle types: multi-copters, traditional helicopters, fixed wing aircraft, boats, submarines, rovers and more. The source code is developed by a large community of professionals and enthusiasts. https://ardupilot.org/</p> <p>ArduPilot is a well known autopilot for drones but it is often associated to only hobby or academic work. This talk will showcase some advanced features and integration of ArduPilot. The talk will present for each type of vehicle some interesting less known features and provide focused explanation on dual autopilot (or more) and advanced video feed usage with BlueOS (https://bluerobotics.com/what-is-blueos/).</p> <p>This should give idea how far people can integrate and what crazy idea are possible with ArduPilot from hobbyist to industrial grade, all staying FOSS and documented, of course !</p> <p>I won't speak about rockets nor GPS denied things. If time permits FROST quantum interoperability will be detailed.</p>
<p>What if you could build an autonomous, outdoor collaborative robot using free, open-source tools and community-driven software? That’s exactly what we did at Botronics. In this talk, we will take you behind the scenes of iXi, our autonomous golf trolley, showing how we use open-source technologies, from high level behaviors and control to simulation, fleet management, monitoring, and user interfaces, to build a real-world robotic system deployed outdoors.</p> <p>You’ll see how tools like ROS 2, Gazebo, Nav2, BalenaOS, Docker, Telegraf, Grafana, Rviz2, and React/React Native come together into a production stack to deploy one of the first outdoor collaborative robots. More than just engineering talk, the objective is to provide a return of experience and lessons learned about what open-source robotics can enable outside the lab: reproducible development, remote deployment, full observability, and real user-facing applications.</p> <p>If you are interested in taking robotics beyond prototypes, building autonomous systems that work in the real world, this session will show you what’s possible using open source stacks from end to end.</p>
<p>ROS 2 was designed to be independent of its underlying communication middleware — a powerful architectural feature, but one that introduces complexity and overhead. </p> <p>While working on rmw_zenoh, we kept wondering: What if we streamlined the ROS 2 layers and built a Rust-native stack from Zenoh up to the RCL API? Could it improve performance? Would it be easier to extend? And could we still support existing RCL-C/C++/Python packages through C bindings?</p> <p>This led us to develop ROS-Z, a Rust/Zenoh-native RCL stack, fully interoperable with ROS 2 via rmw_zenoh. In this talk, we’ll explore our design choices, share performance insights, and highlight the some of the unique features we’ve added to push innovation even further.</p>
<p>EasyNav is a fully open-source navigation framework for robots, designed to be lightweight, modular, and suitable for real-time execution. The project is motivated by the limitations of existing systems, which are tightly coupled to a single environment representation and often introduce unnecessary computational overhead. EasyNav decouples navigation from the underlying map structure, enabling costmaps, gridmaps, NavMap, or other models to be used interchangeably. Its architecture is built around a minimal core and open, extensible stacks that group controllers, planners, localizers, and map managers. The framework is designed to be easy to inspect, modify, and extend through its clear plugin interfaces. This talk will present the motivation, architecture, main features, and evaluation results in simulation and real robots, showing how an open-source approach improves flexibility, transparency, and performance in complex scenarios.</p> <p>Links: - https://easynavigation.github.io - https://github.com/EasyNavigation/</p>
<p><a href="https://github.com/autoapms/auto-apms">AutoAPMS</a> is a heavily extensible development framework for behavior-based ROS 2 applications. It provides a highly modular integration of behavior trees. In this talk, I'm explaining the core concepts while walking through the development workflow using an applied example. This should give you a good idea of whether AutoAPMS is for you or not.</p> <p>The intention of this project is to make it significantly more user-friendly and less error prone to develop autonomous robotics with behavior trees. The core packages are written in C++ and a supplementary Python API exposes high-level features for scripting.</p> <p>The framework relies on the popular BehaviorTree.CPP library under the hood and offers a Nav2-agnostic approach for using it within the ROS 2 ecosystem. It was inspired by BehaviorTree.ROS2 and can be considered a spiritual successor. AutoAPMS took the core ideas of the behavior tree paradigm and supercharged it with the following features:</p> <ul> <li>Convenient resource management using <code>ament_cmake</code> and <code>ament_index</code></li> <li>Inherently extensible due to plugin-based design</li> <li>Flexible and highly configurable behavior execution engine</li> <li>Powerful C++ behavior tree builder API (a supplement to BehaviorTree.CPP)</li> <li>High-level node manifests for registering node plugins without writing a single line of code</li> <li>Support for custom behavior definitions and tree builder algorithms</li> <li><code>ros2 behavior</code> command extending the ROS 2 CLI</li> </ul>
<p>PlotJuggler is an open source QT/C++ application that allow developers to visuale and analyze timeseries from logs, that it is very popular in the robotics and drones community.</p> <p>It supports both static files and real-time streaming.</p> <p>Its plugin-based architecture makes it easy to extend; this allowed people to add more and more formats, in terms of streaming transport (Websocked, MQTT, ZeroMQ, UDP, ROS2, etc.), serialization protocols (DDS, Protobuf, JSON, Proprietary) and file formats (rosbags, PX4 logs, CSV, Arrow Parquet, etc).</p> <p>Furthermore, it includes a Lua-based data editor that allows the user to manipulate and transform data, effectively replacing the need for those "short-lived" Python scripts that people in this community would create to quickly analyze their data.</p> <p>Its Github repository (https://github.com/facontidavide/PlotJuggler) is approaching its 10th anniversary, with 5.5K stars, 2500+ commits and 120+ contributors.</p>
<p>In this session, four seasoned database administrators with sound knowledge of both PostgreSQL and MySQL present an unbiased comparison of the two technologies. Attendees will learn about the architectural and DX differences between the world's two most popular databases.</p> <p>Pep Pla, with his peculiar sense of humour, will open the session with a deep dive into the MVCC architectures between the two. The audience will learn why we need MVCC. Postgres and MySQL take very different approaches to implementation: Postgres relies on row versioning and vacuuming dead tuples, while MySQL does in-place changes and tracks versions with the undo log.</p> <p>A broad-strokes overview from Ben Dicken, who has worked closely with both, will emphasize where ecosystem cross-pollination would help. This includes differences in table storage, bloat management, replication, and process-per-connection vs thread-per-connection architecture.</p> <p>Postgres and MySQL take fundamentally different approaches to logical replication. Rohit Nayak and Shlomi Noach will examine how these designs affect WAL/binlog retention, backpressure, and CDC workloads, explore their failover implications, and highlight key feature-parity gaps between the two systems.</p>
<p>The success of open source databases like PostgreSQL and MySQL/MariaDB has created an ecosystem of derivatives claiming "drop-in compatibility." But as the distance between upstream and these derivatives grows, user confusion and brand dilution can follow.</p> <p>To address this, we explore the challenge of compatibility with de facto standards from two distinct angles: a governance perspective on defining the compatibility criteria, and a systems engineering case study on implementing them.</p> <ol> <li><strong>The Standard:</strong> We present the findings from the <a href="https://2025.pgconf.eu/community-events/establishing-the-postgresql-standard-whats-postgres-compatible/">"Establishing the PostgreSQL Standard"</a> working group held at PGConf.EU 2025. This progress report details the community's consensus on the hard requirements needed to fix the "wild west" of marketing claims, including:<ul> <li>Core SQL: Defining the non-negotiable functions, types, and PL/pgSQL.</li> <li>Protocol: Why wire compatibility is insufficient without consistent transactional and <code>pg_catalog</code> behaviour.</li> <li>Ecosystem: The critical requirements for integration with logical replication and tools like Patroni.</li> </ul> </li> <li><strong>The Implementation:</strong> Maintaining compatibility with MySQL/MariaDB in <a href="https://github.com/pingcap/tidb">TiDB</a>, a distributed database engine, is far more complex than matching syntax for an evolving SQL dialect:<ul> <li>We explore the architectural friction of making TiDB speak the MySQL wire protocol and support the MySQL syntax.</li> <li>We cover compatibility with the MySQL binary log based replication.</li> </ul> </li> </ol>
<p>As analytics ecosystems grow more diverse, organisations increasingly need to query data across warehouses, data lakes, and operational systems without excessive movement or duplication. Query federation has become essential by enabling unified SQL access and intelligent pushdown into heterogeneous sources. This talk introduces the core principles of federation and why it matters for modern OLAP workloads and how it is different to Trino.</p> <p>Using StarRocks as a model system, we highlight its vectorized execution engine, native connectors, and deep Apache Iceberg integration that together deliver high-performance lakehouse querying. We examine common lakehouse challenges—schema evolution, file fragmentation, and object-storage latency—and show how federation and hot/cold data separation help address them.</p> <p>Finally, we explore federating additional sources such as Elasticsearch, PostgreSQL, and Apache Paimon to build a unified analytical architecture.</p>
<p>We all write SQL, but how many of us have looked under the hood of a relational database like PostgreSQL? This talk is a deep dive into the guts of the database engine, tracking a simple SELECT statement from the moment you hit "Enter" to the final result set.</p> <p>We'll lift the veil on the core components: the parser, the planner (and the optimizer's black magic!), and the executor, and see how they transform a text string into a low-level, high-performance operation. Using a live, interactive session on a PostgreSQL instance, we'll expose the role of the shared buffer cache, explain why an index works (or doesn't), explore the true cost of I/O, and understand the significance of the binary log (WAL) on read operations.</p> <p>Whether you're a developer frustrated with slow queries or a database administrator looking to squeeze out every millisecond of performance, you'll leave this talk with a mental model that demystifies query execution and gives you the knowledge to write queries that fly.</p>
<p>While optimizing a new heap storage engine across both MySQL and a PostgreSQL-based database we encountered a puzzling result: while on MySQL the throughput stalled below 500k tpmC, on the other database it achieved over 1 million tpmC. The mystery deepened when three different TPC-C benchmarks each told a conflicting story about MySQL’s speed.</p> <p>This talk details the systematic investigation to resolve these contradictions and reclaim the lost performance. We’ll walk through the methodical process of isolating variables across the entire software stack, dissecting benchmark implementations, profiling execution end-to-end with advanced tools, analyzing client/server protocol behavior, and comparing query optimization plans.</p> <p>The investigation revealed that the performance gap was not caused by a single flaw, but by a cascade of inefficiencies, in multiple areas of the stack. Subtle issues in query planning, protocol handling, and client-side implementation conspired to create overwhelming overhead. By addressing these interconnected problems holistically – through optimizer fixes, protocol enhancements, and client improvements – we transformed MySQL’s performance profile to reveal the engine’s true potential.</p> <p>The outcome was a dramatic turnaround: with additional improvements the performance of the new engine on MySQL reaches almost 2 million tpmC now. </p> <p>This case study underscores a critical lesson: database performance, for OLTP workloads in particular, is determined not by any single component, but by the precise alignment of the entire database stack, from the client down to the storage engine.</p>
<p>RonDB is a high-performance, MySQL-compatible distributed database engineered for real-time, latency-critical workloads. Built on decades of development in the MySQL NDB Cluster—led by the original founder of the NDB product—RonDB extends the NDB storage engine with new capabilities, cloud-native automation, and modern APIs tailored for large-scale AI and online services.</p> <p>This talk will describe how RonDB consistently delivers 1–4 ms latency even for large batched operations involving hundreds of rows and multi-megabyte payloads, and will explain the architectural techniques that make such performance possible. We will highlight RonDB’s role as the online feature store powering the Hopsworks Real-Time AI platform, deployed in production at companies such as Zalando for personalized recommendations and other low-latency machine-learning applications.</p> <p>The session will also introduce key components of the RonDB ecosystem:</p> <p>rondb-helm – Kubernetes and Helm tooling for deploying, managing, and scaling RonDB clusters in cloud environments.</p> <p>rondb-tools – Scripts and automation utilities for quickly setting up local or distributed RonDB testbeds.</p> <p>New API layers, including: • A REST API server offering batch key operations, batch scans, and aggregated SQL queries. • An experimental Redis-compatible interface, enabling RonDB to act as a durable, high-throughput backend behind standard Redis commands.</p> <p>We will outline the active collaboration between the RonDB team and Oracle’s MySQL NDB Cluster engineers, and how RonDB extends and complements the upstream NDB ecosystem. In addition, we will present ongoing cooperation with Datagraph to build a SPARQL interface to RonDB, leveraging Datagraph’s Common Lisp NDB API.</p> <p>Attendees will come away with a clear understanding of how RonDB achieves its performance characteristics, how it integrates with modern real-time AI pipelines, and how to deploy, operate, and experiment with RonDB using the available open-source tools.</p> <p>GitHub repositories: https://github.com/logicalclocks/rondb https://github.com/logicalclocks/rond-helm https://github.com/logicalclocks/rondb-tools https://github.com/datagraph/cl-ndbapi/</p> <p>Web sites of note: https://rondb.com https://docs.rondb.com https://hopsworks.ai https://blog.dydra.com/@datagenous/blog-catalog</p>
<p>DuckDB has traditionally been seen as a last-mile analytics powerhouse, the fastest way to run a SQL query on your laptop. But DuckDB offers more than just fast SQL, of course; it supports full database semantics and ACID transactions, behaving like a fully fledged, in-process OLAP database. The in-process component has sometimes been viewed as a limitation when considering DuckDB as a data warehouse.</p> <p>However, DuckDB now supports reading and writing to most Open Table Formats (OTFs), including Iceberg, Delta, and DuckLake. This capability puts DuckDB in a very different position: it allows DuckDB to act as a SQL engine in the cloud (or on your local machine) and run queries against any OTF stored in remote cloud storage. DuckDB can now be the all-mighty, single-node query engine that powers your data analytics use cases.</p>
<p>Observability data isn’t typically blended with the data that your Analysts are working with. These data types are typically stored in entirely separate databases, and interrogated through different tools.</p> <p>But that needn’t be the case. At Grafana Labs we’ve started blending this data together, to answer questions that we or our customers have, such as: - How much revenue did that downtime cost me? - How did latency impact on sales last Black Friday? - Which customers were impacted by that incident, and which ones are the highest priority to follow up with?</p> <p>The FOSS projects we’re combining to get there are: - The LGTM stack (github.com/grafana) for Observability - Cube core (cube.dev/docs/product/getting-started/core) for Semantic Layer - dbt core (github.com/dbt-labs/dbt-core) for transforming SQL data - Grafana itself to blend, visualise and even alert on the end-result</p> <p>During this talk I’ll describe how you too can fit these pieces together and use them to answer similar questions for your own context.</p>
<p>Everyone is running their applications on Kubernetes these days, most of the time the application servers are stateless so it is easy to do so because the database behind the application is responsible for storing the state. What if you would also want to run you database on the same Kubernetes stack. Will you use stateful sets? Will you use network attached storage? These types of storage are introducing a lot of disk latency because of the mandatory network hops. This is why in many environments the database servers still are dedicated machines that are treated as pets while the rest of the fleet is more like cattle.</p> <p>In this session I will speak about how we run our databases on Kubernetes by using the local ephemeral storage to store your data and also how we are confident we will not loose it in the process of doing so!</p>
<p>PostgreSQL already knows how to parse SQL, track object dependencies, and understand your schema. Most tools that work with schemas reimplement this from scratch. What if you just asked Postgres instead?</p> <p>This talk digs into the techniques that make that possible. We’ll start with the shadow database pattern: applying schema files to a temporary PostgreSQL instance and letting Postgres handle all parsing and validation. Then we’ll explore pg_depend and the system catalogs, where PostgreSQL tracks that your view depends on a function, which depends on a table, which depends on a custom type. I’ll show the exact catalog queries that extract this dependency graph, the edge cases that make it interesting (extension-owned objects, implicit sequences, array types, function bodies that pg_depend can’t see), and how to turn it all into a correct topological ordering for migration generation.</p> <p>I learned this while building <a href="https://pgmt.dev/">pgmt</a>, a tool that diffs PostgreSQL schemas to generate migrations. But the techniques apply to anything that needs to understand a Postgres schema -- linters, drift detectors, visualization tools, CI validation -- and they let you build on Postgres’s own knowledge instead of reinventing it.</p>
<p>This talk discusses the design choices behind this open source project leveraging Debezium : https://github.com/Altinity/clickhouse-sink-connector It reliably replicates data to ClickHouse, a well known open source real time analytics database that can be deployed anywhere. The sink-connector provides an alternative to proprietary solutions that typically lock people in or are only available on the cloud. It works with MySQL, MariaDB. Postgres, Oracle (experimental) and MongoDB. As a bonus, Binary logs analysis and Time Travel will also be presented.</p>
<p>Using SQL from other programming languages can prove to be quite the hassle: wrangling the database rows into the host's language types is tedious and error prone, and making sure the application code stays up to date with the ever-changing database schema is just as challenging.</p> <p>To address these developer experience shortcomings ORMs try to shield the developer from ever having to write any SQL at all. This doesn't feel totally satisfying though: as developers we are always keen on using the right language for the job, so what would it look like to fully embrace SQL instead of trying to abstract it away?</p> <p>In this talk we'll look at Squirrel (https://github.com/giacomocavalieri/squirrel), a library that tackles database access in Gleam (https://gleam.run): a functional, statically-typed language. We'll explore how code generation from raw SQL can help bridge the gap between the database and a functional language without compromising on type-safety, performance or developer experience.</p>
<p>Time Series databases face the significant challenge of processing vast amounts of data. At VictoriaMetrics, we are actively developing an open-source Time Series database entirely from scratch using Go. Our average installation handles between 2 to 4 million samples per second during ingestion, with larger setups managing over 100 million samples per second on a single cluster. In his presentation, we will explore various techniques essential for constructing write-heavy applications such as: - Understanding and mitigating write amplification. - Implementing instant database snapshots. - Safeguarding against data corruption post power outages. - Evaluating the advantages and disadvantages of utilizing Write Ahead Log. - Enhancing reliability in Network File System (NFS) environments. Throughout the talk, we will illustrate these concepts with real code examples sourced from open-source projects.</p>
<p>1) Contributing to MariaDB (Georgi): Learn how to contribute to the MariaDB server codebase. And be prepared for what it takes. And see what you will learn along the way.</p> <p>Have you ever wondered what it would take to actually get your contribution into the MariaDB server codebase?</p> <p>We will take one specific contribution and follow through its processing. It's a bug fix contribution. 2 lines of actual code change. On smaller codebases, used by less people, this would have probably taken minutes to process. It is somewhat different with the MariaDB server's codebase. But for a very good reason!</p> <p>2) Contributing to Postgres (Kevin): Contributing to open source can feel intimidating early in your career, especially with a project as widely used and critical as Postgres. Often, confidence comes after action; the first patch is the hardest. Even small contributions can reach thousands of people.</p> <p>This talk traces my path from setting up a local build and gaining familiarity with the codebase to contributing bug-fix patches and documentation updates. Also, it outlines how the Postgres development process and community operate. The aim is to demystify the process so more engineers feel confident contributing to Postgres, and leave with the context and practical steps to make their first (or next) patch.</p>
<p>From plain-old Postgres to the Grafana stack (Loki, Grafana, Tempo, and Mimir), OpenSearch, Cassandra, and ClickHouse, the landscape of telemetry storage options is as vast as it is overwhelming. With so many choices, how do we decide which datastore is right for the job? In this talk, Joshua will guide attendees through the foundational principles of telemetry—covering metrics, traces, logs, profiles, and wide events—and break down the strengths and limitations of different database technologies for each use case. We’ll examine how traditional relational databases like Postgres can still hold their own, where OpenSearch and Prometheus fit into the picture, and why specialized stacks like LGTM (Loki, Grafana, Tempo, Mimir) are so popular in modern observability pipelines. And, of course, we’ll highlight the growing role of ClickHouse as a versatile and high-performance option for logs, traces, and more and VictoriaMetrics as a drop-in replacement for Prometheus. By the end of this session, attendees will have a clearer understanding of the trade-offs between these datastores and how to make informed decisions based on the unique requirements of their systems. Whether you’re building an observability stack from scratch or looking to optimize an existing setup, this tour of the observability datastore landscape will leave you better equipped to navigate the options.</p>
<p>Change Data Capture (CDC) has become foundational for real-time analytics, cross-region replication, event-driven systems, and streaming ingestion pipelines. Databases like MySQL and Postgres replication expose change streams through a single-writer log. CDC in these systems is trivial. Modern distributed SQL databases like TiDB require a fundamentally different design and handle bigger challenges because they need to order the writes of multiple writers and deal with millions of tables, </p> <p>This talk is about TiCDC’s architecture and how it handles multiple writers, millions of tables, 1000s of writers with its event-driven pipeline. To preserve total order, TiCDC must merge, order, and stream updates coming concurrently from multiple regions, Raft groups, and storage nodes—while preserving correctness and low latency.</p> <p>This talk will explore the challenges and the evolution of TiCDC design over several iterations, With lessons learnt the hard way.</p>
<p>Database usage in practice often involves heavy text processing. For example, in "observability" use cases, databases must extract, store, and search billions of log messages daily. Most databases, including many column-oriented OLAP databases, struggle with such massive amounts of text data. The only way to process text data at scale is by using specialized inverted indexes in databases.</p> <p>This presentation explains how inverted indexes work and which (text) search patterns they support. Where appropriate, we describe our experience and the gotchas we encountered when adding an inverted index to ClickHouse, one of the most popular open-source databases for analytics.</p>
<p>In 2017, Mark Raasveldt and Hannes Mühleisen (who went on to create <a href="https://github.com/duckdb/duckdb">DuckDB</a> presented a VLDB paper entitled <a href="https://15721.courses.cs.cmu.edu/spring2018/papers/14-networking/p1022-muehleisen.pdf">“Don’t Hold My Data Hostage – A Case For Client Protocol Redesign.”</a> Their paper proposed the use of columnar serialization to achieve order-of-magnitude improvements in query result transfer performance. Eight years later, this talk revisits Raasveldt and Mühleisen’s argument and describes the central role that the <a href="https://arrow.apache.org">Apache Arrow</a> project has played in realizing this vision—through the dissemination of Arrow IPC, Arrow Flight, Arrow Flight SQL, Arrow over HTTP, and <a href="https://arrow.apache.org/adbc">ADBC</a> across numerous open source and commercial query systems. The talk concludes with a call to action to introduce Arrow-based transport to the systems that continue to “hold data hostage.”</p>
<p>Our database had reached a point where failure scenarios were becoming increasingly complex and time consuming. A single node could take up to 15 minutes to recover. It was expensive to run and operate, and it simply couldn’t scale to meet the customer demand we were facing. It became clear that we needed a new design. By leveraging a modern architecture and the latest open-source technologies, we rebuilt our database for the cloud era. Recoveries that once took 15 minutes now complete in seconds. Operational costs dropped by 50%, and query latencies improved by 200%. These gains weren’t the result of any single change, but of a holistic redesign powered by technologies like Vortex, DataFusion, Delta Lake, and Rust. </p> <p>In this talk, Thor will walk you through the end-to-end journey of this evolution the failure patterns and scaling limits that forced a rethink,</p> <p>the architectural principles that guided the redesign,</p> <p>the trade-offs and dead ends along the way,</p> <p>how modern open-source components were evaluated and integrated, and</p> <p>the concrete performance and reliability improvements unlocked by the new design.</p> <p>You’ll leave with a blueprint for modernizing a legacy data system: how to identify when your architecture is holding you back, and how to apply today’s open-source ecosystem to build a cloud-native database that’s fast, resilient, and ready for the future.</p>
<p>Apache DataFusion is emerging as a powerful open-source foundation for building interoperable data systems, thanks to its strongly modular design, Arrow-native execution model, and growing ecosystem of extension libraries. In this talk, we'll explore our contributions to the DataFusion ecosystem—most notably <strong><a href="https://github.com/datafusion-contrib/datafusion-federation">DataFusion Federation</a></strong> for cross-database query execution and <strong><a href="https://github.com/datafusion-contrib/datafusion-table-providers">DataFusion Table Providers</a></strong> that connect DataFusion to a wide range of backends.</p> <p>We'll show how we use these components to federate queries to databases such as <strong>TiDB</strong> and <strong>InfluxDB 2</strong>, and how this fits into a broader data fabric/API generation work we're doing at Twintag. We'll also discuss our work on Arrow-native interfaces, including an <strong><a href="https://github.com/datafusion-contrib/datafusion-flight-sql-server">Arrow Flight SQL Server implementation for DataFusion</a></strong> and a prototype Flight SQL endpoint for TiDB, which together enable a fully Arrow-based pipeline spanning query submission, execution, and federated dispatch.</p> <p>The session highlights practical patterns for building distributed data infrastructure using open libraries rather than monolithic systems, and offers a look at where Arrow and DataFusion are headed as shared interoperability layers for modern databases.</p>
<p>Cloud-native databases often use open-source embedded key-value stores on each node or shard. OLTP workloads are read- and write-intensive, typically relying on indexes for data access. Two main on-disk structures are prevalent: B-Trees, such as <a href="https://github.com/wiredtiger/wiredtiger">WiredTiger</a>, and LSM-Trees, like <a href="https://github.com/facebook/rocksdb">RocksDB</a>. This talk explores the similarities and differences in their internal implementations, as well as the trade-offs among read, write, and storage amplification. It also compares these structures to traditional fixed-size block storage in RDBMS and discusses the differences in caching the working set in memory and ensuring durability through write-ahead logging.</p>
<p>Your AI application returns wrong answers. Not because of your LLM choice or vector database—but because of the data engineering ( or lack there of) nobody wants to talk about.</p> <p>This technical deep dive shows why embedding models, chunking strategies, and search filtering have more impact on AI accuracy than switching from one model to another. Using real production data, we'll demonstrate how naive vector search returns Star Trek reviews when users ask about Star Wars, how poor chunking strategies lose critical context (Who want's their AI to respond to how to fix a headache with a head transplant?), and why "just use a vector" without proper data engineering guarantees hallucinations.</p> <p>We'll cover:</p> <ul> <li>Embedding model selection: dimensions, token limits, and silent truncation failures</li> <li>Chunking strategies: when to chunk, how to preserve context, and the double-embedding approach</li> <li>Hybrid search: combining Full Text/BM25 keyword matching with vector similarity</li> <li>Filtering architecture: pre-filter vs post-filter performance trade-offs</li> <li>Production gotchas: triggers, performance, batch processing, and cold start problems</li> </ul> <p>While many of the examples will be for PostgreSQL, This is talk will be database-agnostic, no matter if you are using PostgreSQL, MariaDB, ClickHouse, or others you will learn something! In AI Land, the hard problem is always data engineering, not database selection. </p> <p>Users don't care about inference speed—they care about accuracy. This talk shows how to engineer your data pipeline so your AI doesn't lie.</p>
<p>This is a review of the current state of Free and Open Source Software on Mobile devices. Mobile computing continues to be one of the most conspicuous and rapidly evolving software ecosystems ever, and open source software is at the heart of it - from the Linux kernel, the tooling, languages and libraries needed to write apps, through to devices that run a completely open source stack</p> <p>We will talk about the changes in the way Google releases AOSP code and how that affects developers of custom ROMs and off-the-shelf devices. We will talk about developments in fully Android-free platforms, and we will talk about hardware support, drawing on voices from across the FOSS mobile community.</p> <p>The presentation will be of interest to those already involved in the FOSS and mobile communities, and also to those who are just interested to get an overview of the landscape.</p>
<p>Android support for RISC-V is advancing rapidly, and this talk delivers an in-depth technical update on the open-source AOSP porting effort. We will walk through the current status of AOSP on RISC-V platforms, including ART/LLVM, Bionic, HAL and vendor-interface development, and compatibility work for emerging RISC-V SoCs. The session will examine the key engineering challenges encountered along the way—such as JIT/AOT differences on RISC-V, graphics-stack porting (Mesa, DRM/KMS, GPU drivers), GSI support, SELinux policy bring-up, vendor_boot and dynamic-partition layout, and end-to-end boot-flow integration. We will also highlight upstream contributions completed so far, the remaining gaps in the AOSP tree, and the milestones required to achieve full device bring-up and CTS/VTS compliance. Attendees will come away with a clear understanding of the progress to date and concrete opportunities for community collaboration to accelerate a fully open, fully native Android ecosystem for RISC-V devices.</p>
<p>The Android Open Source Project (AOSP) is more than just the yearly and now half-yearly releases of the Android platform source code. It consists of 3000+ git repositories, 1500+ repo XML manifests, and 1.8+TB of (compressed) source code data.</p> <p>In this talk I want to give a detailed tour of the AOSP releases, the code, and everything that can be found in the AOSP repositories: How are the <code>_rXXX</code> releases assembled? And why do the git tags sometimes go backward? Where do I find the source code for my Pixel devices (until 2025)? What are the Build IDs? What are Brillo manifests, and why are they also in the AOSP? How are security patches released? Why is the number of git repos increasing with every release? And why is it decreasing with Android 16? How did the amount of rust and other code evolve over time? What is Project mainline and apex's? And where do I find the source code for these "Google Play system updates"? Where do I find the AAOS (Android Automotive Operating System) code and its releases?</p> <p>These and other questions I want to answer in my talk.</p>
<p>Building Android is notoriously slow and resource-hungry. Even on high-end hardware, a full AOSP build can take hours, and each release continues to grow by ~10–20%, amplifying compile times and storage pressure. For anyone maintaining custom ROMs, vendor trees, or downstream forks, faster builds are not just nice to have: regulation requiring shipping fixes faster makes build performance a core productivity issue.</p> <p>Over the years, the Android ecosystem has tried to keep pace with this growing complexity. Solutions like ccache and distributed build systems (goma, reclient), and even experiments with Bazel have all aimed to make builds faster and more scalable. But these tools were designed for other projects and struggle with Android’s unique challenges — lack of sandboxing, incomplete dependency tracking, and heterogeneous toolchains.</p> <p>This talk explains how the Android build system actually works, why incremental builds so often fall apart, and where the time really goes. We’ll then walk through the major open-source acceleration approaches, their strengths and limitations, and what it takes to run them effectively in your own infrastructure—whether you’re a hobbyist with a homelab or maintaining a large downstream tree.</p>
<p>At <a href="https://izzyondroid.org/">IzzyOnDroid</a>, we provide <a href="https://izzyondroid.org/about/security/ReproducibleBuilds/">Reproducible Builds</a> (RBs) for Android apps. In this talk, I want to outline:</p> <ul> <li>what Reproducible Builds are and what are some of their advantages</li> <li>how we approach Reproducible Builds in combination with our <a href="https://apt.izzysoft.de/fdroid">Android App Repo</a></li> <li>some of the challenges of Reproducible Builds for Android apps</li> <li>the most frequent sources/causes of failed RBs we encounter regularly (and how to address them)</li> <li>things Android App Developers should be aware of / take care for to give their apps the best chances to succeed with RBs</li> </ul> <p>At the end of the talk, there should hopefully be some time for further questions (Q&A).</p>
<p>Securely signing Android releases, while being a critical process and operation for every AOSP-based project, has been lacking in comprehensive documentation, especially for building a production-grade and enterprise-level signing infrastructure. This talk presents our experience in designing and implementing a Hardware Security Module (HSM)-based signing solution for CalyxOS that ensures transparency and operational practicality while upholding security standards widely endorsed by security experts with limited resources.</p> <p>We will walk through our process of defining criteria for secure signing operations and redesigning a signing infrastructure. In particular, we will discuss the trade-offs and our trajectory to technical decisions, including: * Security and operational pros and cons: Why use an HSM; * Our criteria for evaluating HSM solutions: Exemplified with the comparison between YubiHSM 2, Nitrokey HSM, Amazon Cloud HSM, and Entrust nShield in open-source standards, cost-effectiveness, and operational practicality; * PKCS#11 integration challenges: What it is, why it matters for HSM compatibility, and the specific code changes and scripts we made to to support it; * Key ceremony design: The use of Shamir's Secret Sharing (SSS) schema for recovery and additional backup and lessons from the provisioning process; and * Audit logging and cryptographic verification of signing operations.</p> <p>In addition, this talk invites discussions from participants on experiences in operational security and building trust through transparency and communication. We will focus on how to balance complex Android development needs and overcome challenges with constrained resource and scant systematic documentation. This talk aims to start collaborations on issues such as concurrent multi-device signing, ceremony design, and community-driven criteria across FOSS development teams.</p>
<p>NewPipe is a widely used <strong>FOSS Android app</strong> that provides privacy-respecting access to <strong>YouTube, PeerTube, and other streaming services</strong>. It can search, view channels, play videos, listen to playlists, download media, and more.</p> <p>Developing an application with so many distinct features often involves compromises or <strong>feature trade-offs</strong>. During the talk, we'll explain how TeamNewPipe takes these decisions together with the community. In recent years the team has been supported by <strong>NewPipe e.V.</strong>, a German association which strives to promote access to libre digital media, even outside of the NewPipe app. This more general spirit dates back to the beginning of NewPipe, when the <em>backend library</em> that scrapes data from services was made independent of the user interface, making the backend ideal for use in other projects.</p> <p>Usually it's hard to port Android apps to other mobile Linux platforms due to the use of Java and the tight integration with the Android APIs. The user interface libraries required aren't available outside of Android emulation layers and, even if they were, the user interface paradigms would differ greatly. In this talk we'll go on to describe our efforts to <strong>port the app to Sailfish OS</strong>, a Qt-based mobile Linux platform with a user interface paradigm that differs significantly from Android's. The process took us on a <strong>fascinating journey</strong>, compiling Java code for a platform <em>without a JVM</em> and integrating it with the Qt (C++, QML, Silica) layers above.</p> <p>This talk will cover topics relevant to AOSP users, mobile Linux users, the Sailfish OS community, Android developers and Qt developers.</p>
<p>Since August 2025 IzzyOnDroid has been providing app download stats for the IzzyOnDroid repository and since September, Neo Store has included these download stats in the client, with Droid-ify support hopefully releasing before this talk.</p> <p>This lightning talk will quickly go through: 1. How the download stats system works 2. Which applications already show the stats 3. How to use the stats in your own applications</p> <p>Relevant links: Download stats dashboard: https://stats.izzyondroid.org/ Neo Store: https://apt.izzysoft.de/fdroid/index/apk/com.machiav3lli.fdroid</p> <p>iod-stats-builder: https://codeberg.org/IzzyOnDroid/iod-stats-builder/ iod-stats-collector: https://codeberg.org/IzzyOnDroid/iod-stats-collector</p>
<p>The maps application is one of the main usage of the smartphones nowdays. Let's introduce Cardinal, (not) yet another mobile maps application. It intends to definitely offer an alternative to Google Maps. </p> <p>In this lightning talk, we will introduce what it is, how it differs from other open source maps application (OSMand, Comaps and others), and how we are building it.</p> <p>Project source code: https://gitlab.e.foundation/e/os/cardinal</p>
<p>There are a lot of code releases from AOSP: there is a major release once per year, Quarterly Platform Releases (QPR) every quarter, plus releases specific to particular segments, such as Automotive, or devices, e.g. the Pixel Fold. On top of this there are regular security fixes. </p> <p>This short talk will try to make sense of all of these data points, and show how they relate back to the release number, which is the canonical identifier of a release.</p> <p>Key takeaway: Knowing the way Google identifies releases helps you understand the release cadence and which tag you may want to use when building Android</p>
<p>OpenHarmony offers a compelling FOSS alternative to the mobile OS duopoly, but porting it to real phones presents unique technical challenges. This talk shares practical insights from bringing Oniro, an Eclipse Foundation project focused on making this technology usable beyond its original ecosystem, to mobile devices. We'll cover the complete porting workflow: QEMU-based x86_64 emulation for rapid development cycles, kernel adaptation strategies for diverse chipsets, and our LibHybris integration to bridge OpenHarmony's musl libc with proprietary Android binary drivers, unlocking GPU, and peripheral support on existing hardware. Beyond the technical stack, we'll discuss developer experience improvements that lower contribution barriers: VS Code-based tooling, and early app ecosystem expansion through React Native and cross-platform framework support. Whether you're interested in AOSP alternatives, mainline device enablement, or building truly open mobile platforms, this talk demonstrates a practical approach to accelerating FOSS mobile adoption today.</p>
<p>I maintain the Collabora Office mobile apps: office software for mobile devices based on LibreOffice. I've been at FOSDEM twice before, and each time I've had people approach me and ask if the apps could run on mobile Linux.</p> <p>Each time, I've had to tell them "not yet". This year, I finally have a mobile Linux device running Collabora Office. It's not perfect yet, but it works, and it can give a glimpse into a future where a mobile-optimised Collabora Office is available outside of the mainstream Android/iOS mobile duopoly.</p> <p>I'll give you an overview of how we got here, how I'm doing this, and what's still left to do before we can get my demo on your mobile Linux device.</p>
<p>Let's review what has happened in the lands of upstream kernel development on Fairphone devices in recent times. Where are we now in 2026? Where are the major pain points now? Can you use postmarketOS on a Fairphone as daily driver yet? Let's find out!</p>
<p>After last year's FOSDEM we set <em>"Improve the reliability of postmarketOS!"</em> as main goal for 2025. This lightning talk covers what shiny puzzle pieces we have built throughout last year and the exciting future that awaits us now that we can flip the box on the table and assemble all of them to a nice <del>picture</del> reliable operating system! 🧩</p>
<p>Phones running Linux became reality in last few years, and they do have cameras. Every notebook and most computers do have cameras, too, and there's a lot of effort to get good support for them concentrated around libcamera project. Unfortunately phones have different hardware than computers (dumb vs. USB cameras) and use cases are very different.</p> <p>Pavel will explain challenges presented by phone hardware, explain what is needed to take good photos with phone such as Librem 5 or OnePlus 6, and explain additional challenges with video recording. He'll also talk about his work in this area, Clicks Machine and Millicam and improvements to Megapixels, Millipixels and Libcamera projects.</p>
<p>To understand how we can replace Google push notifications (FCM) with something open source and decentralized, we need to understand how they work and why they are needed in the first place. This talk explains the mechanics of push notifications and why, despite their potentially bad reputation, they are a more elegant solution than having every app maintain its own persistent server connection.</p> <p>While open-source tools like microG can remove proprietary Google software from your Android phone, the actual notifications are still sent via Google's servers (Firebase Cloud Messaging).</p> <p><a href="https://unifiedpush.org/">UnifiedPush</a> is a framework that allows push notifications to be delivered in a decentralized manner or through self-hosted servers. Numerous open-source Android apps already support UnifiedPush, including <a href="https://tusky.app/">Tusky</a>, <a href="https://ltt.rs">Ltt.rs</a>, Fedilab, <a href="https://www.davx5.com/">DAVx⁵</a>, Fennec, Element, and many more.</p> <p>The presentation ends with a short demo on how to use UnifiedPush on Android.</p>
<p><a href="https://phosh.mobi">Phosh</a> is not just a popular user interface, but also a project that aims to propel Mobile Linux forward contributing mobile-specific bits where necessary. With yet another round around the sun it's time to share what we've been up to since our last <a href="https://archive.fosdem.org/2025/schedule/event/fosdem-2025-6323-phosh-yet-another-year-around-the-sun-/">status update</a></p>
<p>So far, almost all mobile phones capable of functioning with close-to-mainline Linux kernels (with the exception of special phones such as the PinePhone) are based on Qualcomm SoCs. Unisoc is an alternative SoC manufacturer from China that is often overlooked due to its focus on the low-end segment and lack of upstream kernel support for important features.</p> <p>In 2024, Jolla released the C2 community phone as a new reference device for Sailfish OS, based on the low-end Reeder S19 Max Pro S from Turkey. This phone uses the Unisoc UMS9230 (Tiger T606 / T7200) SoC. A bit more than a year has passed since the phone was first released and the official port still uses libhybris. Meanwhile, I have been working on an unofficial mainline Linux port and am daily-driving it now. Some things are still not working, but there has been a lot of progress since the last FOSDEM.</p> <p>This talk is going to explore the challenges involved in porting mainline Linux to a new SoC platform, the features I have implemented so far, and the opportunities this creates for Sailfish OS and other mobile Linux projects such as postmarketOS.</p> <p>Linux kernel fork: <a href="https://codeberg.org/ums9230-mainline/linux">https://codeberg.org/ums9230-mainline/linux</a> \ Sailfish OS port: <a href="https://forum.sailfishos.org/t/mainline-linux-kernel-for-the-jolla-c2/21382">https://forum.sailfishos.org/t/mainline-linux-kernel-for-the-jolla-c2/21382</a> \ postmarketOS port: <a href="https://wiki.postmarketos.org/wiki/Jolla_C2_(jolla-c2)">https://wiki.postmarketos.org/wiki/Jolla_C2_(jolla-c2)</a></p>
<p><a href="https://os.gnome.org/">GNOME OS</a> is GNOME's development, testing and QA operating system. It builds the in-development versions of the GNOME desktop and core applications. It is also a modern image-based Linux system.</p> <p>In this talk, I'm going to present recent efforts to run GNOME OS on phones. Right now, the FairPhone 5 and the OnePlus 6 are supported, but ideally we could support any phone that is supported by the mainline Linux kernel.</p> <p>I will briefly present the different tools and projects that make this possible, and what we're hoping to achieve from this initiative: better testing for the GNOME applications, and more ways to do FOSS on Mobile.</p>
<p>"Okay, this Linux on Phones thing ... but it has no apps, right?" It has apps - Sailfish OS and Ubuntu Touch have dedicated app stores, and the newer projects also have many well working apps.</p> <p>This talk is a refresher on my <a href="https://archive.fosdem.org/2024/schedule/event/fosdem-2024-3303-the-linux-phone-app-ecosystem/">2024 FOSDEM talk</a>, with a focus on what changed - a call to action.</p>
<p>It has been two years since the initial mainline Linux support for the Snapdragon 8 Gen 3 (SM8650) was posted on the very day of its marketing announcement and used to present the Qualcomm platforms mainline state in this very conference on an SM8650 HDK development board. What started as basic boot support with display has evolved into a fully-featured upstream ecosystem, but the road was far from smooth.</p> <p>In this session, we will explore the technical evolution of SM8650 support, moving beyond the "it boots" milestone to a fully usable system. We will dissect the challenges of enabling complex subsystems—from the Hexagon DSPs and Adreno 750 GPU to the intricate power domains that modern SoCs demand to properly support runtime power management and suspend-to-ram state.</p> <p>We will also address the often-overlooked bootloader story, showcasing the current state of upstream U-Boot on this platform and how it interacts with the standard EFI boot flow.</p> <p>The Talk Will Feature a Technical Post-Mortem about the whole upstreaming process and a live demonstration running mainline Linux on actual Snapdragon 8 Gen 3 powered device running the mainline kernel with code changes—proving that upstream support is no longer just for development boards.</p>
<p><a href="https://github.com/opencloud-eu/">OpenCloud</a> has the design goal to not use a relational database. This requires a deeper integration with the underlying storage system, ie. through extensive use of extended file attributes. Since features like file revisions, trash and shares are inevitable nowadays, OpenCloud makes use of SDS native supported storage aspects to build these advanced features in an efficient way.</p> <p>In this talk we will give an overview of the storage aspects that are relevant from OpenClouds perspective, the integrations that we currently support as well as ongoing research topics.</p>
<p>Ceph storage: Enterprise meets Community. Our traditional Ceph storage roadmap session starts with everything that is happening in the upstream project this year and what we have planned for the future, and closes with the state of what is backed by vendor-supported products. A 360-degree look at the state of Ceph integration with OpenStack and what is planned going forward in the broader storage space, in particular in regards to features relevant to container workloads.</p> <p>Architectural familiarity with Ceph is required. This session contains zero vendor pitches, and it is a caffeinated tour of what the Ceph community is working on at the feature level. Hang on to your hats, and bring questions!</p>
<p>Garage (<a href="https://garagehq.deuxfleurs.fr/">project website</a>) is a versatile object storage software, focused on decentralized and geo-distributed deployments. The software has been developed under the AGPL for more than 5 years and is now reaching maturity.</p> <p>This talk will cover development and new features of the 2.x releases since the last FOSDEM talk (2024), best practices for administrators, available UIs, and a small tutorial on how to migrate from minio.</p>
<p>The CernVM File System (CVMFS) is a scalable, high-performance distributed filesystem developed at CERN to efficiently deliver software and static data across global computing infrastructures, primarily designed for high-energy physics (HEP). For the Large Hadron Collider (LHC) only, CVMFS is serving around 4 billion files (~2PB of data). CVMFS uses a content-addressable storage model, where files are stored in the form of cryptographic hashes, ensuring integrity and enabling deduplication. It follows a multi-caching architecture where the data are published in a single source of truth (Stratum 0), mirrored by a network of distributed servers (Stratum 1), and propagated to the clients via forward proxies. This multi-layer of caching allows for a cost-effective alternative to traditional file systems, where clients are offered reliable access to versioned read-only datasets with low overhead. In this talk we will focus on how CVMFS interoperates with the highly adopted S3 storage, providing a conventional POSIX filesystem view of the objects, using the available metadata for efficient exploitation of the medium. We will also highlight the benefit of using CVMFS with containerized workflows and demonstrate tools developed to facilitate data publishing.</p> <p>Homepage: https://cernvm.web.cern.ch/fs/<br /> Documentation: https://cvmfs.readthedocs.io/<br /> Development: https://github.com/cvmfs/cvmfs/<br /> Forum: https://cernvm-forum.cern.ch/</p>
<p>With cost and performance requirements becoming more and more relevant in today’s storage products, technologies that leverage algorithmic driven improvements are getting a lot of attention. Erasure coding is the most prominent algorithm and a meanwhile well established standard for saving on-disk space requirements in storage. It is built upon mathematical techniques. In my talk I want to explain and explore these techniques, and thereby the mathematical reasoning underlying these algorithms in a way that does not require a background in mathematics itself (or at least only an insignificant amount). I am not a software engineer myself, just an interested mathematics student who aims to introduce someone who is interested and not too fond of maths to the underlying theory of erasure coding.</p>
<p>Have you ever found your CephFS setup mysteriously broken and had no clue how it got there? Maybe someone ran a CLI command in haste, or a misstep happened weeks ago. We have suspicions, but can’t really recall what might've splintered the system. That changes now.</p> <p>In this talk, we introduce a robust command history logging mechanism for CephFS: a persistent log of CephFS commands and standalone tool invocations, backed by LibCephSQLite. Think of it as “shell history,” but purpose-built for Ceph with time ranges, filters, and structured metadata. Every ceph fs subvolume rm, every ceph config set, every mischievous --force — now recorded, timestamped, and queryable.</p> <p>Want to know what was run last Tuesday at 3 AM? Or who triggered that well-intentioned-but-catastrophic disaster recovery script? Or just list the last 100 commands before things exploded? It’s all there. This helps debug incidents faster, provides a clear audit trail, and opens the door to proactive traceability. So, when things go sideways around CephFS and no one's sure why — this history has your back.</p> <p>This is CephFS-first but not CephFS-only. The path to full cluster command traceability starts here.</p>
<p>Starting with the Tentacle release, Ceph introduces mgmt-gateway: a modular, nginx-based service that provides a secure, highly available entry point to the entire management and monitoring stack. This talk will cover its architecture and deployment, how it centralizes access to the dashboard and observability tools, and how OIDC-based Single Sign-On streamlines authentication. We’ll also show how mgmt-gateway enhances security and access control while delivering full HA for Prometheus, Grafana, Alertmanager, and the dashboard, resulting in a more resilient and user-friendly experience for Ceph administrators.</p>
<p>The purpose of this talk is to highlight how LUA scripting and S3 Lifecycle Policies can be leveraged to enable Ceph S3's dynamic placement and cost-efficient, policy-driven data retention. All details on https://github.com/frednass/s3-dynamic-placement-and-archiving</p>
<p>The <a href="https://github.com/cern-cta/CTA">CERN Tape Archive (CTA)</a> is the open source solution developed at CERN to store more than 1 Exabyte of data from CERN’s experimental programmes. CTA interfaces with two disk systems widely used by the High-Energy Physics (HEP) community, <a href="https://github.com/cern-eos/eos">EOS</a> and <a href="https://github.com/dCache/dcache">dCache</a>. However, until now there has been no integration with systems used outside of HEP.</p> <p>Looking at current industry standards, the leading interface for file and object storage is S3, which includes cold storage extensions for data archival. The CTA team are investigating whether CTA can be fronted by an S3 API. During this talk, we’ll review a proof-of-concept implementation, and look at alternative solutions to explore along with their respective trade-offs.</p>
<p>Umbrella ("U") is planned as the next major release for the Ceph Distributed Storage System open-source project. Ceph File System development in Umbrella is aimed at addressing various pain points around the file system disaster recovery process, performance metrics, MDS tuning, user data protection and backups. Many of these themes were also discussed in the Cephalocon 2024 and various user/dev meetings.</p> <p>This talk details improvements in each of those areas with a specific focus on ease of use and automation. Many noteworthy features have been introduced thereby improving the user experience across the board. Umbrella release aims to provide Ceph File System users and administrators a better and smoother experience.</p>
<p>Concurrent storage access via standard network protocols such as SMB and NFS has become a common feature of many proprietary storage products. Samba, the leading open‑source SMB implementation, has long supported a limited set of multiprotocol scenarios by leveraging kernel interfaces and by allowing aspects of multiprotocol access to be implemented in the filesystem. Over time, several storage vendors have exploited these capabilities while using their own proprietary filesystems.</p> <p>In this talk we will present our plan for a fully open‑source multiprotocol stack built on CephFS, Samba, and NFS‑Ganesha. First, we will describe the testing infrastructure we are creating and the use‑cases we intend to support in the initial release. We will then outline our approach to exclusive file locking and to a unified access‑control model.</p>
<p>This talk introduces an advanced storage acceleration strategy for I/O-intensive container workloads. In environments like CI/CD pipelines or database applications, performance is often constrained by storage latency. Our plan addresses this by implementing a transparent data caching layer that uses high-speed local storage to hold frequently accessed data, significantly reducing retrieval times and load on the primary storage system.</p> <p>With a core focus on disaster recovery and fast StatefulSet failover, the primary cloud storage volume is intentionally left pristine and unmodified, containing solely user data All cache intelligence is kept local to the node. This design is critical for operational robustness, as it ensures the data can be restored to a consistent point in time, a fundamental requirement for reliable disaster recovery This allows the volume to be safely attached to any node for rapid failover maximizing both performance and data safety.</p> <p>project: https://github.com/kubernetes-sigs/alibaba-cloud-csi-driver</p>
<p>For high-performance proxy services, moving data is the primary bottleneck. Whether it is an NFS-Ganesha server or a FUSE-based Ceph client, the application burns CPU cycles copying payloads between kernel and user space just to route traffic. While <code>splice()</code> exists, it imposes a rigid pipe-based architecture that is difficult to integrate into modern asynchronous event loops.</p> <p>We propose a pure software zero-copy design that works with standard network stacks. In this model, a specialized kernel socket aggregates incoming network packets into a scatter-gather list. Instead of copying this data to the application, the kernel notifies userspace—potentially via <code>io_uring</code>—that a new data segment is ready and provides an opaque handle.</p> <p>The application sees the headers to make logic decisions but acts only as a traffic controller for the payload. It uses the handle to forward the data to an egress socket or a driver like FUSE without ever touching the actual bytes. This talk will outline the design of this buffer-handling mechanism and demonstrate how it allows complex proxies like Ganesha and storage clients like Ceph to achieve true zero-copy throughput on standard hardware.</p>
<p>Ad hoc lightning talks. Every speaker gets exactly 5 minutes (or less).</p> <h4>Authenticated Encryption in Storage Systems</h4> <ul> <li>Presenter: David Mohren</li> <li><a href="https://lists.ceph.io/hyperkitty/list/dev@ceph.io/thread/QFQGLWTWNTG45OSNLCHC2NWMWMTDUTCI/">related email thread</a></li> </ul> <h4>HopNet: User-friendly distributed storage with E2E encryption</h4> <ul> <li>Presenter: Allison Bentley (<a href="https://bentley.sh">bentley.sh</a>)</li> <li><a href="https://drive.google.com/file/d/16xI2YtNMACgUifooJVjSHdaHtYotUUAo/view?usp=sharing">Slides</a></li> </ul> <h4>Solid: giving Personnal online data store to the web</h4> <ul> <li>Presenter: Joe</li> </ul> <h4>Filesystems for AI workloads: Linux and the Single Node Bottleneck</h4> <ul> <li>Presenter: Gwen Dawes (University of Cambridge)</li> <li><a href="https://drive.google.com/file/d/1n2L5IsTT6WVjgpJVXthjhIokaJMSiwIy/view?usp=sharing">Slides</a></li> </ul>
<p>The world of SBOMs and software transparency artefacts - In-Toto attestations, VEX updates and much more - all mention digital signatures. But not with what and how we should validate these. One thing is for sure - we don't want to use the existing WebPKI. There are some interesting initiatives, like SigStore, but they do not solve all issues. It's time that we work on solving this problem and define a solution for digital signatures that is distributed, secure and trustworthy. This is a call for help!</p>
<ul> <li>The pace at which quantum computing is evolving right now, threats of <code>harvest-now-decrypt-later</code> becoming more relevant. The widely deployed classical cryptographic algorithms such as RSA and ECC face a real risk of being broken by quantum attacks, most notably through Shor’s algorithm. This looming threat makes the transition to Post-Quantum Cryptography (PQC) urgent, not as a future project, but as a present-day migration challenge. </li> <li>You may have questions whether the transition to PQC is even necessary at the moment. It is true that quantum computers are years away, but it hardly matters because so many governments, telecom, defense entities worldwide are now requiring a transition.</li> <li>In this talk, we would focus on the practical hybrid transition from classical to quantum-resistant cryptography. We would explore NIST’s PQC standardization efforts through newly selected algorithms particularly <code>ML-KEM (key-exchange), ML-DSA and SLH-DSA (digital signatures)</code> in modern cryptographic infrastructures.</li> <li>The transition from classical crypto to a hybrid model enable organizations to begin adopting PQC today without breaking interoperability or relying on fully quantum-resistant stacks before they’re ready.</li> <li>To make this transition concrete, we will demonstrate a <code>TLS connection with hybrid key-exchange and post-quantum signature</code>, showing how post-quantum and classical algorithms can operate together.</li> </ul>
<p>Most container images in production are still unsigned, and even when signatures exist, they often provide no clear guarantee about where the artifact came from or what threat the signature is supposed to protect against. Supply-chain attacks exploit this gap and become an increasingly important issue when publishing or importing open-source software.</p> <p>This talk presents security capabilities in Docker and Moby BuildKit that address these issues. BuildKit executes all build steps in isolated, immutable sandboxes strictly defined by the build definition, and produces SLSA attestations with complete snapshots of the build’s source material.</p> <p>Additionally, Docker will provide a trusted BuildKit instance running inside GitHub Actions infrastructure. Artifacts produced there include signed attestations tied to a well-defined security boundary. The talk explains what guarantees this environment provides and how this differs from traditional approaches.</p> <p>The session also covers how to update container-based pipelines to always validate all BuildKit inputs (images, Git sources, HTTP sources) using Rego policies and BuildKit attestations. These checks apply both to artifacts coming from the new trusted builder instance and to any other verifiable artifacts.</p> <p>These improvements are designed to strengthen container security and raise the baseline for how open-source projects should sign, attest, and verify artifacts.</p>
<p>It is widely considered good practice to sign commits. But leveraging those signatures is hard. <a href="https://sequoia-pgp.gitlab.io/sequoia-git/">Sequoia git</a> is a system to authenticate changes to a VCS repository. A project embeds a signing policy in their git repository, which says who is allowed to add commits, make releases, and modify the policy. <a href="https://sequoia-pgp.gitlab.io/sequoia-git/man/sq-git-log.1.html"><code>sq-git log</code></a> can then authenticate a range of commits using the embedded policy. Sequoia git distinguishes itself from projects like sigstore in that all of the information required to authenticate commits is available locally, and no third-party authorities are required. In this talk, I'll present sequoia git's design, explain how it enforces a policy, and how to use it in your project.</p>
<p>Endpoints are where most security incidents begin. Compromises often start with phishing, software vulnerabilities, or simple misconfigurations on individual laptops and servers. Modern security teams rely on endpoint telemetry for detection, investigation, and response. But for many engineers, this part of the stack remains opaque and difficult to reason about.</p> <p>This talk presents a practical, open-source blueprint for building an endpoint telemetry pipeline that engineers can actually understand and evolve. We start with osquery, a Linux Foundation project that exposes endpoint state as structured, queryable data. On top of that, we build a layered system with clear responsibilities. This includes a control layer for intent and coordination, a data layer responsible for ingestion, buffering, streaming, and storage, a detection and intelligence layer with inspectable logic, and a correlation and response layer designed for humans in the loop.</p> <p>Rather than pitching a product, this talk focuses on boundaries, contracts, and tradeoffs. We walk through real-world design decisions and common failure modes. We also explore why ownership of telemetry matters more than any single tool. Attendees will leave with a mental model they can adapt, a stack they can run locally, and the confidence to build endpoint security systems that are transparent, flexible, and defensible without relying on closed platforms.</p>
<p>HyperDbg is a modern, open-source hypervisor-based debugger supporting both user- and kernel-mode debugging. Operating at the hypervisor level, it bypasses OS debugging APIs and offers stealthy hooks, unlimited simulated debug registers, fine-grained memory monitoring, I/O debugging, and full execution control, enabling analysts to observe malware with far greater reliability than traditional debuggers.</p> <p>When it comes to debugger stealthiness and sandboxing, environment artifacts can reveal the presence of analysis tools - particularly under nested virtualization. To address this issue, we present HyperEvade, a transparency layer for HyperDbg. HyperEvade intercepts hypervisor-revealing instructions, normalizes timing sources, conceals virtualization-specific identifiers, and emulates native hardware behavior, reducing the observable footprint of the hypervisor.</p> <p>While perfect transparency remains a future endeavour, HyperEvade significantly raises the bar for stealthy malware analysis. By suppressing common detection vectors, it enables more realistic malware execution and reduces evasion, making HyperDbg a more dependable tool for observing evasive or self-protective malware. This talk covers HyperDbg’s architecture and features, HyperEvade’s design, and practical evaluation results.</p> <p>Resources:</p> <ul> <li> <p>HyperDbg repository: https://github.com/HyperDbg/HyperDbg/</p> </li> <li> <p>Documentation: https://docs.hyperdbg.org/</p> </li> <li> <p>Kernel-mode debugger design: https://research.hyperdbg.org/debugger/kernel-debugger-design/</p> </li> <li> <p>Research paper: https://dl.acm.org/doi/abs/10.1145/3548606.3560649</p> </li> </ul>
<p>This is a live tutorial of hacking against keyboards of all forms. Attacking the keyboard is the ultimate strategy to hijack a session before it is encrypted, capturing plaintext at the source and (often) in much simpler ways than those required to attack network protocols.</p> <p>In this session we explore available attack vectors against traditional keyboards, starting with plain old keyloggers. We then advance to “Van Eck Phreaking” style attacks against individual keystroke emanations as well as RF wireless connections, and we finally graduate to the new hotness: acoustic attacks by eavesdropping on the sound of you typing!</p> <p>Use your newfound knowledge for good, with great power comes great responsibility!</p> <p>A subset of signal leak attacks focusing on keyboards. This talk is compiled with open sources, no classified material will be discussed.</p>
<p>OAuth tokens are the new crown jewels. Once issued, they bypass MFA and give API-level access that is hard to monitor. The opaque nature of their use and the difficulty in monitoring their activity create a dangerous blind spot for security teams, making them a primary target for attackers. This presentation will delve into the lifecycle of OAuth tokens, explore real-world attack vectors, and provide actionable strategies for protecting these high-value assets. We will also review the tactics, techniques, and procedures (TTPs) of notorious gangs like ShinyHunters and Scattered Spider, as demonstrated in the 2025 Salesforce attacks.</p>
<p>Bots generate roughly half of all Internet traffic. Some are clearly malicious (password crackers, vulnerability scanners, application-level/L7 DDoS), and others are merely unwanted (web scrappers, carting, appointment etc) bots. Traditional challenges (CAPTCHAs, JavaScript checks) degrade user experience, and some vendors are deprecating them. An alternative is traffic and behavior analytics, which is much more sophisticated, but can be far more effective.</p> <p>Complicating matters, there are cloud services not only helping to bypass challenges, but also mimic browsers and human behavior. It's tough to build a solid protection system withstand such proxy services.</p> <p>In this talk, we present WebShield, a small open-source Python daemon that analyzes Tempesta FW, an open-source web accelerator, access logs and dynamically classifies and blocks bad bots.</p> <p>You'll learn: * Which bots are easy to detect (e.g., L7 DDoS, password crackers) and which are harder (e.g., scrapers, carting/checkout abuse). * Why your secret weapon is your users’ access patterns and traffic statistics—and how to use them. * How to efficiently deliver web-server access logs to an analytics database (e.g., ClickHouse). * Traffic fingerprints (JA3, JA4, p0f): how they’re computed and their applicability for machine learning * Tempesta Fingerprints: lightweight fingerprints designed for automatic web clients clustering. * How to correlate multiple traffic characteristics and catch lazy bot developers. * Baseline models for access-log analytics and how to validate them. * How to block large botnets without blocking half the Internet. * Scoring, behavioral analysis, and other advanced techniques are not yet implemented</p>
<p><strong>Backdoors in software are real</strong>. We’ve seen injections creep into open-source projects more than once. Remember the infamous xz backdoor? That was just the headline act. Before that, we have seen the PHP backdoor (2021), vsFTPd (CVE-2011-2523), and ProFTPD (CVE-2010-20103). And it doesn’t stop at open-source projects: network daemons baked into router firmware have been caught red-handed too—think Belkin F9K1102, D-Link DIR-100, and Tenda W302R. Spoiler alert: this is likely just the tip of the iceberg. <strong>Why is this so scary?</strong> Because a single backdoor in a popular open-source project or router model is basically an all-you-can-eat buffet for attackers—millions of systems served on a silver platter.</p> <p><strong>Finding and neutralizing backdoors means digging deep into large codebases</strong> and binary firmware. Sounds heroic, right? In practice, even for a seasoned analyst armed with reverse-engineering tools (and maybe a good Belgian beer), it’s a royal pain. So painful that, honestly, <strong>almost nobody does it</strong>. Some brave souls tried building specialized reverse tools—Firmalice, HumIDIFy, Stringer, Weasel—but those projects have been gathering dust for years. And when we tested Stringer (which hunts for hard-coded strings that might trigger backdoors), the results were… let’s say “meh”: tons of noise, so many missed hits.</p> <p><strong>This is where ROSA (<a href="https://github.com/binsec/rosa">https://github.com/binsec/rosa</a>) comes in</strong>. Our mission? Make backdoor detection practical enough that people actually want to do it—no Belgian beer required (but appreciated!). Our secret weapon: fuzzing. Standard fuzzers like AFL++ (<a href="https://github.com/AFLplusplus/AFLplusplus">https://github.com/AFLplusplus/AFLplusplus</a>) bombard programs with massive input sets to make them crash. It’s brute force, but it works wonders for memory-safety bugs. Backdoors, though, play a different game: they don’t crash—they hide behind secret triggers and valid behaviors. So <strong>we built a mechanism that teaches fuzzers to spot the difference between “normal” and “backdoored” behavior</strong>. We integrated it into AFL++, and guess what? <strong>It nailed 7 real-world backdoors and 10 synthetic ones in our tests</strong>.</p> <p><strong>In this talk</strong>, we’d like to show you how ROSA works, demo it live, and share ideas for making it even better. If you’re into fuzzing, reverse engineering, or just love geeking out over security, you’re in for a treat.</p>
<p><a href="https://landlock.io">Landlock</a> is a Linux Security Module that empowers unprivileged processes to securely restrict their own access rights (e.g., filesystem, network). While Landlock provides powerful kernel primitives, using it typically requires modifying application code.</p> <p><a href="https://github.com/landlock-lsm/island">Island</a> makes Landlock practical for everyday workflows by acting as a high-level wrapper and policy manager. Developed alongside the kernel feature and its Rust libraries, it bridges the gap between raw security mechanisms and user activity through:</p> <ul> <li>Zero-code integration: Runs existing binaries without modification.</li> <li>Declarative policies: Uses TOML profiles instead of code-based rules.</li> <li>Context-aware activation: Automatically applies security profiles based on your current working directory.</li> <li>Full environment isolation: Manages isolated workspaces (XDG directories, TMPDIR) in addition to access control.</li> </ul> <p>In this talk, we will provide a brief overview of the related kernel mechanisms before diving into Island. We'll explain the main differences with other mechanisms and tools, and we'll explain Island's design and how it works, with a demo.</p>
<p>The <a href="https://github.com/google/capslock">Capslock project</a> was started within Google to provide a capability analysis toolkit for Go packages, and has since been open sourced and is being extended to support other languages.</p> <p>In this talk, we'll walk through using the experimental <a href="https://github.com/LawnGnome/cargo-capslock"><code>cargo-capslock</code></a> tool developed through a grant from <a href="https://alpha-omega.dev/">Alpha-Omega</a> to analyse the capabilities of Rust services. We'll then use the result of that analysis to create seccomp profiles that can be applied using container orchestration systems (such as Kubernetes) to restrict services and ensure that updates are unable to silently open new attack vectors, and discuss how this technique can be applied to services written in other languages as well.</p>
<p>Open-weight LLMs (like LLaMA, Mistral, and DeepSeek-R1) have triggered a "Cambrian explosion" of innovation, but they have also democratized offensive cyber capabilities. Recent evaluations, such as MITRE’s OCCULT framework, show that publicly available models can now achieve >90% success rates on offensive cyber knowledge tests, enabling targeted phishing, malware polymorphism, and vulnerability discovery at scale.</p> <p>For the Open Source community, this presents an existential crisis. Traditional security models (API gating, monitoring, rate limiting) rely on centralized control, which vanishes the moment weights are published. Furthermore, emerging regulations like the EU AI Act risk imposing impossible compliance burdens on open model developers for downstream misuse they cannot control, such as post-market monitoring.</p> <p>In this talk, Alfonso De Gregorio (Pwnshow) will deconstruct the "Mitigation Gap"—the technical reality that once a model is downloaded, safety filters can be trivially fine-tuned away. Drawing on his direct consultation work with the European Commission, he will explain how we can navigate this minefield. We will discuss:</p> <p>1/ The Threat Reality: A look at tools like Xanthorox AI and DeepSeek-R1 to understand the actual offensive capabilities of current open weights, and the state of the art in offensive AI.</p> <p>2/ The Policy Trap: Why "strict" interpretations of the EU AI Act could stifle open innovation, and the fight to shift liability to the modifier and deployer rather than the open-source developer.</p> <p>3/ The Way Forward: Technical solutions for "Responsible Release" (Model Cards, capability evaluations) and the necessity of AI-enabled defenses to counterbalance the offensive drop in barrier-to-entry.</p> <p>This session is for security practitioners and open-source advocates who want to ensure the future of AI remains open, while pragmatically addressing the security chaos it unleashes.</p>
<p>Achieving improved security in the open source ecosystem is more than a theoretical goal but a plausible reality as shown by the track record of nonprofit Open Source Technology Improvement Fund, Inc. Following a best practice of independent code review with a process specifically tailored to open source projects and communities, OSTIF has worked on over 100 security audits of projects ranging from git, cURL, kubernetes, php, sigstore, and has audit reports and numerous vulnerability fixings to demonstrate effectiveness.</p>
<p>Everyone's excited (sarcasm) that AI coding tools make developers more productive. Security teams are excited too - they've never had this much job security.</p> <p>LLMs and AI-assisted coding tools are writing billions of lines of code, so teams can ship 10x faster. They're also inheriting vulnerabilities 10x faster.</p> <p>We need to detect AI-generated code and trace it back to its FOSS origins. The challenge: exact matching doesn't work for AI-generated code since each generation may have small variations given the same input prompt. </p> <p>AI-Generated Code Search (https://github.com/aboutcode-org/ai-gen-code-search) introduces a new approach using locality-sensitive hashing and content-defined chunking for approximate matching that actually works with AI output variations. This FOSS project delivers reusable open source libraries, public APIs, and open datasets that make AI code detection accessible to everyone, not just enterprises with massive budgets.</p> <p>In this talk, we'll explain how we fingerprint code fragments for fuzzy matching, build efficient indexes that don't balloon to terabytes, and trace AI-generated snippets back to their training data sources. We'll demo real examples of inherited vulnerabilities, show how it integrates with existing FOSS tools for SBOM and supply chain analysis, and explain how this directly supports CRA compliance for tracking code origin.</p> <p>Bottom line: if AI-generated code is in your dependencies (and it probably is), you need visibility into what it's derived from and what risks it carries. This project gives you the FOSS tools and data to find out.</p>
<p>Your AI model is a new attack surface! Unlike traditional applications where threats are well-documented, ML systems face unique vulnerabilities: adversarial inputs crafted to fool classifiers, data poisoning during training, prompt injection in LLM applications, model extraction through API probing, and membership inference attacks that leak training data. Most security teams monitor network traffic and system logs. Few monitor the AI layer itself. This talk shows how to build security-focused observability for production ML systems using open source tools.</p> <p>I'll demonstrate during the track 3 Threat detection patterns: 1. Adversarial input detection 2. Model behavior monitoring 3. LLM-specific security monitoring</p> <p>everything.... with a fully open source. stack Prometheus for metrics (custom security-focused exporters) Loki for structured logging with retention policies Grafana for security dashboards and alerting OpenTelemetry for distributed tracing</p> <p>Attendees will leave with the following materials: Threat model framework for production ML systems Prometheus alerting rules for common AI attack patterns Log analysis queries for security investigation Architecture for integrating AI monitoring with existing SOC workflows</p>
<p>As cyber threats grow in sophistication, the “trust but verify” model is no longer enough. Organizations are rapidly shifting toward Zero Trust Architecture (ZTA) — a security paradigm where no user or device is inherently trusted, inside or outside the network. </p> <p>Zero Trust Architecture (ZTA) is no longer a buzzword—it’s a necessity. With traditional perimeter-based security models failing to address modern threats like lateral movement and insider attacks, organizations are increasingly adopting ZTA’s "never trust, always verify" philosophy. </p> <p>This architecture is built on several pillars: - Identity-centric protection defining identity as the new perimeter. - Dynamic micro segmentation and contextual access controls to isolate resources. - Continuous monitoring and behavioural analytics to detect sophisticated lateral movements and insider threats. Modern ZTA implementations employ AI and automation for adaptive threat detection and response, dramatically reducing breach costs and attack surfaces for distributed enterprises. Adoption of Zero Trust is rapidly increasing, with industry research indicating that over 70% of organizations are integrating ZTA in their cybersecurity frameworks and at least 70% of new remote access deployments will rely on these principles by the end of 2025. Despite its robust security benefits, ZTA demands substantial investment in identity management, policy enforcement, and ongoing operational monitoring. </p> <p>But how do we move from theoretical principles to practical implementation? </p> <p>This talk explores the why and how of ZTA adoption for mid-level engineers and security practitioners. We’ll break down core ZTA components—identity-centric access, micro segmentation, and continuous monitoring—using real-world examples . </p> <p>Attendees will leave with: • A clear roadmap for phased ZTA adoption, starting with high-value assets. • Strategies to balance security and user experience (e.g., just-in-time access). • Lessons from industry leaders like IBM on overcoming common pitfalls. </p> <p>Whether you’re in DevOps, cloud security, or IT governance, this session will equip you to champion ZTA in your organization</p>
<p>DevRoom organisers welcome all to the Legal & Policy Issues DevRoom</p>
<p>Legal and licensing issues are a vital part of the Free Software ecosystem. While many Free Software developers may have a good idea of the legal and licensing requirements that turn their project into Free Software, there are many more attending FOSDEM who may lack the knowledge or have misconceptions about the legal issues in Free Software.</p> <p>This session hopes to provide an introduction and background to the legal concepts that underpin the freedoms in Free Software, and how the law is an important tool in ensuring our digital freedoms, so that participants can better appreciate the legal and licensing issues to be discussed by speakers in the Legal and Policy Devroom.</p>
<p>Open protocols underpin much of Europe’s digital infrastructure, yet they remain a blind spot in European digital policy. This talk highlights why supporting open protocol governance is crucial for Europe’s digital sovereignty, interoperability, and innovation. It explores how policymakers and developers can together address this gap by recognising protocols as foundational infrastructure and shaping policies that enable resilient, interoperable, and decentralised systems.</p>
<p>Open source initiatives usually bubble up from the grassroots community, and while governments have been paying more attention recently, policy is often subject to the whims of election cycles. This means long-term continuity is never guaranteed.</p> <p>Even when policies are in place, their implementation can be hampered by two significant factors: civil servants' open-source literacy and existing legal/regulatory bottlenecks. Sure, enshrining open source into law would make it mandatory and sustainable, but let’s be real—the legislative process is painfully slow.</p> <p>The Open Culture Foundation (OCF) has been deeply embedded in Taiwan’s open source scene for over a decade. Some of our members have been tracking the government’s on-again, off-again open-source journey for nearly 30 years, since the early community days. Others have even moved from leading government open-source policy to eventually return to the non-profit sector. Throughout this journey, OCF has continually adapted how we collaborate with and support the government, seeking the best communication strategies and case studies—all while managing the inevitable cycles of disappointment and excitement.</p> <p>Most recently, we saw Audrey Tang depart from the Ministry of Digital Affairs (MODA), and the government's visible focus on open source has noticeably dialed down. However, we also found like-minded partners in the Taipei City Government's Department of Information Technology (DOIT). We are now working with them to ensure that open source software continues to be adopted and deployed within the government.</p> <p>In this 30-minute session, we’ll be sharing the different collaboration models we’ve developed with the government and the tangible deliverables we’ve produced. Crucially, we’ll also discuss how we keep the momentum going and move forward even when we face headwinds.</p>
<p>In this Q&A session we will address all the questions our audience might have on the CRA in relation to Free Software. We will kick of the session with a short introduction focussing on current challenges around the implementation of the CRA with a specific focus on Open Source Stewards and Attestation programs and how and where financial support is needed in order to make the CRA work.</p>
<p>Software Freedom Conservancy (SFC) sued Vizio in October 2021 because Vizio did not provide the required source code for the GPL and LGPL works that Vizio chose to use in its TVs, preventing SFC from making privacy and security enhancing changes, among other improvements that the GPL and LGPL require that companies allow in devices they sell. SFC brought the case as a third-party beneficiary of these copyleft agreements, to demonstrate how users of copylefted software can directly enforce the agreements if a company fails to comply.</p> <p>The trial in this case was to finish last week, but a last-minute delay by the court means the trial will happen later this year instead. In the meantime, we'll discuss the case so far, including notable technical points about what Vizio did and didn't provide, what arguments have been made, and what we're likely to see at trial. We look forward to your questions and discussion around this historic case for user rights!</p>
<p>A number of countries are introducing "online safety" laws, which generally impact providers of online services. An example of these is the UK's Online Safety Act 2023.</p> <p>It purports to have extra-territorial effect, applying to anyone, anywhere in the world, who provides a service to people in the UK, if certain criteria are met.</p> <p>While the ostensible aim of these acts is to address concerns relating to the largest social media providers, they are not always well drafted, or else are drafted intentionally broadly, and catch all number of services which are used commonly by FOSS projects, including self-hosted projects.</p> <p>For instance:</p> <ul> <li>git / code forges</li> <li>community forums</li> <li>instant messaging services</li> <li>bug trackers</li> </ul> <p>I have spent far too much pro bono time this year working with FOSS projects to help them with the Online Safety Act 2023, working out whether it poses a realistic risk to them, and what, if anything, they might want to do about it.</p> <p>I've also produced onlinesafetyact.co.uk, as a free, CC-licensed, resource, which has been well used as far as I can tell.</p> <p>This talk will:</p> <ul> <li>raise awareness of this kind of legal framework, which is likely to be increasingly common</li> <li>cover the assessment of risk, to help projects decide which, if any, requirements might pose actual risk to them</li> <li>look at options for "doing something" which, while perhaps not compliant with each and every law, might be heading in the right direction, consistent with the generally reasonably common aims of this kind of framework</li> <li>discuss some of the benefits of thinking through these kinds of issue, so that it is not just about "legal compliance", but whether there are learnings / things to do which can actually make communities safer and give projects less work to do overall.</li> </ul>
<p>This panel will bring together policy/legal experts and enforcement officers from the European Commission to discuss how the Digital Markets Act (DMA) applies to Apple’s iOS/iPadOS and Google’s Android from the perspective of interoperability.</p> <p>In particular, the panel will deal with the European Commission's recent decisions in regulating hardware and software interoperability for Apple’s OSes. The audience will learn what interoperability under the DMA means for Free Software developers, and how they can expect the interoperability solutions to be provided by gatekeeper companies like Apple and Google.</p> <p>More importantly, the discussion will address relevant questions for the effective implementation of the interoperability obligations in the DMA, including: </p> <ul> <li>How can Free Software projects request interoperability from Apple and Google under the DMA? </li> <li>What are the concerns regarding integrity and security of the operating system involving interoperability grants under the DMA?</li> <li>What are the main challenges posed by changes in governance for the Android Open Source Project? </li> <li>What other DMA obligations can Free Software developers rely on to facilitate switching, specially related to data interoperability and portability?</li> <li>What are the consequences if Apple and Google fail to interoperate?</li> <li>Does the DMA effectively shift gatekeeper control away from Apple and Google? </li> <li>What regulatory or community responses, at both the European and global levels, are needed to preserve software freedom in the mobile ecosystem?</li> </ul> <p>The panel will be composed by:</p> <ul> <li>Lori Roussey, Data Rights</li> <li>Victor Le Pochat, European Commission's DMA enforcement team</li> <li>Gabriel Kobus, European Commission's DMA enforcement team</li> <li>Alexander Matern, European Commission's DMA enforcement team</li> </ul> <p>Panel moderation: Lucas Lasota, Legal Researcher and Lecturer at the Halle-Wittenberg University. </p> <p>The language will be English.</p>
<p>We had a canceled session: a wonderful opportunity to crowd source a topic! What would you like to hear about? What is the hot topic you don't already see on the schedule?</p> <p>Let us know what you think by filling out this form, or by writing your suggestion on a piece of paper and handing it to one of the Legal & Policy Devroom organizers.</p> <p>https://sfc.ngo/idea</p>
<p>FOSS communities have historically developed governance models that include within them biases and other problems, often belatedly recognized. For example, there is now general agreement that no dictator can be benevolent. Common alternatives to the "benevolent" dictator— the "meritocracy", "do-acracy", and the self-perpetuating committee — also have serious problems. Often the alternative offered to these kinds of governance systems is for some kind of elected governance body.</p> <p>Democratic governance institutions are messy, however. We'll consider some historical examples of problems that have occurred in various democratic FOSS initiatives and organizations, and will focus particularly on the Open Source Initiative (OSI) board of directors elections of 2025. We'll consider the question: how can we design elected governance bodies for FOSS that truly represent the views of our community and are held properly accountable to their constituencies?</p> <p>Joe 'Zonker' Brockmeier will moderate this panel, and additional individuals have been invited and will be added once they are confirmed.</p>
<p>Clean-room design is a method of recreating and relicensing software without infringing any of the copyrights. So what happens when we use LLM's to recreate thousands of open source projects in seconds, and relicense them all to more permissive licenses? </p> <p>We first started looking at this when in 2025 MongoDB used an AI agent to take thousands of lines of code from a copyleft project, and used Cursor to recreate and relicense it all under apache. The prompts used to do this were left in the repository.</p> <p>What does it mean for the open source ecosystem that 90% of our open source supply chain can currently be recreated in seconds with today's AI agents?</p> <p>In this talk we will be demonstrating the process of large scale clean rooming, and explore what it means for open source, and what it means for community.</p>
<p>Closing of to the Legal & Policy Issues DevRoom by the DevRoom organisers.</p>
<p>Digitization requires efficient software development. Today, this is no longer financially viable without the massive reuse of existing components and thus without the use of open source software as a generic product, also in the context of safety applications. Therefore, ways and means must be found to make open source software usable on a large scale for the railway sector. Due to the cooperative nature of open source software and the low competitive differentiation in the use of such generic products, the collaboration of various stakeholders from the sector under the governance of a Foundation can useful and important. This BOF wants to explore, if there is a critical mass to start a foundational backed project initiative for better spread of awareness for OSS in Railways and which activities exist to expand this approach for the safety-critical parts.</p>
<p>Linux is being used more often in safety-critical areas like cars, planes, medical devices, robots, and trains. But each industry faces similar challenges when trying to meet safety and certification requirements. This BoF is an open discussion about those real-world problems: timing and determinism, documentation, certification, tooling, and system design. Anyone interested in safety-critical Linux is welcome to join, share experiences, ask questions, and explore where collaboration could help.</p>
<p>Labgrid is an embedded board control python library with a focus on testing, development and general automation. It includes a remote control layer to control boards connected to other hosts.</p> <p>This BOF is a chance to meet up with developers and users to discuss anything related to Board Farms and labgrid.</p>
<p>A meet-up for the Hare programming language community to meet each other face to face, discuss our work, and plan for the future of the language.</p> <p>https://harelang.org</p>
<p>Let's chat about Git, Mercurial, Pijul, Jujistu... what makes them great or not so great and what they're currently doing to improve. Present in the room will be two Mercurial developers, the creator of Pijul and other people invested in this space, feel free to come, ask questions and bounce ideas!</p>
<p>Reticulum is a cryptographic mesh networking stack gaining attention for off-grid and emergency communications. The original Python implementation recently reached v1.0 but its maintainer has stepped back from public engagement, and the license prevents distribution in Debian, F-Droid, and major package managers.</p> <p>This session brings together Reticulum users and developers to discuss practical migration paths. We will attempt live switching between implementations: Python Reticulum, RetiNet (AGPL fork), and the Rust rnsd daemon. Participants can bring laptops to test interoperability and identify friction points.</p> <p>Discussion topics: current state of implementations (Python, Rust, C++ microReticulum, Go, Zig), community coordination without upstream, documentation gaps, embedded device support, and real-world deployment experiences.</p> <p>Bring your RNodes, or laptops with Reticulum installed. No prior Reticulum experience required for observers.</p> <p>Project: https://codeberg.org/lgh/Reticulum-rs/src/branch/daemon-mode Original Reticulum: https://github.com/markqvist/Reticulum RetiNet (AGPL fork): https://codeberg.org/skyguy/retinet</p> <p>Lora Settings</p> <p><code>[[interfaces]] name = "FOSDEM LoRa" type = "RNodeInterface" interface_enabled = true port = "/dev/ttyUSB0" frequency = 864200000 bandwidth = 125000 txpower = 5 spreadingfactor = 10 codingrate = 6</code></p>
<p>Showing what's possible with the E-Paper driver board from Modos. Including custom wood frame E-Paper 13 inch displays with 40 hz and color. Macbook M1 16 inch with an E-Paper screen. I will bring my hardware for you to test so you can try it out.</p>
<p>Welcome talk covering some organizational questions</p>
<p>llama.cpp has become a key tool for running LLMs efficiently on any hardware. This talk explores how multimodal features have grown in the project. It focuses on libmtmd, a library added in April 2025 to make multimodal support easier to use and to maintain in llama.cpp.</p> <p>We will first cover main achievements. These include combining separate CLI tools for different models into one single tool called llama-mtmd-cli. Next, we will discuss how libmtmd works with llama-server and show real examples of low-latency OCR applications. We will also talk about adding audio support, which lets newer models summarize audio inputs. Plus, we will cover the challenges of handling legacy code while keeping the project flexible for future models.</p> <p>Looking forward, the talk will share plans for new features like video input, text-to-speech support, and image generation. Attendees will also learn how to contribute and use these multimodal tools in their own project.</p>
<p>Running modern Large Language Model (LLM) workloads on macOS presents a unique challenge: reconciling powerful local hardware with a mature, Linux-first AI tooling and container ecosystem.</p> <p><strong>The Problem: Bridging the OS and Acceleration Gap</strong></p> <p>While containerization offers macOS developers access to Linux-centric tools like Ramalama and the Podman Desktop AI Lab, introducing a virtualization layer immediately compromises GPU acceleration. Direct device passthrough is infeasible, as it monopolizes the display and host system resources. Consequently, achieving high-performance LLM inference requires a sophisticated bridging mechanism.</p> <p><strong>The Solution: Para-Virtualization via GGML API Remoting</strong></p> <p>We present the implementation of an <strong>API-remoting, para-virtualized execution path for llama.cpp</strong>. This novel design is built directly on the <strong>GGML API</strong>, allowing us to selectively offload compute-intensive operations to execute on the macOS host. Crucially, this execution path <strong>natively leverages the GGML-Metal backend</strong>, achieving <strong>full-speed host performance</strong>. This strategy preserves a fully containerized Linux developer experience inside the virtual machine while achieving hardware-level acceleration outside of it.</p> <p><strong>Performance and Implications</strong></p> <p>We will share concrete performance results demonstrating near-native inference speed compared to running llama.cpp directly on the host. The talk will examine the architectural trade-offs of this split-execution model, providing insight into:</p> <ul> <li>The implementation details of the para-virtualized GGML API bridge.</li> <li>The latency overhead of API remoting versus the throughput gain from host GPU execution.</li> <li>How this open-source approach fundamentally changes the future of containerized and accelerated AI tooling on non-Linux platforms, specifically addressing the needs of macOS users in the open-source AI community.</li> </ul>
<p>Deploying neural networks in production environments presents unique challenges: models must run efficiently across diverse hardware, from powerful servers to resource-constrained embedded devices, while maintaining predictable performance without heavy runtime dependencies.</p> <p>This talk introduces <a href="https://github.com/sonos/tract"><strong>tract</strong></a>, <a href="https://sonos.com/">Sonos</a>'s open-source neural network inference toolkit started in 2018 and written in Rust. We'll explore how tract bridges the gap between training frameworks and production deployment by offering a no-nonsense, self-contained inference solution used today to deploy deep learning on millions of devices at Sonos.</p> <p>This toolkit has some unique strengths thanks to embedded graph optimization, automated streaming management, and symbolic abstraction for dynamic dimensions — plus support for multiple open exchange standards including <a href="https://onnx.ai/">ONNX</a>, <a href="https://www.khronos.org/nnef">NNEF</a>, and TensorFlow Lite.</p> <p><a href="https://github.com/sonos/tract"><strong>tract</strong></a> also has a companion project coined <a href="https://github.com/sonos/torch-to-nnef"><strong>torch-to-nnef</strong></a> that strive to export PyTorch models to an NNEF optimized for tract with maximum compatibility. It enables some unique features like quantization, better Fourier Transform support and easier extensibility: this will also be discussed shortly during this presentation.</p>
<p>Can an ESP32-based MCU run (tiny)ML models accurately and efficiently? This talk showcases how a tiny microcontroller can transparently leverage neighboring nodes to run inference on full, unquantized torchvision models in less than 100ms! We build on vAccel, an open abstraction layer that allows interoperable hardware acceleration and enable devices like the ESP32 to transparently offload ML inference and signal-processing tasks to nearby edge or cloud nodes. Through a lightweight agent and a unified API, vAccel bridges heterogeneous devices, enabling seamless offload without modifying application logic.</p> <p>This session presents our IoT port of vAccel (client & lightweight agent) and demonstrates a real deployment where an ESP32 delegates inference to a GPU-backed k8s node, reducing latency by 3 orders of magnitude while preserving Kubernetes-native control and observability. Attendees will see how open acceleration can unify the Cloud–Edge–IoT stack through standard interfaces and reusable runtimes.</p>
<p>During 2025 we ported ExecuTorch, the extension to PyTorch for embedded systems, to a bare metal multi-core RISC-V microcontroller based on the CORE-V CV32E40Pv2 processor.</p> <p>In this talk we'll explain the steps we had to take to achieve this. - removing dependencies on an underlying operating system - how to handle memory management between slow main memory and fast local memory - how to handle tiling and operators on bare metal multicore systems - how to take advantage of custom acceleration</p> <p>The goal is for others to be able to bring up ExecuTorch on other bare metal microcontrollers, learning from our experiences.</p>
<p>As AI workloads move to the browser, the lack of a unified low-level acceleration layer on Linux—equivalent to DirectML or CoreML—creates major bottlenecks. In this talk, we explore how WebNN and next-generation WebLLM can unlock efficient on-device inference on RISC-V, using Tenstorrent hardware and the emerging RVV 1.0 Variable-Length vector ISA. We cover the challenges of WebNN integration on Linux, the importance of WASM support for RVV, and demonstrate progress on running modern LLMs directly in the browser. We will also detail the RVV-enabled WASM implementation path for WebNN and what’s needed upstream.</p>
<p>Leveraging Rust and Khronos' emerging Slang initiative, we introduce our efforts toward a cross-platform GPU LLM inference ecosystem. With a single-source approach we aim to minimize backend-specific code and foster community participation by writing inference kernels once and run them everywhere.</p>
<p>AI workloads increasingly target heterogeneous accelerators, from GPUs and TPUs to novel RISC-V architectures, each with different scheduling, memory, and concurrency constraints. Traditional compilers rely on static heuristics that do not generalize across devices and custom neural network layers.</p> <p>In this talk, we present the <strong>Daisytuner Optimizing Compiler Collection (DOCC)</strong>, a self-learning compiler that closes the optimization loop by continuously collecting performance data from real executions and feeding it back into the compilation pipeline. The system represents code regions using stateful dataflow multigraphs, an open-source intermediate representation that enables symbolic dataflow analysis. Performance profiles in the form of hardware counters and execution times are ingested into an online embedding database that the compiler can query to derive and apply new optimizations.</p> <p>We describe the generation of <a href="https://github.com/daisytuner/sdfglib">SDFGs</a> from <a href="https://github.com/daisytuner/sdfg-dialect">ONNX and PyTorch</a> via IREE, the passes for mapping the IR to backends, and the benchmarking infrastructure running on our super-heterogeneous cluster. We conclude by showing how this feedback pipeline allows the compiler to evolve its optimization strategies automatically, improving schedules without human intervention.</p>
<p>Serving multiple models on a single GPU sounds great until something segfaults.</p> <p>Two approaches dominate for parallel inference: MIG (hardware partitioning) and MPS (software sharing). Both promise efficient GPU sharing.</p> <p>I tested both strategies for video generation workloads in parallel.</p> <p>This talk digs into what actually happened: where things worked, where memory isolation fell apart, which configs crashed, and what survives under load.</p> <p>By the end, you'll know:</p> <ol> <li>How to utilize unused GPU capacity.</li> <li>How to setup MIG and MPS.</li> <li>Memory issues, crashes, and failures.</li> <li>Workload specific configs</li> </ol>
<p>OneAI is an open-source framework that provides the foundation required to manage AI model artifacts and inference workloads across OpenNebula-based cloud infrastructures. In this talk, we present how OneAI discovers, imports, and deploys models directly from Hugging Face Hub into OpenNebula clusters—turning complex AI lifecycle operations into a streamlined, infrastructure-native workflow. OneAI is built around three core components: (1) HFHUB Marketplace, a lightweight catalog that indexes Hugging Face models as metadata, deferring artifact materialization until deployment to dramatically reduce storage overhead; (2) SharedFS Datastore, a specialized OpenNebula datastore that treats directories as images, enabling efficient model storage on high-performance shared filesystems; (3) AI Service REST API, an orchestration layer that provisions model deployments, supervises the vLLM inference engine, and exposes OpenAI-compatible endpoints. We will provide an overview of the architecture behind these components and how they work together to create a clean, reproducible pipeline – from model discovery to fully deployed inference services. OneAI offers a fully open-source alternative to proprietary inference platforms. By building directly on OpenNebula’s capabilities, it reduces TCO by exploiting existing HPC storages, supports secure multi-tenancy, and enables scalable, production-ready inference deployments.</p>
<p>Most Machine Learning tools use CUDA for hardware acceleration, and are as a result only compatible with Nvidia GPUs. AMD has been making a lot of progress enabling simple recompilation with minimal code changes to ROCm for their hardware, but why not use an open and broadly-compatible API instead? That's where Vulkan comes in, which was built up for game development, but also allows compute-only applications, and has broad and good driver support across many hardware vendors.</p> <p>As a follow-up to last year's talk about my work on the llama.cpp/GGML Vulkan backend, this talk will discuss lessons learnt from optimizations and new features that we added since, how viable Vulkan is for Machine Learning and what it is still missing.</p> <p>https://github.com/ggml-org/llama.cpp https://github.com/ggml-org/ggml</p>
<p>Running various forms of inference on microcontroller NPUs is not new. Systems where machine learning is used to analyze sensor data or do light CV on microcontroller-grade systems under 1 watt, under few dozen MB of RAM and FLASH and under 10 USD bill-of-materials are being massively deployed (even if they stay in the long shadow of more flashy LLMs and GenAI). That area, however, historically has been a domain of specialized machine learning frameworks such as emlearn, LiteRT (artist formerly known as TensorFlow Lite) and a few others. </p> <p>The question I will try to answer in this talk is the following: are there any benefits of trying to use more well established, but still pretty tightly optimized frameworks such as ggml and tinygrad for these types of deployments. I will share my experience with adopting these frameworks to targets such as Google Coral NPU and AI Foundry Erbium and what kind of interesting challenges it presented.</p>
<p>The growing energy demands of modern AI models pose a significant barrier to sustainable computing. As model complexity and deployment scale continue to rise, training and inference increasingly contribute to carbon emissions and operational costs. This talk begins by examining the technical challenges of accurately measuring energy consumption at multiple levels of abstraction—from system-wide and process-level metrics down to individual source code methods and API calls. Practical strategies for overcoming these measurement hurdles are discussed. The second part of the talk explores power consumption patterns in GPU kernels, highlighting how thread configuration, block geometry, and power limit settings shape kernel-level energy efficiency. We demonstrate how these characteristics influence power draw and discuss techniques for predicting consumption based on kernel properties. The session concludes with insights and best practices for managing performance–energy trade-offs in GPU-accelerated AI applications, offering a path toward more sustainable AI development.</p>
<p>Silicon engineering seems unobtainable elite industry only for those veterans of the industry that have access to expensive instruments and years of experience, right? Well, not anymore! With AI tools, coding agents and more and more available substrate to hook them up to, you can approach it as a system design, and start in days! Make new models inference on novel accelerator cards, put open cores in FPGA, and other tricks you can do without specialized engineering degrees. Not suggesting to tape it out and put it in production without proper review, but for prototyping and faster feedback cycles it's really changing the game! I'll demo a couple of examples all based on open IP!</p>
<p>The explosive growth of Large Language Models (LLMs) requires massively efficient and scalable inference systems. This talk will share key innovations NVIDIA Dynamo (https://github.com/ai-dynamo/dynamo) adds to enable system-level optimizations while leveraging performance from inference engines such as vLLM, SGLang, and TRT-LLM:</p> <ul> <li>Smart Scheduling that routes requests based on the KV cache hit rate and load, intelligently autoscales, and disaggregates the prefill and decode phases.</li> <li>Hierarchical Memory Management that utilizes HBM, host memory, local disk, and remote storage.</li> <li>Low-Latency Transfer of the KV cache across nodes and the memory hierarchy.</li> </ul> <p>This talk will also introduce production-grade LLM serving features of Dynamo that enable users to: - Find the best configuration for disaggregated serving offline. - Tune performance automatically based on real-time traffic. - Dynamically scale prefill and decode workers via topology-aware gang scheduling. - Leverage LLM-specific fault tolerance.</p>
<p>Running LLMs is currently fraught with friction: dependency hell and the ungoverned management of massive weight files (GGUF, safetensors).</p> <p>In this talk, we introduce Docker Model Runner (DMR), an open initiative to bring the same standard of reproducibility to AI models that containers brought to code. We will explore how DMR streamlines the "pull, push, run, serve" lifecycle by treating AI models as first-class OCI (Open Container Initiative) artifacts, decoupling the model weights from the inference engine.</p> <p>We will dive deep into the architecture of the Docker Model Runner, covering:</p> <p>Models as Artifacts: How we package and distribute GGUF and safetensors formats using OCI-compliant registries, eliminating the need for arbitrary file downloads.</p> <p>A Unified Interface: How DMR abstracts the complexity of underlying inference backends. We will discuss the integration of llama.cpp for broad hardware compatibility (CPU/GPU) and vLLM for high-performance production serving.</p> <p>The Model Driver Pack: How the runner handles hardware acceleration automatically, managing the interface between the container runtime and host resources (NVIDIA CUDA, Vulkan, etc.).</p> <p>Developer Experience: A look at the docker model CLI plugin and the local REST API that allows developers to swap models without changing their client code.</p> <p>Join us to see how we are building a standardized, open ecosystem where docker model run ai/gemma3 is all you need to start building AI applications.</p> <p>Key Takeaways for the Review Committee (Why this fits FOSDEM): Open Standards: The talk focuses on OCI compliance and open weights (GGUF/safetensors).</p> <p>Open Source Integration: It highlights the usage and orchestration of popular open-source projects (llama.cpp and vLLM).</p> <p>Technical Depth: It addresses infrastructure challenges (GPU passthrough, artifact management) rather than just high-level AI concepts.</p>
<p>Last year, I shared Paddler, an open-source LLM load balancer. A year of community feedback and building Poet (a static site generator with AI features) on top of it taught me what actually matters when self-hosting LLMs. This talk shares practical patterns the open-source community needs. What works, what doesn't, and what tooling we still need to build together.</p>
<p>This talk will focus on ET Platform, the AI Foundry's open-source RISC-V based manycore architecture.</p> <p>After a quick introduction, it will show how to get started on building and running the ET platform software in your machine, how to write software for ET accelerators and how to contribute to the project.</p> <p>For more information about AI Foundry and the ET platform visit https://https://github.com/aifoundry-org/et-platform</p>
<p>The ET-SoC-1 chip contains more than one thousand RISC-V cores, with custom vector and tensor extensions on each core, and has recently been given a new open-source lease of life [1]. What do low-level AI software engineers do with novel hardware? Obviously the answer is to make it do matmuls.</p> <p>Join me on a rapid journey from naïve matmul to optimized matmul, learning about ET-SoC-1 along the way. Some of its hardware features will help us, whereas others will be a hinderance.</p> <p>[1] https://github.com/aifoundry-org</p>
<p>RISC-V is rapidly evolving into a serious platform for AI acceleration—from embedded devices to full AI PCs and datacenter-class compute. But building real, production-ready AI systems on open hardware still poses challenges: memory bandwidth bottlenecks, heterogeneous compute scheduling, toolchain maturity, and model deployment efficiency. As part of this session, we will also briefly share DeepComputing’s AI product roadmap to illustrate how these engineering breakthroughs translate into real devices. In this talk, engineers from DeepComputing and Tenstorrent will share how we are solving these challenges together across two ends of the computing spectrum: • AI PC / edge devices: How we integrate high-performance RISC-V CPUs with NPUs, optimize dataflow for multi-die architectures, and overcome compiler/runtime fragmentation to run LLMs locally. • AI servers: How Tenstorrent’s RISC-V cores and scalable mesh architecture handle AI workloads; how we bridge the software gap (compilers, toolchains, scheduling, kernel-level tuning); and how we standardize low-level interfaces for AI compute. The focus is on how these problems are solved—microarchitecture decisions, data movement, kernel optimizations, interoperability layers, and lessons learned from building real products. This session will show why “All in RISC-V, RISC-V All in AI” is no longer a slogan but a practical engineering path forward.</p>
<p>In the last 10 years there's been a hardware race to build the best application-specific integrated circuit (ASIC) for both machine learning training and inference i.e. AI accelerators. What started with vision processing units (VPUs) went through tensor PUs (TPUs) and now we are dealing with neural processing units (NPUs). What's next?</p> <p>This talk will take a systematic look at the different hardware platforms for AI acceleration, but with a focus on the software stacks that support them on Linux. We'll take a look how individual vendors approached their ASICs from the kernel side, and how they exposed the acceleration functionality for user-space.</p> <p>Is it all proprietary or is there liberté? We'll find out together!</p>
<p>Boltz-2 is a state-of-the-art model that builds on the general architecture of AlphaFold 3, predicting biomolecular structures and binding affinities.</p> <p>BoltzGen is a system that builds on Boltz-2 and designs protein binders (potential drugs) to biomolecular targets. </p> <p>We implement both systems on Tenstorrent hardware to make drug discovery more open, more efficient, and cheaper.</p> <p>GitHub Repository: https://github.com/moritztng/tt-boltz My Thesis: https://moritztng.github.io/thesis/thesis.pdf</p>
<p>Welcome and update on the logistics of the dev room</p>
<p><a href="https://lfenergy.org/projects/seapath/">LF Energy SEAPATH</a> is an open source, high-availability real-time platform designed for hosting virtualized protection and control applications within electrical substations. As a complex project bridging electrical and computer engineering, it integrates multiple open source tools and expertise from diverse domains. Following the recent release of version 1.0, the project undertook a refactoring of <a href="https://lf-energy.atlassian.net/wiki/spaces/SEAP/overview">its documentation</a> to improve clarity and accessibility for a growing community of users and contributors</p> <p>This talk will present the documentation strategy for such a complex project, highlighting the challenges encountered and the solutions implemented. Key discussion points include:</p> <ul> <li><strong>Balancing documentation across multiple platforms</strong>: Ensure consistency and reduce redundancy between Confluence, GitHub, and Ansible Galaxy</li> <li><strong>Structuring the wiki</strong>: Organize the information for diverse audiences</li> <li><strong>Establishing clear naming conventions</strong>: A consistent terminology for pages, concepts, and components.</li> </ul>
<p>Documentation is the backbone of successful projects, yet many tools fall short in balancing ease of use, collaboration, and flexibility. <strong><a href="LaSuite Docs">https://github.com/suitenumerique/docs</a></strong> is an open source, block-based editor designed to solve these challenges. Built by the French and German govs, it offers a snappy editing experience, real-time collaboration, fine-grained access control, and powerful features like sub-docs and a headless CMS API. This talk will demonstrate why Docs is the ideal tool for teams looking to create, manage, and scale their documentation effortlessly.</p>
<p>Sometimes you need to mark up what Markdown doesn’t. It’s tempting to pick up a heavyweight Markdown variant, such as MDX, or to build your own just-this-once extension. But extensions to Markdown are often eye-wateringly ugly, fragile, and prone to lock-in. What’s to be done, switch formats? No, you’re too busy for that.</p> <p>In this talk, I’ll teach you about the little-used extension points that already exist in mainstream Markdown flavors, such as CommonMark, and how to take advantage of them before going off the beaten path. In this talk, you’ll learn about:</p> <ul> <li>The risks of inventing or adopting yet another Markdown variant</li> <li>Three extension points that you can start using today with your existing tools</li> <li>When deviating from Markdown can truly help</li> </ul> <hr /> <p><a href="https://ddbeck.com/">Daniel D. Beck</a> is a documentation consultant who helps software engineering teams make tools, processes, and content that reach developer audiences. His talk draws from experience as a longtime contributor and maintainer of open source software and documentation, including as a current maintainer of <a href="https://web-platform-dx.github.io/web-features/">Baseline</a>, a browser compatibility tool, and a past role as technical content lead for <a href="https://developer.mozilla.org/en-US/">MDN Web Docs</a>.</p>
<p><a href="https://www.docling.ai/">Docling</a> is an open source toolkit that simplifies document processing by converting various formats like PDFs and Word documents into structured, searchable data. It can handle complex layouts, tables, code, and formulas to preserve the meaning of the data and maintain the formats and relationships of the information. Find out how you might include <a href="https://github.com/docling-project">Docling</a> in your documentation workflow to emcompass diverse documentation sources and formats - including images and audio. As gen AI and LLMs are changing the way we document things and retrieve info, the importance of quality structured data cannot be understated.</p>
<p>You've perfected your Docs-as-Code pipeline. Your HTML documentation is beautiful, version-controlled, and deploys instantly. Then someone asks for a printing version. Printing? What is it? Ah, a primitive pre-HTML way of publishing, no problem... until you try it.</p> <p>This talk addresses the fundamental mismatch between the web's fluid layout and the paged, fixed-layout world of print. After creating Asciidoctor to Open Document converter (https://github.com/CourseOrchestra/asciidoctor-open-document) I was so stuck in this mismatch that I nearly concluded print output from simple markup was just a toy, and that achieving quality was impossible.</p> <p>Luckily, I found inspiration in Pandoc's architecture, which acts as a "metaconverter" -- a factory for building converters. Based on its ideas I completely rewritten Asciidoctor to Open Document converter into Unidoc Publisher (https://github.com/fiddlededee/unidoc-publisher). This worked excellently and now I can share my experience in this field.</p> <p>I will then map the landscape of rendering solutions. We will compare the core options, which are limited to:</p> <ul> <li>native convertors relying on PDF libraries,</li> <li>Paged Media CSS,</li> <li>TeX (and all around), </li> <li>Text Processors Formats (OpenXML in MS Office, Open Document in LibreOffice). </li> </ul> <p>There's no silver bullet, there is just a sensible path. Hope this talk will help to choose the right solution for your needs.</p>
<p>The addition of a new Extensions SDK in Superset led to a new initiative: a Developer Portal.</p> <p>That, in turn, gave us the chance to re-imagine how we WANT our docs to work: • Bringing in scattered readmes/wikis/etc. under one roof • Creating independently versioned areas for different release cycles and intents • Automating screenshots and content to "keep up" with the codebase • Bringing API docs, React Story book, and more into a centralized interactive portal • Leveraging AI to build and maintain docs... for people AND for humans • Syndicating content from third party sources to be the end-all-be-all of Superset documentation • Leveraging AI (for free!) to provide chat-based support AND learn where our docs are falling short from the result</p> <p>We've learned a lot of hard lessons over the years, and we're happy to share the process, ideas, and tools we've used to take things to the next level.</p>
<p>Documentation often lags behind code changes, leading to inconsistencies and outdated information. This session explores how to automate the generation of comprehensive and up-to-date documentation using a custom Yaml-based domain-specific language alongside Asciidoctor and Antora. By defining product behavior in a DSL, we not only produce the framework for software code but also generate the bulk of the documentation, making the DSL the single source of truth for the project. We'll discuss the power of this approach in keeping documentation aligned with the codebase and also demonstrate how to test code snippets within your documentation. Learn how this practice prevents broken examples and leverages Asciidoctor's capabilities to ensure your documentation remains reliable and accurate.</p>
<p>We introduce a workflow engine that automates and documents complex shell-based tasks in software development. By capturing command sequences as reproducible workflows, the tool reduces technical debt and significantly facilitates maintenance across long-lived projects.</p> <p>Common use cases include wrapping Yocto and Buildroot builds, automating Linux kernel testing and debugging, and supporting routine IT, network, and infrastructure operations.</p> <p>In this interactive talk, we demonstrate (live) how the tool:</p> <ul> <li> <p>builds and documents a more general procedure of cross-compiling the Open Source Software firmware for Broadcom's bcm5719 NIC chip than currently available,</p> </li> <li> <p>automates generating PDF documentation of this procedure,</p> </li> <li> <p>facilitates sharing this procedure and its documentation in a public or commercial context.</p> </li> </ul> <p>Attendees will learn how to transform hard-to-follow shell scripts into reproducible workflows that produce better documentation and improve collaboration.</p>
<p>For nearly a decade, Open Collective has served as the financial and legal infrastructure for over 3,000 open source projects, managing millions in funding. However, for much of that history, the platform itself was owned by Venture Capitalists a tension that sits at the heart of the FOSS funding conversation.</p> <p>In this talk, we reveal how the platform’s largest users, specifically the Open Source Collective—orchestrated a coup to boot out the initial investors and restructure the entity into a 501(c)(6) membership non-profit - Open Finance Consortium (https://oficonsortium.org/). This is a case study in "Exit to Community" (E2C), demonstrating a radical alternative to the traditional startup exit that often threatens FOSS sustainability. https://blog.opencollective.com/the-open-collective-platform-is-moving-to-a-community-governed-non-profit/</p> <p>We will move beyond the celebration of the acquisition to discuss the hard realities that followed. It is one thing to "free" a platform; it is another to sustain it. We will explore:</p> <ul> <li> <p>The Negotiation: How a Fiscal Host leveraged its position to facilitate a transition from private equity to community ownership.</p> </li> <li> <p>Governance vs. Reality: The evolution of our shared governance model and the difficulty of putting democratic ideals into practice while running a complex tech stack.</p> </li> <li> <p>The Financials: The transparent challenges of achieving financial sustainability without the cushion of VC cash flow, and what was sacrificed in the process.</p> </li> </ul> <p>This session is for maintainers, funders, and policymakers interested in the structural future of FOSS infrastructure. We offer not just a success story, but a candid look at the friction involved in building a technology platform that is truly owned by the ecosystem it serves.</p>
<p>Free software has no shortage of talent, ideas, or users, but it does have a funding problem. The largest potential funding source already exists: public procurement. Governments spend billions each year on software and digital services, but most of that money flows into proprietary silos that limit transparency, reuse, and sovereignty.</p> <p>If we take “Public Money, Public Code” - https://publiccode.eu - seriously, we must recognize that procurement (not donations or sponsorships) is the most powerful lever to sustain open source. Every government contract is a potential long-term investment in the commons.</p> <p>This talk examines how procurement practices can become the backbone of sustainable free software ecosystems: • Why procurement reform is essential to digital sovereignty. • How existing frameworks (e.g., the EU Open Source Strategy - https://commission.europa.eu/about/departments-and-executive-agencies/digital-services/open-source-software-strategy_en ) still fall short. • How to structure tenders, contracts, and governance to ensure open deliverables. • Why governments should stop “buying software” and start funding maintenance and collaboration. • The opportunity for community organizations and small firms to compete fairly.</p> <p>Procurement is where ideals meet infrastructure. By redirecting even a small fraction of public IT budgets toward open, reusable solutions, we can achieve what years of advocacy and fundraising have not: a self-sustaining free software ecosystem that serves everyone.</p>
<p>This talk is a call-to-action to join our campaign to convince the European Union that, in order to secure its digital future, it should invest in open source maintenance via an EU Sovereign Tech Fund (EU-STF).</p> <p>Right now, the EU is negotiating its multi-year budget for the period of 2028-2034. Traditionally, the EU budget has been focused on regional development and agriculture, but more and more policymakers are realizing that investment in our digital infrastructure is just as important as maintaining physical roads and bridges. Last year at FOSDEM, we discussed with you what an EU fund for open source maintenance should look like. A lot has happened since then: We have conducted an in-depth study into the political, legal and economic feasibility of an EU-STF, building on the successful example of the German Sovereign Tech Agency. We assembled a coalition of supporters from industry and civil society, and we have presented our proposal to the European Parliament and Member States.</p> <p>Now it’s time to take the campaign to the next level and we need your support to make it happen. The goal of this session is to present the findings of the feasibility study for the EU-STF and demonstrate why mission-driven investment, coordinated by the public sector, is important for the diversification of Europe’s funding landscape. It will demonstrate concretely how such a proposal can directly improve the sustainability and health of the open source community globally, and why this is so important for Europe in achieving its digital future.</p>
<p>This is a session combining the experience of several FOSS projects in their funding journey. Each will have 10 minutes to present, after which a Q&A session will happen. </p> <p>The presenting FOSS projects will be:</p> <ul> <li> <p>Mockoon is a popular open-source API tool, built and maintained from Luxembourg. In this talk, its creator shares the journey of growing a developer tool used by thousands, without external funding. Learn what worked (and didn't) in the pursuit of sustainability through sponsorships, community, and a cloud SaaS offering.</p> </li> <li> <p>DuckDB is the fastest growing data management tool to date. Meanwhile, DuckDB is Free and Open Source Software under the permissive MIT license. DuckDB's development began inside an academic instituted funded by grants. We then moved to a bootstrapped spin-off and have been running ever since. In my short talk, I will describe the meandering route and mental processes that lead us to choose this funding model, the things we do and why we do them, the things to avoid and why to avoid them.</p> </li> <li> <p>WeasyPrint is an open source Python library which transforms HTML/CSS into PDF, with the first commit dating back to April 2011. However we’ve only been making a living from it since 2020. We’ll present the evolution of our free software, how we transitioned from a project developed and used within a company to a product with paying clients, and discuss the different solutions we choose to earn money with free software.</p> </li> <li> <p>GNOME, founded in 1997, is one of the two leading desktop projects on the Linux platform. In this talk, we will talk about the outcome of our community based fundraising, the outcomes we wanted to achieve and results of the fundraising campaign. The talk will conclude with our next steps with feedback from the audience.</p> </li> </ul>
<p>The Domain Name System (DNS) is one of the core pillars of the internet, enabling users to navigate the web reliably and securely. However, underfunded open source DNS projects create systemic risks, exposing millions of users to vulnerabilities and threatening the stability and security of the entire internet. </p> <p>The Nominet DNS Fund aims to tackle these critical gaps by investing in the security, resilience, and long-term viability of these essential open source components, recognising that a robust and secure DNS is fundamental to the internet’s continued operation and the public benefit it provides. Having completed our first round of funding in 2025 and with a view to extending in 2026, this session will share highlights including:</p> <p>RESEARCH Reflections on revisiting research conducted by Demos that led us to create the fund</p> <p>PILOT AND LEARN Analyse some key learning about implementing the fund, including surprises and challenges we face moving forward </p> <p>ITERATE Seek feedback from the devroom in an interactive session to reflect on the fund and shape its future direction. </p> <p>We aim to share learning and future direction in open dialogue with the devroom and have ideas about what devroom participants will get out of the session: </p> <p>Practical Knowledge: Participants will come away with insight from a real case study of funding OS and delve into some of the learning and challenges</p> <p>Conversation points: asking questions such as: How do we better align what's being funded with what's needed? What are the opportunities for better dialogue, feedback and listening? How can applications for funding be more inclusive and accessible?</p>
<p>This talk, based on <a href="https://doi.org/10.12688/openreseurope.20210.1">a paper in <em>Open Research Europe</em></a>, will discuss the current state of research software funding, propose a way of thinking about the different models that are currently used, and suggest new models to better support the global research software community.</p> <p>Today, research software funding operates across a disconnected landscape of public and private grant-making organizations, leading to inefficiencies for software projects and the broader research community. The lack of coordination forces projects to pursue multiple, often overlapping opportunities, and forces funders to independently evaluate projects and proposals, resulting in duplicated effort and suboptimal resource distribution. </p> <p>By examining existing collaboration models, including centralized and distributed approaches, we highlight how joint decision-making mechanisms could improve sustainability for reusable software resources. An international set of examples illustrates how cross-organization cooperation for research software funding can be structured. Such collaborations can optimize grant disbursement and align priorities. Increased collaboration could allow funders to better address the ongoing maintenance and evolution of research software, lowering barriers that hamper discovery across multiple research domains. Encouraging both bottom-up user-driven and top-down coordination mechanisms ultimately supports more robust, widely accessible research software, improving global research outcomes.</p>
<p>The open source funding landscape is changing. Funders struggle to effectively measure and communicate the impact of their programs beyond case-by-case stories. This disconnect threatens the long-term sustainability of funding and thus the sustainability of FOSS. We spent the last year talking with FOSS funding organizations and grant recipients to understand their approach to grant funding, impact reporting, and FOSS sustainability. We also sought to understand the disconnect between the needs of FOSS projects and what funders can provide.</p> <p>In this talk, we share early insights from our interviews. We will share current funder challenges, like differentiating between reactive vs. proactive impact reporting and translating technical outcomes into policy-maker language. Interestingly, we’re are hosting a workshop here at FOSDEM with FOSS funders to co-design on a shared Funding Impact Taxonomy and Measurement Guidelines co-designed. We will share with the audience the the latest learnings and offer a space for further discussion. We may not bring any solutions but we will advance the dialog, so that funders and FOSS projects can better understand each other.</p>
<p>As an OSS developer, finding funding is probably the least inspiring high-priority activity on your list of things to do. This session will present concrete steps for the funding task you already have. These will become the tools to find the funding you need. As the Director of Operations at the <a href="https://erlef.org">Erlang Ecosystem Foundation</a> and Chair of the Sponsorship Working Group, I'm both a seeker of funding and a reviewer of funding requests. There are no secret handshakes or tricks here, just connecting dots to create a purpose and roadmap that will help. I will cover content you can create to help inform potential sponsors, how to approach them, and the fiscal efficiency of funding methods. The information is based on my own experience working with sponsors and projects, so it is not theoretical but also far from universal or complete.</p>
<p>Funding remains one of the biggest challenges in sustaining free and open source software. In this interactive workshop, we will use the results of a global survey and interview series start a conversation around how developers, users and maintainers think about money in FOSS and what it means for the future of our ecosystem. During the session we will explore donation campaign best practices from FOSS projects, discuss the role transparency and clear policies play in how funds are handled, and give participants an opportunity to learn, contribute, connect and explore how we can help make FOSS more sustainable.</p>
<p>Open source foundations face growing demands, more projects, more users, more scrutiny, while still relying on fragile funding models built around grants, sponsorships, and donations. This talk argues that the problem is not funding open source projects, but funding them in isolation.</p> <p>Drawing on experiences from the Apereo and the eBPF Foundations, this session explores a shift from project-centric funding to ecosystem-level investment. Using eBPF as a case study, it shows how funding efforts like security audits, upstream kernel work, directed development, face-to-face collaboration, and ecosystem marketing can strengthen many projects at once and deliver far greater impact per dollar.</p> <p>The talk also introduces Apereo's self-sustainability model, in which foundations, even projects, support themselves through services rooted in community expertise, such as training, events, audits, and operational support, rather than perpetual fundraising. The goal is not to create more foundations, but ones more focused on ecosystems that are resilient by design, and able to support open source as shared infrastructure rather than a collection of individual projects.</p>
<p>This is a merged session combining the following two lightning talks and audience Q&A. 1. "Funding a FOSS Revolution in the Energy Sector" by Maximilian Perzen 2. "An Enterprise Perspective on Open Source Funding" by Tobias Gabriel and Fabian Palmer</p> <hr /> <p><em>"Funding a FOSS Revolution in the Energy Sector" by Maximilian Perzen</em></p> <p>What happens when you try to build a fully open-source ecosystem inside one of the most closed, risk-averse industries on the planet? As a former core contributor to the <a href="https://github.com/PyPSA/PyPSA">PyPSA</a> ecosystem and now co-founder & CEO of a three-year-old FOSS non-profit <a href="https://openenergytransition.org/">OET</a> working on energy and grid planning, I’ve spent the last years hacking exactly that problem: pushing an industry dominated by billion-euro black-box tools toward a future built on shared code and community-driven infrastructure.</p> <p>We began with a Prototype Fund experiment that didn’t survive on its own, but it gave us just enough credibility and momentum to grow. Three years later, our organisation has scaled to 50 people working across major open-source energy planning projects (though mostly around one tool: PyPSA), supporting public, private and philanthropic partners. The “open-source revolution” in grid planning isn’t complete, but we’ve hit enough walls, breakthroughs, and strange funding dynamics to share what’s actually happening behind the scenes.</p> <p>This talk answers the questions we wish someone had answered when we started, including: - Where and how, inside a conservative industry, can open-source realistically get funded? - How do you identify which projects and maintainers are already carrying the ecosystem? - How to expand the ecosystem beyond a single institution and why this is important? - How do you convince institutions, philanthropic or private, to finance long-term maintainer time?</p> <p>This is the inside story of trying to open-source an entire domain and what other hackers can borrow from that journey.</p> <hr /> <p><em>"An Enterprise Perspective on Open Source Funding" by Tobias Gabriel and Fabian Palmer</em></p> <p>Have you wondered how open source funding works inside large companies? Whether you’re trying to start a program at your organization or understand it from a maintainer perspective?</p> <p>In this talk, we’ll share how SAP, one of the world’s largest enterprise software companies, started a direct open source funding program in 2025. We’ll cover the questions we faced, the answers we found, and what we learned along the way: - How to select projects and maintainers to support? - What metrics and tools can support in finding suitable projects? - How to determine the right funding amount? - How to organize the process and budget internally? - How to scale it further in the future?</p> <p>With this talk we would like to share our experience and insights and invite you to share your own experiences and ideas as well.</p>
<p>In a wide array of funding and investment directed at open source, enterprise and venture capital funding rarely gets an important slot in European discussions. </p> <p>However, as shown in our recent "State of Commercial Open Source" research report of ~800 VC-backed commercial open source (COSS) companies, the virtuous cycle created by enterprise contributions and VC funding not only improves upstream open source projects across virtually every metric but drives thriving commercial ecosystems creating tangible economic and societal value. </p> <p>The data is clear: while public funding (so far) often functions as early-stage seed capital or a safety net for critical projects, research shows enterprises contributing over $7.7B annually in funding and paid developer time to open source on a global basis. Furthermore there is a big promise in VC funding for open source, also in Europe, with the number and value of transactions rising in recent years, with $26.4B invested in 2024 and strong investment performance indicators. </p> <p>As vertical sectors like finance, energy, telco, and agriculture increasingly embrace open source as a pillar of their digital transformation, it’s clear that commercial open source has become a superior venture model and a strategic opportunity for Europe, but one that requires engaging diverse stakeholders and mutual education on the opportunities at hand. </p> <p>In this talk we will share Linux Foundation Europe’s experience of building (and balancing) some of the largest global open source ecosystems as well as Commit’s unique perspective as the first fund solely focused on commercial open source investments in Europe.</p>
<p>Create your own drawing by using the online free turtlestitch. You can start off with an example or create your own drawing. When you're finished your drawing will be stitched on an embroidery machine and you can take it home. https://www.turtlestitch.org/</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>How do small electronic devices with buttons, LEDs, sensors, sound, and robotic movements work? What programming languages and hardware are best for learning how to make your own electronically controlled gadgets starting at a young age? Our goal for the MicroBlocks project is to enable youth to be pioneers in STEM fields, working to make a brighter future based on open innovation. </p> <p>This webinar introduces the concepts of smart devices and physical computing using MicroBlocks, a phenomenal open source software tool that has the power to revolutionize STEM learning opportunities globally. Older students can learn to turn their gadgets into IoT devices (“connected, or ‘smart’ devices”) using many built-in networking libraries. Younger students can simply make electronic things that fuel their imagination and curiosity.</p> <p>Wanted for this workshop – the next generation of brilliant young minds!</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>Let’s Code Trees is an interactive workshop where designs created using code can be stitched onto fabric. Suitable for aged 9 upwards.</p> <p>Design and build your own tree, by writing a programme to create it. We'll explore several different ways of drawing trees using Turtlestitch, a block based programming language that turns designs into patterns that can be stitched by an embroidery machine. We'll begin by instructing the turtle to draw simple stems and branches to create a basic tree, then look at how to create more complex trees using blocks, loops and variables. </p> <p>Turtlestitch: www.turtlestitch.org Resources: www.warwick.ac.uk/turtlestitch/patterntocode</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>Let’s discover tonal sounds around us and embark on a sampling safari scavenging kitchen utensils (glasses, bottles, spoons, pots, kettles), office supplies (pencil sharpeners, papers ripping, bursting bags) and our bodies’ (in-)voluntary utterances (whistling, wheezing, sneezing, snipping, rasping, cracking, coughing, clapping) – and then turn them into beautiful melodies! We’ll explore various sampling rates to play back recordings at different pitches and learn how to use the algorithm of the Equal Temperament Chromatic Scale to synthesize them into musical tunes. Then we’ll figure out how to mathematically transform the waveform of our recordings into musical scales of semitones by stretching and compressing the sampled data and use this technique to compute personalized ringtones for our phones.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>In this hands on workshop, you will use MIT App Inventor to build two applications for your Android or iOS device. Those new to MIT App Inventor can have a simple first app up and running in less than 30 minutes. And what's more, our blocks-based tool facilitates the creation of complex, high-impact apps in significantly less time than traditional programming environments. The first app you create will be a cat you can pet to make meow. The second app will allow you to draw your own pictures via touch. Participants must bring both a laptop and a mobile device (phones and tablets are both good, running Android 4.0+ or iOS 12+).</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop and a phone.</p>
<p>MicroStudio is a game engine aimed at beginners, based on code yet very accessible, forgiving, and providing immediate feedback on everything you do. MicroStudio includes a pixel-art sprite editor and a map editor. Accessible online with a simple web browser, it allows multiple users to work live on the same project. It also includes many interactive tutorials and documentation.</p> <p>In this workshop, we will learn how to draw shapes and sprites on screen, how to create animations, and how to check for player input. Finally, we will all create a simple game that we can even run on our smartphones. Once back home, participants can continue working on their project. For this session and later use, participants can use a simple guest (anonymous) account and do not have to create a full microStudio account. They can later convert the guest account to a full account if they want.</p> <p>microStudio is a free and open-source project (MIT license). Available at: https://microstudio.dev Get the source code and run your own instance: https://github.com/pmgl/microstudio Also available as a standalone, offline version for Linux, macOS, Windows and Raspberry PI: https://microstudio.itch.io/microstudio</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>The free open-world game Luanti offers a variety of possibilities to get creative and play together. Luanti is a framework that allows everyone to build their own voxel game – a world made out of blocks which can be placed and removed, items and tools that can be crafted and many more things to discover.</p> <p>Get to know Luanti and learn to develop your own modification that adds a new block to the game. Additionally, you can create a custom crafting recipe and apply effects to your block like making it glow.</p> <p>Depending on how much time we have, we can explore further topics like playing together in the same world or programming chat commands.</p> <p>Please bring your own computer with Luanti installed.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>In this hands-on Scratch workshop, participants will design and build their own interactive mini-game or story world. Using simple blocks, characters, sounds and animations, they will learn how to make things move, react and come alive on screen.</p> <p>The workshop starts with a short guided introduction where everyone creates a basic interactive scene together. After that, participants are free to customize and expand their project: adding characters, inventing challenges, creating stories, or designing playful interactions. Creativity is central there is no “right” result.</p> <p>The workshop is suitable for beginners as well as participants with some Scratch experience. Younger participants can focus on simple interactions and animations, while older or more experienced ones can experiment with variables, scoring systems or more complex logic.</p> <p>By the end of the session, everyone will have a working Scratch project they can continue at home. The goal is to make coding feel fun, accessible and empowering, and to show that programming is a creative tool for everyone.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>
<p>Welcome to the GCC (GNU Toolchain) devroom from the organizers.</p>
<p>RISC-V now spans 100+ extensions and over a thousand instructions. Binutils, QEMU, and other projects maintain separate instruction definitions, leading to duplication, mismatches, and slower support of new features.</p> <p>UDB provides a machine-readable, validated source of truth covering most of the ISA. Our generator currently produces Binutils and QEMU definitions directly from UDB, cutting the effort for standard and custom extension bring-up. And with automated CI checks against current Binutils data, everything stays aligned as the ecosystem evolves.</p> <p>In this talk, we’ll show how UDB enables new and custom extension by:</p> <ul> <li>Automating part of of Binutils support</li> <li>Allowing faster integration on other SW projects like QEMU</li> </ul>
<p>Version 6 of the DWARF debugging information format is still a work in progress, with many changes already accepted. This talk will focus on one fundamental change that has been accepted recently: "<a href="https://dwarfstd.org/issues/230524.1.html">Issue 230524.1</a>", also known as "Location Descriptions on the DWARF Stack".</p> <p>The compiler can emit small programs in a bytecode known as DWARF expressions that a consumer (usually a debugger) can evaluate in order to compute an object's location; where in memory or registers it has been placed. Up until DWARF-5, the execution model of such DWARF expressions was not expressive enough to describe how objects are placed on GPUs, or even on CPUs in some cases too. DWARF 6 addresses this by making DWARF locations regular stack elements on the DWARF expression evaluation stack, which has many interesting cascading consequences, including enabling expressiveness, factorization, and more.</p> <p>In this presentation, we will discuss the execution model of DWARF expressions, the proposed changes and follow-up extensions this change enables.</p>
<p>We present a <a href="https://github.com/intel/dwarf-evaluator">DWARF-6 expression evaluator</a> implemented in OCaml. The evaluator is concise and lightweight. It aims to help tool developers learn and understand DWARF by examining the precise definitions of DWARF operators and by running examples. We believe this will be useful in particular with the "locations on the stack" change that's coming in DWARF-6.</p> <p>The evaluator comes with test cases, which can gradually turn into a reference testsuite. There also exists a <a href="https://intel.github.io/dwarf-evaluator">web playground</a> to run and share examples easily (see DWARF Issue <a href="https://dwarfstd.org/issues/251120.1.html">251120.1</a> for several such examples).</p>
<p>Concurrency in pid 1 and systemd in general is a touchy subject. systemd is very trigger happy when it comes to forking and when combined with multithreading this causes all sorts of issues, so there's an unwritten policy to not use threads in systemd. This has lead to (in my opinion) a sprawling callback hell in every daemon and CLI in the project that performs concurrent operations.</p> <p>In this presentation I'll present my view on the issues with using threads in systemd and why cooperative multitasking implemented using green threads can fix many of them while avoiding callback hell. I'll also briefly go over the unique problems you run into when designing a fiber based system in and the general design for fibers in systemd, finishing with how they're implemented under the hood with ucontext.h.</p> <p>I'm hoping to get feedback on the approach from the devroom, and bring awareness on how systemd is using the GNU toolchain.</p> <p>https://github.com/systemd/systemd https://github.com/systemd/systemd/pull/39771</p>
<p>Last year the GCC COBOL runtime library added libxml2 as a dependency because COBOL defines XML parsing and generation as part of the language. Thus was born an engineering challenge and controversy. Should libxml2 become part of GCC? Should it be linked statically or dynamically? Who will be responsible for CVE reports and security updates? Who, indeed, will maintain libxml2, now that the maintainer has stepped down? </p> <p>Just what every compiler project wonts on their plate on a Monday morning. </p> <p>This talk is about weighing engineering tradeoffs and what those weights are, what we decided was important, and what, probably, we agreed to do.</p>
<p>A brief introduction to GNU Algol 68 programming language through showcasing a real-world baremetal project. We'll cover: - How to setup GNU Algol 68 toolchain for baremetal platforms (Arm and RISC-V microcontrollers). - How to call C code to access machine's capabilities.</p>
<p>OpenMP is a widely used framework for parallelizing applications, enabling thread-level parallelism via simple source-code annotations. It follows the fork-join model and relies heavily on barrier synchronization among worker threads. Running OpenMP-enabled applications in the cloud is increasingly popular due to elasticity, fast startup, and pay-as-you-go pricing.</p> <p>In cloud-based execution, worker threads run inside a virtual machine (VM) and are subject to dual levels of scheduling: threads are placed on guest virtual CPUs (vCPUs), and vCPUs run as ordinary tasks on the host’s physical CPUs (pCPUs). The guest scheduler places threads on vCPUs, while the host scheduler places vCPUs on pCPUs. Because these schedulers act independently, a semantic gap emerges that can undermine application performance. Barrier synchronization, whose efficiency depends on timely scheduling decisions, is vulnerable to this semantic gap, and remains under-explored.</p> <p>This talk presents my PhD thesis project supervised by Julia Lawall and Jean-Pierre Lozi at Inria Paris. The thesis defines Phantom vCPUs to describe problematic host-level preemptions in which guest vCPUs remain queued on busy pCPUs, stalling progress. We show that OpenMP performance can be substantially improved inside oversubscribed cloud VMs by (1) dynamically adapting the degree of parallelism (DoP) at the start of each parallel region and (2) dynamically choosing between spinning versus blocking at barriers on a per-thread, per-barrier basis. We propose paravirtualized, scheduler-informed techniques that accurately guide these decisions and demonstrate their effectiveness in realistic deployments. </p> <p>The first contribution of this thesis is Phantom Tracker, an algorithmic solution implemented in the Linux kernel that leverages paravirtualized task scheduling to detect and quantify Phantom vCPUs accurately. The second contribution is pv-barrier-sync, a dynamic barrier synchronization mechanism driven by the scheduler insights produced by Phantom Tracker. The third and final contribution is Juunansei, an OpenMP runtime extension that demonstrates the practical utility of Phantom Tracker and pv-barrier-sync with additional optimizations.</p> <p>The talk discusses the context and motivation of this work, followed by a brief introduction to the Phantom Tracker, and then takes a deep dive into the libgomp implementation of pv-barrier-sync and Juunansei.</p>
<p>A quick introduction to the recently added Algol 68 GCC front-end.</p>
<p>A critical challenge in C as a general-purpose language is the absence of the notion of secret data in its abstract machine. This results in information disclosure be poorly detected by compilers that lack the required semantics to model any vulnerability related to secrets leakage. Numerous dedicated tools have exists to overcome this limitation; each of which comes with its own annotation rules, tainting model, and more importantly, its own narrow scope for a specific disclosure vulnerability. Such discrepancy has created confusion for the concerned developers that are mostly unwilling to support multiple external tools, especially when they address one problem at a time. In this talk, we introduce the required C constructions to bring secrets to the GCC compiler through its system of attributes. The resulted framework, that we call GnuSecret, does not only define consistent notations and semantics to designate secrets directly in the Gnu-C language, but also propagates them throughout the program code by leveraging the symbolic execution engine embedded into the GCC Static Analyzer (GSA). Of particular interest, GnuSecret is not bound to a specific vulnerability, as its modular design allows it to virtually model any vulnerability related to the MITRE's CWE-200 and its children.</p>
<p>A word of welcome by the LLVM Dev room organizers.</p>
<p>LLVM has recently gained support for an ELF implementation of the AArch64 Pointer Authentication ABI (PAuthABI) for a Linux Musl target. This talk will cover: * An introduction to the PAuthABI and its LLVM support. * How to experiment with it on any Linux machine using qemu-aarch64 emulation. * How to adapt the Linux Musl target to a bare-metal target using LLVM libc.</p> <p>The AArch64 Pointer Authentication Code instructions are currently deployed on Linux to protect the return address on hardware that has support for it. This limited use case can be deployed in an ABI neutral way and run on existing hardware. The PAuthABI, based on Apple's Arm64E, takes the hardware and software backwards compatibility gloves off, and makes use of pointer authentication for code pointers such as function pointers and vtables.</p> <p>The main challenge to adapt the PAuthABI support for bare-metal is initialization of global pointers as on Linux this is done by the dynamic loader. We will need to build our own signer that operates before main.</p>
<p>Ever been debugging a production issue and wished you'd added just one more log statement? Now you have to rebuild, wait for CI, deploy... all that time wasted. We've all been there, cursing our past selves.</p> <p>We've integrated LLVM's XRay into ClickHouse to solve this. It lets us hot-patch running production systems to inject logging, profiling, and even deliberate delays into any function. No rebuild required.</p> <p>XRay reserves space at function entry/exit that can be atomically patched with custom handlers at runtime. We built three handler types: LOG to add the trace points you forgot, SLEEP to reproduce (or prevent) timing-sensitive bugs, and PROFILE for deterministic profiling to complement our existing sampling profiler. The performance overhead when inactive is negligible.</p> <p>Control is simple. Send a SQL query as <code>SYSTEM INSTRUMENT ADD LOG 'QueryMetricLog::startQuery' 'This message will be logged at the start of the function'</code> to patch the function instantly. Results show up in <code>system.trace_log</code>. Remove it just as easily when you're done.</p> <p>I'll cover the integration challenges (ELF parsing, thread-safety, atomic patching), performance numbers (4-7% binary size, near-zero runtime cost), and real production war stories.</p> <ul> <li><a href="https://github.com/ClickHouse/ClickHouse/issues/74249">Issue with the description of the task</a></li> <li><a href="https://github.com/ClickHouse/ClickHouse/pull/89173">PR that added XRay integration</a></li> </ul>
<p>Over the past two years, the LLVM community has been building a general-purpose GPU offloading library. While still in its early stages, this library aims to provide a unified interface for launching kernels across different GPU vendors. The long-term vision is to enable diverse projects—ranging from OpenMP® to SYCL™ and beyond—to leverage a common GPU offloading infrastructure.</p> <p>Developing this new library alongside the existing OpenMP® offloading infrastructure has introduced several interesting challenges, as both share the same plugin system. This is particularly evident in the implementation of the OpenMP® Tools Interface (OMPT).</p> <p>In this talk, we’ll explore the journey so far: • Project history – how the effort started and evolved. • Current architecture – the organization of the offloading library today. • API design – what the interface looks like and how it works. • Plugins – the lower-level components that make vendor-specific integration possible. • Challenges – issues encountered in the current OMPT implementation.</p>
<p>LLVM’s ORC JIT [1] is a powerful framework for just-in-time compilation of LLVM IR. However, when applied to large codebases, ORC often exhibits a surprisingly high front-load ratio: we have to parse all IR modules before execution even reaches main(). This diminishes the benefits of JITing and contributes to phenomena as the “time to first plot” latency in Julia, one of ORC’s large-scale users [2].</p> <p>The llvm-autojit plugin [3] is a new experimental compiler extension for automatic just-in-time compilation with ORC. The project reached a proof-of-concept state, where basic C, C++ and Rust programs build and run successfully. It integrates easily with build systems like CMake, make and cargo, making it practical to apply to real-world projects.</p> <p>In this talk, we will examine the front-loading issue in ORC and explain how llvm-autojit mitigates it. Attendees will learn about pass plugins, LLVM IR code transformations, callgraphs and runtime libraries. And they will see how to experiment with ORC-based JITing in their own projects.</p> <p>[1] https://llvm.org/docs/ORCv2.html [2] https://discourse.julialang.org/t/time-to-first-plot-clarification/58534 [3] https://github.com/weliveindetail/llvm-autojit</p>
<p>Every new AI workload seems to need new hardware. Companies spend months designing NPUs (neural processing units), then more months building compilers for them—only to discover the hardware doesn't efficiently run their target workloads. By the time they iterate, the algorithm has moved on.</p> <p>We present a work-in-progress approach that generates NPU hardware directly from algorithm specifications using MLIR and CIRCT. Starting from a computation expressed in MLIR's Linalg dialect, our toolchain automatically generates synthesizable SystemVerilog for custom NPU architectures and hooks it up automatically to a RISC-V control host with an optimized memory hierarchy.</p> <p>This "algorithm-first" hardware generation inverts the traditional flow: instead of designing hardware then hoping the compiler can use it effectively, we generate hardware that is provably optimal for specific Linalg operations. The approach enables rapid exploration of the hardware/algorithm co-design space: change the algorithm, regenerate the hardware, and immediately see the impact on area, power, and performance. In this talk, we'll demonstrate: * Live generation of NPU RTL from Linalg operations * The MLIR dialect stack that bridges high-level algorithms to CIRCT hardware representations * Performance comparisons between generated hardware and handmade open-source NPUs * Open questions around generalization vs. specialization trade-offs</p> <p>This work aims to make hardware generation accessible to compiler engineers and algorithm researchers, not just hardware designers. We'll discuss both the potential and limitations of this approach, and where the research needs to go next.</p> <p>Target audience: Compiler engineers, hardware architects, ML systems researchers. Basic familiarity with MLIR helpful but not required.</p>
<p>WebAssembly support in Swift started as a community project and became an official part of Swift 6.2. As Swift on WebAssembly matures, developers need robust debugging tools to match. This talk presents our work adding native debugging support for Swift targeting Wasm in LLDB. WebAssembly has some unique characteristics, such as its segmented memory address space, and we'll explore how we made that work with LLDB's architecture. Additionally, we'll cover how extensions to the GDB remote protocol enable debugging across various Wasm runtimes, including the WebAssembly Micro Runtime (WAMR), JavaScriptCore (JSC), and WasmKit.</p>
<p>llvm-mingw is a mingw toolchain (freely redistributable toolchain targeting Windows), built entirely with LLVM components instead of their GNU counterparts, intended to work as a drop-in replacement for existing GNU based mingw toolchains. Initially, the project mainly aimed at targeting Windows on ARM, but the toolchain supports all of i686, x86_64, armv7 and aarch64, and has been getting use also for projects that don't target ARM.</p> <p>In this talk I describe how the project got started, and how I made a working toolchain for Windows on ARM64 before that even existed publicly.</p> <p>https://github.com/mstorsjo/llvm-mingw/</p>
<p>C++ remains central to high-performance and scientific computing, yet interactive workflows for the language have historically been fragmented or unavailable. Developers rely on REPL-driven exploration, rapid iteration, rich visualisation, and debugging, but C++ lacked incremental execution, notebook integration, browser-based execution, and JIT debugging. With the introduction of <a href="https://clang.llvm.org/docs/ClangRepl.html">clang-repl</a>, LLVM now provides an upstream incremental compilation engine built on Clang, the IncrementalParser, and the ORC JIT.</p> <p>This talk presents how the Project Jupyter, Clang/clang-repl, and Emscripten communities collaborated to build a complete, upstream-aligned interactive C++ environment. <a href="https://github.com/compiler-research/xeus-cpp">Xeus-Cpp</a> embeds clang-repl as a native C/C++ Jupyter kernel across Linux, macOS, and Windows, enabling widgets, plots, inline documentation, and even CUDA/OpenMP use cases. <a href="https://compiler-research.org/xeus-cpp-wasm/lab/index.html">Xeus-Cpp-Lite</a> extends this model to the browser via WebAssembly and JupyterLite, compiling LLVM and Clang to WASM and using wasm-ld to dynamically link shared wasm modules generated per cell at runtime.</p> <p>To complete the workflow, Xeus-Cpp integrates LLDB-DAP through clang-repl’s out-of-process execution model, enabling breakpoints, stepping, variable inspection, and full debugging of JIT-generated code directly in JupyterLab.</p> <p>The talk will detail how clang-repl, ORC JIT, wasm-ld, LLDB, and LLDB-DAP come together to deliver a modern, sustainable interactive C++ workflow on both desktop and browser platforms, with live demonstrations of native and WebAssembly execution along the way.</p> <p><strong>LLVM Components Involved :</strong> clang, clang-repl, orc jit, wasm-ld, lldb, lldb-dap.</p> <p><strong>Target Audience :</strong> Researchers, Educators, Students, C/C++ Practitioners</p> <p><strong>Note :</strong> Please make sure to check out the demos/links added to the Resource section. These demos would be shown live in the talk.</p>
<p>This year, systemd had a breakup with its bad practice of including unused headers all over the codebase. This resulted in:</p> <ul> <li>A 33% speedup in from scratch build times</li> <li>A 50% reduction in runtime for our build test CI jobs</li> <li>Thousands of lines of code removed from the codebase</li> </ul> <p>I'll present how I went about this work, using clang-include-cleaner, clang-tidy and ClangBuildAnalyzer, and including the challenges I faced:</p> <ul> <li>A scalable way to organize source to minimize unused headers</li> <li>Macros</li> <li>Different build configurations which change the used headers in a source file due to #ifdef conditionals</li> <li>Missing features in clang-tidy and clang-include-cleaner (and my contributions to LLVM to implement those)</li> </ul> <p>https://github.com/systemd/systemd https://github.com/llvm/llvm-project github.com/aras-p/ClangBuildAnalyzer</p>
<p>Cross-compiling C and C++ is still a tedious process. It usually involves carefully crafted sysroots, Docker images and specific CI machine setups. The process becomes even more complex when supporting multiple libcs and libc versions, or architectures whose sysroots are hard or impossible to generate.</p> <p>In this talk, we present toolchains_llvm_bootstrapped, an open-source Bazel module that replaces sysroots with a fully hermetic, self-bootstrapping C/C++ cross-compilation toolchain based on LLVM.</p> <p>We dive into how the project wires together three Bazel toolchains: - A raw LLVM toolchain based on prebuilt LLVM binaries that cross-compiles all target runtimes from source: CRT objects, libc (glibc or musl), libstdc++/libc++, libunwind, compiler-rt, etc.</p> <ul> <li> <p>A runtime-enabled toolchain that uses those freshly built runtimes to hermetically compile your application code.</p> </li> <li> <p>An optional self-hosted toolchain used to build LLVM entirely from source (pre-release, patched, or local branches), which is then used for the two previous stages; all in a single Bazel invocation.</p> </li> </ul> <p>We also showcase unique use cases enabled by this approach: - Cross-compiling to any target, entirely from source, with little to no configuration.</p> <ul> <li> <p>Whole-program sanitizer setups that are almost impossible with prebuilt sysroots.</p> </li> <li> <p>Targeting arbitrary versions of the glibc.</p> </li> <li> <p>Setup-free remote execution for cross compilation tasks.</p> </li> <li> <p>Applying patches to LLVM, building a new toolchain and testing it against real-world projects, without manual bootstrapping steps.</p> </li> </ul> <p>Project source code: https://github.com/cerisier/toolchains_llvm_bootstrapped</p>