Schedule

Schedule
















 

Day 2
08:00

08:30

09:00

09:30

10:00

10:30

11:00

11:30

12:00

12:30

13:00

13:30

14:00

14:30

15:00

15:30
From printers and Python to pondlife and pathology: research into and using the OpenFlexure Microscope (en)

<p>The OpenFlexure Microscope is an open source, laboratory-grade robotic microscope, used by a diverse community including academic researchers, engineers, educators, pathologists and hobbyists (https://openflexure.org/, https://openflexure.discourse.group/). Users from over 60 countries have developed and used the device for everything ranging from exploring their garden's wildlife, to training medical students to diagnose cancer. Joe presents his experience as an academic member of the OpenFlexure development team for the last eight years. While his work focuses on the medical applications of the Microscope, research is planned and prioritised to benefit all members of the community. Development of the OpenFlexure software has enabled smart microscopy on the OpenFlexure Microscope, with automated sample identification, smart path planning and image processing, bringing novel research techniques such as digital pathology into new environments which traditionally lack the infrastructure to support them (https://gitlab.com/openflexure/openflexure-microscope-server, https://gitlab.com/openflexure/openflexure-microscope). The research builds on FOSS software and libraries, including Arduino and OpenCV, and extends open science by improving access to essential hardware. This is reflected in the range of OpenFlexure publications from outside the core development team, including peer reviewed articles in the fields of engineering, machine learning, medicine and social science.</p>

Community Curation of Natural Science Collections with DiSSCo (en)

<p>At the current rate of digitization, it is estimated that it would take hundreds of years to fully digitize the natural science collections of Europe. In the face of the biodiversity crisis, we urgently need to scale up digitization to equip researchers with the tools to tackle this challenge. </p> <p>The Distributed System of Scientific Collections, DiSSCo, is a fully open source European infrastructure that is bringing together over 300 institutions into a unified, digital natural science collection. DiSSCo harmonizes data into one data model and enables sharing human expertise and machine services across institutions. </p> <p>Through annotating specimen records on the platform, experts from around the world can contribute to curation and enhancement of data. Most crucially, taxonomists, whose expertise is highly specialized and sought after, can easily share their knowledge and improve specimen data across institutions. </p> <p>Leveraging a shared data model, machine agents can further improve and enhance specimen data, through linking to other infrastructures, georeferencing, and even label transcription. Instead of being confined to a single institution, services adapted for DiSSCo can be applied to any specimen in Europe, breaking institutional silos and furthering collaboration. </p> <p>These efforts culminate in a digital extended specimen, which acts as a “digital twin” to the physical object, with links to publications, genetic sequences, and other related information. </p> <p>This presentation gives an overview of the progress of the DiSSCo infrastructure, collaboration with researchers and collection managers, and the future of DiSSCo’s development. </p> <p>https://disscover.dissco.eu/ https://github.com/diSSCo</p>

Colandr 2.0: reflections on a near-decade of free and open evidence synthesis tooling development, management, and use (en)

<p>The exponential growth of scientific literature—doubling roughly every nine years—has made it increasingly difficult for researchers and decision-makers to locate, assess, and synthesize the evidence needed for sound policy and practice. Systematic maps and systematic reviews offer robust, unbiased ways to answer “what works?” but today they depend on manual search and screening workflows that are slow, costly, and vulnerable to human error. The result is a bottleneck: high-quality, up-to-date evidence syntheses are often too labor-intensive to produce at the pace conservation challenges demand.</p> <p>This talk and demo presents an open, community-driven approach to lowering that bottleneck using human-in-the-loop machine learning and transparent evidence-management tooling. In 2018, DataKind and the the Science for Nature and People Partnership, built two free and open-access, web-based workflows for computer-assisted paper screening and evidence management, integrated into a single collaborative application (colandrapp.com). The platform combines active-learning prioritization, reproducible labeling, and interactive visualization to help teams rapidly identify relevant studies from tens of thousands of documents, extract key metadata, and generate portable, shareable review outputs. All components are designed to support open research practices: auditable decision trails, exportable datasets, and interoperability with downstream synthesis and visualization tools. Now, in 2026, we are releasing a significant update to Colandr that ensures the tool continues to be functional and sustainable. Colandr is supported by a global community of researchers and volunteers (colandrcommunity.com) and this session will highlight the additional open source solutions that have been built on top of the Colandr stack in addition to the Colandr product updates. </p> <p>We aim to engage the FOSDEM community around a concrete open research challenge: building trustworthy, extensible tools that keep evidence synthesis fast, reproducible, and accessible. Participants will leave with a clear view of the platform’s capabilities, the design decisions behind it, and a set of well-scoped technical and research directions where open-source contributors can meaningfully push the state of practice forward.</p>

Building Open and Reproducible AI Practices for LMICs (and Beyond) (en)

<p>AI has become an integral part of modern research, offering tremendous opportunities, but also raising important questions for the Open Science community.</p> <p>With the emergence of the Open Source AI Definition (OSAID) and its emphasis on the four freedoms, the “freedom to study” stands out as a cornerstone for achieving true reproducibility. You can read the OSAID definition here: https://opensource.org/ai/open-source-ai-definition.</p> <p>This talk will explore how researchers can design, implement, and sustain reproducible AI practices within their work, especially in Low and Middle Income Countries (LMICs), where infrastructure and culture around reproducibility are still developing. Drawing from practical examples and community experiences, I’ll outline actionable steps for embedding openness and reproducibility in AI workflows. These approaches are adaptable across contexts and can help build a more transparent, collaborative, and trustworthy global AI ecosystem.</p> <p>My perspective is shaped by my work as an Open Source Manager and Project Coordinator with Data Science Without Borders, and as a contributor to The Turing Way, where I advocate for open, inclusive, and reproducible research practices in data science and AI.</p>

Accelerating vLLM Inference with Quantization and Speculative Decoding (en)

<p>vLLM (https://github.com/vllm-project/vllm) has rapidly become a community-standard open-source engine for LLM inference, backed by a large and growing contributor base and widely adopted for production serving. This talk offers a practical blueprint for scaling inference in vLLM using two complementary techniques, quantization (https://github.com/vllm-project/llm-compressor) and speculative decoding (https://github.com/vllm-project/speculators). Drawing on extensive evaluations across language and vision-language models, we examine the real accuracy–performance trade-offs of each method and, crucially, how they interact in end-to-end deployments. We highlight configurations that substantially cut memory footprint while preserving model quality, and show when these speedups translate best to low-latency versus high-throughput serving. Attendees will leave with data-backed guidance, deployment-ready settings, and a clear roadmap for leveraging quantization and speculative decoding to accelerate vLLM inference in real-world pipelines.</p>

OQTOPUS: Open Quantum Toolchain for OPerators and USers (en)

<p>Quantum computing creates new opportunities, but building and operating a quantum cloud service remains a complex challenge, often relying on proprietary, black-box solutions. To bridge this gap, we introduce OQTOPUS (Open Quantum Toolchain for OPerators and USers) [1], a comprehensive open-source software stack designed to build and manage full-scale quantum computing systems. OQTOPUS provides a complete cloud architecture for quantum computers, covering three critical layers: 1.Frontend Layer: Web-based interfaces and SDKs that allow users to easily design and submit quantum circuits. 2.Cloud Layer: A scalable management system for users, jobs, and devices, designed to be deployable on public clouds (see oqtopus-cloud [2]). 3.Backend Layer: The core execution engine that handles circuit transcoding, error mitigation, and low-level device control, utilizing modular tools such as OQTOPUS Engine [3] and Tranqu [4].</p> <p>Developed in collaboration with The University of Osaka, Fujitsu Limited, Systems Engineering Consultants Co., LTD. (SEC), and TIS Inc. (TIS) is already powering operational superconducting quantum computers. This talk will detail the modular architecture of OQTOPUS, demonstrating how developers and researchers can use it to construct their own quantum cloud platforms, customize compilation strategies, and experiment with hybrid quantum-classical workflows. Join us to learn how OQTOPUS is democratizing access to the deepest layers of quantum infrastructure.</p> <p>Project Links: [1] OQTOPUS Organization: https://github.com/oqtopus-team [2] Cloud Layer: https://github.com/oqtopus-team/oqtopus-cloud [3] OQTOPUS Engine: https://github.com/oqtopus-team/oqtopus-engine [4] Tranqu: https://github.com/oqtopus-team/tranqu</p>

NoiseModelling and Its FLOSS Ecosystem for Environmental Noise Assessment (en)

<p>NoiseModelling is an open-source platform for simulating environmental noise propagation and generating regulatory-compliant noise maps at urban and regional scales. Leaded since 2008 by the Joint Research Unit in Environmental Acoustics at Gustave Eiffel University, it provides researchers and practitioners with reproducible, transparent, and scalable modelling capabilities for environmental acoustics. As the modelling core of the Noise-Planet framework, NoiseModelling simulates noise propagation from road traffic, railways, and industrial sources using the standardized CNOSSOS-EU method for emission and propagation. It operates as a Java library or through a user-friendly web interface, tightly integrated with spatial databases H2GIS or PostGIS to handle large-scale urban datasets efficiently. The broader Noise-Planet ecosystem complements NoiseModelling's simulation capabilities with participatory noise measurement through the NoiseCapture mobile application. After more than three years of operation, the platform has collected data from over 100,000 downloads and 74,000 contributors worldwide, enabling citizens and researchers to create high-resolution, crowdsourced noise maps that respect privacy while contributing to scientific research. This integrated approach bridges computational modeling with real-world measurements, promoting open science principles through open-source code, open data, and collaborative research.</p> <p>https://noise-planet.org/</p> <p>https://noisemodelling.readthedocs.io/en/latest/</p>

Open Research Organizers' Panel (en)

<p>The Open Research Devroom Organizers' Panel is a 15 min slot where the organizing team of the devroom will do: - A roundtable presentation of the organizing team - An informal invitation to the audience to join the organizing team of the devroom next year - Open questions and answers regarding organization of the devroom</p>

RRP: Reproducible Research Platform for FAIR Open Research (en)

<p>Research reproducibility remains elusive despite the widespread adoption of FAIR data principles, as data and code lifecycles disconnect, computational environments vanish after publication, and, without explicit environment specifications, reproducing analyses demands expert knowledge even when code is shared. The open-source Reproducible Research Platform (RRP) bridges this by unifying research data management (via openBIS RDMS) with Git-managed code, Docker/repo2docker environments, and Kubernetes scaling into shareable, executable projects. Users mount datasets via traceable permanent IDs into JupyterLab, VS Code, RStudio, MATLAB, or full desktops, enabling instant execution anywhere, from local machines to institutional clusters, without setup hurdles. In this presentation, we demonstrate RRP across diverse research domains and open-source tools. In engineering, RRP facilitates integration of CAD and PCB design workflows into collaborative, shareable projects, enabling open-hardware development with open-source tools. Machine learning practitioners leverage RRP for reproducible training and inference on large microscopy datasets. Molecular biologists use RRP to perform reproducible DNA editing experiments with CRISPR tools linked to DNA materials stored in the RDMS. Software engineers and bioinformaticians benefit from RRP’s support for established IDEs like VS Code and RStudio, preserving user workflows while ensuring reproducibility. Finally, RRP streamlines collaborative manuscript writing by linking research data and analysis code directly to the publishing process, enhancing reproducible scholarship. We built RRP with a modular architecture and open-source ethos, inviting developers to extend its capabilities, integrate new tools, and customize workflows, fostering an evolving ecosystem for reproducible research across diverse scientific domains.</p>

Keeping Legislative Data Accessible (en)

<p><a href="https://openparldata.ch">OpenParlData.ch</a> provides free access to harmonized data from Swiss parliaments. We currently offer data on political actors, parliamentary proceedings, decrees, consultations, votes, and more from <a href="https://admin.openparldata.ch/#/bodies">78</a> parliaments. <a href="https://data-ecosystem-prototype-bf909a.gitlab.io/business_model/use_cases/research.html">Researchers</a> (e.g. political scientists, linguists) but also <a href="https://data-ecosystem-prototype-bf909a.gitlab.io/business_model/use_cases/journalism.html">journalists</a> and <a href="https://data-ecosystem-prototype-bf909a.gitlab.io/business_model/use_cases/lobbying.html">civil society organizations</a> can use our <a href="https://api.openparldata.ch/documentation">API</a> to create their own analyses, visualisations, and tools, thereby promoting transparency, participation, and innovation in Swiss politics.</p> <p>We <a href="https://admin.openparldata.ch/#/pipeline?tab=details">import</a> data (mostly from websites and some APIs), clean, harmonize and publish them openly. The data infrastructure is <a href="https://gitlab.com/opendata.ch/openparldatach/data-infrastructure">open source</a> and currently in beta. In addition to the API, we are developing <a href="https://openparldata.ch/about/standard">standards</a> that enable parliaments and governments to publish uniform open data. Over the next year, we will address the question of how we can efficiently and <a href="https://data-ecosystem-prototype-bf909a.gitlab.io/business_model/index.html">financially sustainably</a> operate a data infrastructure that continues to provide crucial data openly in three years' time and how we can enable other actors to publish interoperable high-quality data. We look forward to sharing what we have learnt and hearing your feedback!</p> <p><a href="https://fosdem-2026-e5d212.gitlab.io/">Presentation Slides</a></p>

Data science from the command line: a look back at 2 years of using xan (en)

<p><a href="https://github.com/medialab/xan">Xan</a> is a command-line tool designed to manipulate CSV files directly from the comfort of the terminal. </p> <p>Originally developed within a sociology research lab to perform common operations on very large datasets collected from the web (exploration, sorting, computing frequency tables, joins, aggregations, etc.), it has become a go-to solution for its users for many more use-cases, including lexicometry analysis, plotting histograms, time series or heatmaps, and even generating network graphs. And while the tool was initially created to deal with very large CSV files, it is now also used by people to process small files, and other file formats. The tool was thus included in the daily data manipulation practices of its users, who saw it as an opportunity to never leave their shells, without having to rely on GUIs or notebooks. </p> <p>This presentation, given by a research engineer after two years of regular use, examines the reasons for this appropriation, which relates both to the constraints of research in the Humanities and Social Sciences and to the interface design choices that make xan effective.</p>

The Skills of a FLOSS Developer and Why They Are Important in Open Research (en)

<p>Open research requires skills that Free/Libre and Open Source Software (FLOSS) developers have been cultivating for decades and that have made them successful in building their communities and business models. Discussing in public, creating inclusive communities, developing governance models suitable for community-driven projects, securing funding are all skills FLOSS developers require to sustain their software projects.</p> <p>These skills are equally needed in open research, when it is not merely understood as open access, but it is conceived as an effort to create communities of practice that overcome geographical, disciplinary, and social boundaries. Developing these skills in open research, however, is still work in progress. For instance, peer review, which is a mainstay of research, usually continues to take place behind closed doors and involves a limited number of actors rather than the entire community with risks of fraud and knowledge gatekeeping. Similarly, open research networks struggle to be as inclusive as FLOSS projects. Participation is traditionally determined by institutional affiliations and funding, and citizen science contributions are often neglected because they do not fit into the scheme of traditional scholarly knowledge. Robust governance models and long-term funding strategies are also lacking in open research in many cases.</p> <p>The talk is a personal reflection based on my experience working in research data management and engaging in my free time with open-source projects and volunteer-based initiatives to promote coding literacy. At times when AI-generated code is marketed as the only possible future of software, including research software, my reflection focuses instead on the human skills and shared values underpinning software development in FLOSS communities, why I consider them a precious asset, and why I hope they will continue to exist and fully transfer into open research.</p>

Research software engineering: a movement and its instantiation at the University of Illinois Urbana-Champaign (en)

<p>In 2012, a small group looking at challenges related to the development and maintenance of research software realized that there was no community identity (e.g., common title, career path, professional association) for the people involved, so they started a process to define and create these. Today, 13+ years later, there are research software engineer (RSE) and engineering (RSEng) groups at more than 100 universities, and <a href="https://researchsoftware.org/assoc.html">RSE societies and associations</a> in more than 10 countries (e.g., <a href="https://society-rse.org">UK</a>, <a href="https://us-rse.org">US</a>, <a href="https://de-rse.org">Germany</a>, <a href="https://be-rse.org/">Belgium</a>), with over 10000 members and annual physical and virtual conferences, including a <a href="https://www.researchsoft.org/irsc/">first global research software conference</a> coming in 2026. This talk will briefly discuss the movement that created this, then will focus on the experience of the University of Illinois Urbana-Champaign, where there is now a group of 45 RSEs in the National Center for Supercomputing Applications (NCSA), and many more across the university. <a href="https://ncsa.illinois.edu/resources-and-services/software-applications/">RSEs at NCSA</a> bring skills and expertise including full-stack development, UI/UX design, GIS, AI, MLOps, DevOps, and data science and engineering with projects such as <a href="https://clowderframework.org/">Clowder</a>, <a href="https://tools.in-core.org/">IN-CORE</a>, <a href="https://chat.illinois.edu/">Illinois Chat</a>, <a href="https://www.earthcube.org/decoder">DeCODER</a>, etc., across multiple scholarly and industrial domains. Beyond technical advancement, the group has been developing and enhancing mentoring RSEs and RSE managers. The talk will discuss how this group was developed, the challenges it overcame, and the challenges that remain.</p>

Trusted by design: set up your research software for community adoption (en)

<p>So, you want to create an open-source research software package — and not just for yourself or your group. You’d like people around the world to use it, and even contribute to it. How do you persuade them it’s worth their time?</p> <p>Open-source projects rise and fall on trust. You may hope to build trust on technical merits: your algorithm is novel; your implementation fast; your tests thorough. All great, but not enough. Many technically excellent projects never break through because they neglect the social foundations of trust, which are laid long before a project matures.</p> <p><strong>And that's good news:</strong> you don’t need to be a top-tier programmer to build a successful open-source tool. Normal researchers do this all the time. What matters most is how you run the project, not how fancy the code is.</p> <p>This talk distils lessons from years of building and maintaining scientific Python tools used by researchers worldwide. I’ll outline the practices that signal reliability and sustainability across a project’s lifecycle: defining and communicating your mission from the start; making a reasonable first release and following it up with consistency; and using open communication channels to embody your values and model healthy norms.</p> <p>Throughout the talk, I’ll draw on examples from <a href="https://movement.neuroinformatics.dev/">movement</a> — a Python package I develop — and other tools built by the <a href="https://neuroinformatics.dev/">Research Software Engineering team</a> I’m part of. That said, the lessons should be applicable to any free open-source project that aspires to attract and sustain a healthy community.</p> <p><strong>Takeaway:</strong> If you behave like a trustworthy project from the beginning, people will treat you like one, and help the project grow into what it promises to be.</p>

Introducing Jupyter Book 2: Next-generation Tools for Creating Computational Narratives (en)

<p>Jupyter Book is a core tool for sharing computational science, powering more than 14,000 open, online textbooks, knowledge bases, lectures, courses and community sites. It allows researchers and educators to create books and knowledge bases that are reusable, reproducible, and interactive.</p> <p>Over the past two years, we have rebuilt Jupyter Book from the ground up, focused on allowing authors to produce machine readable, semantically structured content that can be flexibly deployed, reused, and cross referenced in unprecedented ways. We achieved this by adopting, stewarding, and developing the MyST Markdown Document Engine (mystmd.org), a more flexible and extensible engine that integrates with Jupyter for interactive computation. Jupyter Book 2 represents a major leap forward in how we share and distribute computational content on the web.</p> <p>In this talk, we cover the key ideas driving Jupyter Book 2 and MyST, and showcase real-world examples like The Turing Way, and Project Pythia. We'll demonstrate major new functionality with live demos, and give the audience practical tips for getting started with the new Jupyter Book 2 stack.</p>

Visualising Wikipedia (en)

<p>A presentation of a new tool that allows visualising groups of Wikipedia articles, analysing and monitoring them, supporting the work of volunteers, researchers, and institutions, and creating knowledge landscapes. </p> <p>The prototype focuses on Wikipedia articles related to climate change and sustainability, aiming to assess current coverage of these topics and test interventions. However, the tool developed can be applied to any topic, starting from Wikidata and Wikipedia categories. </p> <p>This free and open software tool is developed in the framework of the international research project “Visual Analytics for Sustainability and Climate Change: Assessing online open content and supporting community engagement. The case of Wikipedia" (2025-2029), led by the University of Applied Sciences and Arts of Southern Switzerland (SUPSI), in collaboration with Wiki Education Foundation, Wikimedistas de Uruguay, Wiki in Africa and Open Climate Campaign, with the endorsement of Wikimedia Italia, the support of the SNSF (10.003.183) and the engagement of many Wikipedia and Wikidata volunteers.</p> <p>The presentation is an invitation to contribute to the design of the tool and its tests. </p> <ul> <li>Research project: https://meta.wikimedia.org/wiki/Visualizing_sustainability_and_climate_change_on_Wikipedia</li> <li>Co-design of the tool: https://meta.wikimedia.org/wiki/Visual_Analytics_for_Sustainability_and_Climate_Change/Tool/Co-design_activities</li> <li>Prototype https://giovannipro.github.io/wikipedia-climate-change/?lang=en</li> <li>The visualisations will be integrated into the dashboard Visualizing Impact by Wiki Education.</li> </ul>

Working with small data that you dare to share (en)

<p>How to work with toxic data? In our project we work with DNS query streams, which contain a lot of data that may expose single users and their browsing behaviour. </p> <p>This talk covers how we have built a large scale statistics platform while preserving the user’s privacy and still being able to find important observations. We cover which algorithms and methods we use to gather the data in a cloud platform and run advanced analytics without touching individual user data. We share how to go from big data sets to small aggregated and minimised sets. </p> <p>We believe the approach of "small data" is applicable to any field where you want to use and share sensitive data. We also invite the audience to audit our work and help build a privacy-first internet statistics platform as one good example.</p>

PyGambit: an open-source software for game theory (en)

<p>The <a href="https://www.gambit-project.org/">“Gambit”</a> project for computation in game theory has been through multiple phases of development, dating back to the 1980s. Game theory as a field &amp; methodology emerged from economics, but increasingly has applications in cybersecurity, multi-agent systems research and AI. Gambit is used across these fields for both teaching purposes, and as a suite of software tools for scientific computing. Recent Gambit development has been carried out at The Alan Turing Institute and has involved a modernisation of the PyGambit Python API, with a particular focus on improving the user experience, including clear user tutorials and documentation. This in turn has helped to guide the prioritisation of features in recent package releases.</p> <p>This talk will introduce some fundamental concepts in game theory using PyGambit, explaining how the package can be used to create and visualise non-cooperative games, and compute their Nash equilibria (where game players have no incentive to deviate their strategies). The talk will also highlight how PyGambit fits into the broader open-source scientific computing ecosystem for research on games via interoperability with the OpenSpiel framework, which is used for reinforcement learning.</p>

Draupnir: a field report on building community focussed T&S tooling within an open federation (en)

<p>Draupnir is a unified platform to grow, manage, and sustain communities on Matrix. Over the last 3 years we have learned many lessons to share with the community on building trust and safety tooling in an open federation.</p> <p>We will discuss just a few of the many problems we have faced, and our experience solving them </p> <p>https://github.com/the-draupnir-project/Draupnir</p>

Community moderation in Matrix (en)

<p>Policy servers (<a href="https://github.com/matrix-org/matrix-spec-proposals/pull/4284">MSC4284</a>) are a new tool available to communities on Matrix to help reduce spam and other unwelcome content, but they aren't the only option. Communities have a whole suite of tools available to them to keep their users safe, such as moderation bots and in-client safety features.</p> <p>In this talk, we'll cover the layers of Trust &amp; Safety (T&amp;S) tooling available to communities, how they work, and what harms they are typically best at mitigating. We'll also demonstrate how to set up a policy server in your community, and discuss what they might be able to do in the future.</p>

Stop Reinventing in Isolation: Bringing Open Source to Trust & Safety Infrastructure (en)

<p>As protocols and platforms grow, so do the demands of policy enforcement, human review workflows, and cross-platform incident response. Trust and safety tools form this critical layer of Internet infrastructure, yet most solutions remain closed, proprietary, and reinvented in isolation. Further, they’re typically out of reach for smaller and decentralized platforms.</p> <p><a href="https://roost.tools">Robust Open Online Safety Tools (ROOST)</a> is building a different future: one where these trust and safety tools are open, transparent, community-governed, and usable by platforms and organizations of all sizes. In this talk, you’ll get a refresher on what “trust and safety” means; hear how ROOST is succeeding with a non-profit and open source approach; learn about the newly-released <a href="https://github.com/roostorg/osprey">Osprey</a> rules engine and investigation tool—already in production across platforms like <a href="https://bsky.social">Bluesky</a> and <a href="https://discord.com">Discord</a>; see a demo of Osprey in action; and finally, learn how to adopt and contribute to Osprey and other open source trust and safety tools with ROOST.</p>

Matrix State of the Union (en)

<p>An overview of all that's been happening with the Matrix protocol in the last year, including:</p> <ul> <li> <p>Project Hydra (state resolution improvements)</p> </li> <li> <p>Trust &amp; Safety improvements</p> </li> <li> <p>Matrix 2.0 MSCs (OIDC, Simplified Sliding Sync, Matrix RTC and Invisible Crypto)</p> </li> <li> <p>P2P Matrix progress</p> </li> <li> <p>Encryption advances with MLS, post quantum</p> </li> <li> <p>Updates on the scores of public sector Matrix deployments we're seeing emerge as countries seek digital sovereignty...</p> </li> </ul> <p>...and more!</p>

Lighter, faster, simpler: An Element Web for the future (en)

<p><a href="https://github.com/element-hq/element-web">Element Web</a> is the oldest and most widely deployed Matrix client, and could well be the most widely deployed decentralised comms client in active service, especially when considering its many forks (Tchap, openDesk Chat, BundesMessenger, SchildiChat, LuxChat, etc.)</p> <p>Over the last 11 years it has accumulated a very significant amount of technical debt, and we believe that one of the main ways to accelerate the uptake of decentralised communication would be to be radically improve the codebase. This means <strong>not</strong> doing a rewrite, and instead figuring out how to carefully switch the engine mid-flight from matrix-js-sdk to matrix-rust-sdk running in WASM, ensuring Element Web benefits from all the improvements which have landed in the Element X mobile apps, while simultaneously stopping reinventing the wheel between the two stacks. We'll demonstrate experiments with <a href="https://github.com/element-hq/aurora">Aurora</a> as our playground for running Element Web's react components on top of matrix-rust-sdk, and explain how we hope to bring decentralised comms to a wider audience by making Element Web as performant and snappy as Element X.</p> <p>This talk should be of extreme interest to anyone who has ever complained about Element Web being slow or RAM hungry, and who wants to see a world where decentralised comms can outrun the centralised alternatives!</p>

MatrixRTC x Godot - A Battle Royale (en)

<p>Discover how MatrixRTC transforms into a "backendless" multiplayer game server and join us for a live Godot game session inside a Matrix widget.</p> <p>The VOIP team at Element will present their progress on abstracting an RTC SDK from the Element Call stack. We want to share the current state as we try to use it to build a multi-player game.</p> <p>If you are familiar with Godot, you will learn how to potentially use Matrix as a free, encrypted backend that handles account creation and persistent storage.</p> <p>At the end, there will be a gaming session with the devroom! Prepare to battle!</p>

Sustainable decentralised comms at Element (en)

<p>Element is the most widely deployed Matrix client, built by the team who created Matrix in order to bootstrap the ecosystem. The last few years have been quite a rollercoaster in terms of figuring out how to ensure Element can contribute to Matrix sustainably long-term - a problem faced by many open source projects whose core team works on the project as their day job.</p> <p>The good news is we think we've now found a sustainable model that works, having moved from Apache to AGPL and having finally released an official Matrix distribution from Element in the form of <a href="https://github.com/element-hq/ess-helm">Element Server Suite (ESS) Community</a> under the AGPL. In this talk we'll give a super quick tour of the journey that we've been on and the learnings encountered along the way, in the hope that other decentralised comms projects can learn from our mistakes and successes. We'll look at the work Element's been doing to sustainably progress Matrix - be that driving forwards Matrix 2.0 spec work, maintaining Synapse, or ensuring that matrix-rust-sdk provides a foundational client SDK suitable for Element X, Fractal, iamb and more.</p> <p>Finally, we'll take a quick look at how Element has ended up bringing decentralised communication to the heart of public sector open source collaboration suites such as Germany's <a href="https://www.opendesk.eu/en">openDesk</a> from ZenDiS, France's <a href="https://lasuite.numerique.gouv.fr/en">La Suite</a> from DINUM, and The Netherlands' <a href="https://github.com/MinBZK/mijn-bureau-infra">MijnBureau</a> from MinBZK - and take a look at what the future may bring!</p>

DMLS vs DMLS: decentralizing/distributing Messaging Layer Security (en)

<p>Messaging Layer Security (MLS) is an IETF standard (RFC9420) for end-to-end encryption in messaging systems. However, it requires a delivery service that determines an ordering of handshake messages, which does not fit with certain messaging architectures. In this talk, we will explore some of the work that has been done to make MLS work in a distributed/decentralized environment, and look at some of the remaining issues.</p>

Engineering XMPP Federation: Building Messaging, Voice & Social Features Across Independent Projects (en)

<p>Building open federated communication systems requires more than publishing specifications. It demands a living ecosystem of independent implementations that actually work together. The XMPP Standards Foundation (XSF) is a standards body, but is also the center of a development ecosystem that encompasses 5+ major servers and 20+ clients, all developed by different individuals and organizations, all highly interoperable and shipping new features at an accelerating pace.</p> <p>This talk will share how all this can work at this scale and will be co-presented by a server developer and a client developer, showing how they work together to fine-tune their implementations.</p> <p>We will first explain how the XSF works on its specifications, how its process has improved over the years, with proven engineering patterns that enable independent projects to build interoperable features without tight coupling (and without central coordination).</p> <p>We will illustrate the talk by showing real-life collaboration examples that came to life in 2025, sharing the points of view of an ejabberd server developer and the Movim client developer.</p> <p>As a conclusion, we will tease new features currently in design for 2026 and give you a glimpse at messaging federation, the XMPP way.</p> <p>This talk is for people who are interested in contributing to a truly decentralized protocol design initiative or who would like to understand what they can expect from XMPP in the future, based on examples of what has been achieved in 2025.</p>

Movim: Building a Decentralized Social Network on XMPP (en)

<p>What if you could have chat, video conferencing, blogging, and social communities all in one place without giving up your data to a centralized platform? Movim is a web-based application that brings the full power of XMPP to end users, combining instant messaging, group chats, video calls, and a complete publishing platform into a unified experience.</p> <p>In this talk, I'll present how Movim leverages the XMPP standard and its extensions (Pubsub, MUC, Jingle) to deliver features users expect from modern social platforms while remaining fully federated, interoperable with other XMPP clients like Conversations and Dino, and capable of bridging to centralized platforms like Discord, Telegram, and WhatsApp!</p> <p>I'll discuss the technical challenges of building a rich web frontend on top of XMPP, showcase the exciting features recently added to the project, and introduce the upcoming planned ones.</p> <p>Whether you're an XMPP enthusiast or curious about decentralized alternatives to mainstream social media, come discover how Movim is bridging the gap between protocol power and user experience.</p> <p>Official website: https://movim.eu/</p>

What are you listening to now?: Implementing "Now Playing" feature in modern XMPP (en)

<p>Do you remember the "Now Playing" feature in MSN Messenger? It was a feature that make you able to see which song are your friends listening at the moment back in 2000s, but unfortunately it is mostly forgotten now. </p> <p>In this talk, I will share the journey on my research on implementing this feature in modern XMPP clients, the protocols of certain operating systems to read the currently playing media, the current status of the support of XEP-0118[^1] and the PoC of a modern "Now Playing" feature.</p> <p>[^1]: <a href="https://xmpp.org/extensions/xep-0118.html">XEP-0118: User Tune</a></p>

Bonfire: Modular Communication Tools on the Open Social Web (en)

<p>Bonfire is a next-generation, open-source platform for building trustful communities and federated networks. It reimagines social communication by allowing communities to enable, disable, or adapt features and even protocols, putting community governance, and autonomy combined with consentful interconnection at its core. Bonfire federates with ActivityPub, with bridging available to ATproto (and hopefully more to come). Bonfire’s federated groups, thread-centric discussions, and modular architecture make it easy to experiment with new forms of moderation, identity, and trust that reach beyond single servers, single platforms, or single protocols. </p> <p>This talk will cover:</p> <ul> <li> <p>Our ongoing work and demo of fully <strong>end-to-end encrypted messaging</strong> (MLS-based) over ActivityPub, one the first two implementations of its kind</p> </li> <li> <p>ActivityPub C2S API use: <strong>how apps can easily integrate with the fediverse</strong> (including MLS messaging) via Bonfire </p> </li> <li> <p>Interoperability: <strong>extending ActivityPub</strong> for advanced user stories, moderation, as well as <strong>bridging</strong> with ATproto and potential future integrations with Matrix, XMPP, etc.</p> </li> <li> <p>Consentful communication flows and privacy-preserving tools for <strong>trust and safety</strong> (such as circles and boundaries)</p> </li> <li> <p>Bonfire’s <strong>modular architecture</strong>: designing “app flavours” with custom governance, moderation, and communication tools for different community needs</p> </li> </ul> <p>Attendees will see a live demo and leave with ideas and tools for composing their own modular, federated, and privacy-focused social communication spaces.</p> <p>Links: </p> <p>Links:<br /> - <a href="https://bonfirenetworks.org">Project</a> - <a href="https://docs.bonfirenetworks.org">Docs</a> - <a href="https://github.com/bonfire-networks">Code</a> - <a href="https://docs.bonfirenetworks.org/federation-interoperability.html">Interop &amp; FEP/Protocol extensions</a></p>

DASL Your Protocols! (en)

<p>DASL (Data-Addressed Structures &amp; Links, https://dasl.ing/) is a suite of small and simple specs that provide a proven, reliable, interoperable toolbox for content-addressing that can be used in other protocols. It has quality implementations in multiple languages, has multiple components used by the AT Protocol, and has some parts also documented in an IETF draft. For the most part, it is a subset of IPFS ruthlessly aimed at interoperability and ease of use. This talk offers a tour and introduction to the core concepts, and provides pointers for reuse in other protocols.</p>

Reverse Google: From email to decentralization (en)

<p>Decentralized Key Management / Self Sovereign Identity holds the promise of a truly decentralized, self-verifying PKI. Approaches like KERI, the Key Event Receipt Infrastructure, balance privacy, verifiability, and the protection from duplicity. But their promises have remained largely academic thus far. In 2026, the Swiss Healthcare System will be the first large-scale deployment of this kind of infrastructure, using it to upgrade the trust, security and privacy levels of its aging email infrastructure. The result will be a production ready technology stack that can be utilised for a large number of use cases around communication.</p> <p>Georg Greve is centrally involved in that transition, and will share the road travelled so far, the current state, and the next steps for this transformation.</p> <p>Background: https://www.hin.ch/de/blog/2025/vom-mailgateway-zum-data-mesh.cfm</p>

AT: The Billion-Edge Open Social Graph (en)

<p>Social graphs are a well-understood technology. Using infrastructure and standardized protocols that are usually de facto controlled by large, commercial platforms, they provide a way of structuring and querying data about individual nodes (often users) in a network and the relationships (edges) between these nodes. They are theoretically extensible, and social graph data can typically also be represented using open standards like RDF which can be published and consumed by other authorities participating in a network. However, trying to enable participation or federation this way is frequently wishful thinking, and does not really facilitate scaling that social graph beyond a particular API representation of rows in one organization’s database.</p> <p>The <a href="https://atproto.com/">Atmosphere</a> — built on AT — presents a different approach. When you write data using Atmosphere APIs, such as by <a href="https://docs.bsky.app/docs/tutorials/creating-a-post">posting to Bluesky</a>, that data is associated with your personal <a href="https://atproto.com/guides/data-repos">data repository</a>. These personal data repositories can be hosted or migrated anywhere across the Atmosphere. Each Atmosphere app declares its own schema (<a href="https://atproto.com/guides/lexicon">Lexicon</a>), and reads and writes its own set of fields. These fields can be read by <a href="https://anisota.net/feed">any other app built on the Atmosphere</a>, allowing users to both a) own and b) span their graphs across the network.</p> <p>This enables several in-demand use cases. Building <a href="https://docs.bsky.app/docs/advanced-guides/federation-architecture">“big world”</a> social apps with AT is only a matter of creating new lexicons to support additional data models, designing app views which serve this data (along with any other data that may already be available to a user’s graph from other AT apps), and <a href="https://atproto.com/guides/self-hosting">self-hosting</a> the necessary infrastructure.</p> <p>We provide <a href="https://github.com/bluesky-social/cookbook/">implementation patterns</a>, along with primitives and tools that are of interest to almost all implementers — like OAuth Scopes and moderation tools. We also provide a social networking app (<a href="http://bsky.social/">Bluesky Social</a>) that serves as both a reference implementation for the protocol, and a critical-mass opportunity to populate users’ social graphs so that other application developers can benefit from shared data. Regardless of which application is using this data, all of it is open, public, and associated with individual users’ data repositories, which can be migrated across the network at will.</p> <p>This talk will provide a demonstration of some fundamental AT technologies, including: "Sipping the Firehose" - working with the stream, a demo of creating records and have them pop right out “Getting backlinks with Constellation” - querying social interactions in real time, and building that data into different interfaces “Lexicon Authoring” - a discussion of best practices for creating additional schemas, with examples from other apps in the Atmosphere</p>

We d-build it, but they didn't come (en)

<p>I had a few talks at conferences, entitled "Disobay: FOSS tools to fight back," where I explained what tools exist for us to protect our communication and why we should use them. I covered several decentralized tools and protocols, and then I asked, "Are there any questions?" One person asked, "How do I convince my friends to move to those tools"? And the audience nodded in agreement. </p> <p>Then I took this topic seriously. With this talk, I aim to cover the subject of their adoption - we all build great tools, but what approaches can we use to encourage people to join the right side? The majority of the cases I would showcase are from real people on my fediverse, Hacker News, and other networks I'm a part of.</p>

Accessible software performance (en)

<p>Nowadays, in the software industry, we already have a lot of ways to improve performance of our applications: compilers become better and better each year in the optimization field, we have a lot of tools like Linux perf and Intel VTune to analyze performance. Even algorithms are still improving in various domains! But how many of these improvements are actually adopted in the industry, and how difficult it is to adopt them in reality? That's an interesting question!</p> <p>In this talk, I want to show you:</p> <ul> <li>Why accessibility of software performance matters</li> <li>How various software optimization approaches are different from the adoption easiness perspective: from different compiler optimizations to semi-automatic optimizations to a manual approach</li> <li>What things can be improved and how</li> <li>Many related open-source examples from my practice</li> <li>Share with you an idea behind the "Software performance" devroom</li> </ul> <p>I hope after the talk you get an interesting perspective on software performance to think about.</p>

Beyond nvidia-smi: Tools for Real GPU Performance Metrics (en)

<p>Relying only on nvidia-smi is like measuring highway usage by checking if any car is present, not how many lanes are full. </p> <p>This talk reveals the metrics nvidia-smi doesn't show and introduces open source tools that expose actual GPU efficiency metrics.</p> <p>We'll cover:</p> <ol> <li>Why GPU Utilization is not same as GPU Efficiency.</li> <li>Deep dive into relevant key metrics: SM metrics, Tensor Core metrics, Memory metrics explained.</li> <li>Practical gpu profiling and monitoring setup.</li> <li>Identifying bottlenecks in inference workloads.</li> </ol> <p>Attendees will leave understanding how to identify underutilized GPU and discover real optimization opportunities across inference workloads.</p>

Keeping the P in HPC: the EESSI Way (en)

<p>In scientific computing on supercomputers, performance should be king. Today’s rapidly diversifying High-Performance Computing (HPC) landscape makes this increasingly difficult to achieve however...</p> <p>Modern supercomputers rely heavily on open source software, from a Linux-based operating system to scientific applications and their vast dependency stacks. A decade ago, HPC systems were relatively homogeneous: Intel CPUs, a fast interconnect like Infininand, and a shared filesystem. Today, diversity is the norm: AMD and Intel CPUs, emerging Arm-based exascale systems like <a href="https://hackmd.io/LXZmuTDdTJi-cQKkG6AZ-w">JUPITER</a>, widespread acceleration with NVIDIA and AMD GPUs, soon also RISC-V system architectures (like <a href="https://tenstorrent.com/">Tenstorrent</a>), etc.</p> <p>This hardware fragmentation creates significant challenges for researchers and HPC support teams. Getting scientific software installed reliably and efficiently is more painful than ever, and that’s before even considering software performance.</p> <p>Containers, once heralded as the solution for mobility-of-compute, are increasingly showing their limits. An x86_64 container image is useless on a system with Arm CPUs, and will be equally useless on RISC-V in the not so distant future. What's worse is that portable container images used today already sacrifice performance by avoiding CPU-specific instructions like AVX-512 or AVX10, potentially leaving substantial performance gains on the table. Containerization also complicates MPI-heavy workloads and introduces friction for HPC users.</p> <p>This talk introduces the <a href="https://eessi.io/"><strong>European Environment for Scientific Software Installations (EESSI)</strong></a>, which tackles these challenges head-on with a fundamentally different approach. EESSI is a curated, performance-optimized scientific software stack powered by open source technologies including <a href="https://cernvm.cern.ch/fs">CernVM-FS</a>, <a href="https://wiki.gentoo.org/wiki/Project:Prefix">Gentoo Prefix</a>, <a href="https://easybuild.io/">EasyBuild</a>, <a href="https://lmod.readthedocs.io">Lmod</a>, <a href="https://computecanada.github.io/magic_castle/">Magic Castle</a>, <a href="https://reframe-hpc.readthedocs.io">ReFrame</a>, etc.</p> <p>We will show how EESSI enables researchers to use the same optimized software stack seamlessly across laptops, cloud VMs, supercomputers, CI pipelines, and even Raspberry Pis—without sacrificing performance or ignoring hardware differences. This unlocks powerful workflows and simplifies software management across heterogeneous environments.</p> <p>EESSI is already being adopted across <a href="https://www.eessi.io/docs/systems/">European supercomputers</a> and plays a central role in the upcoming <a href="https://my-eurohpc.eu">EuroHPC Federation Platform</a>.</p> <p>Come learn why EESSI is the right way to keep the P in HPC.</p>

Towards unified full-stack performance analysis and automated computer system design at CERN with Adaptyst (en)

<p>Slow performance is often a major blocker of new visionary applications in scientific computing and related fields, regardless of whether it is embedded or distributed computing. This issue is becoming more and more challenging to tackle as it is no longer enough to do only algorithmic optimisations, only hardware optimisations, or only (operating) system optimisations: all of them need to be considered together.</p> <p>Architecting full-stack computer systems customised for a use case comes to the rescue, namely software-system-hardware co-design. However, doing this manually per use case is cumbersome as the search space of possible solutions is vast, the number of different programming models is substantial, and experts from various disciplines need to be involved. Moreover, performance analysis tools often used here are fragmented, with state-of-the-art programs tending to be proprietary and not compatible with each other.</p> <p>This is why automated full-stack system design is promising, but the existing solutions are few and far between and do not scale. <strong>Adaptyst is an open-source project at CERN (the world-leading particle physics laboratory) aiming to solve this problem. It is meant to be a comprehensive architecture-agnostic tool which:</strong></p> <ul> <li>unifies performance analysis across the entire software-hardware stack by calling state-of-the-art software and APIs under the hood with any remaining gaps bridged by Adaptyst (so that performance can be inspected both macro- and microscopically regardless of the workflow and platform type)</li> <li>suggests automatically the best solutions of workflow performance bottlenecks in terms of one or more of: software optimisations, hardware choices and/or customisations, and (operating) system design</li> <li>scales easily from embedded to high-performance/distributed computing and allows adding support for new software/system/hardware components seamlessly by anyone thanks to the modular design</li> </ul> <p>The tool is in the early phase of development with small workforce and concentrating on profiling at the moment. Given that Adaptyst has broad application potential and we want it to be for everyone’s benefit, we are building an open-source community around the project.</p> <p>This talk is an invitation to join us: we will explain the performance problems we face at CERN, tell you in detail what Adaptyst is and how you can get involved, and demonstrate the current version of the project on CPU and CUDA examples.</p> <p>Project website: https://adaptyst.web.cern.ch</p>

How to Reliably Measure Software Performance (en)

<p>Reliable performance measurement remains an unsolved problem across most open source projects. Benchmarks are often an afterthought, and when they aren't they can be noisy, non-repeatable, and hard to act on.</p> <p>This talk shares lessons learned from building a large-scale benchmarking system at Datadog and shows how small fixes can make a big difference: controlling environmental noise, designing benchmarks, interpreting results with sound statistical methods, and more.</p> <p>Attendees should leave with practical principles they can apply in their own projects to make benchmarks trustworthy and actionable. We'll illustrate each principle with real data — for instance, environment tuning that cut variance by 100x, or design changes that turned a flaky benchmark into a reliable one.</p>

Pulling 100k revisions 100× faster (en)

<p><a href="https://www.mercurial-scm.org/">Mercurial</a> is a distributed version control system whose codebase combines Python, C and Rust. Over its twenty years of development, significant effort has been put into its scaling and overall performance.</p> <p>In the recent 7.2 version, the performance of exchanging data between repositories (e.g. <code>push</code> and <code>pull</code>) has been significantly improved, with some of our most complicated benchmark cases moving from almost four hours down to 2 minutes, a speedup of over 100x.</p> <p>This talk uses this work as a case study of the multiple places where performance improvements lie. It goes over the challenges that arise from exchanging data in a DVCS, and the levers we can pull to overcome them: higher level logic changes, lower level algorithmic improvements, programming language strengths, modern CPU architecture, network protocol design, etc.</p> <p>Despite the great results, exchanging data in version control remains a complex matter, and we lastly expose our ideas to further tackle its inherent complexity.</p>

Database benchmarks: Lessons learned from running a benchmark standard organization (en)

<p>Database vendors often engage in fierce competition on system performance – in the 1980s, they even had their "benchmark wars". The creation of the TPC, a non-profit organization that defines standard benchmarks and supervises their use through rigorous audits, spelled an end to the benchmark wars and helped drive innovation on performance in relational database management systems.</p> <p>TPC served as a model for defining database benchmarks, including the Linked Data Benchmark Council (LDBC, https://ldbc.org/), of which I've been a contributor and board member for the past 5+ years. Through LDBC's workloads, graph database systems have seen a 25× speedup in four years and a 71× price-performance improvement on transactional workloads.</p> <p>Defining database benchmarks requires a careful balancing of multiple aspects: relevance, portability, scalability, and simplicity. Most notably, the field in the last few years has shifted toward using simpler, leaderboard-style benchmarks that skip the rigorous auditing process but allow quick iterations.</p> <p>In this talk, I will share my lessons learned on designing database benchmarks and using them in practice. The talk has five sections:</p> <ol> <li>The need for database benchmarks</li> <li>TPC overview (Transaction Processing Performance Council)</li> <li>LDBC overview (Linked Data Benchmark Council)</li> <li>The current benchmark landscape (ClickBench, H2O, etc.)</li> <li>Takeaways for designing new benchmarks</li> </ol>

Continuous Performance Engineering HowTo (en)

<p>In the past 30 years we've moved from manual QA testing of release candidates to Continuous Integration and even Continuous Deployment. But while most software projects excel at testing correctness, the level of automation of performance testing is still near zero. And while it's a given that each developer writes tests for their own code, Performance Engineering remains the domain of individual experts or separate teams, who benchmark the product with custom tools developed in house, often focusing on beta and release candidates, with zero performance tests happening in the Continuous Integration work stream.</p> <p>This talk is your guide to Continuous Performance Engineering, aka Continuous Benchmarking. We will cover standard benchmarking frameworks and how to automate them in CI, automating deployments of large end-to-end environments, how to tune your infrastructure for minimum noise and maximum repeatability, and using change point detection to automatically alert on performance regressions with a minimal amount of those annoying false positives.</p>

Writing an ultrafast Lua/JSON encoder+decoder as a LuaJIT module (en)

<p>JSON is one of the most popular data exchange formats. Parsing routines for it exist in every modern programming languages, either built-in, or included in popular libraries such as <a href="https://rapidjson.org/">RapidJSON</a> for C++ or <a href="https://docs.rs/json/latest/json/">json</a> for Rust.</p> <p>The task of conversion between JSON strings and <a href="https://lua.org/">Lua</a> objects has been solved plenty of times before, but either the solutions are not focused on performance, or the parsers are too strict for the "relaxed" format we use at <a href="https://www.beamng.com/game/">BeamNG</a>.</p> <p>What if we want to have the fastest Lua table &lt;-&gt; relaxed JSON conversion possible? We came up with a highly optimized LuaJIT code we use for handling JSONs at <a href="https://www.beamng.com/game/">BeamNG</a> since a few years. But there is a way to go further -- hacking on the C source code of the interpreter itself to add compiled built-in JSON support. How much extra performance can we squeeze out by going a level deeper?</p> <p>Get ready for juicy benchmarks and an optimization story from a real usage perspective.</p>

How To Move Bytes Around (en)

<p>If you take a random program and start profiling it, you'll usually find that the memcpy function is at the top. However, this doesn't necessarily mean memcpy is slow. The most hopeless thing a C++/Rust developer can do (while no one is watching) is optimize memcpy to move bytes faster. That's exactly what we'll do.</p>

A Performance Comparison of Kubernetes Multi-Cluster Networking (en)

<p>Driven by application, compliance, and end-user requirements, companies opt to deploy multiple Kubernetes clusters across public and private clouds. However, deploying applications in multi-cluster environments presents distinct challenges, especially managing the communication between the microservices spread across clusters. Traditionally, custom configurations, like VPNs or firewall rules, were required to connect such complex setups of clusters spanning the public cloud and on-premise infrastructure. This talk presents a comprehensive analysis of network performance characteristics for three popular open-source multi-cluster networking solutions (namely, <a href="https://skupper.io/">Skupper</a>, <a href="https://github.com/submariner-io/submariner">Submariner</a> and <a href="https://istio.io/">Istio</a>), addressing the challenges of microservices connectivity across clusters. We evaluate key factors such as latency, throughput, and resource utilization using established tools and benchmarks, offering valuable insights for organizations aiming to optimize the network performance of their multi-cluster deployments. Our experiments revealed that each solution involves unique trade-offs in performance and resource efficiency: Submariner offers low latency and consistency, Istio excels in throughput with moderate resource consumption, and Skupper stands out for its ease of configuration while maintaining balanced performance.</p>

Load Testing Real React Applications for Production Performance (en)

<p>In this talk, we'll explore how we built comprehensive load testing for React applications at Mattermost, achieving 100,000 concurrent users in production-like environments. We'll begin by revealing why traditional API testing missed critical browser issues that only emerged at scale. Next, we'll demonstrate our open-source tool that uses Playwright to run thousands of real browsers, measuring React-specific metrics like component render times, memory leaks, and state management bottlenecks. Finally, we'll share the optimization journey that reduced browser memory and enabled true production readiness, ensuring our React application performs flawlessly for enterprise customers.</p>

Welcome to the Gaming and VR Devroom (en)

<p>Welcome and setup time</p>

Beyond Git: Collaborative Version Control for Godot (en)

<p>Version control remains one of the biggest barriers to open source contribution—especially in game development, where programmers, artists, and designers must collaborate using tools like Git which are designed for code, not creative assets or interdisciplinary teams. At Ink &amp; Switch, we're prototyping a new collaboration system built directly into the Godot editor, supporting real-time co-editing, branching, and visual review of changes. In partnership with the Endless Foundation, we're evaluating this system with students in introductory Godot classes. This talk will demo our progress, explore why version control poses unique challenges for game development, and share early lessons from bringing these tools to students.</p>

Keeping Games Alive: The Role of Open Source in the Netrunner Revival (en)

<p>When a beloved game loses its publisher, its community often fades with it. Android: Netrunner was one such casualty, it was a deeply strategic card game released in 2012 that built a passionate global following before its official cancellation in 2018. Rather than let it disappear, a volunteer collective called Null Signal Games stepped in almost immediately after to keep on supporting the game. Null Signal Games has since regularly released new cards, organized tournaments, and kept the game going for over 7 years. The world championship in 2025 had over 360 players, the second largest ever Netrunner tournament since its entire lifespan.</p> <p>A key part of this revival is due to the use of open source software. Platforms like Jinteki.net, NetrunnerDB, and AlwaysBeRunning.net provide the digital backbone. They enable online play, deck-building, and community/tournament scheduling. On top of that there are also a bunch of smaller projects that help with a variety of small tasks, such as the online comprehensive rules or an implementation to play vs AI.</p> <p>This talk explores how open source infrastructure and community involvement has sustained Netrunner beyond corporate support. We’ll look at how technical and creative volunteers coordinate across continents on such a variety of projects and what lessons other fan communities and developers can learn from this model.</p> <p>Null Signal Games: https://nullsignal.games/ Jinteki.net: https://github.com/mtgred/netrunner Netrunnerdb: https://github.com/Null-Signal-Games/netrunnerdb Alwaysberunning: https://github.com/madarasz/always-be-running</p>

Breaking architecture barriers: Running x86 games on ARM (en)

<p>I'm presenting FEX, a translation layer to run x86 software on ARM devices, and the challenges it brings to the table: The design a high-performance binary recompiler, translation of Linux system calls across architectures, and forwarding of library calls to their ARM counterparts.</p> <p>Gaming in particular poses extreme demands on FEX and raises further questions: How do we enable GPU acceleration in an emulated environment? How can we integrate Wine to run Windows games on Linux ARM? Why is Steam itself the ultimate boss battle for x86 emulation? And why in the world do we care more about page sizes than German standardization institutes?</p> <p>Learn why x86 is such a pain to emulate and what tricks and techniques make your games fly with minimal translation overhead. Be prepared to learn cursed knowledge you won't be able to forget!</p>

Porting game engine renderer to Vulkan as an absolute beginner (en)

<p>Overte (https://overte.org/) is a free and open source social virtual worlds platform with VR support. It uses custom renderer and OpenGL. In this talk I will present workflow I used for porting Overte to Vulkan. I will also present resources for learning Vulkan and development tools necessary for porting a game renderer to Vulkan.</p>

The state of Open Source XR: Monado and beyond (en)

<p>This talk provides an introduction and overview over the state of open source XR. It focuses on the Monado runtime and its current state when it comes to OpenXR extensions and hardware drivers, but also covers the context of the wider ecosystem: How does it relate to OpenHMD, OpenComposite, xrizer, wlx-overlay-s, Electric Maple, WiVRn, Godot, and a variety of other projects?</p> <p>https://monado.dev/ https://github.com/WiVRn/WiVRn https://gitlab.freedesktop.org/monado/electric-maple https://gitlab.com/znixian/OpenOVR https://github.com/Supreeeme/xrizer https://github.com/galister/wlx-overlay-s https://github.com/godotengine/godot</p>

SlimeVR Full Body Tracking (en)

<p>SlimeVR is a fully open source hardware and software project turned company that produces both he required hardware and software for IMU based Full Body Tracking for VR, Motion Capture and VTubing. Over the last 4 years we have grown from a team of 2 and a desire to make cool stuff to an industry leading company with over 10 full time employees, 29.000+ customers and an active community over on discord with 69.000+ members!</p> <p>In short, SlimeVR uses IMU's (Inertial Measurement Unit) to estimate a virtual skeleton that can then be used for various purposes such as: Virtual Reality games, Motion capture through VMC or with BVH files and Vtubing which has become more and more popular over the years. Whilst we sell the hardware needed, people can also fully build their own hardware with off the shelf components!</p> <p>We have a huge passion for open source and we love sharing our ideas and mindset with the rest of the world. On top of that, we would love to hear from everyone else as well! That's why we would love to attend the Gaming and VR Devroom at fosdem 2026.</p> <p>We would love to showcase and share how we came to be, and show off some of the hardware and software that we have developed over the years. Including our latest and greatest recently announced Butterfly trackers. http://slimevr.dev/smol Our software has seen tremendous strides in recent years and has been embraced by names such as Sony for their motion capture product (Mocopi).</p> <p>We would also love to show off some of the hardware in action! If possible we could set up a demo where the avatar on screen is tracked off of the speaker in real time!</p>

Leveling Up OpenXR: New Extensions, Better Workflows, and Advances in Open-Source Gaming (en)

<p>OpenXR continues to gain traction as the cross-platform standard for XR, but gaming introduces unique challenges that often require specialized extensions. This talk will explore the recent advances in OpenXR, with a focus on gaming-relevant extensions, and how an open source runtime like Monado makes these capabilities accessible to developers.</p> <p>We will cover: * The latest OpenXR extensions for hand-tracking, body-tracking, haptics, and spatial entities. * Latest updates in Monado that introduce and simplify access to gaming-oriented XR features. * Practical examples of how Khronos and the OpenXR standard have simplified developer workflows, reducing integration overhead, and making it easier to implement XR features consistently across hardware and platforms.</p> <p>Attendees will gain insight into how open standards and open source implementations are driving the next generation of interoperable AR/VR gaming experiences.</p>

20 Years of Eurobattle.net: A Retrospective on the PvPGN Server and Its Open Source Ecosystem (en)

<p>In 2003, a group of Warcraft III enthusiasts built a free community server using the open-source PvPGN project. Over twenty years and a million games later, Eurobattle.net remains one of the longest-running unofficial Warcraft III servers in existence. This talk traces its evolution from early bnetd and PvPGN roots through the rise of GHost++ and GProxy projects, which fundamentally transformed Warcraft III map hosting, to our own project forks and extensions that keep the ecosystem alive today. Attendees will learn about the architecture behind Eurobattle.net, challenges maintaining decades-old C++ stack, learn about the community aspects, and see a short live demo.</p>

Crunching code like it is 1982 (en)

<p>Introduction &amp; Welcome to the Retrocomputing devroom</p>

Eliza: Rewriting the original AI chatbot from 60 years BC (Before ChatGPT) (en)

<p>When the Eliza psychotherapist chatbot was released by Joseph Weizenbaum, in 1966, people believed it real. Even the secretary of its creator thought the machine had feelings, as they discussed relationships and personal issues. But why? How could a simple computer text interface act so human?</p> <p>In this session our speaker, a computer historian and associate at the Centre for Computer History, uncovers the workings of Eliza, the Eliza effect, and its impact in the modern world and films like "THX 1138" and "Her." From the computer hardware to the programming language, and the scripts used to simulate the human traits of empathy and comprehension, we look at how 233 lines of code was convincing enough to change the world... and then how that code was transmogrified into JavaScript so that anyone can read and understand it.</p>

Charming Gray Buttons of the XX century: how widget toolkits evolved with computer architectures (en)

<p>The talk covers an evolution of widget toolkits, which have been started 40 years ago along with the historical changes in a desktop GUI. Widget toolkits are reviewed from three points of view: architecture, user experience, and programming principles. More than 90% of historically significant widget toolkits have open source licenses: some are opensourced after decrease of their commercial demand (like OpenLook and Motif), others are developed as a part of FLOSS world (Tcl/Tk, GTK+, Qt) or in systems cloned by the open source community (GNUStep, Haiku OS, etc.).</p> <p>Reviewed toolkits of 1980s include early Unix GUI of Andrew Toolkit and Project Athena, followed by OpenLook and Motif, and main non-Unix toolkits: WinAPI and NeXTSTEP GUI. Significant toolkits of 1990s include Tcl/Tk, wide range of wrapper toolkits including MFC and Java AWT and Swing, and the appearance of two main Linux widget libraries, GTK+ and Qt. Also the burst of visual theming occurred in the second half of 1990s is examined for Unix and Windows platforms (as in their artistic styles, so in used architectural approaches). The list of milestones is finished with the Apple Cocoa style, closing the XX century experiments (but theming efforts had 10 more years of boiling). From the architecture point of view, the talk covers the recurring efforts in the event processing techniques, targeting at hiding callbacks from a GUI developer with available object-style metaphors.</p>

MEP2, a Simple Mail Transfer Protocol (but not that one) (en)

<p>About one month after I was born in 1983 a company called MCI introduced their "Electronic mail" system. Originally a BBS-style system, where users dialed into MCI to edit, send, and receive mail. Users could send electronic mail to each other, send a physical letters, and even manage their telexes without ever leaving the comfort of whatever room they had with a telephone and an acoustic coupler.</p> <p>It became necessary to have offline email clients. Rather than use SMTP or POP they came up with MEP2 (Message Exchange Protocol 2). MEP2 combines the functionality of SMTP, POP, and some LDAP features together.</p> <p>In this talk I will discuss the history of MCI, MEP2 protocol, and the mail server I implemented that can speak it.</p>

ngdevkit: Free and Open Source C/C++ development on the Neo Geo in 2026 (en)

<p>The Neo Geo, the classic cartridge-based arcade and home video game system turned 35 in 2025. By now, it has been thoroughly reverse-engineered and documented online. Recently, there has been a surge in homebrew demos and newly published homebrew games for the Neo Geo. And although development in 2026 is way easier than it was in the 90's, too many available tools are still GUI-only, closed-source or Windows-only binaries, which leaves a lot to be desired. ngdevkit [1] was born out of this observation. The ambition of this project is twofold: first, to be a fully open source, easy to use development kit; second, to prove that your entire game development workflow can rely exclusively on open source software for compiling code, creating graphics, composing chiptunes, designing sound FX...</p> <p>This talk will give an overview of C programming for the Neo Geo with ngdevkit, and will discuss the main components of this open source development kit. ngdevkit provides a toolchain that leverages binutils, GCC, newlib and SDCC for code compilation, GnGeo or Mame for code execution, and GDB for source-level debugging. It also comes with an open source reimplementation of the original Neo Geo BIOS, with full ABI compatibility. In addition, this development kit provides the necessary crt0 and runtime to boot the game processor (68k) and the sound processor (Z80), and uses a custom linkscript to expose hardware features (video RAM, backup RAM, memory mapped registers, I/O state) as regular C variables. At last, it provides the first fully open source sound driver and chiptune player on the Neo Geo hardware. Throughout the talk, we will discuss how ngdevkit was made possible thanks to a vast trove of public domain documentation and a vast collection of open source software.</p> <p>[1] https://ngdevkit.dev</p>

The joys and horrors of NES dynamic recompilation (en)

<p>In this talk we'll explore the fascinating world of emulators and recompilation, by building together a dynamic recompiler for NES games, which will translate in real time code written for the game system into machine code directly executable by our host computer.</p>

Hacking the last Z80 computer ever made (en)

<p>The Z80 CPU has been extremely popular in home computers of the eighties, but as 16-bit and 32-bit processors became more popular, the only new computers built using the Z80 were continuations of some legacy lines (like the Amstrad PCW).</p> <p>And yet, in 1999 a company named Cidco unveiled a completely new computer line named the MailStation. with a Z80 CPU clocked at 12 MHz and 128 kB of RAM. It was a specialized machine for sending and receiving emails, addressed at people for whom configuring Web access on a PC was too complicated. Yet it was still a computer, with a screen, keyboard, means of communicating with the outside world and possibility of running user apps. Most likely the last new Z80 computer ever designed.</p> <p>In my talk I would like to present this machine, show how it can be hacked to run custom software, and encourage the audience to join me in documenting the machine and writing custom firmware for it.</p> <p>MailStation emulator: https://github.com/MichalPleban/mailstation-msemu</p> <p>Host appliation to transfer software to the MailStation: https://github.com/MichalPleban/mailstation-mailtransfer</p> <p>MailStation hardware documentation: https://github.com/MichalPleban/mailstation-hardware</p>

Early Electronic Computing in Belgium: Analysis and Simulation of the IRSIA FNRS Mathematical Machine (en)

<p>The first generation of computers (vacuum tube-based) emerged from WWII for scientific, military, or business purposes. In this pioneering time, the term “mathematical machines” was also used to distinguish them from human computers. This talk presents a working software simulator of the Belgian Mathematical Machine (MMIF), a little-known computer funded after WWII by IRSIA-FNRS and inaugurated 70 years ago at the Bell Company in Antwerp. We will show, including using the stepping mode, how it deals with programs and data using separate "RAM" drums (Harvard-style) and carries out computations with a high-precision floating-point calculation unit. You will discover the not-so-odd instruction set, coding style and how complex functions required for applications in ballistics and thermodynamics were implemented as a specific library. In addition to releasing the simulator as Open Source, the NAM-IP museum also publicly archived the available technical documentation.</p>

Why build an 8-bit homebrew computer in 2026 (en)

<p>Who needs to build their very own 8-bit homebrew computer in 2026? I'd say everyone should, especially if you work in IT! The Memo-1 is my personal attempt at understanding computers from the transistor up to the UI: a complete 6502-based system built from scratch, using a French Minitel as a smart terminal, with sound, joystick ports and an extension slot for expansions. In this talk, I'll share what I learned from building the Memo-1, from wiring the CPU and designing a simple bus architecture to writing a Minitel library in 6502 assembly. Beyond the nostalgia, it's been a fantastic hands-on way to rediscover and demystify how computers really work.</p>

Dial-up revisited: Why it's needed and how to run an oldschool ISP (en)

<p>Dial-up was the main way to connect to the Internet back in the 90s. Unfortunately, within the time almost all of the dial-up service providers are shut down, because of obvious reasons. It used to connect our living room to the world via 56 kbps (or less) bandwidth rate, in comparison, modern broadband global mean is two thousand times faster. But sometimes we still need it to connect our legacy hardware to the world, retro (or lowres) computing purposes, sometimes even to circumvent censorship.</p> <p>In this talk, after a brief on the dial-up connection and it's nature, notes and methods on running a personal dial-up ISP and connecting to it will be covered; starting from hardware requirements for both ISP and client side and the software stack for GNU/Linux operating system to run a dial-up system, using only free/libre software.</p>

Accelerating scientific code on AI hardware with Reactant.jl (en)

<p>Scientific models are today limited by compute resources, forcing approximations driven by feasibility rather than theory. They consequently miss important physical processes and decision-relevant regional details. Advances in AI-driven supercomputing — specialized tensor accelerators, AI compiler stacks, and novel distributed systems — offer unprecedented computational power. Yet, scientific applications such as ocean models, often written in Fortran, C++, or Julia and built for traditional HPC, remain largely incompatible with these technologies. This gap hampers performance portability and isolates scientific computing from rapid cloud-based innovation for AI workloads.</p> <p>In this talk we present <a href="https://github.com/EnzymeAD/Reactant.jl"><code>Reactant.jl</code></a>, a free and open-source optimising compiler framework for the Julia programming language, based on MLIR and XLA. <code>Reactant.jl</code> preserves high-level semantics (e.g. linear algebra operations), enabling aggressive cross-function, high-level optimisations, and generating efficient code for a variety of backends (CPU, GPU, TPU and more). Furthermore, <code>Reactant.jl</code> combines with <a href="https://enzyme.mit.edu/">Enzyme</a> to provide high-performance multi-backend automatic differentiation.</p> <p>As a practical demonstration, we will show the integration of <code>Reactant.jl</code> with <a href="https://github.com/CliMA/Oceananigans.jl"><code>Oceananigans.jl</code></a>, a state-of-the-art GPU-based ocean model. We show how the model can be seamlessly retargeted to thousands of distributed TPUs, unlocking orders-of-magnitude increases in throughput. This opens a path for scientific modelling software to take full advantage of next-generation AI and cloud hardware — without rewriting the codebase or sacrificing high-level expressiveness.</p>

ROCm™ on TheRock(s) (en)

<p>ROCm™ has been AMD’s software foundation for both high-performance computing (HPC) and AI workloads and continues to support the distinct needs of each domain. As these domains increasingly converge, ROCm™ is evolving into a more modular and flexible platform. Soon, the distribution model shifts to a core SDK with domain-specific add-ons—such as HPC—allowing users to select only the components they need. This reduces unnecessary overhead while maintaining a cohesive and interoperable stack.</p> <p>To support this modularity, AMD transitions to TheRock, an open-source build system that enables component-level integration, nightly and weekly builds, and streamlined delivery across the ROCm™ stack. TheRock is designed to handle the complexity of building and packaging ROCm™ in a way that’s scalable and transparent for developers. It plays a central role in how ROCm™ is assembled and delivered, especially as the platform moves toward more frequent and flexible release cycles.</p> <p>In this talk, we’ll cover the entire development and delivery pipeline—from the consolidation into three super-repos to how ROCm™ is built, tested, and shipped. This includes an overview of the development process, the delivery mechanism, TheRock’s implementation, and the testing infrastructure. We’ll also explain how contributors can engage with ROCm™—whether through code, documentation, or domain-specific enhancements—making it easier for developers to help shape the platform.</p> <p>Online resources TheRock: https://github.com/ROCm/TheRock rocm-libraries: https://github.com/ROCm/rocm-libraries rocm-systems: https://github.com/ROCm/rocm-systems </p> <p>Most projects are under MIT license.</p> <p>Speaker JP Lehr, Senior Member of Technical Staff, ROCm™ GPU Compiler, AMD</p> <p>© 2026 Advanced Micro Devices, Inc. All rights reserved. AMD, the AMD Arrow logo, ROCm, and combinations thereof are trademarks of Advanced Micro Devices, Inc. Other product names used in this publication are for identification purposes only and may be trademarks of their respective companies. LLVM is a trademark of LLVM Foundation. The OpenMP name and the OpenMP logo are registered trademarks of the OpenMP Architecture Review Board.</p>

JUBE: An Environment for systematic benchmarking and scientific workflows (en)

<p>Wherever research software is developed and used, it needs to be installed, tested in various ways, benchmarked, and set up within complex workflows. Typically, in order to perform such tasks, either individual solutions are implemented - imposing significant restrictions due to the lack of portability - or the necessary steps are performed manually by developers or users, a time-consuming process, highly susceptible to errors. Furthermore, particularly in the field of high-performance computing (HPC), where large amounts of data are processed and the computer systems used are unique worldwide, not only performance, scalability, and efficiency of the applications are important, but so are modern research software engineering (RSE) principles such as reproducibility, reusability, and documentation.</p> <p>With these challenges and requirements in mind, JUBE [1] (Jülich Benchmarking Environment) has been developed at the Jülich Supercomputing Centre (JSC), enabling automated and transparent scientific workflows. JUBE is a generic, lightweight, configurable environment to run, monitor and analyze application execution in a systematic way. It is a free, open-source software implemented in Python that operates on a "definition-based" paradigm where the “experiment” is described declaratively in a configuration file (XML or YAML). The JUBE engine is responsible for translating this definition into shell scripts, job submission files, and directory structures. Due to its standardized configuration format, it simplifies collaboration and usability of research software. JUBE also complements the Continuous Integration and Continuous Delivery (CI/CD) capabilities, leading to Continuous Benchmarking.</p> <p>To introduce and facilitate JUBE’s usage, the documentation includes a tutorial with simple and advanced examples, an FAQ page, a description of the command line interface, and a glossary with all accepted keywords [2]. In addition, a dedicated Carpentries course offers an introduction to the JUBE framework [3] (basic knowledge of the Linux shell and either XML or YAML are beneficial when getting started with JUBE). A large variety of scientific codes and standard HPC benchmarks have already been automated using JUBE and are also available open-source [4].</p> <p>In this presentation, an overview of JUBE will be provided, including its fundamental concepts, current status, and roadmap of future developments (external code contributions are welcome). Additionally, three illustrative use cases will be introduced to offer a comprehensive understanding of JUBE's practical applications: - benchmarking as part of the procurement of JUPITER, Europe’s first exascale supercomputer; - a complex scientific workflow for energy system modelling [5]; - continuous insight into HPC system health by regular execution of applications, and the subsequent graphical presentation of their results.</p> <p>JUBE is a well-established software, which has already been used in several national and international projects and on numerous and diverse HPC systems [6-13]. Besides being available via EasyBuild [14] and Spack [15], further software has been built up based on JUBE [16,17]. Owing to its broad scope and range of applications, JUBE is likely to be of interest to audiences in the HPC sector, as well as those involved in big data and data science.</p> <p>[1] https://github.com/FZJ-JSC/JUBE [2] https://apps.fz-juelich.de/jsc/jube/docu/index.html [3] https://carpentries-incubator.github.io/hpc-workflows-jube/ [4] https://github.com/FZJ-JSC/jubench [5] https://elib.dlr.de/196232/1/2023-09_UNSEEN-Compendium.pdf [6] MAX CoE: https://max-centre.eu/impact-outcomes/key-achievements/benchmarking-and-profiling/ [7] RICS2: https://risc2-project.eu/?p=2251 [8] EoCoE: https://www.eocoe.eu/technical-challenges/programming-models/ [9] DEEP: https://deep-projects.eu/modular-supercomputing/software/benchmarking-and-tools/ [10] DEEP-EST: https://cordis.europa.eu/project/id/754304/reporting [11] IO-SEA: https://cordis.europa.eu/project/id/955811/results [12] EPICURE: https://epicure-hpc.eu/wp-content/uploads/2025/07/EPICURE-BEST-PRACTICE-GUIDE-Power-measurements-in-EuroHPC-machines_v1.0.pdf [13] UNSEEN: https://juser.fz-juelich.de/record/1007796/files/UNSEEN_ISC_2023_Poster.pdf [14] EasyBuild: https://github.com/easybuilders/easybuild-easyconfigs/tree/develop/easybuild/easyconfigs/j/JUBE [15] Spack: https://packages.spack.io/package.html?name=jube [16] https://github.com/edf-hpc/unclebench [17] https://dl.acm.org/doi/10.1145/3733723.3733740</p>

Scaling Gmsh-based FEM on LUMI: Efficiently Handling Thousands of Partitions (en)

<h2>Content</h2> <p>High-frequency wave simulations in 3D (with e.g. Finite Elements) involve systems with hundreds of millions unknowns (up to 600M in our runs), prompting the use of massively parallel algorithms. In the harmonic regime, we favor Domain Decomposition Methods (DDMs) where local problems are solved in smaller regions (subdomains) and the full solution of the PDE is recovered iteratively. This requires each rank to own a portion of the mesh and to have a view on neighboring partitions (ghost cells or <em>overlaps</em>). In particular, the <em>Optimized Restricted Additive Schwarz</em> algorithm requires assembling matrices at the boundary of overlaps, which requires creating additional elements after the partitioning.</p> <p>During the last two years, I pushed our in-house FEM code (GmshFEM) to run increasingly large jobs, from 8 MPI ranks on a laptop, through local and national clusters, up to more than 30,000 ranks on LUMI. Each milestone provided its own challenges in the parallel implementation: as the problem size increases, simple global reductions can go from being a minor synchronization to being a major bottleneck, redundant information in partitioned meshes can eat hundreds of gigabytes of RAM, and load-balancing issues can become dominant.</p> <p>In this talk, I will describe how we tackled these challenges and how the future versions of Gmsh will take into account these issues. In particular, the next version of the MSH file format will be optimized to reduce data duplication across subdomains. I will also present the new API for querying information about partitioned meshes, such as retrieving elements in overlapping regions.</p> <h2>About Gmsh</h2> <p>Gmsh (https://gmsh.info/) is an open-source (GPL-2) finite element mesh generator widely used in scientific and engineering applications. It provides a graphical interface, a scripting language for automation, and language bindings (C/C++, Fortran, Python, Julia). In this work, Gmsh serves as the front-end mesh generator for large-scale distributed FEM simulations using our in-house solver GmshFEM (https://gitlab.onelab.info/gmsh/fem).</p>

Productive Parallel Programming with Chapel and Arkouda (en)

<p>As the computing needs of the world have grown, the need for parallel systems has grown to match. However, the programming languages used to target those systems have not had the same growth. General parallel programming targeting distributed CPUs and GPUs is frequently locked behind low-level and unfriendly programming languages and frameworks. Programmers must choose between parallel performance with low-level programming or productivity with high-level languages.</p> <p><a href="https://chapel-lang.org/">Chapel</a> is a programming language for productive parallel programming that scales from laptops to supercomputers. This talk will focus on the ways that Chapel addresses the above gap, giving programmers used to high level languages like Python access to distributed parallel performance. Chapel has long been open-source, but recently moved to become one of the many amazing projects hosted under the <a href="https://hpsf.io/">High Performance Software Foundation</a>.</p> <p>The talk will include a description of Chapel and its performance as well as a few examples of Chapel programs. I will also present Arkouda, an exploratory data science tool for massive scales of data. Arkouda is built in Chapel and completely closes the accessibly gap for Python programmers to access supercomputer-scale data analysis.</p>

Track Energy & Emissions of User Jobs on HPC/AI Platforms using CEEMS (en)

<p>With the rapid acceleration of ML/AI research in the last couple of years, the already energy-hungry HPC platforms have become even more demanding. A major part of this energy consumption is due to users’ workloads and it is only by the participation of end users that it is possible to reduce the overall energy consumption of the platforms. However, most of the HPC platforms do not provide any sort of metrics related to energy consumption, nor the performance metrics out of the box, which in turn do not encourage end users to optimize their workloads. </p> <p>The Compute Energy &amp; Emissions Monitoring Stack (CEEMS) has been designed to address this issue. CEEMS can report energy consumption and equivalent emissions of user workloads in real time for SLURM (HPC), Openstack (Cloud) and Kubernetes platforms alike. It leverages the Linux perf subsystem and eBPF to monitor the performance metrics of the applications, which can help the end users to identify the bottlenecks in their workflows rapidly and consequently optimize them to reduce the energy and carbon footprint. CEEMS supports eBPF-based continuous profiling and it is the first monitoring stack to support continuous profiling on HPC platforms. Another advantage of CEEMS is that it can systematically monitor all the jobs on the platform without the end users having to modify their workflows or codes. </p> <p>Besides CPU energy usage, it supports reporting energy usage and performance metrics of workloads on NVIDIA and AMD GPU accelerators. CEEMS has been built around the prominent open-source tools in the observability ecosystem, like Prometheus and Grafana. CEEMS has been designed to be extensible and it allows the HPC center operators to easily define the energy estimation rules of user workloads based on the underlying hardware. CEEMS monitors I/O and network metrics in a file system agnostic manner, allowing it to work on any parallel file system used by HPC platforms. Finally, the talk will conclude by showing how CEEMS monitoring is used on the Jean-Zay HPC platform with more than 2000 nodes that have a daily job churn rate of around 20k jobs.</p>

Partly Cloudy with a Chance of Zarr: A Virtualized Approach to Zarr Stores from ECMWF's Fields Database (en)

<p><a href="www.ecmwf.int">ECMWF</a> manages petabytes of meteorological data critical for weather and climate research. But traditional storage formats pose challenges for machine learning, big-data analytics, and on-demand workflows. </p> <p>We propose a solution which introduces a Zarr store implementation for creating virtual views of ECMWF’s Fields Database (FDB), enabling users to access GRIB data as if it were a native Zarr dataset. Unlike existing approaches such as VirtualiZarr or Kerchunk, our solution leverages the domain-specific MARS language to define virtual Zarr v3 stores directly from scientific requests, bridging GRIB and Zarr for dynamic, cloud-native access. </p> <p>This work is developed as part of the <a href="https://warmworld.de/">WarmWorld Easier</a> project, aiming to make climate and weather data more interoperable and accessible for the scientific community. By combining the efficiency of FDB with the flexibility of Zarr, we unlock new possibilities for HPC, big-data analytics, and machine learning pipelines. </p> <p>In this talk, we will explore the architecture, discuss performance considerations, and demonstrate how virtual Zarr views accelerate integration in open-source workflows.</p> <p>This session will: - Explain the motivation behind creating virtual Zarr views of ECMWF’s Fields Database. - Detail the design and implementation of a custom Zarr Store that translates Zarr access patterns into MARS requests. - Discuss performance trade-offs and scalability in HPC contexts. - Showcase real-world examples of how this approach may support data science workflows, machine learning, and distributed computing.</p>

Zero‑Touch HPC Nodes: NetBox, Tofu and Packer for a Self‑Configuring SLURM Cluster (en)

<p>Over the last five years, we ran an HPC system for life sciences on top of OpenStack, with a deployment pipeline built from Ansible, manual steps (see <a href="https://archive.fosdem.org/2020/schedule/event/hpc_openstack/">FOSDEM 2020 talk</a>). It worked—but it wasn’t something we could easily rebuild from scratch or apply consistently to other parts of our infrastructure.</p> <p>As we designed our new HPC system (coming online in early 2026), we set ourselves a goal: treat the cluster as something we can declare and then recreate, not pet and nurture. The result is a “zero‑touch” style pipeline where a new node can go from “just racked” to “in SLURM and running jobs” with no manual intervention.</p> <p>In this talk, we walk through the end‑to‑end workflow:</p> <ul> <li>NetBox as DCIM and source of truth: racking a server and adding it to NetBox is the trigger; MACs, serials and IPs are automatically imported from vendor tools and IPAM/DNS into our automation.</li> <li>Using Tofu/Terragrunt (instead of Openstack's Heat orchestration service) to provision OpenStack/Ironic, SLURM infrastructure and network fabric across three environments (dev plus two interchangeable prod clusters for blue/green rollouts).</li> <li>Image‑based deployment with Packer and Ansible: we split roles into “install” and “configure”. Packages and heavy setup are baked into images, while an ansible-init service runs locally on first boot to apply configuration and join the cluster.</li> <li>Making nodes self‑sufficient, including fetching the secrets they need via short‑lived credentials and a minimal external dependency chain.</li> </ul> <p>Come and see how we built a reproducible HPC/Big-Data cluster on open‑source tooling, reusing as much of the stack as possible for the rest of our infrastructure.</p>

Accelerating complex Bioinformatics AI pipelines with Kubernetes (en)

<p>Bioinformatics is an interdisciplinary scientific field that deals with large amounts of biological data. The advent of transformer models applied to this field brought very interesting scientific innovations, including the introduction of Protein Language Models (PLMs) and Antibody Language Models (AbLMs). The complexity of training or fine tuning PLMs/AbLMs along with inference tasks requires a non-trivial amount of GPU resources and a disciplined approach, where DevOps and MLOps methodologies fit very well. In this session we will present a series of tasks related to fine tuning PLMs/AbLMs for classification of SARS-CoV-2's spike proteins. We will highlight how Kubernetes can be used to execute large numbers of computationally intensive tasks on GPU hosts, including best practices for sharing Nvidia GPUs (MIG, Time Slicing, MPS) as part of an open source stack orchestrated with Apache Airflow. While these methodologies can be applied to any Kubernetes cluster, including on hyperscalers, this talk is meant to facilitate the (re)use of on-prem hardware infrastructure, presenting a fully open-source stack that can be easily deployed and maintained on bare metal.</p> <p>Source code: https://github.com/alexpilotti/bbk-mres https://github.com/alexpilotti/bbk-mres-airflow</p> <p>Overview of the scientific research made possible by this pipeline: https://cloudba.se/NeBzX</p>

Observability for AI Workloads on HPC: Beyond GPU Utilization Metrics (en)

<p>When you run LLMs or large-scale ML training on HPC clusters, traditional monitoring falls short. GPU utilization at 95% tells you nothing about model quality. Memory bandwidth looks healthy while your inference latency silently degrades. Your job scheduler reports success while concept drift erodes prediction accuracy. This talk introduces a practical observability framework specifically designed for AI workloads on HPC infrastructure, what I call "Cognitive SLIs" (Service Level Indicators for AI systems). I'll cover three critical gaps in current HPC monitoring: 1. Model-aware metrics that matter 2. GPU observability beyond utilization 3. Energy and cost accountability</p> <p>The demo shows a complete stack built with open source tools: Victoria metrics with custom AI-specific exporters, Grafana dashboards designed for ML engineers (not just sysadmins), and OpenTelemetry instrumentation patterns for PyTorch/JAX workloads.</p> <p>Attendees will leave with the following resources :</p> <p>1)Architecture patterns for instrumenting HPC AI workloads 2) Victoria Metrics recording rules and alerting strategies for ML metrics 3)Grafana dashboard templates (GitHub repo provided) 4) Understanding of how AI Act logging requirements intersect with HPC operations</p>

Developing software tools for accelerated and differentiable scientific computing using JAX (en)

<p><a href="https://docs.jax.dev/en/latest/">JAX</a> is an open-source Python package for high-performance numerical computing. It provides a familiar NumPy style interface but with the advantages of allowing computations to be dispatched to accelerator devices such as graphics and tensor processing units, and supporting transformations to automatically differentiate, vectorize and just-in-time compile functions. While extensively used in machine learning applications, JAX's design also makes it ideal for scientific computing tasks such as simulating numerical models and fitting them to data.</p> <p>This lightning talk will introduce JAX's interface and computation model, and some of its key function transformations. I will also briefly introduce the <a href="https://data-apis.org/array-api/latest/#">Python Array API standard</a> and explain how it can be used to write portable code which works across JAX, NumPy and other array backends.</p>

High Performance Jupyter Notebooks with Zasper (en)

<p>Data science tools have come far, with <strong>Project Jupyter</strong> at the core. But what if we could greatly boost their performance, without leaving the Python ecosystem?</p> <p>Introducing Zasper, an IDE for Jupyter notebooks build in Go with up to <strong>5× less CPU and 40× less RAM</strong> thats also blazingly fast.</p>

Update on the High Performance Software Foundation (HPSF) (en)

<p>The High Performance Software Foundation (HPSF) is a hub for open-source, high performance software with a growing set of member organizations and projects across the US, Europe, and Asia. It aims to advance portable software for diverse hardware by increasing adoption, aiding community growth, and enabling development efforts. It also fosters collaboration through working groups such as Continuous Integration, Benchmarking, and Binary distribution.</p> <p>This talk will give an overview of HPSF and an update on its latest activities. We’ll talk about new member projects, new member organizations. We’ll give an update on plans for the European HPSF Community Summit 2026 and HPSFCon 2026. We’ll talk about how HPSF is supporting member projects and building collaborations that advance the HPSF community, and we’ll talk about project support and outreach activities.</p> <p>Find out how you can benefit from joining or collaborating with HPSF, and help to improve the HPC open source world.</p>

Package management in the hands of users: dream and reality (en)

<p>Are HPC users autonomous? How much flexibility does one have when deploying software on a supercomputer? How close to one’s laptop development environment is it? How have EasyBuild, Spack, Guix, and Apptainer helped improve the situation in the past decade?</p> <p>In this talk, I will look at the situation with lucidity. While Spack and EasyBuild enable software deployment by users, their primary user base appears to be HPC system administrators. Thus most HPC admins let users bring their own Singularity/Apptainer images when their needs are not satisfied—effectively “giving up” on complex deployment.</p> <p>Brave and fearless, the Guix-HPC effort has not given up on the goal of putting reproducible package management in the hands of users, with successes and disappointments. I will report on our experience with Tier-2 supercomputers now providing Guix, and on ongoing work with French national supercomputers (“Tier-1”) as part of NumPEx, the French national program for HPC.</p> <p>We will look back at the set of challenges overcome in past years—from supporting rootless execution of the build daemon, to making the bring-your-own-MPI approach viable and to enhancing support for CPU micro-architecture optimizations—and those yet to come.</p>

Spack v1.0 and Beyond: Managing HPC Software Stacks (en)

<h2>Abstract</h2> <p>Spack is a flexible multi-language package manager for HPC, Data Science, and AI, designed to support multiple versions, configurations, and compilers of software on the same system. Since the last FOSDEM, the Spack community has reached a major milestone with the release of Spack v1.0, followed closely by v1.1. This talk will provide a comprehensive overview of the "What's New" in these releases, highlighting the changes that improve robustness, performance, and user experience. We will cover among other things the shift to modeling compilers as dependencies, the package repository split, and the new jobserver-aware parallel installer.</p> <h2>Description</h2> <p>With the release of Spack v1.0 in July 2025 and v1.1 in November 2025, the project has introduced significant architectural changes and new features requested by the community. In this talk, we will dive into the key features introduced across these releases:</p> <ul> <li><strong>Compilers as dependencies.</strong> Spack has fulfilled an old promise from FOSDEM 2018. Compilers are modeled as first-class dependencies, dependency resolution is more accurate, and binary distribution and ABI compatibility checks are more robust.</li> <li>The <strong>separation of the package repository</strong> from the core tool and the introduction of a versioned Package API allows users to pin the package repository version independently from Spack itself and enables regular package repository releases.</li> <li><strong>Parallel builds with a new user interface.</strong> Spack has a new scheduler that coordinates parallel builds using the POSIX jobserver protocol, allowing efficient resource sharing across all build processes. The decades-old jobserver protocol is experiencing a major renaissance, adopted recently by Ninja v1.13 (July 2025) and the upcoming LLVM 22 release. We’ll talk about how this enables composable parallelism across make, ninja, cargo, GCC, LLVM, Spack, and other tools.</li> </ul> <h2>Expected Prior Knowledge / Intended Audience</h2> <p>This talk is aimed at Research Software Engineers (RSEs), HPC system administrators, and Data Scientists who use or manage software stacks. Familiarity with Spack is helpful but not strictly required; the talk will be accessible to anyone interested in package management and software reproducibility in scientific computing.</p>

Status update on EESSI, the European Environment for Scientific Software Installations (en)

<p>A few years ago, the <a href="https://eessi.io/">European Environment for Scientific Software Installations</a> (EESSI) was <a href="https://archive.fosdem.org/2021/schedule/event/eessi/">introduced at FOSDEM</a> as a pilot project for improving software distribution and deployment everywhere, from HPC environments, to cloud environments or even a personal workstation or a Raspberry Pi . Since then, it has gained wide adoption across <a href="https://eessi.io/docs/systems/">dozens of HPC systems</a> in Europe, being installed natively in EuroHPC systems and becoming a component within the <a href="https://my-eurohpc.eu/">EuroHPC Federation Platform</a>. </p> <p>This session will highlight the progress EESSI has made, including the addition of new <a href="https://www.eessi.io/docs/software_layer/cpu_targets/">CPU</a> and <a href="https://www.eessi.io/docs/software_layer/gpu_targets/">GPU</a> targets, with broader support for modern computing technologies and much <a href="https://www.eessi.io/docs/available_software/overview">more software</a>, featuring 600+ unique software projects (or over 3500 if you count individual Python packages and R libraries that are included) shipped with it. EESSI's capabilities have expanded significantly, turning it into a key service for managing and deploying software across a wide range of infrastructures.</p> <p>We will provide an overview of the current status of EESSI, focusing on its new capabilities, the integration with tools like <a href="https://spack.io/">Spack</a> and <a href="https://www.openondemand.org/">Open OnDemand</a>, as well as its growing software ecosystem. Through a live hands-on demo, we will showcase how EESSI is being used in real-world HPC environments and cloud systems, and discuss the future direction of the platform. Looking ahead, we will cover upcoming features and improvements that will continue to make EESSI a solid enabler for HPC software management in Europe and beyond.</p>

Using OpenMP's interop for calling GPU-vendor libs with GCC (en)

<p>GPU vendors provide highly optimized libraries for math operations such as fast Fourier transformation or linear algebra (FFT, (sparse)BLAS/LAPACK, …) to perform those on devices. And OpenMP is a popular, vendor-agnostic method for parallelization on the CPU but increasingly also for offloading calculations to the GPU.</p> <p>This talk shows how OpenMP can be used to reduce to reduce vendor-specific code, make calling it more convenient, and to combine OpenMP offloading with those libraries. While the presentation illustrates the use with the GNU Compiler Collection (GCC), the feature is a generic feature of OpenMP 5.2, extended in 6.0, and is supported by multiple compilers.</p> <p><em>In terms of OpenMP features, the 'interop' directive provides the interoperability support, the 'declare variant' directive with the 'adjust_args' and 'append_args' clauses enable to write neater code; means for memory allocation and memory transfer and running code blocks on the GPU ('target' construct) complete the required feature set.</em></p> <ul> <li>The <strong>OpenMP specification,</strong> current, past and future version, errata and example documents can be found at https://www.openmp.org/specifications/; a list of compilers and tools for OpenMP is at https://www.openmp.org/resources/openmp-compilers-tools/</li> <li><strong>GCC's OpenMP documentation</strong> is available at https://gcc.gnu.org/onlinedocs/libgomp/ (API routines, implementation status, …) and, in particular, the supported interop foreign runtimes are documented at https://gcc.gnu.org/onlinedocs/libgomp/Offload-Target-Specifics.html; GCC supports offloading to Nvidia and AMD GPUs. GCC supports OpenMP interop since GCC 15, including most of the OpenMP 6.0 additions, including the Fortran API routines.</li> </ul>

A Brief* overview of what makes modern accelerators interesting for HPC (en)

<p>Evaluating and discussing what makes different types of accelerators interesting for which types of workloads, and the mental model most appropriate for choosing them. </p> <p>Why it's sometimes a good idea to ignore them all and *just use a CPU, all the way to when FPGAs become interesting as a means of doing more science</p>

Welcome to the Open Hardware and CAD/CAM Devroom (en)

<p>Introduction to the Open Hardware and CAD/CAM Devroom</p>

Verilog-AMS in Gnucap (en)

<p>Gnucap is a free/libre versatile and modern, modular, analog and mixed-signal simulator. Verilog-AMS is a standardised behavioural language for analog and mixed-signal systems based on the IEEE 1364-2005 industry standard, commonly known as Verilog. Verilog and its extensions offer a portable representation for circuits and device models consistent across application domains. With funding from NLnet we are pushing for standardisation in an otherwise heterogeneous environment of traditional and incompatible tools.</p> <p>We are working on a first open source (and free/libre) Verilog-AMS implementation. It consists of extensions for Gnucap that elaborate circuits represented in Verilog, provide suitable simulation algorithms and interface with artifacts from related projects. The companion tool Modelgen-Verilog deals with behavioural models for mixed-signal devices, turning them into plugins for Gnucap.</p> <p>In this talk we will explain the need for standard support in free software tools and summarise the developments since FOSDEM-25. We have filled gaps in the simulator infrastructure and extended the standard coverage vastly improving the user experience. We will outline some related ongoing activities, e.g. on porting open source PDKs to Verilog, on the Qucs schematic editor and on device libraries as well as testing and QA.</p>

ECAD / MCAD collaboration with IDX (en)

<p>PCB design often require a lot of exchange with mechanical CAD softwares especially when the mechanical integration has a lot of constraints. Today, most of the time, the ECAD/MCAD collaboration is done through STEP, DXF, SVG, or other file formats, and usually a combination of several of them.</p> <p>The IDX protocols aims at using a single protocol, that will keep tracks of the changes incrementally as the design goes on, and even use a shared library of components, bridging the gap between the electrical and the mechanical worlds.</p> <p>Implemented in KiCad at first, it will allow interfacing with most commercial MCAD softwares used in the industry, and certainly pave the way for the open source ones.</p>

KiConnect 1 Year In (en)

<p>Just about a year ago I started on my 3rd attempt at building a new FreeCAD workbench to provide bidirectional syncing between FreeCAD and KiCAD with a focus on multiple boards and minimal user interaction. With KiCAD v9 being release with it's new long-term API it made sense to try again.</p> <p>This is a followup to my KiCon 2025 which I will detail some of the progress that has been made since, and impressions of the KiCAD API as I've used it more.</p>

Dune 3D - 2½ years in the 3rd dimension (en)

<p>Dune 3D is parametric 3D CAD application I started developing about 2½ years ago. It combines the solver from Solvespace with OpenCASCADE for a geometry kernel under a modern Gtk4-based user interface.</p> <p>In this talk, I'll go into how the project evolved in the past two years as well as what's ahead.</p> <p>https://dune3d.org/</p>

Designing EUR 20 Open Source Hardware running Free/Libre Open Source Software IoT home server (en)

<p>There are thousands of different IoT devices on the market. To control them, you currently have a few options:</p> <ol> <li> <p>Use the vendor’s cloud service. This approach has many problems: there is no interoperability between different vendors, so you end up installing 10 different cloud apps for 10 different devices; there are privacy concerns; and anything beyond the basics usually requires paid features.</p> </li> <li> <p>Use an open-source platform such as Home Assistant, OpenHAB, Domoticz, FHEM, PiDome, or Majordomo. These platforms are powerful but often too complex, time-consuming to learn, and relatively expensive to run—typically EUR 100+ and tens or even hundreds of hours of study.</p> </li> </ol> <p>Currently, there is no simple, easy-to-use, and low-cost solution on the market.</p> <p>We accepted this challenge and are now designing an open-source hardware solution running Free/Libre Open Source Software. Our goal is a device that costs around EUR 20 for the end user, offers more functionality than typical vendor cloud services, and remains fully open for modification and customization by anyone interested.</p> <p>After six months of work, we already have a functioning hardware prototype and software that supports basic features.</p> <p>In this presentation, I will discuss the challenges we encountered, demonstrate our current progress, and highlight the major obstacles we are facing. If others share a similar interest, your help and collaboration are very welcome.</p>

LibrePCB 2.0 – More Than Just a New Look (en)

<p>LibrePCB 2.0 is an exciting milestone of our mission to provide an easy-to-use, modern, Open-Source PCB design software. With its completely redesigned user interface and new design concepts, the productivity and general user experience have been significantly improved. In this talk I will demonstrate the capabilities and advantages of LibrePCB 2.0, including other new features and improvements beyond its new UI. Also you will get an update about other aspects of the LibrePCB project, like our funding status or why &amp; how we started the transition from C++/Qt to more modern technologies.</p> <hr /> <p><a href="https://librepcb.org/">LibrePCB</a> is an Open-Source EDA software to design PCBs, providing the following advantages:</p> <ul> <li>Cross-platform: Windows/Linux/MacOS/Others | x86/ARM</li> <li>Intuitive &amp; easy-to-use UI</li> <li>Powerful library concept</li> <li>Human readable file format</li> </ul> <p>Whether you are a newbie or a professional engineer, LibrePCB is made for you - <a href="https://librepcb.org/download/">just give it a try</a>!</p>

The Blackpants are Pants for your Blackhat (en)

<p>I'm the developer of the Flipper Blackhat, a 100% open source WiFi addon board for your Flipper Zero. Unlike other modules, it doesn't use an ESP32, but a Allwinner Linux SoM. The question I hear most often is: "What’s the point of the Flipper Zero?"</p> <p>The Blackpants are a carrier board for the Blackhat, and my answer to this question. No longer do you need the Flipper Zero!</p> <p>In this talk I'll overview all the hardware and software of both the Blackpants and the Blackhat and my journey throughout developing the device! </p> <p>https://github.com/o7-machinehum/Blackpants</p> <p>https://github.com/o7-machinehum/flipper-blackhat</p> <p>https://youtu.be/tdRWB2ILRtY?si=evX8zsZ_B1GQfZtv</p>

How Open Hardware Projects Create Ecosystems (en)

<p>We're members of a hacker team that made <a href="https://blepis.0xlina.gay">Blepis</a>, a hacker-friendly and fully open-source Linux PDA. The Blepis project is a continuation of <a href="https://beepy.sqfmi.com/">Beepy PDA</a>, which in turn <a href="https://hackaday.com/2025/06/04/the-blackberry-keyboard-how-an-open-source-ecosystem-sprouts/">was made possible</a> thanks to a string of open-source hardware projects. We're here to tell you that story, share our own radical open-source strategy and how it's already been helping other open-source PDA projects grow, and also tell more about our project's journey.</p>

Collaboration, Iteration, Documentation, and Validation: An OpenFlexure Microscope Story (en)

<p>Developing hardware is hard. It's quite literally in the name. Building a global open source collaboration is also hard, and even harder when every new contributor needs to source physical components.</p> <p>In general the hardware development toolchain is locked down vastly expensive walled gardens, limiting contribution and collaboration to well funded organisations.</p> <p>This talk will explore how the OpenFlexure Microscope project uses (and abuses) a whole toolchain of open source software to manage, automate, and accelerate the design of a lab-grade microscope in use all over the world.</p>

KiCad Status (en)

<p>What to expect for the KiCad version 10 release, what the project hopes to achieve during version 11 development, and all the latest news about the KiCad project.</p> <p>https://www.kicad.org/</p>

FreeCAD - state of affairs (en)

<p>This is a generic state-of-affairs talk about <a href="https://freecad.org">FreeCAD</a>, a manner for people to catch up with all that has happened in the FreeCAD universe since last FOSDEM. We will show what is new in FreeCAD itself, what is cooking in the development kitchens, and a glimpse over community happenings and what the <a href="https://fpa.freecad.org">FPA</a>, the non-profit behind the project, has been doing.</p>

OCCT3D 8.0: Evolving the Open Source Geometry Kernel (en)

<p>OpenCascade Technology (OCCT) serves as the geometric backbone for the open-source CAD/CAM ecosystem, powering major platforms like FreeCAD, KiCad, and numerous industrial IFC viewers.</p> <p>In this session, the member of OCCT3D (Capgemini Engineering) will unveil the roadmap and technical achievements of the upcoming Version 8.0.0 release. We will discuss the architectural evolution required to support modern modeling challenges and the balance between industrial robustness and open-source flexibility.</p> <p>Key topics will include:</p> <ul> <li>The 8.0.0 Milestone: A breakdown of major breaking changes, API cleanups, and the transition strategies for developers.</li> <li>Core Algorithms: Improvements in Boolean operations, meshing robustness, and tolerance handling.</li> <li>Interoperability: Updates on data exchange formats.</li> </ul> <p>This talk is essential for developers relying on OCCT for their applications and users interested in the future of the underlying kernel that drives open hardware design.</p> <p>Project: https://github.com/Open-Cascade-SAS/OCCT Forum: https://dev.opencascade.org/forums OCCT3D: https://occt3d.com/</p>

A love letter to KiCAD ERC (en)

<p>The Electrical Rule Checks (ERC) in a CAD design software are a set of heuristic checks to help spotting potential mistakes in schematics. However, they have subtleties and quirks, which can lead people to fight against them instead of using them to their full potential. In this talk, I will discuss some of the pain points I have experienced or have whitnessed people experience while using ERC, give some tips, and encourage people to use them and even try and improve them even more. It will be illustrated by a few real-life blunders that a good use of ERC could have prevented. TL;DR: I love ERC.</p>

Externally verifying Linux’s real-time deadline scheduling capabilities (en)

<p>A number of industrial applications now demand hard real-time scheduling capabilities from the kernel of a Linux-based operating system, but scheduling measurements from the system itself cannot be completely trusted as they are referenced to the same clock as the kernel-under-test. Yet, if the system can output signals to hardware as it runs, their timing can be analysed by an external microcontroller, and a second "external" measurement obtained to compare with the system's own report.</p> <p>Codethink wrote embedded Rust firmware to run on a Raspberry Pi Pico which analyses the timings of characters received on a UART serial port. On the other end of the serial port is our "Rusty Worker": a Rust program on a Linux system which uses the <code>sched_setattr</code> syscall to request that Linux schedules it with specified parameters, and then measures its own scheduling period and runtime. The single-threaded and interrupt-based architecture of this firmware allowed accurate external measurements of the Rusty Worker’s scheduling parameters at microsecond precision, and meant it was easy to extend to monitor the "petting" behaviour of a watchdog.</p> <p>Rust was a natural choice for the verification firmware and Rusty Worker. Higher level or interpreted languages would increase non-determinism and reduce our confidence in the accuracy of the collected timing data, whereas C or C++ programs risk undefined behaviour unacceptable in a safety-related context. Yet, Rust really came into its own with the relative simplicity of the cargo toolchain for embedded targets, so reproducibly building the firmware with a self-built toolchain (and without access to the internet) was just as straightforward as building the Rusty Worker for a Linux target.</p> <p>Having equipped our suite of bare-metal CI runners with KiCad-designed custom PCBs that feature a Raspberry Pi Pico and Debug Probe, we are able to run “soak” tests to collect thousands of self- and externally-measured deadline scheduling parameters for each iteration of our <a href="https://www.codethink.co.uk/ctrl-os.html">Codethink Trustable Reproducible Linux (CTRL OS)</a>, as soon as engineers push a new commit. We then use the open source <a href="https://gitlab.com/CodethinkLabs/trustable/trustable">Eclipse Trustable Software Framework (TSF)</a> to facilitate automatic “real time” aggregation and statistical analysis of the external scheduling measurements for each commit, clearly communicating the results and trends to senior stakeholders and junior engineers alike.</p> <p>TSF challenges us both to robustly, systematically, and continuously evidence our claims about Linux’s capabilities as a real-time operating system, and to scrutinise the software used for testing as strictly as the software under test. We are excited to share how we work towards these goals with external scheduling measurements and embedded Rust.</p>

Instrument and Unit Test an Asm-only OS Kernel by Turning it into an Anykernel (en)

<p>OS kernel development is often connected with time consuming testing process and non-trivial debug technics. Although emulators like QEMU and Bochs ease this work significantly, nothing can compare with convenience of userspace developer environment. Moving parts of the kernel to the userspace binary is not straightforward, especially if the kernel has almost no compatibility with POSIX and is written entirely in assembly. Still, sometimes it is doable. The talk shares experience, architecture and design decisions of compiling VFS, block, and some other subsystems of KolibriOS as Linux® interactive shell program and a FUSE filesystem. Implemented unit testing framework and coverage collection tool for assembly (flat assembler) programs are also discussed.</p>

Testing on hardware with Claude AI (en)

<p>Talk about a project that implements a hardware-in-the-loop testing framework for validating Linux distributions on specific development boards. The system uses a universal testing harness that automatically detects target hardware platforms and adapts generic testing scripts to board-specific configurations with Claude AI help. Platform adaptation is achieved through specific configuration files that define board-specific parameters, enabling the same testing codebase to validate different hardware capabilities. The GitHub Actions CI/CD integration provides automated testing across multiple platforms, with matrix-based execution that flashes appropriate images and runs comprehensive validation including hardware-specific feature testing.</p>

Building a multi-arch CI pipeline for 13 targets. What could possibly go wrong? (en)

<p>The <strong>ci-multiplatform</strong> project is a generic, OCI-based multi-architecture CI system designed to make cross-platform testing practical for open-source projects using GitLab CI. Originally created while enabling RISC-V support for Pixman (https://gitlab.freedesktop.org/pixman/pixman), it has since grown into an independent project under the RISE (RISC-V Software Ecosystem) umbrella: https://gitlab.com/riseproject/CI/ci-multiplatform, with a mirror on freedesktop.org: https://gitlab.freedesktop.org/pixman/ci-multiplatform</p> <p>The project provides multi-arch layered OCI images (Base GNU, LLVM, Meson) based on Debian, GitLab Component-style templates, and fully automated downstream test pipelines for the included examples. It supports creating customized OCI images, building and testing across 16 Linux and Windows targets – including x86, ARM, RISC-V, MIPS, and PowerPC – using unprivileged GitLab runners with QEMU user-mode emulation. Architecture-specific options (e.g., RISC-V VLEN configuration) allow developers to exercise multiple virtual hardware profiles without any physical hardware, all within a convenient job-matrix workflow.</p> <p>The talk covers how the system is engineered, tested, and validated across multiple GitLab instances, and what happens when unprivileged runners, QEMU quirks, toolchain differences, and architecture-specific behaviours all converge in a single pipeline. I will show how projects can adopt ci-multiplatform with minimal effort and turn multi-arch CI from a maintenance burden into a routine part of upstream development.</p>

Unit Testing in Fortran (en)

<p>Testing is central to modern software quality, yet many widely used Fortran codebases still lack automated tests. Existing tests are often limited to coarse end-to-end regression checks that provide only partial confidence. With the growth of open-source Fortran tools, we can now bring unit testing and continuous validation to legacy and modern Fortran projects alike. </p> <p>This talk surveys the current landscape of Fortran testing frameworks before focusing on three I have evaluated in practice — pFUnit, test-drive and veggies — and explaining why pFUnit is often the most robust choice. I will discuss its JUnit-inspired design, use of the preprocessor, and the compiler idiosyncrasies that can still make adoption challenging. I will examine the hurdles that make testing Fortran hard: global state, oversized subroutines, legacy dependencies, and compiler-specific behaviour. </p> <p>I will then present community-oriented efforts to improve testing practices in Fortran, including development of an open-source Carpentries-style training course on testing in Fortran, with plans to expand into a broader introduction to sustainable Fortran development using open-source linting and documentation tools such as Fortitude and Ford. </p> <p>Attendees will gain practical guidance for introducing effective testing into existing Fortran codebases, and insight into current efforts towards modern workflows that support reproducibility and continuous delivery.</p>

Testing ESPHome in the real world (en)

<p>ESPHome is a versatile framework to create custom firmware for various microcontrollers. In this talks we will look at how to automatically test the latest ESPHome firmware on an ESP32.</p> <p>As ESPHome devices are used to interact with the real world, we will also look at how to test that the LUX sensors is able to detect light variations.</p> <p>In order to test the ESP32 device, we are going to use lava on the command line, directly inside a gitlab runner.</p>

Unified Quality Feedback Across CI/CD Pipelines (en)

<p>The CI/CD server Jenkins provides powerful build-quality visualizations through plugins such as <a href="https://plugins.jenkins.io/warnings-ng/">Warnings</a>, <a href="https://plugins.jenkins.io/coverage/">Coverage</a>, and <a href="https://plugins.jenkins.io/git-forensics/">Git Forensics</a>. These plugins aggregate and visualize data from static analysis tools, coverage reports, software metrics, and Git history, enabling teams to track quality trends across builds. We have now brought this functionality to other widely used CI/CD platforms, including GitHub Actions and GitLab CI.</p> <p>This talk presents portable, UI-independent implementations of these capabilities for GitHub Actions and GitLab CI: the <a href="https://github.com/uhafner/quality-monitor">quality monitor</a> GitHub Action and the <a href="https://github.com/uhafner/autograding-gitlab-action">GitLab autograding-action</a>. Both tools share a common architecture and codebase with the Jenkins plugins. They automatically analyze pull requests and branch pipelines, generate structured comments and concise Markdown summaries, and enforce configurable quality gates. The solutions are language-agnostic and integrate seamlessly with more than 150 static analysis, coverage, test, and metrics report formats—including Checkstyle, SpotBugs, SARIF, JUnit, JaCoCo, GoCov, and GCC. Additionally, both tools provide an autograding mode for educational use, enabling instructors to assess student submissions through a flexible, configurable point-based scoring system.</p>

CI/CD with Gerrit, AI-Enhanced Review, and Hardware-in-the-Loop Testing in Jenkins Pipelines (en)

<p>CI/CD with Gerrit, AI-Enhanced Review, and Hardware-in-the-Loop Testing in Jenkins Pipelines This presentation will explore advanced Continuous Integration (CI) strategies essential for open-source embedded systems development, moving beyond standard software testing to encompass physical hardware validation. We will begin by establishing the necessity of integrating rigorous unit and integration testing directly into the development workflow, demonstrating how to effectively define these steps within Jenkins Declarative Pipelines (DSL). The core of our approach involves deep integration with Gerrit Code Review, ensuring that tests and static analysis are triggered automatically upon every patch set creation, providing fast feedback to developers. A significant portion of the talk will focus on achieving true end-to-end validation through Hardware-in-the-Loop (HIL) testing. We will detail the implementation of Labgrid, an open-source tool used to manage and control remote hardware resources (such as embedded boards and IoT devices). This integration allows the Jenkins pipeline to reserve, provision, and execute automated, system-level tests directly on physical target devices before firmware changes are merged. Furthermore, we will introduce two critical elements for pipeline stability and code quality. Firstly, we will demonstrate the utility of an AI-Powered Error Explanation component (e.g., via the Explain Error Plugin). This feature leverages large language models to analyze complex Jenkins log files and pipeline failures, translating cryptic errors into human-readable insights and suggested fixes, which dramatically cuts down debugging time. Secondly, we will showcase the Warnings Next Generation (Warning-NG) Plugin, which serves as a central aggregator, collecting and visualizing issues and potential vulnerabilities reported by various static analysis tools, thereby enforcing strict, quantifiable quality gates within the CI process. Attendees will gain practical, cutting-edge insights into implementing a robust, AI and hardware-enhanced CI/CD workflow suitable for modern open-source projects.</p>

Non-Blocking Continuous Code Reviews (en)

<p>The problem with the current most commonly accepted way of running code reviews using Pull Requests is that they have the nasty habit of blocking the flow of delivery. They introduce a cost of delay. Any delay reduces feedback. Consequently, it drives down quality.</p> <p>The usual way to achieve fast, efficient and effective Continuous Code Reviews without disrupting the flow of delivery is through Pair Programming or Team Programming. However, for various valid reasons, these can be a cultural stretch for many teams and organisations.</p> <p>In 2012, a novice team practising trunk-based development set in place a fairly uncommon but efficient alternative to implementing continuous code reviews on mainline without ever blocking the flow of delivery.</p> <p>This team went from a bunch of rag-tags to becoming a reference team within the organisation, with auditors falling to the floor due to the high quality the team delivered. Target audience: software engineers, test engineers, infrastructure engineers, team leads, engineering managers, CTOs</p>

Developer Experience is more than just Productivity metrics (en)

<p>With everything changing in tech at a frenetic pace, the emphasis on developer productivity has overshadowed the true essence of developer experience (DevEx). While frameworks like SPACE, getDX, and DORA metrics provide valuable insights, they often miss the mark on capturing developers' real, day-to-day experiences using tools and services, instead focusing strictly on the bottom line for the company. Meanwhile, developers and practitioners are job-hopping more than ever. This talk will explore the origins and evolution of "developer experience," dissect popular frameworks, and advocate for a more balanced approach that values the practitioner's perspective. At the end we will set a path towards integrating top-down metrics with bottom-up feedback, ensuring an approach to developer experience that fosters innovation and satisfaction.</p>

Self-Healing Rollouts: Automating Production Fixes with Agentic AI (en)

<p>Even with robust CI/CD, production rollouts can hit unexpected snags. While in Kubernetes Argo Rollouts excels at Progressive Delivery and automated rollbacks to mitigate deployment issues, what if we could go a step further?</p> <p>This session explores how to elevate your release process by integrating Agentic AI and asynchronous coding agents, with Argo Rollouts canary deployments. We'll demonstrate how an intelligent agent can automatically analyze a rollout failure, pinpointing the root cause. Beyond diagnosis, these agents can take proactive steps on your behalf, suggesting and even implementing code fixes as new pull requests, which can be redeployed automatically after PR review. This approach moves us closer to truly self-healing deployments.</p> <p>Join us to learn how to combine the power of Kubernetes and Argo Rollouts with the autonomous capabilities of Agentic AI, achieving a release experience that is not only seamless but also resilient.</p>

Your Cluster is Lying to ArgoCD (And How to Catch It) (en)

<p>We love ArgoCD, but it creates a classic "map vs. territory" problem. We treat Git as our "map", our single source of truth. But the cluster is the "territory", and it's often more complex than the map shows. This becomes a crisis with the 3 AM hotfix: an SRE fixes production, changing the territory. ArgoCD, loyal to the map, sees this as drift and helpfully overwrites the fix, re-breaking the cluster. The problem is that Git isn't our Truth, it's our Intention. This talk introduces a pragmatic solution: Cluster-Scoped Snapshotting. We’ll show a simple pattern that dumps the entire live cluster state (the "territory") into its own "reality" Git repo. To automate this, we wrote a small open-source tool called Kalco, but the pattern is the real takeaway. This "reality" repo gives us a powerful "pre-flight diff" in our CI pipeline, comparing our "intention" (the app repo) against the "truth" (the snapshot repo). This simple check lets us bootstrap existing clusters, create a complete audit log, and stop our pipeline before it merges a change that conflicts with a critical live fix.</p>

The Most Bizarre Software Bugs in History (en)

<p>We've all heard that we should test our software, but what happens when we don't? Sometimes, it leads to strange and unexplainable events.</p> <p>Is 'testing more' always the right solution? What do these bugs reveal about software and its failures? And how can we use these lessons to build more resilient systems?</p> <p>Let's explore together the most bizarre software bugs in history!</p>

Bug reporting made less buggy (en)

<p>Forgotten files, incomplete system info, back and forward emails... Bug reporting can be messy process and sometimes wastes a lot of time on both developer and user side. However, a lot of it can be normalized and automated. In this talk we introduce CLI tool <strong>DebugPack</strong> that helps us to simplify the bug reporting process for our team and ensures that developers always have the necessary information for successful bug hunting.</p> <p>https://gitlab.nic.cz/labs/bird-group/debugpack</p>

Bringing automatic detection of backdoors to the CI pipeline (en)

<p><strong>Software backdoors aren’t a myth—they’re a recurring nightmare</strong>. Time and again, we’ve watched malicious code slip into open-source ecosystems. The notorious xz compromise grabbed headlines, but it wasn’t the first act in this drama. Earlier breaches included the PHP incident in 2021, as well as vulnerabilities in vsFTPd (CVE-2011-2523) and ProFTPD (CVE-2010-20103). And here’s the unsettling truth: these examples likely just scratch the surface. <strong>Why does it matter?</strong> Because a single backdoor in a widely used project turns into a hacker’s dream buffet—millions of machines served up for exploitation.</p> <p><strong>Tracking down and eliminating backdoors isn’t a quick win</strong>—it’s like diving headfirst into sprawling code jungles. Sounds epic? In reality, even for a veteran armed with reverse-engineering gear, it’s a grueling slog. So grueling that most people simply don’t bother. The good news? <strong>New tools such as ROSA (<a href="https://github.com/binsec/rosa">https://github.com/binsec/rosa</a>) prove that large-scale backdoor detection can be automated</strong>—at least to a significant extent. Here’s the twist: traditional fuzzers like AFL++ (<a href="https://github.com/AFLplusplus/AFLplusplus">https://github.com/AFLplusplus/AFLplusplus</a>) test programs with endless input variations to trigger crashes. It’s brute force, but brilliant for uncovering memory-safety flaws. Backdoors, however, play by different rules—they don’t crash; they lurk behind hidden triggers and perfectly valid behaviors. ROSA changes the game by training fuzzers to tell “normal” execution apart from “backdoored” behavior.</p> <p>But there’s a catch: <strong>ROSA’s current use case is after-the-fact analysis, helping security experts vet full software releases</strong> (including binaries). Following the <a href="https://en.wikipedia.org/wiki/Shift-left_testing">shift-left paradigm</a>, <strong>our goal is to bring this detection magic into the CI pipeline</strong>—so we can stop backdoors before they ever land. Sounds great, but reality bites: ROSA produces false alarms and can require a significant test budget to find backdoors, which are a nightmare in CI. <strong>In this talk</strong>, we would like explore the methodological and technical upgrades needed to build a ROSA-based backdoor detection prototype that thrives in CI environments. Think reduced resources, and minimal noise—all within the tight resource windows CI jobs demand.</p>

AI-based failure aggregation (en)

<p>Modern automated testing environments generate vast amounts of test results, making failure analysis increasingly complex as both the number of tests and failures grow. This presentation introduces an AI-driven approach to failure aggregation, leveraging text embeddings and semantic similarity to efficiently group and analyze unique failures. The workflow integrates open-source, pre-trained models for text embedding (such as Sentence Transformers) and vector similarity search using PostgreSQL with pgvector, enabling scalable and low-barrier adoption.</p>

Building CDviz: Lessons from Creating CI/CD Observability Tooling (en)

<p>In 2024, I left my job to build <a href="https://cdviz.dev/">CDviz</a> full-time—an open source platform for CI/CD observability using CDEvents, an emerging specification with minimal ecosystem adoption. This talk shares lessons from building production tooling on early-stage standards.</p> <p>You'll see: - Why I chose to build on <a href="https://cdevents.dev">CDEvents</a> despite limited adoption - Technical challenges: converting diverse tool events into a unified format - Architecture decisions: PostgreSQL/TimescaleDB for storage, Grafana for visualization - Live demo: CDviz tracking deployments with real metrics - What worked, what didn't, and lessons for building on emerging specs</p> <p>This is a builder's story about creating interoperability tooling before the ecosystem is ready—and why standardization matters even when adoption is slow.</p>

Automated Testing of VoIP Infrastructure: Lessons from the Field (en)

<p>Testing VoIP infrastructure at scale is far from straightforward. These systems route calls and enrich the caller experience, with features such as playing prompts, interactive menus, and caller queues. With so many features and interactions, manually testing every scenario is impossible, so test automation is essential.</p> <p>As a software tester for a real-world VoIP infrastructure, I built an automated framework using the open-source SIPSorcery library (https://github.com/sipsorcery-org/sipsorcery) to create programmable softphones that simulate complex call interactions. The talk covers the most interesting challenges faced, such as verifying who can be heard and seen in audio and video calls, mimicking specific physical phones, and making timing-sensitive tests run reliably.</p> <p>Attendees will take away insights into the challenges of large-scale VoIP testing and practical strategies for designing automated tests that are reliable, repeatable, and maintainable.</p>

Formal Verification in Rocq, an Exhaustive Testing (en)

<p>In this talk, we present formal verification, a technique for mathematically verifying code and ensuring it is safe for any possible inputs.</p> <p>We explore in particular the theorem prover Rocq, and how we use it to model and verify production code at Formal Land. We show the two primary methods to create a code model, by testing or proving the equivalence with the implementation, and the main classes of properties that are interesting to formally verify on a program.</p>

Welcome to Identity and Access Management devroom! (en)

<p>Welcome to the devroom, rules and initial setup.</p>

An Introduction to the OpenID Shared Signals Framework (en)

<p>As security threats become more sophisticated, the need for efficient, real-time communication between identity providers and relying parties is essential. The Shared Signals Framework (SSF) and related specifications such as CAEP and RISC address this challenge by providing a standardised way for systems to exchange security related signals, such as session revocations, credential breaches, and other identity-related incidents, in a secure and scalable manner. This talk introduces the Shared Signals Framework and explains how it enhances security and operational efficiency in modern identity ecosystems. We'll explore how SSF can be supported in Keycloak to enable real-time event-driven communication between providers and relying parties. Attendees will learn how Keycloak can help to detect and mitigate threats, and improve overall system security with SSF.</p>

Nextcloud as Identity Provider? SCIM Client Integration for Multi-Platform Collaboration (en)

<p>We introduce the <a href="https://github.com/nextcloud/scim_client">SCIM client app</a> for <a href="https://nextcloud.com/">Nextcloud</a> that allows Nextcloud users and groups to be automatically synced to external services that support the <a href="https://tools.ietf.org/wg/scim/">SCIM</a> standard. This enables Nextcloud to act as an authoritative store of user identity information, simplifying user management across multiple connected services.</p> <p>This talk will discuss the motivations behind the app as well as its practical use cases.</p>

Keeping applications secure by evolving OAuth 2.0 and OpenID Connect (en)

<p>OAuth 2.0 and OpenID Connect have been around for years to secure web and mobile applications alike with growing popularity.</p> <p>To keep your applications and their data secure, these standards are evolving to align with security best practices.</p> <p>Join this talk to see how the FAPI 2.0 Security Profile and the upcoming OAuth 2.1 standard promotes and enforces best practices, how to adapt your applications, and how Keycloak as an Open Source IAM can help you. Expect a demo and examples for some of the enhancements.</p>

Inside ProConnect: Building a Modern Federated Identity Provider for Government Services (en)

<p><a href="https://www.proconnect.gouv.fr">ProConnect</a> is an open-source Federated Identity Provider written mainly in TypeScript and designed to connect professionals with government services. Developed by the French Interministerial Digital Directorate (<a href="https://www.numerique.gouv.fr/numerique-etat/dinum/">DINUM</a>), it builds on the experience of <a href="https://franceconnect.gouv.fr/">FranceConnect</a> while introducing a lightweight, modern architecture.</p> <p>This talk will present the story behind ProConnect—from its origins as an open-source fork of FranceConnect to the motivations that guided its redesign. We will provide a high-level overview of its main components (identity management, federation, moderation workflows, administrative tools) and demonstrate how the platform operates in practice.</p> <p>A particular focus will be placed on the <a href="https://github.com/proconnect-gouv/federation">identity broker layer</a> and its technical foundations, including the use of panva/node-oidc-provider, panva/openid-client, and related tooling. We will look under the hood at how ProConnect implements current practices in identity federation and how its evolving architecture continues to take shape through ongoing development.</p>

Privacy and Sovereignty in a Post Quantum Open World (en)

<p>Each month it seems we are made aware of a break in security. Some report of a data base of identity information that is reported as captured by an entity of some type. Lists of passwords, ID numbers, bank account information, credit card information. And these are only the ones we hear about, since many of these break-ins are not reported, or kept quiet.</p> <p>Often we hope that the data is encrypted, but as we all know quantum computers are coming quickly and quantum computers can take present-day encrypted data even with the highest key lengths and break them in minutes which would have taken conventional high performance computers centuries to break.</p> <p>Another threat comes from the sovereignty of your system and data. While many cloud companies have put additional servers in various countries (even yours) the companies that generate that software (often closed source) are headquartered in the United States and therefore under US laws like the Patriot Act.</p> <p>You want a system that is made with Open Source, which allows you to run it on standard equipment that you can inspect, in the country that you want to run it.</p> <p>A system that puts security first. This talk will detail such a system.</p>

SUSEID - Sovereign IAM at SUSE (en)

<p>SUSE’s IAM evolution mirrors its corporate journey, beginning with deep dependency on Novell (later MicroFocus) Access Manager, following its transition to independence. As the organization grew, individual departments adopted several tools to solve immediate authentication needs.</p> <p>This led to a proliferation of unmanageable authentication silos across customer portals, partner networks, and internal employee systems. Recognizing the inefficiencies and risks of this fragmented landscape, SUSE IT has set the goal to consolidate these scattered silos by unifying identities into a single, modern governance solution.</p> <ul> <li>Authentik: https://goauthentik.io/</li> <li>389-ds: https://www.port389.org/</li> <li>PostgreSQL: https://www.postgresql.org/</li> <li>Patroni: https://patroni.readthedocs.io/en/latest/</li> <li>RKE2: https://docs.rke2.io/</li> </ul>

Credentials for Linux: Bringing Passkeys to the Linux desktop (en)

<p>Passkeys are now first-class citizens on Windows, macOS, Android and iOS - but the Linux desktop still has no standard FIDO2 platform APIs for browsers and native apps. </p> <p>This talk presents <strong>Credentials for Linux</strong> (<a href="https://github.com/linux-credentials">github.com/linux-credentials</a>), a cross-desktop effort to bring Passkeys and other credentials to Linux in a way that works for sandboxed apps and browsers alike.</p> <p>We’ll cover:</p> <ul> <li><strong>Very short refresher on passkeys &amp; platform authenticators</strong>: Why WebAuthn/FIDO2 passkeys matter, what platform authenticators are, and how this is solved on Windows Hello, Android and Apple platforms today, and the current state on Linux. </li> <li><strong>Architecture of Credentials for Linux</strong></li> <li><a href="https://github.com/linux-credentials/libwebauthn"><code>libwebauthn</code></a>: a Rust FIDO2/U2F platform library with support for USB, BLE and Hybrid authenticators (ie. Android &amp; iOS smartphones), designed with pluggable transports and passkey features such as resident keys and user verification. </li> <li><a href="https://github.com/linux-credentials/credentialsd"><code>credentialsd</code></a>: a D-Bus service and proposed XDG portal for credential management, including a reference UI, Firefox integration (web extension + patched Flatpak build) and distro packages via OBS (Fedora/openSUSE). </li> <li><strong>What this looks like for apps and browsers</strong>: Demo and design walkthrough of a sandboxed Firefox using <code>credentialsd</code> to talk to hardware security keys and phones, and how native applications can use the same D-Bus API. </li> <li><strong>Roadmap, open problems and call for collaborators</strong>: TPM-backed platform authenticators, origin binding and unprivileged APIs for browsers, and how we’d like to work with GNOME, KDE, Flatpak, password managers and distributions. </li> </ul> <p>The talk is aimed at people interested in identity and access management on the desktop: browser and desktop maintainers, distribution engineers, security practitioners and anyone who wants to help make passkeys a first-class citizen of the Linux platform.</p>

Cockpit and passwordless login (en)

<p>If you've ever used Cockpit you might know of the different authentication methods it currently supports. It can be pretty much anything, such as username and password, Kerberos, public keys, Single Sign-On (SSO), or smart cards. But given the nature of Cockpit being a web-based interface we can only support public key authentication through our Flatpak package called Cockpit Client as browsers themselves are sandboxed and can't access your system keys.</p> <p>If we don't want to setup SSO or smart cards for a system, we're pretty much left with username and password authentication in the browser using PAM modules. Password authentication is less than ideal, let's see if passkeys can save the day! We'll look over what it takes to support WebAuthn with PAM modules, what limitations there are, and what tools currently exist to help us with this - such as Yubico's pam-u2f, sssd, and FreeIPA.</p> <p>Cockpit is a web-based graphical interface for server management of a variety of Linux distributions. Our modifications of the system are made using system APIs and commands with our authentication functioning in the same way with the help of PAM modules.</p>

Passwordless authentication mechanisms from the GUI (GDM) (en)

<p>The world is moving toward more modern and secure authentication methods. This transition is driven by a global push for Zero Trust Architecture (ZTA), which many organizations are adopting as a security mandate.</p> <p>In this context, the FreeIPA, SSSD, and GNOME Display Manager (GDM) ecosystems have been working to meet these evolving demands. </p> <p>As a result, GDM has received several improvements to enhance the authentication experience. Two new mechanisms have been added: passkeys and external IdP (web login). Users can now choose among the supported authentication mechanisms, and the PAM conversation has been extended to support this new scenario with multiple authentication options.</p> <p>In this talk, we’ll cover what the GDM authentication architecture looks like and how it handles PAM conversations. We will discuss the new PAM extension that uses JSON messages to support these mechanisms, the changes made in GDM to allow selecting different authentication methods, upcoming enhancements, and provide a demonstration of the current implementation.</p>

Reduce attack surface or keep compatibility: lessons of sudo-rs and run0 transition plans (en)

<p>An ongoing effort to reduce potential attack surface on privileged components of system administration by rewriting them in modern programming languages or introducing new components creates additional problems as well. The system management at scale requires centralization of the access controls, yet most of the new tools do not have such capabilities or don't really concern with such use cases.</p> <p>In this talk we'd reflect on our experience of supporting large organizations relying on the infrastructure provided by FreeIPA and SSSD.</p>

Linux-PAM Demystified and Beyond (en)

<p>Linux-PAM (Pluggable Authentication Modules) is a crucial but often misunderstood component of modern Linux systems. This talk provides a comprehensive introduction to PAM, explaining how it enables system administrators to configure authentication, account management, session setup, and password policies without recompiling applications.</p> <p>We begin by exploring the problems PAM was designed to solve—hardcoded authentication logic, inflexibility, and inconsistent security policies across applications. The talk then covers PAM's four management groups: authentication (verifying identity), account management (checking access restrictions), session management (setting up user sessions), and password management (enforcing password policies and token changes).</p> <p>Attendees will learn how to read and write PAM configuration files, understand the behavior of different control values (required, requisite, sufficient, optional), and leverage advanced control syntax for complex authentication flows. Special attention is given to the "frozen stack" concept—a frequently misunderstood behavior where PAM fixes the module sequence during the first API call.</p> <p>Through real-world examples and practical configuration insights, attendees will learn how to troubleshoot PAM issues and understand the impact of PAM configuration changes.</p> <p>Beyond understanding current PAM functionality, the talk explores the future of PAM: potential enhancements to address modern authentication needs, architectural improvements and the challenges that stand in the way of evolution. We'll discuss compatibility constraints, the need for backward compatibility with existing deployments, and the tensions between maintaining a stable API and introducing new features.</p> <p>This talk is suitable for system administrators, security engineers, and developers who want to understand and effectively configure PAM-based authentication on Linux systems.</p>

SSH logins in practice: certificates vs. OPKSSH (en)

<p>SSH is the default access method for Linux servers, typically configured with passwords or public/private key authentication. However, in large multi-user deployments, these methods have significant drawbacks: security of private keys on unmanaged clients, key management on the server side, and the difficulty of integrating multi-factor authentication.</p> <p>Alternative methods exist but are not always easy to implement. In this talk, I compare two of the most promising approaches—OpenSSH certificates and OpenPubKey (OPKSSH)—based on a recent evaluation for a multi-user compute cluster with dozens of machines and hundreds of unmanaged clients. I discuss the advantages and limitations of each approach, including client configuration, required additional software, and operational complexity.</p> <p>The presentation includes live demos illustrating how each method works from both the client and server perspective, and a closer look at the inner workings of SSH certificates and OPKSSH.</p> <p>Links: https://www.openssh.org https://github.com/openpubkey/openpubkey https://github.com/openpubkey/opkssh</p>

The journey after a breaking change: rewriting bind-dyndb-ldap for modern BIND (en)

<p>bind-dyndb-ldap is a dynamic database plugin that allows the BIND DNS server to store and retrieve all DNS zone and record data directly from an LDAP directory server. This deep integration is essential for centralized identity management solutions, particularly in FreeIPA setups.</p> <p>To achieve its function, bind-dyndb-ldap must utilize BIND's internal, lower-level APIs. When a recent major BIND release introduced significant breaking changes, what began as a simple compilation bug because of a missing header quickly escalated into a massive technical challenge. The core problem: adapting years of legacy code to the new BIND server architecture.</p> <p>This talk will cover the challenges of planning the redesign, how we faced the technical challenges when adapting old code to modern APIs and the lessons learned through the journey.</p> <p>https://pagure.io/bind-dyndb-ldap https://github.com/freeipa/freeipa https://www.isc.org/bind/</p>

Implementing Encrypted DNS in Fedora and Kubernetes Clusters with FreeIPA DNS (en)

<p>In modern identity-centric infrastructures, DNS is a critical—but often overlooked—component of a Zero-Trust Architecture. This talk, positioned within the IAM devroom's core infrastructure and security track, explores how environments that rely on FreeIPA as their authoritative DNS can adopt encrypted DNS end-to-end without sacrificing performance or operational clarity.</p> <p>We present the results of our work integrating encrypted DNS across Fedora systems and Kubernetes clusters while seamlessly interacting with FreeIPA's BIND-based DNS service. Throughout this process, we identified key integration challenges, their practical resolutions, and the tangible security benefits gained from encrypting internal DNS traffic.</p> <p>To validate the feasibility of this approach at scale, we performed extensive workload and performance tests—covering multiple orders of 1,000+ DNS requests per second—comparing encrypted vs. non-encrypted scenarios. These tests demonstrate how to achieve stronger security guarantees without imposing unacceptable latency or throughput penalties.</p> <p>As part of this effort, we extended FreeIPA's DNS service with Prometheus-ready metrics, enabling real-time visibility into encrypted DNS performance, request patterns, and system-level statistics. These observability enhancements provide operators with the data required to meet and maintain Zero-Trust mandates.</p> <p>By the end of the talk, attendees will understand not only how to deploy encrypted DNS in hybrid Fedora and Kubernetes environments, but also how to measure, validate, and operationalize it in a way that fully aligns with Zero-Trust principles.</p>

Migrating Multi-Factor Authentication: FreeIPA WebUI's Journey from Dojo to React (en)

<p>Building FreeIPA’s modern WebUI meant leaving Dojo behind for React, but we couldn't leave our robust authentication capabilities behind. We needed to bring password, OTP, Kerberos, and certificate support into the new era. This raised a fundamental question: how do we translate these complex legacy flows into clean, modern code?</p> <p>We invite you to explore this adaptation journey with us. We’ll discuss shifting from scattered widget logic to unified Redux state management and declarative components, while reimagining our API layer. This process didn't just replicate old features—it evolved them, delivering a more secure and optimized codebase through the power of strict type safety.</p>

Creating a new CA backend for FreeIPA with the help of AI (en)

<p>-- At first it was a funny idea to give AI a try --</p> <p>With the help of Claude a new light weight CA backend for FreeIPA has been created. It is written in Python and uses python-cryptography. The the goal is full dogtag compatibility for use with FreeIPA.</p> <p>The talk will show the journey: The experience with AI, the good and also not so good steps and results. In the end the actual state will be shown.</p>

Why Open Source Looks Different in China: When Vendor Strategies, Policy Signals, and Market Pressure Converge (en)

<p>Open source is often discussed through a familiar narrative: community-led collaboration, neutral governance, and voluntary participation driven by shared technical interests.</p> <p>However, when looking at China in 2025, open source often looks noticeably different — not because different tools are used, but because the constraints shaping them are fundamentally different.</p> <p>This talk explores how open source in China has evolved under the convergence of three forces: vendor-led engineering realities, explicit policy signals, and intense market pressure — especially under economic tightening and global uncertainty. In this environment, open source is frequently not a starting ideal, but a practical mechanism: to establish de facto standards, to gain global trust, and increasingly, to remain viable through international adoption.</p> <p>The talk examines why many projects are company-led rather than community-born, why governance often lags behind engineering, and why “going global” is less about expansion than about survival.</p> <p>The perspective offered is not representative of any state or corporation, but comes from someone who has worked between Taiwanese, Chinese, and global open source communities for over a decade. The goal is not to defend or promote a particular model, but to provide developers familiar with Western open source traditions with a clearer mental framework for understanding how open source behaves under non-ideal conditions — and what that means for future collaboration and governance in an increasingly interconnected open source world.</p>

Four Year Bus (en)

<p><a href="https://cspp.ie">CS++</a> is an entirely-led student computer science society in TU Dublin. Our goal is to give our members experiences and skills they won't get in class, this includes going to FOSDEM!</p> <p>Ontop of that, CS++ maintains a cluster of servers that runs services for themselves and several other societies in the university. Which we have to maintain even though students are in university for only four years.</p> <p>This <em>Four Year Bus</em> talk covers how we went from an empty room to our current tech stack, as well as how we manage training, handover and long-term planning when everyone involved has a timer until they are hit by a bus.</p>

Okular: The Universal Document Viewer (en)

<p>Okular is multi-platform, fast and packed with features, Okular allows you to read PDF documents, comics and EPub books, browse images, visualize Markdown documents, and much more.</p> <p>In this talk we will give a quick overview of the past, present and future of Okular.</p>

SucréLA: open source usb 3.0 logic analyzer based on FPGA (en)

<p>The goal of the talk is to present the SucréLA project. SucréLA is a fast (USB 3.0) and fully open logic analyzer. For the feature set, it takes inspiration on the great Saleae products. But the goal is to be more affordable for hackers and be fully open source. The board is open (all Kicad files), the PC software is open (sigrok/PulseView), the FPGA gateware is open (in Migen, based on LiteX SoC toolkit, available on gitlab), the mcu fw is open (also on gitlab) and you only need open source tools to hack it (gcc, NextPNR and Yosys: no closed source fpga toolchain needed). The idea is for someone to easily be able to understand, modify, improve and repair it. </p> <p>Everything is available at https://gitlab.com/yannsionneau/SucreLA/</p> <p>Licenses: LGPL v2.1 and CERN-OHL-W v2</p>

graffito: pretty cellular automata devoid of meaning (en)

<p>The humble cellular automaton is a well-studied concept in computer science and has been around for many decades.</p> <p>A very famous cellular automaton is Conway's Game of Life, which models a simple two-dimensional system of cells living and dying. This cellular automaton, and many others like it, are expressly designed to simulate some aspect of the real world, however simplified the model might be.</p> <p>I instead like to design cellular automata that have pretty animations and do not attempt to model reality in any way.</p> <p>In this talk I'll present my small cellular automaton framework "graffito" that I have been working on for the past three years in my spare time. I'll give a few examples of how I like to go about creating new automata and try to inspire you to create your own. I think it's really fun, and sometimes you might surprise yourself with something very cool-looking!</p> <p>graffito is written in the Futhark programming language, but the takeaways from this talk will be applicable to any language you might want to use for writing cellular automata.</p>

PerlOnJava: A Perl Distribution for the JVM (en)

<p>PerlOnJava provides a Perl distribution designed to run natively on the Java Virtual Machine (JVM). It allows Perl scripts to integrate seamlessly with Java-based ecosystems while offering familiar tools and modules for Perl development.</p> <p>https://github.com/fglock/PerlOnJava</p>

Why I Volunteer at FOSDEM and You Should Too! (en)

<p><strong>FOSDEM is legendary, but it doesn't run on magic, it runs on people.</strong></p> <p>Apart from the core organizers, an enthusiastic team of volunteers helps make FOSDEM the fun and safe community event we all love every year. As a long-time attendee, I made the jump to volunteering during the event and discovered a new side of the conference.</p> <p>In this talk, I'll share my personal journey and what volunteering involves: from simple tasks like setting up directional signs or assisting at the InfoDesk, to setting up and tearing down before and after the event, or helping the video streaming team. I'll share stories of the folks I've met, the behind-the-scenes glimpse I got into this impressive organization, and how truly impressed I am by its operation.</p> <p>However, the real reason to join is a chance to give back, meet new people, and become an active community builder. FOSDEM needs you to make the event a fun and safe place for all visitors. </p> <p><strong>What's in it for you?</strong> Join this session to learn how easy it is to sign up, the tasks you can pick (even just for a few hours!), and how you can join the effort to make FOSDEM 2026 the best one yet. </p> <p>You can learn how to sign up at https://volunteers.fosdem.org/.</p>

The v4 tape in the Unix history repo (en)

<p>In 1974 Ken Thompson sent a copy of the then-current Unix distribution to Marin Newell. Fast forward to to July 28th, 2025. In a storage closet of the Robert Ricci’s Flux Research Group at the Merrill Engineering Building Aleks Maricq a research associate found a tape labeled v4 Unix among the documents of Jay Lepreau. This could be significant, because no other version of its source code have survived. The finding was widely reported on the web and even broadcast TV. To avoid high-altitude cosmic radiation and airport scanner damage lab members Jon Duerig and Thalia Archibald undertook an 11 hour drive it to the Computer History Museum in December 2025. There it was decoded and made available using a sophisticated analog to digital pipeline. A few days later, I integrated the tape's contents in the Unix History Repository. This makes available on GitHub a repository, covering the period from Unix's inception in 1970 as a 2.5 thousand line kernel and 48 commands, to 2025 as a widely-used 41 million line system. The 2 GB repository contains about 850 thousand commits and more than eight thousand merges. Based on the repository's contents I provide details regarding the tape's contents, dating, code provenance, and the evolution of programming language adoption.</p>

Open Food Facts : Getting together to reduce health and environmental impacts of consumption (en)

<p>Through open source, open data and community, Open Food Facts is transforming consumption in many countries! In this talk, we'll dive into how Open Food Facts is helping reshape the food system to reduce its impacts on health and the environment. We'll go through how Open Food Facts helps create a trove of information, and turn it into actionable data for consumers, researchers and policy makers.</p> <p>We'll show how we are mobilizing technology (mobile crowdsourcing, artificial intelligence and more classic tech) in the pursuit of food enlightenment.</p> <p>We'll explore how citizens and consumers are using this database to make smarter, healthier food choices, steering the food industry towards a more transparent and sustainable future.</p> <p>We will finally talk about 2025's exciting developments, Open Prices, the new features in the app (Cosmetics, new circular features of Open Products Facts), and how you can help.</p>

AtomVM: Elixir, Erlang, and Gleam on Microcontrollers (en)

<p><a href="https://elixir-lang.org/">Elixir</a>, <a href="https://www.erlang.org/">Erlang</a>, and <a href="https://gleam.run/">Gleam</a> are functional languages that run on the BEAM virtual machine and are widely used for highly concurrent, fault-tolerant systems. However, the standard BEAM VM is too heavyweight for most microcontrollers.</p> <p><a href="https://github.com/atomvm/AtomVM/">AtomVM</a> is a from-scratch implementation of the Erlang VM designed for constrained devices such as the <a href="https://www.espressif.com/en/products/socs/esp32">ESP32</a> and <a href="https://www.raspberrypi.com/products/raspberry-pi-pico/">Raspberry Pi Pico</a>, and it can run in as little as 32 KiB of RAM. The project has been around since 2017 and has grown in community and features (support for multiple MCU families, JIT, and ahead-of-time compilation to native code), so it can now be used in production for both professional and hobbyist projects.</p> <p>This talk will introduce AtomVM and show how it can be used in real embedded projects, and it will also explain the benefits of using BEAM languages on microcontrollers: such as supervision trees, lightweight processes, and native clustering. We will see how the foundations of a language originally used by Ericsson to power high-reliability telephone switches are still valuable for today’s connected devices.</p> <p>No previous knowledge of Erlang, Elixir, or Gleam is required.</p> <p>Links:</p> <ul> <li>https://atomvm.org/</li> <li>https://doc.atomvm.org/</li> <li>https://github.com/atomvm/AtomVM/</li> </ul>

Physics in Julia: combining Unitful.jl with DifferentialEquations.jl (en)

<p>Julia is a language particularly well suited for scientific computing - both thanks to inherent language features (including built-in CPU and GPU parallelism, math-oriented multi-dimensional array handling, and top notch performance), as well as thanks to an actively maintained ecosystem of packages. In this talk, I will focus on two of them: <a href="https://juliaphysics.github.io/Unitful.jl/stable/">Unitful.jl</a> and <a href="https://docs.sciml.ai/DiffEqDocs/stable/">DifferentialEquations.jl</a>, and on the challenges in using them in concert. <a href="https://juliaphysics.github.io/Unitful.jl/stable/">Unitful.jl</a> enables to programmatically express and JIT-compile-time verify the consistence of physical units across the user codebase - contributing to readability, testability and maintainability of the code. <a href="https://docs.sciml.ai/DiffEqDocs/stable/">DifferentialEquations.jl</a> - a flagship Julia numerical computation package - offers numerical solvers for modelling problems across a wide range of domains, including physics. However, as pointed out in several instances by the community, and as will be demonstrated in the talk, getting the two to work together requires attention. I will present a robust design pattern for combing them - leveraging the fundamental trait of physics, namely that physical dimensionality in mathematical models is solely originating from the constants. This solution benefits from Julia syntax, but is in general applicable to analogous tools in other JIT-compiled languages.</p>

Trust the Math, Fear the Compiler: How Optimizations Undermine Cryptographic Software (en)

<p>Computer systems can unintentionally leak bits of secret information through observable variations in their behavior such as runtime or power consumption. These so-called "side-channels" can be harmful for the security of cryptographic systems where just a few bytes of leaked key material may compromise loads of sensitive data.</p> <p>In this talk, we will explore how we mitigate typical side-channels in <a href="https://github.com/randombit/botan">the open-source cryptography toolkit "Botan"</a> and why this has increasingly become a game of cat and mouse against modern compiler optimizations. We will also present how established open-source tools such as valgrind can help find subtle side-channels in a semi-automatic way.</p>

os-test: Measuring POSIX compliance on every single OS (en)

<p>os-test: Measuring POSIX compliance on every single OS</p> <p>What happens if you run tests on every POSIX system? You find a <em>lot</em> of bugs in every single OS. I parsed the new POSIX.1-2024 standard into API definitions, generated tests, and measured exactly how much of the standard is implemented. I invoked every libc function to see if they work, and began writing detailed test suites. As it turns out, if there's a sentence in POSIX, someone probably implemented it incorrectly. I found missing interfaces, incompatible declarations, namespace pollution, a lot of bugs, interesting benign differences, and many more issues. I published all tests and results as os-test. The volume of test failures makes it virtually impossible to report all individual issues to each upstream. However as all of the data is publicly available online, vendors are now beginning to incorporate os-test feedback into their development and testing process, which ultimately leads to improved POSIX compliance and software interoperability.</p> <p>In this talk we will dive into the challenges of testing 16 different operating systems, survey the main findings of os-test, and finally determine which operating system takes the lead when it comes to POSIX conformance.</p> <p>https://sortix.org/os-test/ https://sortix.org/blog/os-testing-posix-headers/</p> <p>os-test is currently funded by Next Generation Internet Zero Commons.</p>

Securing time with NTS (en)

<p>Whether it's at the top, bottom, left or right, chances are that whatever screen you are currently looking at is showing you what the current time is. While your device will have a built-in clock, it is generally pretty unreliable, either completely losing its knowledge about the current time or drifting away slowly over time. NTP is one of the most important ways by which your device every once in a while figures out what the time is and will adjust its clock accordingly. But NTP is completely insecure, allowing almost anyone with relative ease to change your system clock.</p> <p>That could result in you missing an appointment, but it could also result in things like TLS certificates being valid/invalid while the opposite is true, kerberos tickets and TOTP tokens failing, databases not synchronizing properly or log traces on distributed systems being almost impossible to decipher.</p> <p>NTS is here to solve that, but it has seen very little adoption so far. One of the things we need is a good NTS source of time that anyone can use as a default, but NTS has some limitations making it hard to create something like time.ntp.org. We (Trifecta Tech Foundation, makers of ntpd-rs) have some ideas, but we need your help to get it off the ground.</p> <ul> <li>https://experimental.ntspooltest.org/</li> <li>https://github.com/pendulum-project/nts-pool/</li> <li>https://github.com/pendulum-project/ntpd-rs/</li> <li>https://datatracker.ietf.org/doc/html/rfc8915</li> </ul>

Self-hosting a student radio station (en)

<h2>Radio's not dead!</h2> <p>TU Dublin's student <a href="https://tudradio.neocities.org/">radio society</a> has revived itself after a few years of inactivity. In this talk I'll discuss how we got our new beginning as an internet radio station and our migration to becoming fully open source and independent with the help of our <a href="https://cspp.ie">computer science society</a></p> <p>I will will discuss the challenges of self-hosting internet radio software like <a href="https://www.azuracast.com/">Azuracast</a> and <a href="https://icecast.org/">Icecast</a>, running an active student society, getting your station out there in the college, and overcoming challenges student societies face post COVID.</p>

Free Software, Computer Reuse, and Digital Product Passports: Experiences from eReuse.org (en)

<p>The right to repair and reuse is becoming a central pillar of Europe’s digital and environmental agenda. This lightning talk shows how free software can play a concrete and enabling role in this transition, drawing on the real-world experience of <a href="https://ereuse.org/software/">eReuse.org</a> and its <a href="https://github.com/eReuse/">free software tools</a> DeviceHub, Workbench, and IdHub. Introducing cases of computer reuse, we show how these tools support hardware profiling, inventory management, device digital identifiers, refurbishment, traceability, and lifecycle impact, and how they are used by social reuse and refurbishment entities in different countries. These organisations collect unused computers from donors, refurbish them, and distribute them to new users to extend the useful life of these devices, demonstrating a practical circular economy enabled by open digital infrastructures. We then connect these practices with the emerging concept of Digital Product Passports (DPP): how reuse-oriented data models, transparency, and interoperability already implemented in free software ecosystems can inform future DPP implementations for electronic products. In this context, DeviceHub and IdHub provide support for DPPs using DIDs and Verifiable Credentials. Finally, we situate this work in the broader political and economic context: EU sustainability regulation, and the strategic role of free software and SMEs in ensuring that DPPs remain open, auditable, and beneficial for society rather than becoming closed compliance tools. The talk concludes with a short, practical reflection on how developers can contribute to reuse, repair, and digital sovereignty through free software.</p>

From Prototype to Production: Crowdfunding and Shipping the Modos Paper Dev Kit (en)

<p>Modos is an open-hardware company building an ecosystem of E Ink devices to reimagine personal computing with a focus on creating calm, inclusive, and humane technology. It started as an idea shaped by community input, then grew into Modos as we built early prototypes, received a grant, and continued iterating on the hardware through many revisions until where we are today, after a successful crowdfunding campaign, with devices shipping and the foundation in place for the next phase of the ecosystem.</p> <p>In this talk, we will briefly discuss the underlying technology, share what we learned while building and refining our prototypes, and outline our next steps and future direction. We will cover how we plan to grow an ecosystem of compatible open hardware and applications, and where we want to take Modos next as the community continues to help shape the roadmap.</p>

git blame for your dependencies (en)

<p>Your lockfile shows what dependencies you have but not how you got there. git log on a lockfile is useless noise. Who added left-pad? When did we pick up that transitive dependency? Why do we have three JSON libraries?</p> <p><a href="https://github.com/git-pkgs/git-pkgs">git-pkgs</a> is a git subcommand that indexes your dependency history into a SQLite database. It parses manifests across 30+ ecosystems (Gemfile, package.json, Dockerfile, GitHub Actions etc) and tracks every add, update, and removal with full commit attribution. Query when any dependency arrived, who added it, and what the commit message said. You can even diff dependencies across branches.</p> <p>I'll demo the tool and show how a simple schema lets you answer questions your package manager can't.</p>

Amber Lang - Easily write Bash with a transpiler (en)

<p>Amber is an experimental programming language that transpiles to Bash, designed to make shell scripting more readable, safer, and easier to maintain. While Bash is ubiquitous, its syntax and error-prone patterns often slow down development, especially for complex scripts. Amber addresses these issues by offering a clearer syntax, basic typing, structured control flow, and a growing standard library, while still producing compatible Bash code (3.2–5.3).<br /> Written in Rust and supported by modern tooling such as an LSP and editor plugins, Amber aims to improve the developer experience of writing portable shell scripts without abandoning the Bash ecosystem.</p> <p>Slide link: https://mte90.tech/Talk-Amber/</p>

Youth Hacking 4 Freedom 2026 a programming competition for teenagers (en)

<p>Youth Hacking 4 Freedom is the FSFE’s very own programming competition for teenagers (14 to 18 years) from Europe. With YH4F the FSFE conveys the values and knowledge surrounding Free Software, provides the chance to develop your own project idea, learn valuable skills for project management, problem solving and of course: programming!</p> <p>The fifth round of the FSFE's programming competition “Youth Hacking 4 Freedom” is open for registration and will start with the beginning of 2026. "Youth Hacking 4 Freedom" is a programming competition for European teenagers from 14 to 18 years old. The participants have the chance to work on their own project idea with the guidance of experts from the Free Software universe. There are no limitations for the projects as long as they are published under a Free Software license. In this competition young people can test their skills, learn how to work on a project under a deadline, and most importantly have fun while meeting different people from Europe. The contestant can also win up to 4096 Euro. Hear all about the competition and how to participate in it.</p>

Open sourcing democracy: using FLOSS and Access To Information to surface bugs in your government (en)

<p>After a brief presentation of Access To Information laws ("ATI", which allow citizens to request info or documents from the State), this talk will introduce Alaveteli.org a ruby-on-rails web app designed to make it easier for people to exercise their rights.</p> <p>We will make a parallel between debugging FLOSS, and understanding how our democracies function with ATI. We will present a few examples of requests and campaigns to show how these transparency laws can empower individuals and make democracies more resilient.</p>

Signed, Sealed, Stolen: How We Patched Critical Vulnerabilities Under Fire (en)

<p>What happens when your server starts signing messages you didn't send?</p> <p>Recently, the <a href="https://continuwuity.org">Continuwuity project</a> (a Rust-based <a href="https://matrix.org">Matrix</a> homeserver) fell victim to a targeted, active exploitation campaign. Attackers leveraged two critical vulnerabilities (CVSS <a href="https://github.com/continuwuity/continuwuity/security/advisories/GHSA-22fw-4jq7-g8r8">9.9</a> and <a href="https://github.com/continuwuity/continuwuity/security/advisories/GHSA-m5p2-vccg-8c9v">9.3</a>) affecting the entire ecosystem of <a href="https://conduit.rs/">Conduit</a>-derived servers. By exploiting flaws in the way that servers join and leave chat rooms, attackers forced the server to cryptographically sign unexpected events, with disasterous results. This allowed them to forge "leaves" to decimate public rooms, forge ACL rules to brick them, and temporarily take over an account to exfiltrate over 5,000 messages from the maintainers' private internal chat.</p> <p>In this talk, Nex and Jade will take you inside the war room during the incident. We'll walk through the attack chain, explaining how attackers tricked the server, and how we figured out what happened. We'll also have a brief look at how we hardened our project against similar exploitation in the future.</p>

FOSDEM infrastructure review (en)

<p>Join us for the traditional FOSDEM infrastructure review.</p>

What are you missing in Haiku? (en)

<p>Haiku is an open-source operating system that specifically targets personal computing. Inspired by the BeOS, Haiku is fast, simple to use, easy to learn and yet very powerful.</p> <p>Since we don't have a booth this year, we want to take the opportunity for a more focused discussion about all the things you miss in Haiku, as a user or as a developer, to enjoy using it.</p> <p>Hardware support, features, documentation, accessibility (there's a lot to do there too)… What's missing for Haiku as a daily driver to you?</p>

Optics (Photonics) tooling BoF (en)

<p>As data rates continue to rise and electrical interconnects approach their physical limits, somehow interest in optical (photonic) technologies is gaining momentum. This BoF session will explore how community collaboration of software and hardware developers, hobbyists, physicists, engineers etc can contribute to next-generation optics (photonics) tools. We will discuss the current ecosystem of optical (photonic) tools, how newcomers can get started, the key challenges, and whether there is momentum to propse a dedicated devroom next year.</p>

Sailfish OS Community BoF (en)

<p>Sailfish OS has been providing daily-usable Linux on phones for over a decade, with its unique blend of gesture-based mobile interface, Android AppSupport and enthusiastic community. Join the Sailfish OS Community Birds of a Feather event to talk about Sailfish OS, meet the Sailfish community, share experiences and ask questions.</p> <p>The Jolla Team will be present to answer your questions and share insights about future developments.</p> <p>The Sailfish OS BoF has been running for many years at FOSDEM and always attracts an enthusiastic community. We look forward to seeing you there!</p>

OpenStack Community Meetup BOF (en)

<p>In this Birds of a Feather session, members of the OpenStack Community will have the opportunity to get together to discussion issues ranging from development to operations. It is also a goal of this session to welcome potential contributors and users who might want to learn more about the project and how they can get involved.</p> <p>The OpenStack project is part of the OpenInfra Foundation. Code for the project is hosted at opendev.org</p>

AI alignment for Open Source (en)

<p>AI alignment is the effort to design Artificial Intelligence systems so their goals, behaviors, and decisions are consistent with human values and intentions, making them safe, helpful, and reliable. In the context of open source, this BoF will explore what it means for AI to be aligned with open source (what we have built, know, value, expect). Insights will inform work we're doing in the CHAOSS Community as part of AI in Open Source Working Group</p>

OpenMates Dev Meetup (en)

<p>AI doesn’t have to slop. OpenMates is aiming to not just be an open source AI agents web app, but an alternative to big tech AI platforms with both better usability, functionality, ethics, user interests first, privacy and provider independence. Focused on everyday users and everyday tasks, without requiring deep technical knowledge. While also being an awesome software, API and CLI to use for every developer. OpenMates can not only answer questions but use various apps to fulfill tasks, can consider personal infos if the user explicitly chooses that (while still focusing on data minimization and maximum user privacy), and has a general focus on educating and inspiring users. And this is only the early beginning.</p> <p>After over a year of work and over 3000 commits, OpenMates is currently available in an alpha version as both a fully featured self hosting edition on <a href="https://github.com/glowingkitty/OpenMates">GitHub</a> &amp; on <a href="https://openmates.org">OpenMates.org</a> for those who don’t want to self host. Web app and REST API are usable, CLI is planned. OpenMates currently uses various existing APIs / LLM providers, and support for offline models via Ollama, LM Studio, etc. is planned for the months ahead.</p> <p>Join the development meetup to learn more about OpenMates, shape its future and contribute.</p>

Hachyderm.io & Nivenly BOF (en)

<p>We had so munch fun at last year's BOF that we're back for more!</p> <p>Come hang with us to talk about Hachyderm, hear stories about running one of the larger Mastodon sites, learn more about of infra, talk trust &amp; safety, and hear what's going on with the Nivenly Foundation.</p> <p>We'll have several current maintainers on hand. All are welcome!</p> <p>--</p> <p>Hachyderm (https://hachyderm.io) is a curated network of tech industry professionals from around the globe, focused on building a respectful community. We're a safe space for LGBTQIA+ folks, we support Black Lives Matter, and we welcome anyone who follows the rules and needs a home or fresh start.</p> <p>We're hackers, professionals, enthusiasts, and we're passionate about life, respect, and digital freedom. We believe in peace and balance.</p> <p>--</p> <p>The Nivenly Foundation (https://nivenly.org) is a democratically run nonprofit on a mission to bring sustainable governance and autonomy to open source projects and communities around the globe, founded on the principle that project maintainers should share in their projects’ success.</p>

Shaping the Future of Events and Calendars in the Fediverse (en)

<p>Events in the Fediverse are gaining momentum. As an appendix to the Social Web track on Saturday, this BoF offers an open discussion space to shape the future of federated event publishing and calendars.</p> <p>Several free and open-source projects in this area are already collaborating across the Fediverse. An in-person meeting creates space to deepen that cooperation, welcome users, operators, developers, and all interested participants, and to build trust between communities and projects. Together, we aim to refine shared goals, discuss challenges, and explore how social and technical aspects of federation come together to support a healthy, interoperable open social web for event management and calendars.</p> <p>https://event-federation.eu https://gancio.org https://lauti.org https://mobilizon.org https://bonfirenetworks.org</p>

Open Craft: Exploring Taiwanese Culture and Open Source Communities (en)

<p>Learn the essential skills of <strong>Chinese calligraphy</strong> and <strong>chopsticks</strong> in a fun, hands-on session! Start by creating your own Spring Festival couplets, mastering the brush and forming meaningful characters. Then, switch to chopsticks as you practice savoring dim sum, noodles, rice, beans, and tofu with precision and ease.</p> <p>Along the way, you’ll also explore <strong>Taiwan’s vibrant open-source communities</strong>, discover exciting conferences, and pick up insider tips for sightseeing around the island. Whether you’re a beginner or a cultural explorer, this session promises a unique, immersive, and enriching experience!</p>

Tor Relay Operator Meetup (en)

<p>Welcome to the Official FOSDEM Tor Relay Operator Meetup. This BOF is for current or up-and-coming Tor Relay or Bridge operators interested in meeting like-minded people for an hour-long session with the Tor community. We start with a quick update from the official Tor Project, followed by a longer discussion/Q&amp;A to explore what is happening in our community right now.</p> <p>We have no agenda for the meeting, so that everybody can bring up questions or topics related to the Tor ecosystem here.</p>

Mozilla Community Meetup (en)

<p>Spend some time with members of the Community team at Mozilla along with Mozilla Contributors. This is a great opportunity to learn about contribution opportunities across all Mozilla—for both developers and non-developers (user support, localization, documentation, ideas and product feedback). Newcomers are welcome (encouraged!) to ask questions and for old timers to have a casual chat with other contributors about their works; or help newcomers to get started. We'll also brainstorm on ways for the community to get more involved moving forward. Hope to see ya there!</p>

Open beyond the License (en)

<p>Open source can be legally open yet practically closed.</p> <p>We can all read the code and reuse the licence. But who gets heard, who gets funded, who sets direction, and who feels welcome? This is still shaped by time zones, language, access to money and mentoring, and project governance.</p> <p>This BoF is a structured, friendly discussion for maintainers, contributors, newcomers, community folks, designers, docs writers, translators, researchers, event organisers, and anyone affected by open-source decisions (even if you've never opened a PR).</p> <p>We'll map the points where openness breaks, share approaches that have worked, and leave with 2-3 concrete actions we can try in the next few months: small, testable steps that make participation wider and influence more fairly distributed.</p>

Know Your Enemies: Live Exploit of a PHP Engine Security Breach (en)

<p>All programming languages have their foundations: the engine that interprets your code and makes everything run. In PHP, this is the Zend Engine, a critical piece of software that powers millions of applications worldwide. When everything works, you don’t even think about it. You deploy to production, and the engine does its magic behind the scenes.</p> <p>But what happens when something goes wrong in that core? What if a subtle bug opens the door to a full security breach? Suddenly, the invisible foundation becomes the most important part of the story.</p> <p>Let’s shine a light on two such cases: a recent, real vulnerability in the PHP engine (which has since been patched), and a backdoor that, just a few years ago, actually made it into the release candidate and allowed remote code execution. We’ll walk through how each issue could be exploited and, most importantly, what lessons developers can draw from them. And yes, there will be live, local, sandboxed demos of both exploits in action. Ready to dive in?</p>

The Hidden Life of Infrastructure: How Control Moves Through Code, Chips, and Nations (en)

<p>This talk is about how risk and control moves through the computational stack, from transistors to firmware, from chip monopolies to satellite networks, from invisible maintainers to AI accelerators. We'll walk through the failures that mattered: Heartbleed. Log4Shell. Spectre. The Garmin ransomware attack. The XZ backdoor. Not because they broke things, but because they showed us where power actually lives, and how fragile those concentrations really are.</p> <p>Every one of those failures revealed something: how physical constraints shape digital power, how a single unpaid maintainer can hold up half the internet, how optimization culture erodes resilience. They showed us that nations, economies, and individual freedom now depend on infrastructure most people will never see.</p> <p>But here's the thing: Open Source built that infrastructure. And Open Source can reshape it. This is about understanding where we are, how we got here, and what it means to build systems that distribute power instead of concentrating it. Because the people who write the code should be the ones who decide how it works, and who it works for.</p>

Reverse Engineering the World's Largest Music Streaming Platform (en)

<p>Spotify is the world's largest music streaming service, yet it has never fullfilled the flexibility and platform support needs of the ones enjoying home automation, open streamers and more. For over a decade, the librespot family of projects has been filling that void through reverse engineering of Spotify's products.</p> <p>This talk takes you through one of the longest-running efforts to open up the Spotify ecosystem. We'll explore the technical approaches used to reverse engineer the official clients, the evolution of the project as Spotify's architecture changed, and the delicate balance of operating in legal grey areas while keeping the open source project alive. </p> <p>All of this brought to you by the maintainer of <a href="https://github.com/devgianlu/go-librespot">go-librespot</a> and memeber of <a href="https://github.com/librespot-org">librespot-org</a>.</p>

Fear and Loathing in the App Stores: when FLOSS principles collide with the Gatekeeper interests (en)

<p>The promise of smartphones was freedom in your pocket. The reality? Two corporate gatekeepers controlling what software billions of users can run on devices they supposedly own. This talk examines the uncomfortable compromises FLOSS developers face when trying to distribute apps through iOS and Android app stores, where every principle we hold dear—user freedom, privacy, transparency, and community control—runs headlong into the profit-driven interests of the global mobile duopoly.</p> <p>We'll explore the battleground where free software principles meet platform restrictions: mandatory code signing that undermines reproducible builds, opaque review processes that can arbitrarily reject apps exercising user freedom, 30% revenue cuts that punish sustainable FLOSS funding models, and Terms of Service that can revoke your ability to distribute software overnight. The Digital Markets Act promised to open these walled gardens, but has it? Or have we merely traded one gatekeeper's rules for slightly different ones?</p> <p>This isn't just about technical hurdles—it's about fundamental questions. Should FLOSS projects compromise on GPL compliance to reach users? Is it ethical to pay fees and developer taxes when that money funds the very infrastructure restricting user freedom? When F-Droid and alternative app stores offer true freedom but reach only 2% of users, do we accept the compromise or maintain ideological purity while our potential impact dwindles?</p> <p>The stakes are existential. As our digital lives increasingly occur on locked-down mobile devices, FLOSS becomes the last line of defense against surveillance capitalism, planned obsolescence, and the erosion of user agency. If we can't effectively distribute free software on the platforms where users actually are, we risk relegating FLOSS to irrelevance precisely when it's needed most.</p> <p>But there's hope. New regulatory frameworks, emerging alternative stores, advances in progressive web apps, and creative technical solutions offer paths forward. We'll discuss practical strategies for maximizing reach while minimizing compromise, building communities that value freedom over convenience, and preparing for a post-duopoly future.</p> <p>This talk will challenge both the compromisers and the purists, asking uncomfortable questions: Are we collaborating with platforms that fundamentally oppose our values? Or are we pragmatically meeting users where they are? The answer may determine whether free software thrives or withers in the mobile era.</p>

Open Source Design, the wake-up call for developers! (en)

<p>The Free and Open Source ecosystem has continued to evolve and adapt itself despite an ever-changing landscape that, paradoxically, seems to find pleasure in threatening its very own fabric.</p> <p>And yet our resilience won't be able to sustain another direct hit, this time coming from the fact that Open Source lives at odds with the UX/UI Design Process.</p> <p>Open Source, both as a social contract and as a practice, cannot afford not to fully own the strategic space that dictates how we connect with end users.</p> <p>In this talk I will explain why this has become so crucial and why, while open-source developers are the most likely audience to suffer the most if this is not dealt with, they are also the most naturally equipped to lead a new design&amp;code worldwide alliance.</p>

FreeSewing: How to buy less, create more, and feel great about it (en)

<p><a href="https://freesewing.eu/">FreeSewing</a> is an <a href="https://codeberg.org/freesewing/freesewing">open source</a> project that provides a core (Javascript) library for designing parametric sewing patterns, as well as a growing collection of designs and supporting tools. We've been around for more than a decade, and in that time have built a large user base among the maker community. </p> <p>FreeSewing designs are implemented as code giving you unmatched power and flexibility. You can mix and match parts from different designs, extend them, or add options that turn one base design into many. Our choice for Javascript means you can run all of this in your browser. Suffice to say, these are not your grandma's sewing patterns.</p> <p>This talk will cover why I started FreeSewing, the pain points it aims to address, and how it works under the hood. I'll also cover our tech stack, and the choices we've made in this area, as well as how we needed to adapt as we outgrew our earlier choices. In addition, I'll cover some of the lessons learned after more than a decade of designing parametric sewing patterns for bodies in all shapes and forms. I will also include tips for running an open source project for a prolonged period of time while avoiding the pitfalls of maintainer burn-out.</p> <p>I'll bring some cool swag too.</p>

Automating translation of a bestseller to spark children's interest in coding (en)

<p>The story “Ada &amp; Zangemann – A Tale of Software, Skateboards and Raspberry Ice Cream” inspires the software freedom community because it covers more than the simple value of learning to program. It also covers the importance of control over technology and its impact on society. In this way the story is inspiring many kids, teens, parents and many others to learn programming and shape technology.</p> <p>I too was captivated by the story. Working on a Dutch translation sent me down the path of improving the automation to help others like me to translate the story and publish it in different formats. The free culture license of the book enables and compels the community to adapt it, and they have. The community keeps surprising us with new formats to convey the story. Since its release it has been translated into 30 languages, published as a book in 7 and as movie in 5. And it is available in a growing number of other formats: epub, online book, bilingual book and kamishibai.</p> <p>Translation and localization is the primary purpose of the automation. More interesting and ambition is to support the increasing number of formats: from printed book, to online book, voiceover text and subtitles. This wide variety of formats presents a unique challenge for which no ready-made solution exists. By leveraging open standards (XML, Docbook, ITS) and Free Software (Scribus, itstool, gettext, xsltproc, pandoc, Weblate) we created automation that enables translators to add new languages while also enabling new formats to be added. This includes a novel method for inserting text and images into Scribus. This multi-media setup can be used as inspiration for other free culture multi-media projects.</p> <p>In this presentation we will tell the story how the automation developed over time. We'll share the inspiring stories from the community that leveraged the automation and influenced its development. The technical challenge of the automation is fun, but the community stories give it meaning and motivate me to keep at it.</p> <p>With this presentation we hope to inspire others to contribute to the Ada &amp; Zangemann community by translating, adding a new format or contributing to the automation and to share own materials benefiting our community as Open Educational Resources.</p>

From Drones to Data: Building an Open Mapping Ecosystem for All (en)

<p>At the Humanitarian OpenStreetMap Team (HOT), we envision an ecosystem of open mapping technology that enables everyone, and in particular vulnerable communities, to make open map data available in order to use in disaster response and humanitarian context. We focus on building with our community and involving our users in every step of the process.</p> <p>In this session, we would like to take you on a journey in introducing the full end-to-end open mapping workflow and the open source tools enabling that process - from the newly developed Drone Tasking Manager to fAIr (our AI assisted mapping service), Field Tasking Manager, ChatMap and uMap. We will share some stories from case studies in testing the end to end mapping workflow in Indonesia and Sierra Leone and the lessons learnt.</p> <p>We hope that you will leave this talk inspired and with an understanding on how YOU can become part of the open mapping ecosystem and contribute to the technology development!</p> <p>HOTOSM website: https://www.hotosm.org/tech-suite HOTOSM Github: https://github.com/hotosm</p>

The Filesystem Diaries: Scaling Btrfs in an Enterprise (en)

<p>Btrfs was merged into the Linux kernel in 2009, arriving with bold promises—and, let's be honest, a reputation for instability. I first tried it on my laptop in 2011. It wiped my data. Twice. On the bright side, it taught me the value of backups.</p> <p>Fast forward to 2025: btrfs is no longer the experimental filesystem of the past. It's stable, mature, feature-rich, and fully part of the Linux kernel. But old reputations die hard. Even today, Google Cloud Platform doesn’t officially support it—not because of technical shortcomings, but because customer demand hasn’t pushed the issue.</p> <p>At Chronosphere, we decided to take a fresh look. After months of evaluation and testing, we migrated petabytes of customer data across thousands of disks to btrfs. This talk is our story: why we made the leap, what we learned along the way, and how we’re helping bring btrfs into wider enterprise adoption—including working with Google to support it natively.</p> <p>I'll share the decision-making process, key performance and reliability insights, and the quirks you only discover when running btrfs at scale. Whether you're btrfs-curious or just love a good ops tale, you'll walk away with real-world takeaways—and maybe a newfound respect for this once-maligned filesystem.</p> <p>If you know what NTFS, ext4, or ZFS are, you’re ready for this journey.</p>

The Meshiverse OR The Revolution of the Little Radios (en)

<p>In an era where our identities and rights are increasingly mediated by devices we call “phones”, the boundaries between digital citizenship and corporate feudalism are blurring. This talk explores the intersection of technology, autonomy, and community within the unique context of transformational festivals, temporary autonomous zones (TAZs) (or future isolated neightborhoods and local communities?) where experimentation and reappropriation of tools take center stage.</p> <p>Starting from a cyberpunk reflection — <em>high tech, low life</em> — the talk questions how much of that dystopian vision has already become reality: from algorithmic control to the loss of privacy and digital dependency. Drawing on the legacy of radio as an anarchic medium and the new rise of mesh networks such as <strong>Meshtastic/Meshcore/Reticulum</strong>, <strong>The Things Network</strong>, and <strong>Helium</strong>, Davide Gomba connects past and future: from Marconi lighting up the Cristo Redentor in 1931 to today’s decentralized communication protocols.</p> <p>Through examples from <strong>Lutopia’s “Ozorian Experiment” (2024)</strong> and the ongoing <strong>Burning Mesh</strong> initiative, the talk presents how off-grid communication can become both a poetic and political act - reclaiming connection, rebuilding resilience, and teaching new forms of digital literacy. Between <strong>cyberpunk dystopia and techno-anarchic optimism</strong>, “The Meshiverse OR The Revolution of the Little Radios” is a manifesto for the right to communicate freely - even, and especially, when the network goes dark.</p>

Introduction to Local First & Welcome to our devroom (en)

<p>Welcome to the "Local First, sync engines and CRDTs devroom", first edition this year at FOSDEM'26. We are excited to propose you a full day of amazing talks ranging from CRDT libraries and frameworks, to local first projects using them, and including academic research, UX design, sync protocols and engines.</p> <p>We believe Local First software is the future of app development. But what is Local First software? In this short introduction we will touch upon the general concepts and describe this new paradigm that gathers an ever growing community of enthusiast engineers, designers, researchers and developers, following the motto: "You own your data, in spite of the cloud".</p> <p>Please come early to the devroom to take your seat, as we will start on time (9:00AM sharp). The room will be open as early as 8:30AM. It has limited capacity, and when reached, the door will be closed. We have an amazing lineup of great speakers, and you surely do not want to miss one bit of it. See you on Sunday morning! Advice from the devroom managers: Don't miss the next talk: Jazz is a great framework and Giordano will start with an introduction to CRDTs for those who don't have prior knowledge. And then, second advice: stay with us all day, we have selected only amazing talks!</p>

CRDTs, E2EE, permissions and Jazz! (en)

<p>CRDTs are an exciting primitive for distributed state. In local-first apps, synced CRDTs can be framed as a natural extension to reactive local state, allowing developers to build eventually consistent multi-device and multi-user apps, with business logic living completely on the client, only requiring generic syncing infrastructure.</p> <p>A key feature that traditional backends solve remains a challenge, though: how do permissions work in this world? In addition to being a batteries-included framework that makes local-first state practical, Jazz uniquely solves local-first permissions, by coupling public-key cryptography with CRDTs in a way that allows for dynamic, expressive permission structures which can be defined on the client and are enforced globally, in an auditable way.</p> <p>Advice from the devroom managers: Don't miss this talk! Jazz is great framework and Giordano will start with an introduction to CRDTs for those who don't know what it is. And then, second advice: stay with us all day, we have selected only amazing talks!</p>

Taming your Yjs documents (en)

<p>Yjs is one of the oldest and most widely used libraries that enhance web editors by allowing multiple users collaborate over documents in real time, also without requiring continuous network connection. Evernote and Jupyter Notebooks are among many of its prominent users.</p> <p>During this presentation we'll address some of the common pitfalls that new developers may encounter when working with Yjs library, what architectural foundations are causing them to happen and what can we do to overcome them.</p>

Local-First in Production: How We Built Plane's Collaborative Wiki with Yjs (en)

<p><a href="https://github.com/makeplane/plane">Plane</a> is an open source project management tool used by thousands of teams. A year ago, we shipped Wiki — a collaborative documentation system built on Yjs with real-time editing, offline support, and version history.</p> <p>Yjs is remarkable. Kevin Jahns and the community have built something incredible — real-time sync, conflict resolution, offline editing, all handled elegantly. But integrating a powerful library is just the start. This talk is about what comes after.</p> <p>I'll cover the production challenges we solved building on top of Yjs, the crux of it would be around: </p> <ol> <li>Server-side edits — making backend mutations (AI, automations, database state sync in case of subdocuments) coexist with live client editing without users feeling out of sync</li> <li>Scaling the sync layer — infrastructure decisions for thousands of concurrent documents with awareness working as expected.</li> <li>Large document performance — what breaks when documents get massive, and how we fixed it without breaking our servers, horizontally scaling sticky ws connections.</li> <li>Version history — snapshots and visual diffs using StateVectors and the StructStore (deep-dive: palanikannan.com/blogs/version-history-and-snapshots-in-yjs) and what works at scale! </li> <li>Offline-first in practice — making "syncs when you're back" actually reliable, especially say when you open your tab that chrome killed due to inactivity :p</li> <li>Permissions and reacting to them in realtime, inline comments sync and so much more!</li> </ol> <p>Plane is <a href="github.com/makeplane/plane">fully open source</a> with 38k+ stars and a vibrant OSS community. Real problems, real code, no theory slides.</p>

Automerge + Keyhive Design Overview (en)

<p>Automerge is a mature library for building local first applications by enabling version control for structured data. The strategy is to capture all edits to data at a very fine grain (e.g. per keystroke when editing text) and then present a good API for managing concurrently edited versions of this data. </p> <p>The version control approach to collaboration makes working concurrently feasible and makes servers fungible - it increases user autonomy, but it introduces problems as you can't rely on access control on the network boundary. Keyhive is a local first access control architecture which we think is a compelling point in the design space which solves these problems.</p> <p>In this talk we will give a high level overview of the motivation, design, problems, and future directions of the broader Automerge ecosystem.</p>

NextGraph: E2EE sync engine, SDK, graph DB, and reactive ORM (en)

<p>NextGraph is a protocol, a framework, and a platform that supports easy development of Local-First, decentralized, secure and private apps.</p> <p>By combining the best of the local first world (Yjs, Automerge CRDT libraries), a graph database, DID (decentralized identifiers) for users and documents, and end-to-end encryption plus encryption at rest, we provide an SDK that offers all the requirements of portability, interoperability and security needed today for building a true alternative to Big Tech platforms and products.</p> <p>This talk will be composed of two parts. Niko will first introduce the general architecture of our platform, engine, protocol and SDK, giving an overview of its components, and some details on the E2EE sync protocol, cryptographic capabilities/permissions/access control. We will show how we support any kind of CRDT, including Automerge and Yjs, and the CRDT for Graph database (RDF) that we have developed.</p> <p>Then Laurin will introduce the new ORM TypeScript SDK for <strong>NextGraph</strong> that turns document/database records into ordinary, typed objects with two‑way binding. By proxying those objects and emitting signals, the SDK provides a framework‑agnostic reactive layer that integrates cleanly with React, Vue, and Svelte. And more frameworks could be easily added in the future.</p> <p><strong>CRDT support</strong> - The SDK works with Yjs, Automerge, and, most notably, <strong>RDF</strong> - a graph data format designed for application interoperability. The SDK includes a converter that transforms <strong>SHEX</strong> shapes (an RDF schema language) into TypeScript type definitions for type safety.</p> <p><strong>Reactive POJOs</strong> - Objects are wrapped in a proxy, so any property change triggers a signal, which updates both the UI and sends a JSON patch to the backend. Signals provide an efficient, event‑driven mechanism for state propagation and have been gaining popularity in modern front‑end ecosystems.</p> <p><strong>You will see</strong> a live demo walking through a simple property change, showing how the mutation is instantly persisted to the local database, reflected in UI components across React, Vue, Svelte, and synchronized with the network across devices and user accounts.</p>

ElectricSQL: Query-driven Sync in TanStack DB (en)

<p>Building fast, resilient, and collaborative applications increasingly demands more than reactive UI frameworks and client-side state management. The next generation brings reactivity to the data layer itself—letting applications stay in sync with the backend automatically through a sync-engine architecture.</p> <p>This talk explores how <a href="https://tanstack.com/db">TanStack DB</a> provides a practical path toward such architectures without requiring a rewrite or commitment to a particular backend. You can start with familiar API-driven workflows using <a href="https://tanstack.com/query">TanStack Query</a> and progressively adopt richer sync through <a href="https://electric-sql.com/">Electric</a> or any real-time backend. TanStack DB acts as the connective tissue: a unified, fast, reactive client database that keeps application state synchronized with your backend.</p> <p>The focus of this presentation is TanStack DB’s newest capability: query-driven sync. Instead of preloading large collections or keeping oversized in-memory datasets, TanStack DB loads exactly the data a query needs—whether that’s a page of results, a slice of a document, or a relational join. Under the hood, an incremental view-maintenance engine built on differential dataflow ensures queries update efficiently as new data arrives.</p> <p>This enables applications to handle larger data volumes, compute reactive queries efficiently, and move toward a true sync-engine architecture—without sacrificing the incremental adoption story that makes TanStack DB practical for real-world teams.</p>

BlockNote, Prosemirror and Yjs 14: Versioning and Track Changes (en)

<p>Yjs is a widely used library to build collaborative applications. BlockNote and Prosemirror are text editors that closely integrate with Yjs.</p> <p>In this talk, we'll preview upcoming functionality for Attributed Version History (who wrote what, and when?) and Track Changes (suggestions). We'll explore major new functionality coming in Yjs 14 (changesets and attributions), y-prosemirror and BlockNote that will make this possible.</p> <p>The BlockNote team (Nick, Yousef and Matthew) has collaborated closely with Yjs (Kevin Jahns) on these topics, funded by ZenDiS (OpenDesk) and DINUM (La Suite Docs).</p>

Towards a Local-First Linux Desktop with Modal, Reflection and p2panda (en)

<p>This talk will introduce our work within various collectives working together toward a more local-first future for modern Linux desktop and mobile platforms.</p> <p>We'll introduce you to <a href="https://modal.cx">Modal</a>, a collective focused on bringing local-first principles to Linux Desktop and Mobile. We'll also showcase <a href="https://github.com/p2panda/reflection">Reflection</a>, our GTK-based text editor, and <a href="https://p2panda.org/">p2panda</a>, the underlying peer-to-peer stack.</p> <p>Modal is a new collective dedicated to development, design, organizing, policy campaigning, and more, to make computing more useful, secure, and resilient. Our work centeres around software infrastructure projects, including GNOME, postmarketOS, p2panda, systemd, and the Linux kernel. We aim to make it simple to sync data across your devices while providing easy-to-use local-first APIs for applications. By doing this, we're creating an ecosystem of free software apps that leverage this infrastructure for synchronization and real-time collaboration. The foundation of all this technology is the p2panda project, which is built with "walkaway" principles in mind. p2panda's modular networking stack allows applications to operate autonomously on a wide variety of infrastructures—whether it's the Internet, Bluetooth, Wi-Fi Direct / Aware, or even sneakernet - giving you flexibility and control over how and when your devices sync.</p> <p>p2panda aims to provide everything you need to build modern, privacy-respecting and secure local-first applications. Over five years of research, testing, exploration and collaboration with other teams, we've identified emergent patterns which have been solidified in p2panda's "building blocks". We'll present an overview of the peer-to-peer problem space and describe how each of our modules are designed to provide Connectivity, Discovery, Sync, Encryption, Access Control, and more.</p> <p>We'll showcase concrete software built around Modal and p2panda, including Reflection, our native, GTK-based text editor. Reflection not only serves as a real-world example of a local-first application, but also as a "template" for developers looking to build similar apps. Alongside Reflection, we're developing a GObject interface for common p2p primitives, wrapped around p2panda and UI components. This interface aims to simplify the process of integrating decentralized networking into applications.</p> <p>Finally, we'll discuss our work on a system service designed to enhance applications with p2p features, enabling a unified user experience at the OS level. This system service manages key tasks like permissions for networking activity, node trust management, multi-device support, and identity management through the address book. It is agnostic to any specific p2p framework, which we hope will foster greater interoperability across different platforms and p2p technologies in the future.</p>

Teamtype: multiplayer mode for your text editor – towards a Collaborative Editing Protocol (en)

<p>Files on your hard drive are the ultimate local-first storage. But to allow real-time collaboration from within text editors, developers currently have to reinvent the wheel each time: Figure out how to hook into buffer changes correctly, implement displaying remote cursors, finding a way to get the required events in and out of the editor.</p> <p>In addition, for each combination of editor and collaborative use-case, there needs to be a separate plugin: For example, there is a Vim plugin to connect to an Etherpad, or you need individual editor plugins when wanting to live-code music or visuals together.</p> <p>Similar problems have already been solved by different editor-facing protocols: To integrate "language intelligence" tools (that provide autocompletion or refactorings), you can use the Language Server Protocol (LSP). Likewise, debugging support can be added via the Debug Adapter Protocol (DAP), and support for LLM tooling is now provided via the Model Context Protocol (MCP).</p> <p>We think that there's a gap for a "Collaborative Editing Protocol" (CEP, working title) that allows text editors to talk to "collaboration servers", and thus provides them with collaboration functionality. Per editor, this protocol would only need to be implemented once, making the resulting software components interoperable. You'd have plugins for Neovim and for Emacs that speak CEP, and you'd have an Etherpad bridge that also speaks it, and you could use all of them together!</p> <p>In this talk, we want to outline the requirements for a protocol like that. We'll discuss different approaches, and demonstrate the proof-of-concept protocol we built for our local-first peer-to-peer pair programming software "Teamtype". We're looking to form a group to iterate on a "collaboration protocol" together, and eventually standardize it!</p>

Radicle: Local-First Code Collaboration (en)

<p>Git came and changed the landscape of collaborating on code in a decentralised and efficient manner – once you get to grips with the command-line, of course. GitHub capitalised on the fact that the social element of collaboration was missing from Git, while social platforms were emerging left, right, and centre. Our beloved, decentralised tool succumbed to the powers of centralisation...</p> <p>To empower Git users once more, the Radicle protocol (heartwood<a href="https://app.radicle.xyz/nodes/seed.radicle.xyz/rad:z3gqcJUoA1n9HaHKufZs5FCSGazv5">^1</a>) is a decentralised forge to allow people to collaborate in a sovereign and local-first manner. It introduces the ability to define social artifacts that live alongside your code and are present right-there on your disk.</p> <p>Let's dive in to see how we did this, and how you can get involved in shaping a better future for collaborating together. </p>

Miru: Building a collaborative video editor with offline support (en)

<p><a href="https://miru.media/">Miru</a> is a set of web-based tools for media editing. In this talk, I'll present the video editing features that we're developing, and our journey to intuitive collaboration with offline support using CRDTs. I'll outline some similarities and differences between a video editing timeline and a rich text document, the CRDT libraries we evaluated, and what approaches did and didn't work for our editor.</p>

Using CRDTs for collaborative commenting in your favourite free software desktop word processor (en)

<p>We implemented a prototype that enables real-time collaborative editing in Writer.</p> <p>This prototype takes the form of a special read-only mode that allows inserting, deleting, and editing comments by way of the y-crdt/yrs CRDT library.</p>

Teleportal: A real-time collaborative editing framework (en)

<p><a href="https://teleportal.tools">Teleportal</a> is a framework for creating a web-standards based backend &amp; client for realtime collaborative applications. It is based on the popular <a href="https://yjs.dev/">Y.js CRDT</a>, and implements a synchronization protocol on top. Teleportal focuses on giving the building blocks to create a server implementation, rather than being a single monolithic implementation. The project was built out of the desire for an optimized replacement of <a href="https://tiptap.dev/docs/hocuspocus/">Hocuspocus</a> (in both scale, performance &amp; features). It currently implements communication over HTTP, HTTP + SSE, Websockets, but should scale to other bidirectional protocols. As well as being storage implementation agnostic &amp; offering E2EE (alpha), there are plans to implement file uploads, user customizable messaging &amp; more.</p>

A Local First collaborative workplace? (en)

<p>The DINUM introduces <strong>LaSuite</strong>, an MIT-licensed open-source collaborative suite designed to streamline the work of public servants. It includes four core applications:</p> <ul> <li> <p><strong>Docs</strong> (real-time collaborative editing, co-developed with Germany and the Netherlands)</p> </li> <li> <p><strong>Drive</strong> (WOPI-compatible file sharing)</p> </li> <li> <p><strong>Meet</strong> (LiveKit-based video conferencing)</p> </li> <li> <p><strong>AI Assistant</strong> (powered by Vercel AI).</p> </li> </ul> <p>LaSuite prioritizes seamless UI/UX and offers a <strong>fully reusable design system and UI Kit</strong>—from simple components to complex interfaces (e.g., search and sharing modals).</p> <p>We're following closely the work of the Local First community as it is part of our requirement to deliver e2ee collaboration accross the whole state.</p> <p>This talk will cover the architecture, development workflow, and highlight the <strong>UI Kit</strong> as a reusable resource for the Local First community to build their own collaborative apps.</p>

Composing capability security and CRDTs (en)

<p>CRDTs allow for decentralized replication of data. Capability security allows for decentralized control over behavior. Local-first applications often use access-control list (ACL) security which has significant downsides versus capabilities, especially in a decentralized context. In this talk, I'll examine how CRDTs and capabilities can be composed to improve the security of local-first applications using a group chat prototype as a case study.</p>

Designing for Local-First: UX Patterns for a Network-Optional World (en)

<p>CRDTs and local-first sync engines provide exciting opportunities for creating new experiences for our users, but with technological advances come new challenges, such as:</p> <ul> <li>When the network connection is restored, how do we replace stale data without disorienting the user?</li> <li>If an app allows partial loading of remote data, how do we communicate what is and what is not available offline?</li> <li>If actions cannot be completed because of no or limited network connection, how can they know which actions haven’t been completed and retry them?</li> <li>In a multiplayer app, how do we communicate in a non-disruptive way which content has changed and who has changed it?</li> </ul> <p>These are questions that hadn’t needed to be addressed in a world of server-first apps, but we will need to take some thought in how to pair clear and informative UX with sync technologies to create the best possible user experiences for our apps.</p> <p>In this talk, we will go over pitfalls that we should avoid when making local-first apps and some patterns that can help make better experiences for our users.</p>

Local-First Peer-to-Peer apps with js-libp2p, IPFS and OrbitDB (en)

<p>I am working on several prototypes with js-libp2p, IPFS and OrbitDB for peer-to-peer syncing CRDTs in OrbitDB. I'd like to talk about what it all means in practice from a web developer perspective working with those technologies, WebAuthN/Passkeys, DIDs, UCANs, decentralised storage and pinning networks — also from a security perspective in times when cloud services are failing and account breaches are becoming the norm.</p> <p>An account-less, offline-first and local-first simple-todo PWA with WebAuthN: https://simple-todo.le-space.de/#/orbitdb/zdpuAskw4Xes4nxR1YNV8TxK2qmrDgceAqEoGHDtTAUhQWvDP</p>

SQLRooms: Local-First Analytics with DuckDB, Collaborative Canvas, and Loro CRDT Sync (en)

<p><a href="https://sqlrooms.org">SQLRooms</a> (<a href="https://github.com/sqlrooms/sqlrooms">GitHub</a>) is an open-source React framework for building local-first data analytics applications powered by <a href="https://duckdb.org">DuckDB</a>. SQLRooms can run entirely in the browser using DuckDB-WASM, or connect to a shared session-backend running native DuckDB for larger datasets—in both cases, enabling privacy-preserving analytics where data stays under user control.</p> <p>In this talk, I'll present SQLRooms' local-first architecture and our ongoing work on real-time collaboration using <a href="https://loro.dev">Loro CRDT</a>. We're building a Canvas module with SQL query cells and <a href="https://vega.github.io/vega-lite/">Vega-Lite</a> visualization cells, a Notebooks module, and an underlying DAG (directed acyclic graph) engine that tracks dependencies between cells—automatically re-executing downstream cells when data changes. These modules will support collaborative editing via <code>@sqlrooms/crdt</code>, with sync enabled through WebSockets using <a href="https://pypi.org/project/sqlrooms-duckdb-server/">sqlrooms-duckdb-server</a>.</p> <p>A key insight for analytics apps: DuckDB serves as a read-only query engine—the underlying data doesn't need to be synced. Only the UI state requires CRDT synchronization: queries, notebooks, canvas layouts, annotations, and comments. This CRDT state can be persisted both in a shared session-backend DuckDB and on local machines for offline access.</p> <p>For session-backend deployments, sqlrooms-duckdb-server provides a shared DuckDB instance where all connected clients query the same data—useful for large datasets or when consistent results matter. This can be deployed with e.g. <a href="https://developers.cloudflare.com/containers/">Cloudflare Containers</a> for on-demand, per-session instances.</p> <p>I'll discuss our choice of Loro over Yjs and how separating data (read-only DuckDB) from collaborative state (CRDT) simplifies the sync architecture while enabling privacy-preserving collaborative analytics.</p>

A Programming Language Perspective on Replication (en)

<p>Distributed systems replicate data to improve availability, scalability, and fault tolerance. Ensuring that replicas remain eventually consistent is difficult. Current practices advocate for the use of Replicated Data Types (RDTs) which guarantee convergence out-of-the-box, e.g. CRDTs. However, programming distributed systems using these RDTs is non-trivial due to the lack of appropriate abstractions for replica discovery, update propagation, etc.</p> <p>At our research lab at the Vrije Universiteit Brussel, we look at what it means for developers to build and utilise eventually consistent data types in their applications. The majority of current RDT approaches are ad-hoc, they require a dedicated implementation for each data type. However, building advanced collaborative applications requires custom RDTs that are tailored to the needs of the application. That implies extending or composing existing RDTs, or designing new ones.</p> <p>Our goal is to develop abstractions and methodologies for the systematic construction of applications requiring replicated state. In this talk, we particularly focus on two main aspects: (1) non-ad hoc approaches to efficient RDT implementations, and (2) simplifying the development of application-specific RDTs:</p> <p>Many approaches use ad-hoc solutions to track causality and ensure eventual convergence, e.g. keeping meta-data in the implementation. In a lot of cases, their design does not translate well into efficient implementations and is not suitable for resource-constrained runtimes. We present Flec[1, 2, 3], a framework that guides developers in making informed decisions during the development process, by providing an API that gives developers a uniform and structured way to deal with functional system requirements. This can range from network constraints to security and authorization aspects.</p> <p>To simplify the development of collaborative applications using RDTs, we investigate alternative approaches where RDTs can be automatically derived from their sequential implementation [4, 5]. By means of an analysis we can detect conflicting operations, and automatically derive functional CRDTs. In some datatypes, certain application invariants would be impossible to guarantee with CRDTs. For these cases, we support automatically detecting where an application would have to synchronise and output an RDT with mixed consistency. </p> <p>[1] <a href="https://cris.vub.be/ws/portalfiles/portal/116156754/Jim_Bauwens_PhD_thesis.pdf">Jim Bauwens, 2024. Flexible CRDTS for a demanding world. PhD Thesis</a> [2] Jim Bauwens and Elisa Gonzalez Boix. 2020. Flec: a versatile programming framework for eventually consistent systems. Proceedings of the 7th Workshop on Principles and Practice of Consistency for Distributed Data. Association for Computing Machinery, New York, NY, USA, Article 12, 1–4. <a href="https://doi.org/10.1145/3380787.3393685">DOI</a> [3] <a href="https://gitlab.soft.vub.ac.be/jimbauwens/flec">https://gitlab.soft.vub.ac.be/jimbauwens/flec</a> [3] Kevin De Porre, Carla Ferreira, Nuno Preguiça, and Elisa Gonzalez Boix. 2021. ECROs: building global scale systems from sequential code. Proc. ACM Program. Lang. 5, OOPSLA, Article 107 (October 2021), 30 pages. <a href="https://doi.org/10.1145/3485484">DOI</a> [4] <a href="https://github.com/verifx-prover/verifx/tree/main">https://github.com/verifx-prover/verifx/tree/main</a></p>

Willow - Protocols for an uncertain future (en)

<p>Centralised systems were designed with the best of intentions, but were turned against us anyway. And peer-to-peer systems will be exactly the same.</p> <p>How do we make the next generation of protocols more difficult to weaponise?</p> <p>This is the lens which we'll use to look at <a href="https://willowprotocol.org">Willow</a>, a family of publicly-funded, open source peer-to-peer protocols. How can we learn from the ways both centralised and peer-to-peer systems have been abused in the past, and apply that to new designs? We'll take a look at some of the (surprising) paths Willow has taken to make it harder to turn against us.</p> <p>Please enjoy this illustrated, slightly musical presentation from the <a href="https://worm-blossom.org">worm-blossom</a> collective.</p>

Get to know local-first pioneers PouchDB & CouchDB — Look ma, offline with no CRDTs! (en)

<p><a href="https://pouchdb.com">PouchDB</a> and <a href="https://couchdb.apache.org">CouchDB</a> have been an absolute Local-First Dream Team since 2013. In this workshop, we’ll show you why. Join us for hands-on time with PouchDB itself, a look at a fleshed out demo app to see how the Open Source projects PouchDB, CouchDB and app state fit together, and a quick glance at a convenient Open-Source way to easily host your own CouchDB.</p> <p>We’ll cover:</p> <ul> <li>Local (in-client) data storage</li> <li>Client-to-Server data synchronisation</li> <li>Working offline and handling conflicts</li> <li>How to use database events to power your UI</li> </ul> <p>We’ll also share a bit about why we believe it is important to build on Open Source projects with a clear governance structure, so you can rely on it for the long-term.</p> <p>Time permitting, we’ll share some of the extraordinary projects we have built with PouchDB &amp; CouchDB: </p> <ul> <li>A COVID Vaccination infrastructure for all of Bavaria</li> <li>Fighting Ebola with first-responder support software</li> <li>Route planning for humanitarian relief efforts in an active crisis zone</li> </ul>

Seed Hypermedia: The Future of Digital Sovereignty (en)

<p>What if the web was designed for sovereign communities, instead of centralized platforms? <a href="https://seed.hyper.media/">Seed Hypermedia</a> brings first-class support for decentralized identity, provenance, and community governance, unlike the traditional web where these features are afterthoughts. Local-First principles and CRDTs are foundational to our protocol and software. The result isn’t just “offline-first documents,” it’s a model of a resilient and deeply-connected web that cannot be captured.</p>

Domain crate update: developments, plans; what would you like to see? (en)

<p>Two years have passed since we presented Domain crate, our DNS library written in Rust (https://github.com/NLnetLabs/domain) here at FOSDEM. We added a lot of functionality (for example, DNS client and server support, DNSSEC validation, DNSSEC signing) and started writing our first applications. The most notable application is our new DNSSEC signer called Cascade (https://github.com/NLnetLabs/cascade). In this presentation, I go over the work we have, what our plans are for the coming year. And we would like to hear from you, what would you like to see in a DNS library.</p>

Orchestrating PowerDNS deployments with servfail-sync (en)

<p>Given a large enough network of distributed nameservers, updating their configs and keeping all of them in sync becomes a highly error-prone activity. The problems multiply when multiple sysadmins and different operating systems are involved. We have created a low-complexity solution for syncing the NS configuration and keeping all servers aware of the current shape of the network.</p> <ul> <li><a href="https://git.sakamoto.pl/servfail/servfail-sync">Repo</a></li> <li><a href="https://beta.servfail.network/">Project</a></li> </ul>

Running a highly available, ad-blocking, private DNS setup in Kubernetes (en)

<p>DNS is the most critical service that runs on small, client-focused networks. Hosting your own DNS unlocks interesting possibilities: Lower latencies, caching, DHCP hostname integration, and ad and malware blocking just to name a few. However, it also comes with great responsibility: For clients, if DNS is down, the internet is down.</p> <p>In this session we will explore how we can have all those delightful features while maintaining resiliency and zero-downtime upgrades, using Kubernetes as a platform. We will cover well-established, open source projects such as <a href="https://thekelleys.org.uk/dnsmasq/doc.html">dnsmasq</a> and <a href="https://github.com/DNSCrypt/dnscrypt-proxy">dnscrypt-proxy</a>, explaining what they are, how they work, and how to compose them.</p> <p>In the platform side of things, we will use Kubernetes and <a href="https://github.com/metallb/metallb/">metallb</a> to provide self-healing, as-code infrastructure and layer 3 failover respectively. Prior experience with Kubernetes is not required to get the most out of this session.</p>

Anatomy of a Resilient Nameserver: Concurrency, Resolution, and Protection (en)

<p>On paper, DNS is a simple request-response protocol. In reality, building an authoritative nameserver that delivers under heavy load, processes malformed packets safely, and resists DDoS attacks is a complex engineering challenge.</p> <p>This talk peels back the layers of erldns, DNSimple's open-source high-performance DNS server, to explore the fundamental architecture required to handle millions of queries per second. We will focus on:</p> <ul> <li>Simplified Resolution: How a special binary tree structure drastically simplifies the DNS resolution logic, making complex requirements like empty non-terminals and handling zone cuts trivial.</li> <li>Concurrency Models: How to structure a system that isolates failures per-request so that a crash in one query never brings down the server.</li> <li>Traffic Management: Strategies for handling UDP floods and managing TCP connection pools without exhausting resources.</li> <li>Packet Handling: The nitty-gritty of parsing binary DNS wire formats safely.</li> </ul> <p>While the reference implementation uses Erlang, the architectural lessons on isolation, supervision, and fault tolerance are applicable to any language. This session is designed for developers and operators who want to understand the "nuts and bolts" of how robust DNS software is built.</p> <p>Project Links: - DNS Server (erldns): https://github.com/dnsimple/erldns - DNS Library (dns_erlang): https://github.com/dnsimple/dns_erlang</p>

Breaking the bad, stopping the ugly by using Open Source (en)

<p>Isn’t monitoring DNS queries a really bad idea? If the monitoring crosses the line to surveillance, we agree. Monitoring for bad actors is still needed and valuable for cybersecurity. Building such a platform in Open Source and running it as a non-profit is much better than letting commercial actors consume this data without making it an open data commons. For sure many won’t protect the user’s privacy the way we do.</p> <p>This is the story about the DNS TAPIR Open Source project - the reason we started it, our core principles and the architecture .</p>

lwresd: how can be obsolete daemon reused for new features (en)

<p><em>lwresd</em> was present long ago in Debian 4, acompanied by the libc library plugin <em>libnss_lwres</em>. It was intended to be a simpler cache than a standard name server, but it never gained wide adoption. Because it offered no significant advantages over using a DNS server like <em>named</em> directly. It was removed from BIND9 after version 9.11.</p> <p>I have a few ideas on how to use it over Unix domain sockets to unlock new features. With some significant modifications to the original concept, it may make sense to revive the lwresd daemon.</p> <ul> <li>Deprecated lwresd docs: <a href="https://downloads.isc.org/isc/bind9/9.11.37/doc/arm/Bv9ARM.ch05.html">BIND 9.11.37 ARM</a></li> </ul>

Querying DNS for software updates (en)

<p>As a developer, how do you add an automated check for software updates to your application? You could use DNS! DNS is lightweight, provides redundancy, responses are cacheable, and going through your network resolver gives you some privacy.</p> <p>But, making DNS changes as part of a software release is not ideal, I've done it. Can we automate this? We can for Go applications! Gopherwatch.org is a free service that monitors the Go sumdb, a transparency log (like certificate transparency) containing all Go "modules" (libraries/applications) and their published versions. Gopherwatch.org provides a DNS interface for querying the latest version for all Go applications/libraries, and the latest Go toolchains.</p> <p>We'll look at how the Gopherwatch DNS interface works and discuss limitations and possible future improvements. If there's time, we'll also look at how the DNS interface is used to provide one-click or even fully automated software updates for Go services.</p>

DNS: A Love Affair with Lovecraftian Horrors (en)

<p>The DNS is a hoary protocol, with ancient secrets that man was not meant to know.</p> <p>It is said that learning too much about the dark corners of this ancient knowledge might drive one mad.</p> <p>Here is your chance to learn mostly useless things about DNS!</p> <p>This presentation will cover quirks of the DNS protocol which are probably surprising, and hopefully interesting.</p> <p>Warning: Due to constraints no entities from beyond time and space will be summoned during this talk.</p>

Welcome! How to make localization comfortable for everyone involved (en)

<p>In this kickoff session, I will introduce the essence of the Translations devroom and showcase ideas on how to make the localization process comfortable for everyone involved, be it developer, translator, manager, or user; of course, these groups overlap. There will be significant time for interaction between attendees. Following talks will dive into specific experiences and effective practices.</p>

Using automatic translations, the do's and don'ts (en)

<p>We used automatic <a href="https://translate.mattermost.com/">translations</a> in the <a href="https://www.mattermost.com/">Mattermost-project</a> for a few specific languages. In this talk you will learn from our mistakes. (yes, initially we did break the product) But you will also learn from our best practices and how we keep the human in control for better translations. We flagged auto-translated strings, made better tests to prevent that your product breaks and imported safely these translations with a rollback possibility</p>

It's a gaas! Translating bad grammar into good. (en)

<p>Any application with dynamic text is probably wrong! The days of writing "You have " + count + "email(s)" should be behind us, but they're not! Whether it is printed on a screen or spoken via synthesis, the way the text is written is just as important as the words themselves! This talk covers the problems of generating text dynamically in code, and how to solve it.</p> <p>Getting the grammar correct is hard. Not because the code is difficult, but because there's a lot of it! While the source code might have been written by people of 100 nationalities, the output text is generally English. And when your primary language is English it's doubly hard to ensure every text string is correctly, grammatically. "You have 1 email(s)" looks bad. So does, "The warrior picks up a axe". And so on. This talk covers the GaaS library which codifies the rules of language style and grammar so our textual output can compete with that of proprietary software.</p>

What translating Thunderbird taught me (en)

<p>I contribute to Mozilla Project <a href="https://blog.mozilla.org/l10n/2025/10/24/localizer-spotlight-bogo/">since 2005.</a> I spent the majority of that time translating, localizing and QA-ing that effort.</p> <p>In the last years I am focusing on Thunderbird both <a href="https://pontoon.mozilla.org/bg/thunderbird/contributors/">Desktop</a> and <a href="https://hosted.weblate.org/user/bogomil/">Mobile</a>.</p> <p>I'd love to share some things I learned for that time which will help you to grow as a translator and as a community member: - Is consistency important. Tips and trick I use to keep myself motivated - How do you test a translation with the consumers - Why localizing the mobile version is a bigger challenge that the desktop</p>

Bridging the Gap from Wordpress to Weblate (en)

<p>Localization of Wordpress content has many solutions, most of them in the form of Wordpress plugins that come with their own way of doing things and a lot of quirks. Weblate is a very mature solution that in our experience is a lot more reliable and easy to work with than any of these plugins. For our own CMS pages, we were wondering how to best explore this path and created a Deno- / TypeScript-based preprocessing tool that can extract messages from Wordpress Elementor pages for use in Weblate, as well as create localized variants of these pages using the Weblate translations as input. While we focus on the localization of Elementor pages in particular, we'll also touch on the subject of Gutenberg blocks due to their widespread use.</p> <p>Note that this talk may be somewhat hard to apply to existing setups because of the preprocessing happening outside Wordpress, working under the assumption that you are fine regenerating static HTML whenever you want to "deploy" your Wordpress pages. On the positive side, it eliminates the need for any Wordpress caching tools!</p>

Do translations make us happy? How localization builds open source communities (en)

<p>Localization is often seen as a purely technical task, but for many contributors, translation work is deeply personal. It is about cultural identity, community belonging and keeping a language alive in fast-moving technical ecosystems. Working with the Spanish localization team for OpenTelemetry, I discovered that what brings people back is not only the desire for accurate terminology, but the joy of building something meaningful with others who share the same language. Contributing to localization OpenTelemetry motivated me to start a new Romanian localization group and inspire contributors who had never participated in open source before. This talk explores why localization communities thrive, what motivates contributors beyond the mechanics of translation and how language-driven belonging can open the door to new contributors in cloud native and open source projects. I will share practical lessons, common challenges, and strategies for creating or sustaining localization groups that make both software and humans better.</p>

Making the best of partially translated pages (en)

<p>In this session I’ll share some challenges we faced at Wikimedia Deutschland with partially translated pages. We have some interesting example cases such as sentences which are partly left-to-right and partly right-to-left. I’d like to open up for discussion so we can share insights on how to approach such cases to get the best outcomes, and how to balance tradeoffs to avoid very confusing text. <a href="https://phabricator.wikimedia.org/T386200">Epic: Generate Human-Readable Change-logs in Wikipedia Watchlists</a></p>

Playing online games without language barriers: a Luanti server (en)

<p>In 2020, a group of friends and I started a Luanti minigames server called "A.E.S.". One of the aspects that fascinated us about Luanti was being able to provide translated content according to the language set on the client - even for online servers. What we didn't know was that, we can't really ask translators to learn git if they want to contribute. Having a tailor-made translation format didn't help either. Fast forward of a few years and, thanks to Codeberg staff, we migrate to Weblate; which is when the boom of translations happened. A.E.S. now features 14 languages and, with Luanti switching to an industry standard (.pot/.po files), life becomes even easier. People can now play their favourite games without having to struggle with a language they might not know -so as to focus on the game itself.</p> <p>https://aes.land/</p>

An introduction to Plan 9 (en)

<p>This talk will cover the context, origins, and core concepts of the Plan 9 operating system.</p> <p>It will focus around Plan 9's high-level ideas that make it unique, and fundamentally different from Unix. This includes files, namespaces, the 9p protocol, networking, graphics, and the limitless potential of file servers, which can only be achieved due to its design.</p> <p>I will aim to provide a genuine understanding of Plan 9's approach; not just what the concepts are, but why they exist and how they solve real problems that traditional Unix cannot.</p> <p>Although this talk assumes familiarity with Unix-like systems, it is not required to understand what will be presented. In fact, heavy assimilation with Unix tends to be a handicap rather than an advantage.</p>

GEFS: A Good Enough File System (en)

<p>GEFS is a new file system built for Plan 9. It aims to be a crash-safe, corruption-detecting, simple, and fast snapshotting file system, in that order. GEFS achieves these goals by building a traditional 9p file system interface on top of a forest of copy-on-write Bµ trees. It doesn�t try to be optimal on all axes, but good enough for daily use.</p>

Audio and music production on Plan 9 (en)

<p>Over the past two decades, Plan 9 has seen many improvements and contributions and been made accessible on modern hardware by projects such as 9front. While appealing for certain tasks, audio processing has not been in the spotlight much. Despite the many ports and tools now available, information about them is splintered across many websites and code repositories and it can be difficult to piece together the overall picture. In particular, Plan 9 typically isn't known for music production, yet while it cannot approach the feature set of modern digital audio workstations (DAWs) on other systems, it is quite capable. This talk will explore the topic of audio processing on Plan 9 from a musician's perspective, show what can be done currently, and discuss its limitations and needs. Basic knowledge of Plan 9 is assumed. Topics covered: driver support, decoding/encoding, audio players, recording and editing, visualization, MIDI tools, trackers, synthesis, production.</p>

Facing the Complexity: The Challenges of Adopting Microkernels for Cloud Infrastructure (en)

<p>The ongoing digitalization has made cloud services and data centers the backbone of significant parts of our modern society and economy. Thus, exposing more and more sensitive data to a plethora of novel threats, both in terms of security and safety. However, most of today's cloud infrastructure runs on monolithic system software that makes it hard to harden against security leaks or unwanted outages by relying on too coarse-grained capabilities or having to orchestrate multiple security enforcement systems simultaneously. Even worse, solutions meant to improve performance or mitigate interference from co-located workloads can increase security risks by weakening or circumventing OS security policies. With capabilities, modern microkernels offer fine-grained access control via a single enforcement mechanism, while moving system services to the user space mitigates the failure of individual services and prevents a total system failure. However, despite their advantages, microkernels have seen little adoption among cloud service providers. This talk will present the benefits of a cloud architecture based on a microkernel and discuss the challenges of building such an architecture on a modern microkernel through the example of a prototype based on the Genode Operating System Framework.</p>

Making the NOVA microhypervisor fit for thousands of devices and interrupts (en)

<p><a href="https://github.com/udosteinberg/NOVA">NOVA</a> is a modern open-source (GPLv2) microhypervisor that can host and harden unmodified guest operating systems. NOVA is typically accompanied by a component-based OS that runs deprivileged and implements additional functionality, such as platform services and user-mode device drivers.</p> <p>Over the years, the interrupt subsystem of modern client and server platforms has evolved significantly, by (1) scaling up from only a few pin-based to thousands of message-signaled interrupts and (2) scaling out the delivery of those interrupts across dozens or hundreds of CPU cores. </p> <p>Architectural differences between ARMv8-A and x86_64, such as</p> <ul> <li>Interrupt types: PIN/MSI (x86) vs. (E)SPI/(E)PPI/LPI (Arm)</li> <li>CPU-local vectors (x86) vs. global INTIDs (Arm)</li> <li>Interrupt remapping by IOMMU (x86) vs. interrupt translation by GIC ITS (Arm)</li> <li>Source identifier as bus/device/function (x86) vs. device/stream ID (Arm)</li> </ul> <p>pose a challenge to the design of a uniform API for managing interrupts and devices and motivated the introduction of a new type of kernel object in NOVA: Device Contexts</p> <p>After a brief discussion of NOVA features added recently, the majority of the talk will focus on NOVA's new interfaces for managing hardware devices and interrupts.</p> <p>Links:</p> <ul> <li><a href="https://github.com/udosteinberg/NOVA">NOVA Source Code</a></li> <li><a href="https://gitlab.com/bluerocksec/NOVA/-/tree/proof/ver">NOVA Formal Specification</a></li> <li><a href="https://hypervisor.org/">Additional Information</a></li> <li><a href="https://archive.fosdem.org/2025/schedule/event/fosdem-2025-5083-a-formal-specification-of-the-nova-microhypervisor/">FOSDEM 2025 Talk</a> - focused on Formal Verification</li> <li><a href="https://archive.fosdem.org/2024/schedule/event/fosdem-2024-3227-using-the-nova-microhypervisor-for-trusted-computing-at-scale/">FOSDEM 2024 Talk</a> - focused on Trusted Computing</li> <li><a href="https://archive.fosdem.org/2023/schedule/event/nova">FOSDEM 2023 Talk</a> - focused on Advanced Features</li> <li><a href="https://archive.fosdem.org/2020/schedule/event/uk_nova">FOSDEM 2020 Talk</a> - focused on ARMv8-A</li> </ul>

skiftOS: Building a microkernel-based operating system from the ground up (en)

<p>This talk gives an overview of skiftOS’s architecture, focusing on its microkernel core and service model. It explores the design trade-offs behind keeping the kernel minimal yet practical, and the lessons learned from building a complete, usable operating system on top of it.</p> <p>The session is aimed at developers interested in microkernels, operating system internals, and the challenges of scaling a small core into a functional ecosystem.</p> <p>Project Repo: https://codeberg.org/skift/os</p>

Rethinking CPU scheduling for dynamic workloads on Sculpt OS (en)

<p>The <em>Genode OS Framework</em> is certainly not a newcomer but still under very active development. While the framework supports various third-party microkernels, its custom-tailored <em>base-hw</em> kernel has proven valuable for putting Genode-specific (kernel) concepts to the test. One of those concepts that we have been test-driving for about a decade was the <em>quota-aware CPU scheduling</em>, which combined CPU-quota trading with priority-based scheduling. However, with Sculpt OS as a major use case of Genode as a desktop OS that focuses on dynamic workloads, it was time to rethink what we expect from a kernel's CPU scheduler.</p> <p>In this talk, Johannes Schlatow and Stefan Kalkowski share the story and lessons learned from re-designing and re-implementing the kernel scheduler with a particular focus on fairness, tunable latency and ease of configuration.</p>

Capability Based Security in Redox (en)

<p><a href="https://www.redox-os.org/">Redox</a> is a Unix-like microkernel operating system, community developed and written in Rust. Funded through NGI Zero Commons and NLnet, Redox is developing Capability Based Security as a fundamental part of interprocess communication and file I/O. This presentation will look at our strategies for implementing capabilities, POSIX file descriptors, namespaces, containment, and escalation.</p>

Transactions: Making CMRX kernel internals lock-free (en)

<p>As kernels manage hardware, in certain cases the only way to prevent race conditions in kernel code is to disable interrupts. This is a kernel way of granting code exclusive access to resources at lowest levels.</p> <p>In the realm of embedded devices, it is often not feasible to keep interrupts disabled for prolonged period of time. This affects the design of portions of the kernel which modify data structures accessible from within interrupt context. Despite very limited API offered by the kernel to interrupt handlers, this still affects key data structures in kernel - scheduler table and notification table. This in turn means that any use of threading or notification API would require interrupts to be disabled for potentially prolonged time periods.</p> <p>To avoid prolonged periods of disabled interrupts we went for some inspiration into the land of lock-free and wait-free programming. We took basic primitives used in lock-free programming and modified them to avoid excessive overhead such primitives have. The resulting mechanism is not lock-free anymore yet offers semantics which allows us to lock (disable interrupts) for much shorter and well predictable periods of time. </p> <p>The resulting mechanism resembles database transactions to certain extent. This talk will provide introduction to the transaction subsystem, reason on why it offers benefits over raw locks and elaborate on the topic "How not to loose your hair while trying to work with ever-changing data consistently".</p>

Practical Persistence on Microkernels (ft. PhantomOS) (en)

<p>This presentation describes the technical implementation of PhantomOS, an orthogonally-persistent operating system, on modern microkernel architecture using the Genode framework. The talk center on the engineering challenges encountered during the porting process, especially the adaptation of the core persistence mechanisms. The talk will also touch on work on network persistence and the added WASM runtime.</p> <p>As part of the port, the snapshot process was reworked and separated into its own Genode component. The talk will cover how the component utilizes backlink data structures and CRC validation to achieve efficient state storage with minimal overhead. A live demonstration will showcase the reliability and performance characteristics in a real-world environment.</p> <h3>Relevant Links:</h3> <ul> <li>PhantomOS: http://phantomos.org</li> <li>PhantomOS (Genode port): https://github.com/rumenmitov/phantomuserland-snapper</li> <li>Snapper: https://github.com/rumenmitov/snapper</li> </ul>

Writing axle OS's desktop compositor (en)

<p>axle OS (<a href="https://github.com/codyd51/axle">GitHub</a>, <a href="https://axleos.com/blog/">blog</a>) is a hobby microkernel and userspace which includes many home-grown utilities such as <a href="https://github.com/codyd51/axle/tree/paging-demo/rust_programs/linker/src">an x86_64 assembler + ELF linker</a>, a <a href="https://github.com/codyd51/axle/tree/paging-demo/programs/subprojects/net">TCP/IP/(ARP/DNS</a>/<a href="https://github.com/codyd51/axle/tree/paging-demo/programs/subprojects/realtek_8139_driver">NIC</a>/etc)]( stack, <a href="https://github.com/codyd51/axle/tree/paging-demo/rust_programs/sata_driver/src">SATA support</a>, a <a href="https://github.com/codyd51/axle/tree/paging-demo/rust_programs/ttf_renderer/src">TrueType renderer</a>, a <a href="https://github.com/codyd51/axle/tree/paging-demo/rust_programs/gb_emu/src">GameBoy emulator</a>, and more. Everything is built around message passing, from process launches and virtual memory operations, to driver events and GUI updates.</p> <p>axle OS lacks a GPU driver, but features a compositing desktop window manager with transparency effects and animations. Since the compositor runs on the CPU, I’ve put significant effort into making redraws as efficient and targeted as possible to create a smooth and responsive experience.</p> <p>In this talk, I’ll give a tour of axle’s CPU-bound compositor from first principles. We’ll go on a journey of live visualisations, seeing how each successive optimization allows the compositor to perform progressively less work per frame, building up towards a general strategy for redraws that comprehensively covers screen updates.</p> <p>Developing a compositor that plays optimisation tricks involves lots of testing, which can be onerous in an OS that’s primarily developed in an emulator and which must boot itself before the compositor can run. Therefore, we’ll also take a look at a host-side userspace harness I made for the compositor: the compositor can run on my host-native macOS, or as a part of the full axle OS distribution. I developed a simulator which allows me to record user interaction (such as dragging a window around with a mouse), capture the composited frames, and write a test suite that replays these events and ensures the composited frames don’t deviate from the correct output.</p> <p>We’ll investigate R-trees, different compositing strategies, client request rate limiting, and the various types of redraws that the compositor must be able to handle. This talk aims to be an engaging and ‘interactive’ experience for the audience, with lots of guiding visualisations motivating each optimization we make to our compositor, following the journey towards axle OS’s contemporary CPU compositor.</p>

Updates on GNU/Hurd progress: rump drivers, 64bit, SMP, software bootstrapping ... (en)

<p>It has been a while since the last FOSDEM update on GNU/Hurd, so we have a lot to talk about :)</p> <p>Driver support improvement is on its way through using netbsd's rump layer, now being used in production although there are a few things left to fix. Some SMP support has been added, which should allow at least compilation to be run in parallel. Hurd support was added to the rust ecosystem, which became more and more a necessity due to various software now requiring it. The x86_64 port is essentially complete, which mostly required fixing the MIG RPC layer, and telling various software that it exists. To bootstrap the Debian GNU/Hurd x86_64 distribution, many of the crossbuilding, rebootstrapping and build profiles tools were used to make it relatively smooth. Additionally, the Guix/Hurd distribution is also on its way, as well as an Alpine/Hurd distribution. And more to discover during the talk!</p>

Microkernels: The last 15 years in retrospective (en)

<p>Since the first Microkernel OS Devroom at FOSDEM 2012 and culminating today, there have been exactly 15 devrooms in 15 years dedicated to microkernel-based operating systems at each FOSDEM. As surprising or shocking this may sound to somebody who has been there all along, this time period already constitutes a small piece of history. While the computing world of today is not dramatically different or unrecognizable compared to 2012, maybe except for a few "minor" technologies such as HTML5 and LLMs ;), there have definitively been some changes and shifts of priorities.</p> <p>Let us take this opportunity for a small retrospective of the last 15 years in the context of open-source microkernel-based operating systems. What problems have we been facing back then and how do they relate to the problems we face today? What have been the ups and downs? What are the important lessons learned?</p>

VideoLAN VLC meeting (en)

<p>VideoLAN https://www.videolan.org/ tech meeting for VLC.</p> <p>We will speak about the upcoming VLC 4.0 milestone.</p>

The Future of Reticulum: Community Roadmap and Protocol Specification (en)

<p>With internet shutdowns, censorship, and fragile infrastructure becoming a fact of life, communities need communications that keep working. Reticulum is a practical, open networking stack for resilient, decentralised communication across very different links, from Wi-Fi and Bluetooth to LoRa and packet radio.</p> <p>Project: https://reticulum.community/</p> <p>This BoF brings together people building with Reticulum (and those curious about it) to share what's working and align on what comes next. Reticulum is at an inflection point: as the original lead developer steps back from public coordination, this is our moment to turn Reticulum into a community-run project that can realise it’s potential as an alternative communication system.</p> <p>This is a discussion-led working session with people actively deploying and experimenting, including:</p> <ul> <li>a draft formal protocol specification (reviewers and contributors welcome)</li> <li>lessons from a real-world community mesh in Aruba</li> <li>members of the Amsterdam Reticulum community</li> </ul> <p>We'll focus on: agreeing priorities for the next 3-12 months, defining a lightweight coordination model (triage/reviews/releases) and turning interoperability learnings into a shared protocol spec scope and an initial conformance/test-vector plan that enables independent implementations.</p> <p><strong>Outcome:</strong> leave with a short set of priorities, named owners for follow-ups, an agreed spec/outline and test-vector plan and a scheduled next check-in.</p>

NLnet office hour (en)

<p>NLnet foundation offers financial support to free and open source technologies. Everybody is welcome to drop by this Birds of a Feather meetup. If you have questions about funding possibilities, are a grantee with ideas or remarks, or just want to come by and say hi. Many of the NLnet team will be there and we are looking forward to meet you. https://nlnet.nl/</p>

Wilber talks - GIMP meet-up (en)

<p>Come and chat with a GIMP developer about the current and future state of GIMP. Share your experiences, art created with GIMP and just have a nice time meeting each other. Also get a GIMP sticker!</p>

Open source real time video mixing exchange (en)

<p>Let's see if we can exchange some ideas and/or collaborate together on open source real time video mixing! Represented / present should be some of the people behind https://github.com/FOSDEM/video-fazantix and https://github.com/ddvtech/mistserver and perhaps more!</p>

Geometry shaders in panvk with libpoly (en)

<p>A couple years ago, Alyssa Rosenzweig developed a compute-based geometry and tessellation shader implementation for the Asahi (OpenGL) and Honeykrisp (Vulkan) drivers. Since then, the core of this implementation has been extracted into a common library within Mesa called libpoly. In this talk, Faith will talk about the changes needed to libpoly as well as panvk in order to integrate libpoly into panvk for geometry shader support on Mali GPUs.</p>

FOSDEM videobox 2026 (en)

<p>This years update on the FOSDEM videobox!</p> <p>FOSDEM is a massive event with 30 different tracks spread over two days. Our goal is to not only capture video of every talk, but also to fully live stream everything. In this talk, the current versions of the hardware and software powering this crazy endeavour will be presented.</p>

From Bookworm to Trixie: Upgrading the Raspberry Pi graphics stack (en)

<p>In October 2023, when Raspberry Pi 5 was announced, a new version of Raspberry Pi OS based on Debian 12 Bookworm was released. After two years, in October 2025, the new release based on Debian 13 Trixie was released. </p> <p>This talk will review what improvements have been made in the graphics stack of the Raspberry Pi, focusing on the kernel (v3d) and user space (v3d/v3dv) GPU driver upgrades. </p> <p>Now all Trixie Raspberry Pi users are taking advantage of Mesa 25.0.7. It exposes Vulkan 1.3 and OpenGL 3.1 with significant performance improvements on Raspberry Pi 4/5.</p> <p>We will also review what could be expected based on current and upcoming development cycles - from Mesa 25.0 to the latest upstream work - and how these advances improve the capabilities on the Raspberry Pi platform.</p> <p>[1] <a href="https://www.mesa3d.org/">https://www.mesa3d.org/</a> [2] <a href="https://www.raspberrypi.com/">https://www.raspberrypi.com/</a></p>

Mesa3D: the heart of the linux graphics stack (en)

<p>Along the years, FOSDEM and its Graphics Devrooms have featured many talks about the status of different Mesa3D drivers. But what is Mesa3D? How did the project start? How is it structured?</p> <p>This talk provides a comprehensive introduction to Mesa3D, aimed at people who have some graphics knowledge, but have never written a GPU driver. We will trace the project from its origins to being the industry standard for several vendors nowadays.</p> <p>More specifically, we will cover its architecture and components, how it translates API calls from standards like Vulkan or OpenGL into hardware instructions, how the shader compilation process looks like, and various other topics.</p> <p>Attendees will leave with a clear understanding of what happens behind the curtains when they invoke a draw command.</p> <p>https://mesa3d.org/</p>

Window Managers after Xorg (en)

<p>With the sunsetting of Xorg based environments the need for bespoke window management experiences has not gone away. But a new approach is needed that fits the Wayland paradigm.</p> <p><a href="https://canonical.com/mir">Mir</a> is a library for building Wayland compositors that supports a wide range of projects with their own Window Management needs: 1. embedded displays with a single fullscreen app (<a href="https://ubuntu.com/frame">Ubuntu Frame</a>); 2. phones and tablets with multiple fullscreen or staged apps (<a href="https://lomiri.com/">Lomiri</a>); 3. "floating" Desktop Environments (<a href="https://lomiri.com/">Lomiri</a> and <a href="https://github.com/Miriway/Miriway">Miriway</a>); and, 3. "tiling" Desktop Environments (<a href="https://miracle-wm.org/">Miracle-wm</a>).</p> <p>We will cover a range of topics including: 1. building a compositor with Mir and customizing the window management; 2. integration with Desktops Environments such as <a href="https://www.xfce.org/">XFCE</a>, <a href="https://lxqt-project.org/">LXQt</a>, <a href="https://mate-desktop.org/">MATE</a> and <a href="https://buddiesofbudgie.org/">Budgie</a>; and 3. the deployment in distributions (<a href="https://www.fedoraproject.org/spins/lxqt/">Fedora LXQt Spin</a> and <a href="https://www.fedoraproject.org/spins/miraclewm/">Fedora Miracle Window Manager Spin</a>)</p>

Tyr: a new Rust GPU driver for the Linux Kernel (en)

<p>This talk introduces Tyr, a new Rust-based GPU driver for the Linux kernel. We’ll begin with a brief look at how modern GPUs work before diving into Arm’s GPU architecture and explain how it’s supported at the kernel level, highlighting the key components of a Linux GPU driver. We’ll conclude with an overview of the project’s current status and what’s ahead on the roadmap.</p>

Event-driven X (en)

<p>Like most window-system architectures, X is fundamentally event-driven. So why not use an API that reflects that?</p> <p>This talk is about an X interface library which is built on event-driven paradigms from the ground up. It sits in the same place in the software stack as Xlib and xcb; it's an alternative to them for an application to use when talking to the X server, most appropriate for applications which are themselves event-driven.</p>

Separating the Wayland Compositor and Window Manager (en)

<p>Current Wayland compositor implementations handle window management and compositing in the same monolithic process. Wayland does not however force this architecture.</p> <p>I am the author of the <a href="https://isaacfreund.com/software/river/">river</a> Wayland compositor. It supports a custom Wayland protocol, <a href="https://isaacfreund.com/docs/wayland/river-window-management-v1/">river-window-management-v1</a>, which allows a special "window manager" Wayland client to handle all window management policy, draw server side decorations, setup keybindings, and more.</p> <p>My goal with this work is to make hacking on Wayland window managers significantly more accessible and promote ecosystem diversity. There is already a <a href="https://codeberg.org/river/wiki/src/branch/main/pages/wm-list.md">growing list of window managers</a> developed for the new protocol.</p> <p>This talk will give an overview of this new protocol and the advantages/disadvantages of separating the Wayland compositor and window manager. There will also be a brief demo.</p>

0 A.D.: Vulkan and its obstacles in open-source game (en)

<p>I've added Vulkan to our game (0 A.D. https://play0ad.com/) in the beginning of 2023 and game version with its support was released in the beginning of 2025. Since that we've collected many different feedbacks and issues with Vulkan: our implementation, driver issues and hardware problems. I'm going to share most significant ones for us including device selection and creation, RPI visual artifacts, "remote" debugging and performance fluctuations.</p>

Wayland input method wrap up (en)

<p>Chinese or Korean style of text field switching? Synchronization or YOLO? text-input, input-method, virtual-keyboard?</p> <p>This will be a summary of my work on problems in Wayland input (methods).</p> <p>How to fix your Wayland problem? How to get your protocol accepted? Which projects will implement it? How long is it going to take?</p> <p>Less about code, I will talk more about needs and people, based on my experiences over the past year.</p> <p>Honestly, I'm the worst person to work on input methods. Why did no one kick me out from this sandbox yet?</p>

Improving shader compiler testing performance, or have many cores, will compile shaders. (en)

<p>Testing shader compilers is hard. There are many test suites available, but they primarily test simple shaders. As a result, the test suites have many coverage gaps. Testing real applications is necessary. It is impractical to test every application on every platform for every change to the compiler. As a proxy, the shaders from those applications can be compiled, and changes to the resulting shader code can be checked against various metrics. If the compiler itself is built with additional validation checks, functional regressions may also be detected. Hours might still be required to test a single change. This talk discusses software and hardware techniques to best utilize available computational resources for this testing.</p>

BLog: High-Performance Per-Component Binary Logging (en)

<p>When a kernel component like a storage driver misbehaves in production, developers face a difficult choice. They either have too little information to solve the bug or they enable slow console-level debug logs that ruin performance. This talk introduces a per-component binary logging mechanism designed to support verbose logging in production with negligible run-time cost.</p> <p>We achieve this efficiency by moving the heavy lifting to build time. using preprocessor macros, we emit parameter serialization stubs and save location-specific formats in a separate side table. At run time, the hot path only records a location ID, a timestamp, and the raw parameters. No format expansion occurs until the logs are read. We support high concurrency using a mostly lock-free multi-level allocator that allows dozens of CPUs to write simultaneously.</p> <p>We also introduce a significant architectural change by adding a single TLS pointer to <code>struct task_struct</code>. This tags each thread with a private logging buffer. If a thread stalls or deadlocks, the tag remains attached to the buffer. This allows post-mortem analysis to reveal the exact context-specific history of that thread.</p> <p>Unlike <code>ftrace_printk</code> which dumps everything into a single global ring, our logger maintains one ring per component context. This allows you to capture exactly the data you need for a specific file system or operation. The memory footprint is minimal. Each record is only eight bytes. This saves 16 bytes per entry compared to the standard <code>bprint_entry</code>. This efficiency reduces memory accesses and facilitates a truly production-ready binary logging infrastructure.</p> <p>We can finally keep verbose logging active at all times. This ensures that when a crash or deadlock occurs, the high-fidelity history needed to solve it is already waiting in memory.</p>

Netboot without throwing a FIT (en)

<p>For years, Ahmad’s ideal has been simple: unpack a rootfs on a server, mount it over NFS (or usb9pfs), boot directly into it, and everything just works™.</p> <p>But as secure boot becomes the default on many embedded systems, squeezing in a network-booted kernel is getting harder and often falls outside the supported boot flow entirely.</p> <p>Fortunately, some recent improvements in the kernel build system pave the way for a far less invasive netboot setup. This talk gives a quick tour of the key pieces:</p> <ul> <li>The image.fit target for arm64 introduced in v6.10</li> <li>The modules-cpio-pkg target introduced in v6.19</li> <li>Initramfs that bind mounts its modules over the rootfs</li> <li>Optional concatenation of multiple initramfs in the bootloader</li> </ul> <p>In ten minutes, you’ll see how these changes raise the netboot FITness of Linux, so you can keep printk-debugging to your heart’s content.</p>

OF-nodes, Fwnodes, Swnodes, Devlinks, Properties - Understanding How Devices Are Modeled in Linux (en)

<p>The linux kernel driver model has grown over the years and acquired several different mechanisms for passing device configuration data to platform drivers. This configuration can come from firmware (device-tree, ACPI) or from the kernel code itself (board-files, MFD, auxiliary drivers).</p> <p>For a less experienced driver developer, the different APIs that are used to access device properties can be quite confusing and lead to questions: should I use the OF routines? Maybe fwnode or the generic device properties? What are software nodes in this model and what even is a device property? How are devices linked according to their provider-consumer relationship and their probe order ensured, if at all?</p> <p>This talk will discuss the history and evolution of device properties - from legacy, custom platform data structures, through the introduction of the open-firmware API and its generalization to firmware nodes alongside other fwnode implementations up to the generic device property API. It will also touch on the devlinks and how they tie into this model.</p> <p>The goal of this beginner/intermediate level talk is to give a clear picture of how device configuration should be handled in the kernel.</p>

Flexible math operations on network packet fields with Nftables (en)

<p>A new RFC for Netfilter/nftables arrived recently in the netfilter-devel mailing list [1], introducing flexible math operation support for network packet fields. This could solve some migration problems from iptables to nftables and in addition empower other use-cases.</p> <p>This demo will quickly show how it works with simple real-world scenarios.</p> <p>[1] https://lore.kernel.org/netfilter-devel/20250923152452.3618-1-fmancera@suse.de/</p>

Combining Trace(r)s: Kernel ftrace & LTTng UST (en)

<p>Tracing complex systems often requires insights from both the kernel and userspace. While tools like Linux's ftrace excel at kernel-level observability and LTTng provides low-overhead userspace tracing, unifying these disparate data sources for a holistic view remains a challenge: using LTTng for kernel tracing requires an out-of-tree kernel module, which can be a barrier for many users.</p> <p>This talk introduces bt2-ftrace-to-ctf - a new open-source project designed to bridge this gap. Our solution processes a trace.dat file from ftrace (kernel part) and a LTTng UST for userspace, then aligns and rewrites the trace in the Common Trace Format (CTF), as used by LTTng. The resulting output is directly consumable by tools like Trace Compass, enabling comprehensive, synchronized analysis of system behavior across all layers without the need for custom kernel modules.</p> <p>The project consists of two key components:</p> <ul> <li>A Babeltrace2 plugin: This plugin allows babeltrace2 to directly read trace-cmd's trace.dat files, providing a standardized interface for ftrace data. It includes source and sink components for flexible data handling and metadata emission.</li> <li>A trace.dat to CTF converter: This utility utilizes the Babeltrace2 plugin to transform ftrace data into an LTTng-alike kernel trace in CTF format. Crucially, it can also combine this kernel trace with an existing LTTng userspace trace, producing a single, unified trace directory.</li> </ul> <p>In the talk, we will give an overview on the tool and discuss challenges during its implementation.</p> <p>Project: https://github.com/siemens/bt2-ftrace-to-ctf (MIT, LGPL-2.1-or-later)</p>

Reproducible XFS Filesystems - Populating Images Without Mounting (en)

<p>Creating filesystem images typically requires mounting, copying files, and hoping your build environment doesn't introduce non-determinism. New capabilities in mkfs.xfs solve both problems. You can now populate an XFS filesystem directly from a directory tree at creation time, no mount required. I'll cover the implementation approach, discuss design, and show how to use it. Useful for distributions, embedded systems, and anyone who needs verifiable filesystem artifacts.</p> <p>Reference commits: https://git.kernel.org/pub/scm/fs/xfs/xfsprogs-dev.git/commit/?h=for-next&amp;id=8a4ea72724930cfe262ccda03028264e1a81b145</p> <p>https://git.kernel.org/pub/scm/fs/xfs/xfsprogs-dev.git/commit/?h=for-next&amp;id=4a54700b4385bbedadfc71ee5bb45b0fc37fabb7</p>

Verification of Linux kernel code (en)

<p>Correctness of operating system kernel code is very important. Testing is helpful, but does not always thoroughly uncover all issues. In the Whisper team at Inria, we are exploring the possibility of applying formal verification, using Frama-C, to Linux kernel code. This entails writing specifications, constructing loop invariants, and checking correctness with the support of a SMT solver. This talk will report on the opportunities and challenges encountered.</p>

How to develop and test a PWM driver (en)

<p>Most SoCs provide a PWM controller which it used mainly to drive LEDs, a display backlight or a fan. Less often a PWM controls a motor.</p> <p>The motor use case has a higher demand for exact control of the produced output. In the development cycle for Linux 6.13, the preferred abstraction for a PWM driver changed to be able to fulfill these needs.</p> <p>After a quick introduction about what a PWM actually does, Uwe (who is also the Linux PWM subsystem maintainer) will present the new API with its requirements and the hardware and software he uses to develop and test a driver.</p>

Update on the SLUB allocator sheaves (en)

<p>Sheaves are a new percpu caching layer for the SLUB allocator. To some extent it's a return to the SLAB percpu arrays (and magazines in the original Bonwick's paper), but avoiding the pitfalls of the SLAB implementation, attempting to get the best of both SLAB and SLUB approaches.</p> <p>In 6.18 sheaves were merged and enabled for maple node and VMA caches. There's ongoing work to fully convert all caches in 7.0. This talk will discuss the status, explain the tradeoffs involved and present some results and lessons learned.</p>

seccomp listeners for nested containers (en)

<p>This talk is a follow-up for LPC 2025 "seccomp listeners for nested containers" from "Containers and Checkpoint/Restore" MC [1].</p> <p>I'll give an update of patch-set progress in LKML, overview of technical challenges. In case if it is merged upstream by the time of this talk at FOSDEM, I'll show a demo of this feature and give a detailed overview of implementation and potential future improvements.</p> <p>[1] https://lpc.events/event/19/contributions/2241/</p>

TPMs and the Linux Kernel: unlocking a better path to hardware security (en)

<p>TPMs have been present in modern laptops and servers for some time now, but their adoption is quite low. While operating systems do provide some security features based on TPMs (think of BitLocker on Windows or dm-verity on Linux) third party applications or libraries usually do not have TPM integrations.</p> <p>One of the main reasons of low TPM adoption is that interfacing with TPMs is quite hard: there are competing TPM software stacks (Intel vs IBM), lack of key format standardization (currently being worked on) and many operating systems are not set up from the start to make TPM easily available (TPM device file is owned by root or requires privileged group for access). Even with a proper software stack the application may have to deal with low-level TPM communication protocols, which are hard to get right.</p> <p>In this presentation we will explore a better integration of TPMs with some Linux Kernel subsystems, in particular: kernel keystore and cryptographic API. We will see how it allows the Linux Kernel to expose hardware-based security to third party applications in an easy to use manner by encapsulating the TPM communication complexities as well as providing higher-level use-case based security primitives.</p>

A Modern Look at Secure Boot (en)

<p>The basic concept of Secure Boot is now well established (and widely used in Linux for nearly 15) years. Most people now decline to take ownership of their systems (by replacing the CA keys in the UEFI db variable) and instead pivot trust away from the UEFI variables to the MoK (Machine Owner Key) ones instead, which can be updated from the operating system. Thus if you want to secure boot your own kernel, you usually create a signing key and load that into MoK.</p> <p>This talk will go quickly over the history, how you take ownership, what problems you encounter, how you create and install your own signing keys in MoK and how the kernel imports all these keys into the keyring system and uses them (verifying module signatures and IMA signed policy) including the differences betwen the machine and secondary_trusted keyrings. We'll also discuss some of the more recent innovations, like adding SBAT to the rather problematic UEFI revocation story and how it works.</p>

usermode linux without MMU (en)

<p>Usermode Linux (UML) has been developed and maintained in linus tree for decades and well used by kernel developers as an instant way of virtualization within userspace processes, without relying on hypervisor (i.e., qemu/kvm) or software partition (i.e., namespace). Recently unit testing framework for kernel tree, KUnit, bases UML as an underlying infrastructure for the framework, which brings us more opportunities to use UML. However, this testing capability of KUnit+UML is currently limited to MMU-full codebase where there are certain portion of code with <code>ifndef CONFIG_MMU</code> in the kernel tree. As a result, nommu code lacks the chance of testability and often introduces regressions in the rapid development cycle of linux kernel.</p> <p>This talk introduces yet-another extension to UML, based on the architecture without MMU emulation, in order to exercise nommu code with a plenty of testing framework implemented on KUnit+UML . The kernel is configured with the option <code>CONFIG_MMU=n</code>, and we've implemented a different syscall hook and handling mechanisms with the different interactions to the host processes. With that, existing userspace programs (we've used Alpine Linux image with patched busybox/musl-libc) can run over this UML instance under nommu environment. As a bonus using different implementation to the host interactions, we got speedups in several workloads we've tested including <code>lmbench</code> and <code>netperf</code>/<code>iperf3</code> benchmarks.</p> <p>I will briefly overview its implementation, the comparison with the original UML architecture, and share several measurement results obtained during the development. We will also share the upstreaming status which we have been proposed [*1].</p> <p>*1: https://lore.kernel.org/all/cover.1762588860.git.thehajime@gmail.com/</p>

The limits of ABI stability in the kernel (en)

<p>At Chainguard, we want to re-use binary objects across Linux kernel builds of different major versions. For us this is useful for FIPS certification of individual kernel components while still allowing us to build new kernels and not pin the entire kernel forever. To achieve this, we performed a number of experiments with the kernel build system and spoke to other kernel developers about their efforts to achieve the same thing. I will discuss approaches to re-using binary objects, the limits of each, and how the linux kernel could have a stable(r) ABI.</p>

VFS News (en)

<p>In this session we're going to take a look at new developments in the VFS layer and related areas.</p>

Reproducing a syzbot Bug in 5 Minutes — Now with virtme-ng! (en)

<p>This live demo shows how to pick a real syzbot-reported bug and reproduce it locally in under five minutes using virtme-ng. No disk images, no complex QEMU setup—just build, reproduce and verify the fix. Perfect for anyone who wants to turn kernel fuzzing reports into real patches. Important note: I am going to use pre-built upstream kernel containing a bug due to the talk time constarins. Hovewer, steps to rebuild an upstream kernel and use it in virtme-ng will be described.</p> <p>Full Description: syzbot continually discovers kernel issues, but reproducing them can be slow or intimidating. In this lightning talk, we’ll use virtme-ng to rebuild a mainline kernel and instantly run a real syzbot reproducer inside an ephemeral VM. We’ll trigger the crash, inspect the backtrace, apply the upstream fix, and rerun the test to verify the resolution—all live. This workflow reduces setup time from hours to minutes and lowers the entry barrier for new contributors. Every attendee will leave knowing how to reproduce syzbot bugs safely and efficiently on their own system.</p> <p>Live Experiments &amp; Demonstrations:</p> <ul> <li>Select an active syzbot issue (syzbot.appspot.com) and show its reproducer.</li> <li>Build a mainline kernel and launch it via virtme-run --kdir . --repro repro.c.</li> <li>Trigger the crash and display kernel backtrace.</li> <li>Apply the upstream patch or manual fix.</li> <li>Re-run the reproducer and verify crash disappearance.</li> </ul> <p>Key Points:</p> <ul> <li>Use virtme-ng for instant kernel test environments.</li> <li>Run real syzbot reproducer without manual QEMU setup.</li> <li>Observe, patch, and verify kernel bugs live.</li> <li>Encourage new contributors to validate fuzzing results.</li> <li>Demonstrate a fully reproducible workflow in &lt; 5 minutes.</li> </ul>

What Is Still Missing in System Call Tracing (en)

<p>This talk follows last year's presentation "Status and Desiderata for Syscall Tracing and Virtualization Support" and reports on progress and remaining gaps in Linux system call tracing.</p> <p>The talk presents a set of Linux kernel patches, intended for upstream submission, that address the following limitations and aim to make system call tracing and virtualization more expressive, portable, and efficient.</p> <p>Over the past year, support for PTRACE_SET_SYSCALL_INFO has been merged into the mainline kernel. While developing a portable version of VUOS across multiple architectures, several limitations of the current tracing interfaces became evident. In particular, skipping a system call by setting its number to -1 is insufficient, as it does not allow the tracer to control the return value or errno, nor to adjust the program counter. As a consequence, the current VUOS proof-of-concept replaces skipped system calls with getpid and fixes up the return value at PTRACE_SYSCALL_INFO_EXIT, doubling the number of context switches and incurring a measurable performance cost. Updating the program counter currently requires non-portable, architecture-specific code using PTRACE_POKEUSER or PTRACE_SETREGSET.</p> <p>Additional issues arise with seccomp_unotify. Tracing all system calls is difficult because file descriptors must be transferred from the traced task to the tracer; common techniques based on UNIX domain sockets and ancillary messages require sendmsg and recvmsg themselves to be excluded from tracing. Furthermore, there is currently no support for virtualizing the F_DUPFD command of fcntl, nor for allowing a tracer to atomically close a file descriptor in the traced process.</p>

Tuning Embedded Linux for Low Power (en)

<p>Power saving has always been a major preoccupation in embedded systems, as by definition, they could have energy constraints. As embedded systems become increasingly pervasive, from IoT devices to industrial controllers, power efficiency is more critical than ever. This talk is aimed at developers, system integrators, and Linux enthusiasts. Whether you’re optimizing a battery-powered board or a power sensitive industrial board, you’ll walk away with practical insights and actionable tools. This talk will explore how to reduce electrical consumption on an embedded Linux system by leveraging software techniques such as kernel low power state (Suspend-To-RAM, Suspend-To-Disk), devices management. We’ll cover how to disable unused peripherals or scale CPU frequencies</p>

Solving Pre-silicon Kernel Upstream for RISC-V First Ever (en)

<p>Upstreaming kernel support traditionally happens only after silicon becomes available, but this approach often delays software enablement and ecosystem readiness. For the first time in the RISC-V world, we are tackling the challenge of pre-silicon kernel upstreaming—enabling Linux kernel features ahead of actual chip availability. In this session, we will share the methodology, toolchains, and collaborative workflows that make this possible, including the use of simulation platforms, pre-silicon verification environments, and CI/CD integration for early kernel testing. Attendees will learn how these efforts accelerate software-hardware co-design, reduce bring-up cycles, and ensure that by the time silicon arrives, the kernel is already upstream-ready. This pioneering approach not only shortens time-to-market but also sets a new model for open source hardware-software collaboration in the RISC-V ecosystem. Key Takeaways: - Why pre-silicon kernel upstreaming is a game-changer for RISC-V. - The tools and processes used to validate and upstream before silicon. - Lessons learned and best practices for collaborating with the open source community.</p>

Rich Packet Metadata - The Saga Continues (en)

<p>So here's the deal: if you want to tag a packet (<code>sk_buff</code>) with some info that actually sticks around as it travels through the Linux network stack, your only real option right now is a measly 32-bit <code>SO_MARK</code> field. That's not a lot of room, and everyone's fighting over those bits. In this talk, we'll share Cloudflare's quest to get 128+ bytes of metadata attached to packets—enough space to do cool stuff like keeping config consistent across network layers, classifying packets in XDP, and figuring out exactly why a packet got dropped.</p> <p>We've been at this for a while, and we'll walk you through the three main chapters of our journey—the dead ends, the duct tape solutions, and what we think might actually work:</p> <p><strong>Part One: SKB Traits.</strong> Remember that per-packet key-value store idea called "SKB Traits"? We'll tell you why we got excited about it and why we eventually tossed it out in favor of not having a second metadata area.</p> <p><strong>Part Two: XDP Metadata.</strong> Next up, we tried piggy-backing on <code>skb-&gt;data_meta</code> and brought in <code>bpf_dynptr</code> to wrangle the metadata. Spoiler: it gets messy. L2 tunnels and pulling packet headers can leave your metadata corrupted or just plain gone. We'll dig into our attempts to untangle metadata tracking from MAC header offsets and the backward compatibility headaches that come with it.</p> <p><strong>Part Three: SKB Extension.</strong> Finally, we'll show you our latest idea: using <code>sk_buff</code> extensions (<code>skb_ext</code>) backed by BPF local storage. The nice thing here is that metadata lives separately from packet headers. But we're not out of the woods yet—memory allocation on the hot path is still an open problem.</p>

Unlocking extra cluster capacity with enhanced Linux cgroup scheduling (en)

<p>Cluster orchestrators such as Kubernetes rely on an accurate model of the resources available on each worker node in a cluster and on the resources a given job requires, using this information to place the job onto a suitable worker node in the cluster. If either is inaccurate, the orchestrator will make poor job placement decisions, resulting in poor performance.</p> <p>I observe that Linux kernel scheduling overheads can, for workloads making heavy use of Linux's group scheduling (cgroups) which include common serverless workloads, become so significant as to make the orchestrator model of worker node resources inaccurate. In practice this effect is mitigated by over-provisioning the cluster.</p> <p>I propose and evaluate an enhancement to the Linux Completely Fair Scheduler (CFS) that mitigates these effects. By prioritising task completion over strict fairness, the enhanced scheduler is able to drain contended CPU run queues more rapidly and reduce time lost to context switching. Experimental results show that this approach can deliver equivalent performance using up at least 10% fewer worker nodes, significantly improving cluster efficiency.</p>

Introduction the Open Source & EU Policy devroom (en)

<p>An Introduction from the Organisers to the Open Source &amp; EU Policy devroom.</p>

Global collaboration and Europe's digital sovereignty goals: debate (en)

<p>European digital sovereignty is moving from slogan to strategy. Faced with dependencies and in line with its resilience goals, the EU increasingly turns to open source as a pillar of its technological autonomy. Yet the debate often stalls on the questions: Where is software “made”? Who “owns” the code? And can sovereignty be achieved simply by adopting European-labelled alternatives? - all questions that often are not compatible with how open source actually works, and potentially leading to missing out on the vast potential of the global OS ecosystem for Europe.</p> <p>In this panel, the speakers will focus not on trying to define “European open source” but on the fact that sovereignty is less about origin or ownership than about capability, participation, and influence. Drawing on perspectives from the industry and SMEs, as well as the global open source ecosystem, the discussion will focus on the future-looking (and pragmatic) idea of interdependent autonomy: where strategic independence is strengthened, not weakened, by deep engagement in global open source communities.</p> <ul> <li>What is the most omitted in digital sovereignty discussions, and should not be?</li> <li>If you were to point to one action that Europe should focus on in the next 10 years for its digital sovereignty, what would it be?</li> <li>What should open source foundations do in order to strengthen this interdependence, while not hampering EU’s goals of supporting its own, homegrown industry?</li> <li>How can European companies build viable business models on open technologies without retreating into protectionism or undermining global collaboration?</li> </ul>

Power to the Public Stack: Governing Europe’s Digital Commons (en)

<p>Europe’s IT landscape has long been heavily reliant on just a few large American tech providers, and this is equally true for the systems used in public administration. This dependence jeopardises the administrative services that underpin our states’ functioning. To counter this, Europe needs a tech stack that strengthens digital sovereignty at every level, from databases and virtualisation to operating systems and end-user applications. </p> <p>Various governments and governmental organisations in Europe are already working to provide building blocks for a sovereign public infrastructure. The newly founded European Digital Infrastructure Consortium for Digital Commons (DC-EDIC) can fuel this development. This session brings together actors involved in setting up DC-EDIC in conversation with civil society and the wider open source community. We will explore the EDIC's role in supporting the open source ecosystem, as well its connections to European policy: </p> <ul> <li>How can we support long-term sustainability for open source public infrastructure?</li> <li>What capacity barriers still stand in the way of OS adoption?</li> <li>What governance models can enable meaningful participation from stakeholders?</li> </ul> <p>With this session, we hope to help steer the EU's ambitions for digital sovereignty toward models that genuinely empower the open source community and reinforce the sustainability of Digital Commons.</p>

The Euroshack (en)

<p>As it takes a village to raise a child, it takes a global open ecosystem to build a Euroshack. Inspired by the Frugal Manifesto, we envision the Euroshack as the first agile prototype of a truly open EuroStack: modest in form, ambitious in purpose. Grounded in pragmatism and powered by free and open software, the Euroshack avoids nationalist overtones and instead champions a scalable, dependable core. “Shack” is a humble name, but it reflects a bold mission: to secure digital sovereignty and protect our electronic freedoms in Europe from the mood swings of oligarchs. With its modular, adaptable structure, the Euroshack is built to grow, evolve, and empower.</p>

The Missing Level: Why EU Open Source Fails Locally (en)

<h2>Abstract</h2> <p>Europe has bold ambitions for open source and digital sovereignty, yet most initiatives struggle to deliver meaningful change where it matters: at the level of local institutions. Despite strong strategies and political commitments, implementation stalls because the policy frameworks guiding European digital transformation ignore a simple truth. Europe is built on a multi-level governance system where local actors carry the responsibility for execution but lack the incentives, support, and capacity to act.</p> <p>Drawing on hands-on experience from Denmark’s OS2 (<a href="https://os2.eu">os2.eu</a>) community, where more than 85% of municipalities jointly develop and maintain open source solutions, this talk examines why current EU-level open source policy risks failing in practice. It unpacks three systemic barriers:</p> <ol> <li><strong>Weak incentives at local level:</strong> Municipalities lack resources, competencies, and organisational maturity to prioritise open source adoption. Financial savings are not an effective incentive, because open source is not a budget trick; it requires long-term investment in capacity.</li> <li><strong>Multi-level governance creates structural friction:</strong> Authority is distributed across EU, national, and local levels. While this strengthens democracy, it fragments responsibility. National governments centralise; local authorities implement without adequate support; and EU ambitions rarely translate into actionable change.</li> <li><strong>Vendor dominance distorts procurement and advice:</strong> Large IT vendors shape decision-making, reinforce proprietary dependency, and overshadow sovereign alternatives. The barriers are governance- and leadership-related, not technical.</li> </ol> <p>The talk ends with practical policy recommendations: risk-bearing EU capital for local transitions, stronger alignment between EU-level commitments and local implementation realities, and a cultural shift where every new digital project must explicitly break with “doing things the way we always have”.</p> <h2>Speaker bio</h2> <p>Rasmus Frey is Chief Executive and Secretary at OS2 (<a href="https://os2.eu">os2.eu</a>), Denmark’s open-source community for public digital collaboration.</p> <p>He works at the intersection of governance, innovation, and technology, helping municipalities and public institutions co-develop and reuse digital solutions through open collaboration and shared ownership.</p> <p>Rasmus contributes to European networks on open-source governance and digital sovereignty, with a focus on institutional design and democratic digital infrastructure.</p>

Panel: Public Procurement for Digital Sovereignty (en)

<p>Roundtable discussion with policymakers and the community: how can the public procurement framework, that is currently being reformed, be used to achieve digital sovereignty goals? Open Source provides many answers to the questions digital sovereignty raises, but how can public procurers be empowered to buy more Open Source, what are their expectations, and what hurdles exist?</p>

EU Cloud Sovereignty Framework explained (en)

<p>A Blueprint for Trusted European Digital Services</p> <p>The European Commission’s Cloud Sovereignty Framework (Version 1.2.1, Oct. 2025) is a critical blueprint for defining, assessing, and ensuring the sovereignty of cloud services used within the European Union. Born from initiatives like Gaia-X, CIGREF's Trusted Cloud Referential, and EU legislation (NIS2, DORA), this framework supplements security requirements with sovereignty-specific safeguards to reduce dependency on non-EU actors and proprietary systems.</p> <p>This session will dive into the technical and legal requirements of the framework, which uses a dual assessment approach: the Sovereignty Effective Assurance Level (SEAL) and a quantitative Sovereignty Score.</p> <p>Key Components</p> <p>In this talk Emiel will break down the framework's core pillars:</p> <ol> <li>The 8 Sovereignty Objectives (SOVs)</li> </ol> <p>The assessment is built around eight objectives that define what sovereignty means in a cloud context:</p> <p>SOV-1: Strategic Sovereignty SOV-2: Legal &amp; Jurisdictional Sovereignty SOV-3: Data &amp; AI Sovereignty SOV-4: Operational Sovereignty SOV-5: Supply Chain Sovereignty SOV-6: Technology Sovereignty SOV-7: Security &amp; Compliance Sovereignty SOV-8: Environmental Sustainability</p> <ol> <li>The 5 Sovereignty Effectiveness Assurance Levels (SEALs)</li> </ol> <p>The SEAL levels determine the minimum required level of assurance a cloud provider must meet for each objective:</p> <p>SEAL-0: No Sovereignty SEAL-1: Jurisdictional Sovereignty SEAL-2: Data Sovereignty SEAL-3: Digital Resilience SEAL-4: Full Digital Sovereignty</p> <p>This talk is crucial for open-source developers, EU-based cloud providers, and policymakers interested in contributing to or complying with the future of digital service procurement in Europe. We will discuss that digital sovereignty starts with open source and how open-source technology can directly contribute to achieving the highest SEAL levels and the maximum Sovereignty Score.</p> <p>We will also dive into the EU first policy and how that helps EU organizations to be more sovereign.</p>

Simpl: data spaces implemented in open source (en)

<p>Simpl is the open-source smart middleware platform that enables cloud-to-edge federations and all major data initiatives funded by the European Commission. </p> <p>https://simpl-programme.ec.europa.eu/ https://code.europa.eu/simpl</p>

Digital Omnibus: is the EU's tech simplification a Risk or Opportunity for Open Source? (en)

<p>The recently proposed Digital Omnibus aims to simplify a series of digital regulations, such as the GDPR, the Data Act and other laws, such as the ePrivacy directive. The goal of this legislative package is to reduce administrative burdens on organisations and boost innovation, although it can have significant impacts on open source communities, foundations and SMEs building open-source software. </p> <p>Using Matrix as a case study, this talk will go through the areas of the Omnibus proposal which might have potential impacts on the wider FOSDEM community, namely proposals around redefinition of key concepts, changes to incident reporting requirements (and how they align with CRA requirements) and data sharing. It also aims to identify opportunities which might be brought on by the Omnibus, particularly around standardisation of approaches and improved collaboration.</p>

The Fediverse and the EU's Digital Services Act: solving the challenges of modern social media? (en)

<p>This panel will bring together lawmakers who worked on the Digital Services Act and the Fediverse community for a panel on the challenges modern social media bring, from disinformation to hate speech and censorship, and how the EU's Digital Services Act and the Fediverse try to solve them.</p> <p>Further information on speakers and content will be provided shortly.</p>

Age verification: a threat to the open-source ecosystem (en)

<p>This session will explore the specific consequences for the Open Source community arising from the EU's policy agenda on protecting children online. While there is a very real need to ensure reasonable child safety measures, many lawmakers favour blunt 'solutions' that can have serious consequences for privacy and data protection, and can particularly impact free and open source software projects.</p> <p>For example, the draft CSA Regulation (sometimes referred to as "chat control") contains provisions that could make the use of age verification tools effectively mandatory for many online communications providers (messages, emails etc.) and app stores. Whilst a final law has not yet been agreed, negotiations are likely to be in their final stage by FOSDEM 2026.</p> <p>In addition, calls from lawmakers for a minimum age for the use social media are getting increasing traction. Proposals range from implementing such age gating at the level of online platforms, app stores or operating systems. </p> <p>This could not only impact code collaboration platforms, which could inadvertently be classified as social media. Mandatory age verification at the OS level could pose insurmountable problems for open source operating systems. Furthermore, projects that now rely heavily on a distributed system to offer software downloads and collect as little data as possible from their users would be forced to either thoroughly test every application they offer in advance or, even worse, completely centralize for the sake of age verification. Finally, age verification could threaten users’ ability to install apps outside of proprietary app stores. For all these reasons, open source developers should raise their voices in the age verification debate.</p>

How Is the European Commission Planning to Break Cryptography This Time? (en)

<p>The 2024 European elections marked the start of the new 5 year mandate of the European Parliament followed by forming a new political direction of the European Commission. What does this change mean for cryptography and its regulation in Europe? How can encryption be framed as a vital tool to secure fundamental rights in the digital age, rather than as a law enforcement nightmare? The talk will primarily focus on the recent developments in political narratives around securing access to encrypted data by law enforcement authorities, the current European Commission’s plans as presented in ProtectEU: the European Internal Security Strategy, and the impact on privacy, security, and Free and Open Source Software.</p>

How to engage with policymakers as civil society (en)

<p>Whether you are new to the Brussels EU Policy maze or already experienced in arguing your case with policymakers, this session wants to help you find your way.</p> <p>Who are the right contacts to reach out to, and how to find their contact details?</p> <p>How does my submission to a call for feedback develop the most impact?</p> <p>What can I do to make my voice heard?</p> <p>This interactive session brings together experts from different civil society organisations, with experience from past or present work in the European institutions, and Open Source practitioners at FOSDEM to advocate for fundamental rights, digital, and Open Source policy towards the European institutions, including the European Commission, Parliament and Council.</p>

Building a Democracy Data Space: open interoperability for participatory platforms (en)

<p>Participatory platforms are now widely used across Europe for consultations, participatory budgeting, petitions, and deliberation. However, despite this growth, civic tech ecosystems remain deeply fragmented: platforms are isolated, data is locked into silos, and citizen contributions rarely travel across institutional levels or over time. This fragmentation limits transparency, weakens democratic legitimacy, and prevents collective learning at scale.</p> <p>This talk presents the Democracy Data Space, an open, interoperable infrastructure designed to reconnect participatory processes across platforms, institutions, and territories while preserving local autonomy and data sovereignty. Inspired by European data space principles and built on open standards, this initiative explores how interoperability can enable traceability of citizen contributions, federated identity, shared governance rules, and cross-platform democratic intelligence.</p> <p>We will share:</p> <p>The political and technical problems caused by today’s civic tech silos The core architectural principles of a Democracy Data Space How open protocols and federated data spaces enable democratic traceability Early experiments, governance challenges, and next steps for this european data space for democracy This session is aimed at open-source developers, civic tech builders, data space practitioners, and anyone interested in building public digital infrastructure for democracy.</p>

HowTheyVote.eu - how we make European Parliament roll-call votes more accessible (en)

<p>We present <a href="https://howtheyvote.eu">HowTheyVote.eu</a>, a free and open-source website that makes roll-call votes in the European Parliament more accessible and transparent. We briefly showcase the site’s features and how we built it, focusing on the different official data sources we combine. We will discuss good and not-so-good practices of the European Parliament’s websites and take stock of what we learned from four years of scraping parliamentary data. Lastly, we present examples of <a href="https://howtheyvote.eu">HowTheyVote.eu</a> data being used in journalism, research, and civil society, showcasing how accessible voting records can inform debates and thus ultimately strengthen European democracy.</p> <p>The European Parliament is the only directly democratically elected EU institution, and, as such, the voting behavior of its members is of particular interest. With a significantly larger number of right-wing MEPs since last year's elections, keeping an eye on the developments in Parliament has become more important than ever. Although the Parliament publishes information such as roll-call vote results and plenary minutes on its website, it can be difficult to find out what exactly MEPs voted on or how a particular vote turned out, as the data is scattered across multiple sources, published in different formats, and made available at different times.</p> <p>We started <a href="https://howtheyvote.eu">HowTheyVote.eu</a> in 2021 as a free and open-source project to address these problems. On <a href="https://howtheyvote.eu">HowTheyVote.eu</a>, users can search for votes and view results. We also publish our entire <a href="https://github.com/howTheyVote/data">dataset</a> under an open-data license.</p>

Solving Europe's problems with Open Source (en)

<p>Across Europe, open source is increasingly used to address systemic challenges in a variety of sectors, including agriculture, energy, and public infrastructure. However, its full potential depends on how projects, policies, and markets are being shaped in those verticals. </p> <p>This panel brings together concrete experiences from digital agriculture, energy system modelling, and public procurement to explore how open source enables innovation, transparency, and technological sovereignty across vertical industries. Drawing on EU-funded projects, open science methodologies, and real-world procurement practices, speakers will discuss how open source supports interoperable solutions, trustworthy policymaking, and resilient public infrastructures. The session highlights the critical role of policy choices - funding, licensing, procurement rules, and governance - in turning open source software into sustainable ecosystems that serve Europe’s economic, environmental, and democratic goals.</p>

CRA overview for everyone, including projects and smaller organisations (en)

<p>This talk is for a broad audience, including projects and smaller organisations that don't have compliance and policy staff. The primary goal is to give people information so that they can check if they have CRA obligations, and what compliance work might be required. It will also show what projects can do voluntarily to make compliance work easier for others that want to use their software.</p> <p>The secondary goal of this session is to enable more people to participate or provide feedback. Eclipse Foundation and other entities of the FOSS ecosystem are creating educational materials and compliance tools. To ensure that such tools are useful for the entire ecosystem, feedback is needed from all types of projects and organisations. Do the current information resources meet your needs? What more would be useful?</p>

Could Compliance Costs Sustain FOSS? A Theory of Voluntary Attestations (en)

<p>What if open source software projects could receive ongoing and sustaining funding from the corporations that use those project commercially — without changing the license or charging a fee for usage? This may sound self-contradictory; soon, it may be more than theoretical.</p> <p>In Article 25 of the Cyber Resilience Act, one can see that the European Commission has the opportunity to create a Delegated Act for Voluntary Security Attestations. This could open a path for open source project maintainers, stewards, or third parties to reduce manufacturer's cybersecurity compliance obligations in exchange for sustained funding. The exchange benefits companies by reducing their compliance costs, but without turning the open source foundation into a manufacturer itself, without assuming liability, and without jeopardizing a steward's non-profit status.</p> <p>In this presentation, Æva Black will introduce their ongoing work with the Eclipse Foundation to develop an understanding of how such a programme might function and how it might impact different segments of our community-of-communities.</p> <p>This presentation is part one of a two-part series. Part two will feature a panel discussion with representatives of open source foundations and the European Commission.</p>

Could Compliance Costs Sustain FOSS? A Panel With The Public Sector (en)

<p>What if open source software projects could receive ongoing and sustaining funding from the corporations that use those project commercially — without changing the license or charging a fee for usage? This may sound self-contradictory; soon, it may be more than theoretical.</p> <p>In Article 25 of the Cyber Resilience Act, one can see that the European Commission has the opportunity to create a Delegated Act for Voluntary Security Attestations. This could open a path to reduce manufacturer's CRA-related compliance costs in exchange for support for the volunteers maintaining open source projects -- and to do this without becoming a manufacturer, without assuming liability, and without jeopardizing a steward's non-profit status.</p> <p>In this panel, we will hear different perspectives on how this could improve the sustainability of open source across Europe, explore the potential impacts of different approaches, and invite audience participation and questions.</p> <p>This presentation is part two of a two-part series. In part one, Æva introduced their ongoing work with the Eclipse Foundation to develop a holistic view of how such a program might function.</p>

Participating in Standardisation around the CRA (en)

<p>In this short talk, Jordan Maris and Simon Phipps of the OSI will explain how the Open Source Community can get involved in building the standards for the EU's Cyber Resilience Act, and why you should!</p>

Effective standard-setting (en)

<p>The European Commission’s report on Regulation 1025 openly acknowledges what practitioners have long observed: the EU standardisation system is struggling to deliver the kinds of outcomes needed to support the Union’s ambitious push into digital regulation. In this presentation, Tobie draws on his long experience driving large-scale standardisation efforts in organisations such as OASIS, W3C, JDF, Ecma, and the WHATWG, as well as on his work introducing open-source development practices within them. He will discuss why these practices work, the benefits they bring, how they could be adopted by the European Standardisation Organisations, and which transition mechanisms could help bridge the gap until the ESOs are able to catch up.</p>

Welcome to the Audio, Video & Graphics Creation (en)

<p>Opening of the Audio, Video &amp; Graphics Creation Devroom</p>

Qt Multimedia: easy audio and video integration in Qt apps (en)

<p>QtMultimedia is a submodule of the Qt framework that allows users to integrate various audio and video features into Qt-based cross-platform applications. https://doc.qt.io/qt-6/qtmultimedia-index.html</p> <p>We, the QtMultimedia developers, are going to present the APIs and capabilities we provide, along with their use cases and limitations. We’re open to questions, feedback, and proposals.</p>

F3D, Fast and minimalist 3D Viewer (en)

<p>F3D is a fast and minimalist open source 3D viewer designed to handle a wide range of formats, from simple 3D meshes to complex volumetric datasets. Its goal is to make 3D visualization accessible, lightweight, and efficient across platforms. Anyone with a 3D model on their computer definitely wants to install and use F3D to quickly and efficiently view their 3D models. From gamedev, to simulations researchers, via graphical artists, F3D provides value to many different fields.</p> <ul> <li>Generate thumbnails for all your 3D files in your file manager</li> <li>Double click and view your models easily</li> <li>Keyboard centric interactions for efficiency</li> <li>CLI oriented with dozens of options and configuration file support</li> <li>C++/Python/javascript API for devs</li> </ul> <p>In this talk we will cover the different use cases the F3D can help with and solve actual issues the 3D users have been having for a long time without resorting to much bigger softwares like Blender or ParaView.</p> <ul> <li>https://f3d.app</li> <li>https://github.com/f3d-app/f3d</li> </ul>

Graphite: a busy year in review (en)

<p>Graphite is reinventing open source design tools by combining vector and raster workflows through a node-based, procedural approach borrowed from the 3D industry. We did already give a lightning talk at the last FOSDEM, but since then a lot has changed. We now have a desktop app in addition to the web based UI and have worked on a bunch of features and UX improvements. In this talk, we'll give an Overview of what Graphite is and what we have achieved over the last year.</p> <p>https://graphite.art/</p>

Where's GIMP going after 3.2 (en)

<p>The GNU Image Manipulation Program (<a href="https://www.gimp.org/">GIMP</a>) is Community-driven Free software for high-end image creation and manipulation. Last year GIMP celebrated its 30th birthday!</p> <p>In March 2025 the GNU Image Manipulation Program team team was proud to release <a href="https://www.gimp.org/news/2025/03/16/gimp-3-0-released/">GIMP 3.0</a>. This represented the culmination of 7 years of hard work done by members of the GIMP community. Many major and long-awaited features were introduced including non-destructive editing, multi-layer operations, infinite canvas, more advanced colour management and much more.</p> <p>The GIMP team had made a decision that starting with the 3.0 release the length of development cycles would be reduced. This has been followed, and has lead to the next big release - the 3.2.</p> <p>Today a core developer who joined the team within the past year presents the latest release of GIMP, takes a look at what's being worked on by the members of the GIMP community, and shares the experience of becoming a GIMP developer. You can look forward to hearing something about all the file formats GIMP aims to support, full CMYK mode, improved text support, hardware-accelerated image operations and more!</p>

GStreamer 1.28 and beyond (en)

<p>This talk will take the usual bird's eye look at what's been happening in and around the <a href="https://gstreamer.freedesktop.org">GStreamer multimedia framework</a> in the last release cycle(s) leading up to the new 1.28 feature release, and look forward at what's next in the pipeline.</p> <p>Whether codecs, closed captions, MPEG-TS, HLS + DASH adaptive streaming, speech-to-text transcriptions, text-to-speech synthesis, voice cloning, analytics, WebRTC, RTMP, Vulkan, Direct3D12, Wayland, VA-API, GTK, Qt/QML, AMD HIP + NVIDIA CUDA, bindings, or Rust - we've got you covered!</p>

How to do a Podcast with Free Software? (en)

<p>Bonnie and Øjvind are the host and editor of the FSFE's Software Freedom Podcast, a podcast dedicated to Free Software. In this talk they will share their knowledge and skills on how to produce podcasts using Free Software, sharing different tools and techniques with you to create your own podcast projects.</p> <p>This is the perfect talk for everybody who wants to share their ideas and thoughts with others through podcasts. Learn the basics of recording, editing, and publishing podcasts with Free Software tools, and discover how to create quality content without relying on proprietary software. Everybody is welcome to join us from beginners and those looking to switch to Free Software!</p>

Podlibre: Podcast Audio Editing for the AI Age (en)

<p>We're building Podlibre—an open-source, cross-platform podcast editor designed specifically for podcasters' workflows, not adapted from music production tools. This is a work-in-progress demo and call for feedback from the FOSS audio community.</p> <p><strong>Why podcasters need their own tool:</strong></p> <p>Most podcasters currently rely on DAWs like Audacity, Ardour, or Reaper—tools designed for musicians with workflows that don't match podcast production. Podcasters need noise reduction, mouth click removal, transcript editing synchronized with audio, chapter markers, metadata management (ID3, RSS, Podcasting 2.0 tags), and one-click publishing—not MIDI sequencing or complex mixing boards.</p> <p><strong>What we'll show you:</strong></p> <ul> <li><strong>Live WIP demo</strong> of Podlibre's plugin-based architecture</li> <li><strong>Automated transcription</strong> running locally on your laptop—no cloud services required</li> <li><strong>Transcript correction UI</strong> optimized for keyboard-only editing (inspired by Aegisub but podcast-focused)</li> <li><strong>Workflow customization</strong>: how our plugin system lets you build your own production pipeline</li> <li><strong>Publishing integrations</strong>: direct export to Castopod, Funkwhale, Faircamp, and local storage</li> </ul> <p><strong>What we need from you:</strong></p> <p>Podlibre is funded by Ad Aures (creators of Castopod) and NLnet, currently in active development. We're here to gather feedback from the FOSS audio community: What features matter? What libraries should we integrate? How can we build bridges with existing audio tools (PipeWire, LV2, VST)?</p> <p>Join us to shape a podcast editor that serves the 350,000+ active podcasters who deserve open-source tools built for their craft.</p>

Get the most out of Linux for music production (en)

<p>What does it take nowadays to get the most out of your Linux system so that it can be used as a music production power house? This talk will explore the possibilities and hand some guidelines to squeeze out as much headroom your system has for all those resource hungry plugins. Along the way some myths might get debunked and some helpful tools will get introduced.</p> <p>During the talk I will walk through how to set up your system so it can do low-latency real-time audio. With low-latency I mean round-trip latencies below 10 ms. I will show which tools can help with getting your system to perform better for doing music production. Such tools include <a href="https://codeberg.org/rtcqs/rtcqs" title="rtcqs">rtcqs</a> and <a href="https://github.com/gaheldev/Millisecond" title="Millisecond">Millisecond</a> for finding and fixing possible bottlenecks, jack_iodelay or <a href="https://ardour.org" title="Ardour">Ardour</a> for measuring round-trip latencies and <a href="https://github.com/Gimmeapill/xruncounter" title="xruncounter">xruncounter</a> to do DSP load stress tests.</p> <p>I will also look backward briefly to 15 years ago when I did a similar talk at the <a href="http://lac.linuxaudio.org/2011/recordings/day1_1400_Configuring_your_system_for_low-latency_real-time_audio_processing.ogv" title="Video of my talk about system configuration during LAC2011 in Maynooth">Linux Audio Conference in Maynooth</a>, what has changed since then, what has improved? I will also glare a bit at the future as the Linux Audio Conference will be held in Maynooth again this year and chances are I will dive deeper into this matter during that conference.</p> <p>After the talk you will hopefully have a better grasp of what the key factors are for getting a better performing machine that has as little of those dreaded xruns as possible!</p>

midiMESH: Network MIDI with Elixir on ESP32 via AtomVM (en)

<p>This talk demonstrates how to build a wireless MIDI controller using Elixir, ESP32 microcontrollers, and AtomVM, proving that functional programming can run efficiently on resource-constrained embedded devices.</p> <p>We'll explore how BEAM VM's lightweight processes and message-passing model naturally fit embedded systems programming, particularly for real-time applications like MIDI. The session covers practical implementation details: WiFi connectivity, UDP networking, MIDI message generation, and interfacing with physical controls like knobs and faders on ESP32-C3 hardware with just 400KB RAM.</p> <p>Attendees will learn about AtomVM's subset of the BEAM VM designed for microcontrollers and the potential for building distributed music applications. We'll discuss how networked MIDI enables new possibilities for multi-device music systems and collaborative performance setups built on BEAM's distributed computing capabilities.</p> <p>The project is fully open source and demonstrates a compelling use case for Elixir beyond traditional web services, showing how the language's concurrency model excels in IoT and real-time embedded systems.</p>

Modular in the DAW: Cardinal origins, tips and tricks (en)

<p>Over the past years we developed <a href="https://cardinal.kx.studio/">Cardinal</a>, an open-source eurorack simulation audio plugin based on <a href="https://vcvrack.com/">VCV Rack</a>. It integrates over 1300 modules, is available under the GPL-3.0-or-later license and comes in various plugin formats (lv2/vst2/vst3/clap/au) and configurations (synth/fx/main).</p> <p>In this talk we explain the reasons for starting the project and how we think this improves the original Rack for running as an audio plugin. We will also showcase some tips and tricks for integrating with the plugin host and some advanced use cases like running it on embedded hardware.</p>

Livecoding soundscapes in Kotlin with Compose Multiplatform (en)

<p>Kotlin's Compose Multiplatform allows for the creation of beautiful user interfaces in a declarative, functional paradigm. But the Compose compiler isn't limited to creating UI or even visuals.</p> <p>In this talk, we explore using the Compose compiler to create soundscapes and other pieces of music. I will present a library and domain-specific language (DSL) for musical composition.</p> <p>We'll start by looking at the building blocks of musical compositions and how Kotlin and Compose Multiplatform can be used to implement them in a declarative and functional way. This includes tone generators/synths, shaping the envelope of a sound, playing samples, expressing various timings and simultaneously playing multiple tracks, and creating a drum machine. We'll also see how a powerful DSL allows us to more conveniently express complex rhythms.</p> <p>Following that, we'll look at how to implement the audio generation backend on multiple platforms, and some ways to optimise the Compose code – the precise timings required for music present a particular challenge. We'll also see how the audio generation integrates with existing Compose components, and how to create enlightening visualisations of the code and music.</p>

Become an orchestra composer using FOSS! (en)

<p>A couple of years ago I made a presentation called "Become a rockstar using FOSS!": it was a clickbait-y title, since I'm (obviously) not a rockstar at all, but it was a nice opportunity to introduce people to the music production ecosystem in Linux, which is huge and yet not that known to most. At the time, I mostly talked about the typical workflow for creating and recording music with either real or virtual instruments, but with a focus more on rock/pop music, in order to keep things simpler.</p> <p>In this presentation I'll address a different point of view, that is how you can have a full symphonic orchestra in your laptop, write music for it and then have it performed in ways that are hopefully realistic enough to be used within the context of your compositions (unless you know 80 people that can play your music for you, that is!). I'll present my typical workflow, and the different pieces of software I used to make it possible for me to write purely classical music (symphonic poems), but also orchestral arrangements for songs in different genres (e.g., folk, progressive rock or metal) that I published as a hobby in my free time over the years.</p> <p>Again, a clickbait title because I'm not really an orchestra composer... but FOSS definitely helped make me feel like one, and it can help you too!</p>

Linux Pro audio... like a pro! (en)

<h1>How to produce music with Linux/FLOSS professionally</h1> <h2>Real penguins do not need apples to make music...</h2> <p>A case study on how an <em>entirely</em> Linux/FLOSS based production chain can be a viable alternative to the proprietary/paid one(s). I will concentrate on the production of a pop song, from the draft to the full-fledged, platform-ready master.</p> <p>Many topics will be briefly discussed here: hardware, tools, practices, objectives, comparisons and interoperability and whatever; all you need to know to get the job done, professionally.</p> <p>Here are some links related to this talk:</p> <ul> <li><a href="https://youtu.be/RCGfQJ_T4aw?si=KnxGmCJsJhRoPm5K">“Oh Nena”</a>, the finished song</li> <li><a href="https://ardour.org/">Ardour</a>, a DAW</li> <li><a href="http://hydrogen-music.org/">Hydrogen</a>, a drum machine</li> <li><a href="https://jackaudio.org/">JACK Audio Connection Kit</a>, low latency audio backend</li> <li><a href="https://fedoraproject.org/">Fedora Linux</a>, the underlying OS</li> </ul>

MIDI Live performer (en)

<p>JavaScript is a great language for it’s ease and low barrier to entry, fast turnaround workflows, and trying quick experiments. It’s generally not so great for real-time tasks, such as music playback or for working with live musicians.</p> <p>And yet, that’s what this library does.</p> <p>In this talk we look at how the midi-live-performer library can act as a real-time MIDI looper, echo unit, and auto-accompaniment system. There’s a slight detour to show midi-info, which provides user-friendly names for MIDI messages, both in real-time and not. Then we explain how it works, where the weaknesses in timing lay, and how it formed the basis for a solo recording of the multi-instrumentalist work “In C”</p>

PAW, a programmable DAW (en)

<p>Over the past few years, I've been prototyping <a href="https://lambein.xyz/paw-live2023/">PAW</a>, a DAW based on ideas from live coding and bidirectional programming. Like with live coding, in PAW you write code to describe a piece of music incrementally. As part of this, you also build a GUI for direct manipulation of that same code, providing similar affordances to traditional DAWs.</p> <p>PAW stems from my observations that regular DAWs tend to be limited in what they let users do, due to fundamental limitations with traditional GUIs. I believe that mixing in ideas from live coding, and programming at large, can help savvy users shed those limitations, while retaining familiar GUI affordances and usability.</p> <p>The software is open source, but not yet quite usable. My goal with this talk is to share ideas with other people in the field of music production software.</p>

Rehorse: sheet music and rehearsal app for bands (en)

<p>Music ensembles are moving from sheet music to tablets with PDFs. Many apps exists but all are focuses on individual musicians, not on bands. Rehorse is a web app with offline support that can be self-hosted by a band. The band librarian makes the music available to the band members. They can annotate the sheet music, practice with recordings with convenient section repeats. The app lists rehearsal and concert playlists and has (optional) access management to prevent members from downloading all parts, but e.g. only those from their section.</p> <p>Recordings and sheet music are stored offline so the sheet music is available even at performances where no network is available.</p> <p>Rehorse has been under development and in use in several bands for years. This talk invites new users and potential contributors. It goes into the workflows that musicians expect and the high standards that they are used to from other apps.</p> <p>https://codeberg.org/vandenoever/rehorse</p>

Independent and sustainable audio publishing with Faircamp (en)

<p><a href="https://simonrepp.com/faircamp/">Faircamp</a> is a static site generator for audio producers - a system that creates fast, maintenance-free and indestructible websites for music, podcasts and other types of audio on the web. In this talk I will introduce you to Faircamp - where it comes from, what it offers, and where the project is heading in 2026 and beyond.</p> <p>At the end of this talk I would also like to introduce you to other projects and communities that are working hard to bring back dignity, agency, control and a chance for a livelihood to independent musicians, podcasters, labels and audio producers all over the world.</p> <p>Links: - <a href="https://simonrepp.com/faircamp/">Website</a> - <a href="https://cdm.link/faircamp-intro/">Article: «Faircamp lets you put sound, podcasts, and music on your own site» (CDM)</a> - <a href="https://simonrepp.com/posts/2026-faircamp-desktop-application/">Blog post: «2026 will be the year of the Faircamp desktop application»</a></p>

Building Sustainable Businesses Around Open Source Projects (en)

<p>Are you interested in talking about how to build sustainable businesses around open source projects without sacrificing the ideals of the free open source movement? The non-profit association behind Open Source Founders Summit wants to invite those with an interest in financing open source projects with services, support and/or associated commercial products to join us! We'll talk about how to balance developing the project versus developing the commercial offering, go to market motions, product strategy, and more.</p>

FOSS In India (en)

<p>The FOSS Community in India has been growing over the last decade[0]. This BoF is to discuss how to grow and nurture it further. The organizers are the folks behind the FOSS United + FLOSS/fund booth, and we'd love to talk about what's happening in the space (including the amazing IndiaFOSS conference).</p> <p>[0]: &gt; India alone added more than 5 million developers on GitHub this year (over 14% of all new accounts) and is on track to account for one in every three new developers on GitHub by 2030.</p>

HCI is dead, long live HDI (en)

<p>The paradigm we have been using for decades is HCI (Human Computer Interaction) it talks about the computer as the interface. We already know this is broken and not compatible with the enshittified data world we live in now. HDI (Human Data Interaction) provides a better methodology and should be applied by designers, policy makers and developers. Lets learn and discuss together...</p>

TiDB Community Birds-of-a-Feather (en)

<p>This session brings together TiDB community members to share the latest updates on the TiDB <a href="https://github.com/pingcap/tidb">project</a> and the community. There will also be an open Q&amp;A, giving attendees an opportunity to ask questions, and provide feedback directly to the TiDB team and community members.</p>

Software Freedom Podcast with Dr. Lucas Lasota (en)

<p>The Free Software Foundation Europe's "Software Freedom Podcast" is at FOSDEM and doing an on sight recording! You can join us and be part of the upcoming SFP episode. For this episode we will talk with Dr. Lucas Lasota from the Just Transition Center of the Martin Luther University of Halle Wittenberg, about, "can the Digital Markets Act (DMA) help to protect Free Software developers working with AOSP?".</p> <p>We are happy to welcome everybody interested in the topic to the recording of the Software Freedom Podcast!</p>

WebGPU: Melting your computer in the post-american era (en)

<p>I used to write a lot of open source CUDA 5-10 years ago. Now that NVIDIA lost interest in us poor consumer plebs, my software has a more expensive entry barrier. That is why I write WebGPU these days, the same code can melt my laptop and my phone. Its great. Come and lets burn some chips. https://en.wikipedia.org/wiki/WebGPU</p>

CVMFS install party + adoption Q&A (en)

<p>Get help in understanding and setting up CVMFS, a highly scalable network filesystem.</p> <p>The session is initiated by a contributor to CVMFS. Core maintainers of CVMFS may be joining us.</p> <p>Developers and adopters of other Software Defined Storage technologies are also welcome to join and lead their discussions.</p>

TRANS*FEMINIST SERVER SESSION (en)

<p>TRANS*FEMINIST SERVER SESSION - a shellscript session to update and configure our feminist networks, meet each other, find solidarities and alliances in computing. </p> <p>As a daemon we want to learn about switch mode in tinc or vpn software to use wake up on lan (WOL) to switch on our backup server.</p>

Environmental Sensors and Operational Applications (en)

<p>Let’s discuss open source environmental sensing and operational open source monitoring platforms for ecosystem restoration, resource sustainability, and pollution. We can look at some open source examples in groundwater flow monitoring, greenhouse gas emissions, and reforestation.</p> <p>Low cost environmental monitoring is needed to ensure paths forward for sustainable ecosystems and life ways through ever-increasing industrial utilization of the earth system. However, proprietary and high cost solutions limit access to and deployment of monitoring systems, slowing community responses and restoration engineering. Operational open source environmental platforms facilitate community driven initiates to meet these needs long term.</p>

WoodpeckerCI User Meetup (en)

<p>Meet and chat what's currently going on. How to solve problems with WoodpeckerCI. Get new ideas and feedback.</p> <p>Just chat :)</p>

Open Buro: Integrating applications to create a Smart Platform Experience (en)

<p>In the competition with Microsoft 365, <strong>FOSS solutions suffer from an architectural limitation : a simple SSO does not create a platform...</strong></p> <p>To offer a true Smart Platform Experience around the mail, we must go beyond silos solutions and build deep, consistent, cross-functional integration between independent services.</p> <p>The aim of this BOF room is to foster discussions &amp; ideas to see what could be such a "standard" : both the technical and governance subjects will be discussed.</p> <p>It is the extension of the conference : <a href="https://fosdem.org/2026/schedule/event/GMKDKW-foss-vs-office-365/">Open Buro: Integrating applications to create a Smart Platform Experience</a></p> <p>Based on the integration of DINUM's LaSuite into Twake.AI, we will analyze what is missing to offer a “Smart Platform Experience”: a standardized cross-functional layer that brings together independent services.</p> <p>Samuel Paccoud, director of lasuite.numerique.gouv.fr, will comment this integration and the perspectives he identifies.</p> <p>We will see how such a standard can enable a modular ecosystem, where each application remains independent but can interoperate deeply, forming a credible and sustainable sovereign workplace. This is the mission of the Open Buro consortium: to create an open foundation where architecture becomes a political act.</p>

GUI apps with Go (en)

<p>There is so much happening with graphics in Go now, and it’s all open source 😎. Let’s chat about projects and frameworks. I come with apps and also knowledge of the Fyne toolkit (https://fyne.io) but the discussion is open to all.</p>

Distributions DevRoom: Opening Remarks (en)

<p>Welcome to the FOSDEM 2026 edition of the Distributions DevRoom! Meet the organizers of this year's Distribution DevRoom, learn a little bit about the history of our DevRoom, and go over some ground rules for the day.</p>

The Varlink IPC System (en)

<p>The systemd project and some others have been adopting the Varlink IPC system recently, in places traditionally reserved for D-Bus. In this talk I'd like to explain why Varlink matters, and is a major step forward from D-Bus for almost all areas of Linux OSes. I'll talk about patterns, lifecyles, tracing, parallelism, security, and a lot more.</p>

Commoditizing the Build: How Containers Save Our Contributor Base (en)

<p>For decades, building a Linux distribution has been considered a highly specialized craft. To participate, one had to master complex toolchains—building package files, navigating the intricacies of dependency resolution, and operating hard-to-grok build systems like OBS or Koji &amp; Pungi &amp; ImageBuilder. While extremely powerful, this entire stack presents a massive barrier to entry. The result is a demographic crisis: the average age of package maintainers is rising, and new contributors are not motivated to learn these legacy tools.</p> <p>In this talk, we argue that the solution lies in the commoditization of the build process. By adopting docker and podman as a build tool and OCI (Open Container Initiative) images as the native artifact, we bridge the gap between "distro builders" and the millions of developers who already know how to write a Dockerfile.</p> <p>We will explore current successes like Universal Blue and Fedora Atomic, but we will also go further. What if we built the individual packages themselves from Dockerfiles?</p> <p>Join us to explore how OCI-based workflows don't just solve technical problems—they solve a growing social problem. By making the tools of creation accessible to a larger base, we can foster the next generation of contributors!</p>

Packaging eBPF Programs in a Linux Distribution: Challenges & Solutions (en)

<p>eBPF introduces new challenges for Linux distributions: programs depend on kernel, CO-RE relocations, pinning behavior, and version-aligned bpftool or libbpf tooling. This session looks at what it really takes to package eBPF programs as RPMs and explores specific, real world usecases in Fedora. We’ll explore issues such as pinned maps, privilege models, reproducible builds, SELinux implications, kernel-user ABI considerations, and managing kernel updates without breaking packaged eBPF assets. The talk presents practical solutions, best practices, and tooling ideas to make eBPF a first-class citizen in mainstream distributions.</p>

From Code to Distribution: Building a Complete Testing Pipeline (en)

<p>How do you ensure code works across distributions before it reaches users? The Packaging and Testing Experience (PTE) project is an open-source approach to solving the upstream-to-downstream testing challenge.</p> <p>The traditional model fragments testing: upstream tests their code, distribution maintainers test packages, and users discover the gaps. PTE bridges this by creating a continuous testing pipeline where upstream changes are automatically built, tested in realistic distribution environments, and validated before integration.</p> <p>Our approach consists of three open-source components working together:</p> <ol> <li><a href="https://tmt.readthedocs.io">tmt</a> - A CI-agnostic test management framework that defines tests once, runs anywhere </li> <li><a href="https://testing-farm.io/">Testing Farm</a> - On-demand test infrastructure providing clean VMs, containers, bare metal, and multi-host environments </li> <li><a href="https://packit.dev/">Packit</a> - Integration glue connecting upstream repositories to distribution workflows</li> </ol> <p>But this isn't just about specific tools - it's about the philosophy: making tests portable, infrastructure on-demand, and integration automated. tmt works with any distribution. Testing Farm's architecture could inform similar services. The integration patterns apply broadly.<br /> In this talk, we'll share:</p> <ul> <li>How all of these work together and what we’ve learned along the way. </li> <li>How we integrate and share tests from upstream projects down through Fedora, CentOS and RHEL. Both for the packages and their integration with each other as well. </li> <li>How other distributions can adopt these approaches. </li> <li>Where collaboration could reduce duplication across the ecosystem.</li> </ul>

Relying on more transparent & trustworthy sources for Arch Linux packages (en)

<p>The software supply chain for Linux distributions is under growing pressure. Several distributions have recently suffered from infected packages caused by compromised or malicious upstream sources, including core libraries, leading to significant security implications.</p> <p>These incidents prompted Arch Linux to reflect on the way we handle our package sources. With the objective of bringing greater transparency to our packaging process, we revisited historical decisions and established updated guidelines and best practices for selecting trustworthy sources for our packages, in order to prevent (or at least mitigate) such potential security threats in the future.</p> <p>This talk will share an overview of the <a href="https://rfc.archlinux.page/0046-upstream-package-sources/">specifications and guidelines</a> we established during this reflection.</p>

Building ISOs from OCI containers (en)

<p>TL;DR: Write a Containerfile, use image-builder to convert it to an ISO with a live environment.</p> <p>bootc revolutionized how we build and consume image-based systems: just build an OCI container in your preferred git forge, publish it in a registry, and voilà, anyone can come and rebase their bootc-based system to it. A great example is Bazzite: one of the most popular gaming-oriented distributions today.</p> <p>However, the first-day experience is still lacking: the installers don’t run in a live environment, and their building process is a nightmare and far from container-friendly.</p> <p>The team behind the osbuild/image-builder project recently started experimenting with introducing a way to build an ISO with a live environment directly from an OCI container image. All techniques you know from building bootc systems can be applied here, so the build pipelines can be shared. Additionally, if you want such an ISO to be a bootc installer, the resulting artifact will be surprisingly small due to the high level of deduplication.</p> <p>Come to this talk to learn how to build your own ISO using just a bunch of podman commands!</p> <p>https://github.com/osbuild/image-builder-cli https://osbuild.org/docs/developer-guide/projects/image-builder/usage/#bootc</p>

What Image-Based Systems Taught Us About Linux Distributions: Lessons From Kairos and Why We Built Hadron (en)

<p>Over the last several years, the Kairos project has built image-based, immutable systems on top of multiple Linux distributions like Ubuntu, Debian, Alpine and others. This experience has revealed a recurring set of engineering constraints shared across traditional distros: assumptions about package managers, filesystem layout, dependency chains, downstream patches, boot tooling, or init system behavior that work well for classic installations, but create friction in image-based, cloud-native and edge-focused environments.</p> <p>This talk presents the design principles that emerged from this work: minimal bases, upstream-first components, predictable boot paths, trusted boot chains, reproducibility, and clear separation between the immutable system image and extensible runtime layers. We will discuss both the technical challenges and the architectural conclusions that followed.</p> <p>These lessons ultimately led us to build Hadron, a new minimal Linux distribution developed by the Kairos team: musl-based, systemd-powered, upstream-aligned, and designed specifically for image-based systems. Hadron is not intended to replace any existing distribution; rather, it is a small, focused reference implementation of what an OS optimized for this model can look like.</p> <p>The goal of this talk is to share practical insights with the wider distribution community and contribute to the ongoing evolution of image-based Linux.</p> <p>https://github.com/kairos-io/hadron https://github.com/kairos-io/kairos https://kairos.io/</p>

The saga of official binary packages for Gentoo Linux (en)

<p>You all used to know <a href="https://www.gentoo.org/">Gentoo Linux</a> as a source-based Linux distribution, where compiling things on your own machine was both pleasure and pain, right? Well, some time ago we announced that we now also offer <a href="https://www.gentoo.org/news/2023/12/29/Gentoo-binary.html">binary packages for download</a>. And while of course a few purists protested, overall this initiative was a resounding success. Now you can mix and match between binary and source based installation, and find your own balance between convenience and tuning.</p> <p>A lot of LEGO blocks had to come together (and occasionally be stepped on) to make this happen. From quality control and automated rebuilds on the source installation side, to a new package format and support for GPG signing, to package delivery and designated build hosts, extended support in the package manager, ... Let us tell you the story of an experiment that worked out great, and discuss further possible future improvements.</p>

CentOS MythBusters (en)

<p>CentOS is the Community Enterprise Operating System, a Linux distribution built by the CentOS Project. For over two decades, CentOS has powered servers and workstations around the world. During this time it has accumulated its fair share of myths, tall tales, and urban legends. Many of these stem from the transition from the legacy CentOS Linux variant to the modern CentOS Stream variant.</p> <p>In this session, we won't just tell the myths, we'll put them to the test. In the spirit of the TV show MythBusters, we'll use observable data, historical events, and project insights to rate each myth as BUSTED, PLAUSIBLE, or CONFIRMED. Attendees will gain a better understanding of the advantages of CentOS and the state of the CentOS Project, which they can use to make informed choices for their own deployments.</p>

Distributing Rust in RPMs for fun (relatively speaking) and profit (en)

<p>This talk gives an overview of how Rust libraries ("crates") and applications are packaged as RPMs for Fedora Linux, and how this distribution mechanism addresses multiple shortcomings of the limited functionality of the distribution mechanism built-in to cargo, the Rust package manager:</p> <ul> <li>Application updates that are integrated with the system package manager.</li> <li>Automatic distribution of security updates independent of application releases.</li> <li>System integration features like shell completions, manual pages, launchers, etc.</li> <li>Test coverage for CPU architectures that are usually not available in CI systems.</li> </ul> <p>Packaging Rust crates as individual RPM packages also simplifies package maintainer responsibilities, despite increased up-front work:</p> <ul> <li>Security issues in library code are patched once instead of once per affected package.</li> <li>Audits can happen once per crate / version instead of once per vendored copy.</li> <li>Test coverage for library crates (not possible when using vendored dependencies).</li> </ul>

The road ahead to post-quantum cryptography for Fedora (en)

<p>Does your distribution need to care about attacks by quantum computers, and if yes, where? Which parts of Fedora already support post-quantum cryptography (PQC), and what still needs to be done? And what does the European Union have to do with any of this?</p> <p>Answers for these questions, and more, will be provided in this talk. You'll leave with a rough idea whether the risk is relevant for you and why the risk is no longer the only thing driving a migration. Don't expect hyped statements, we'll stick to the technical details and facts. You may learn how to make your OpenPGP key quantum-safe.</p> <p>Attend if: - you're vaguely aware of what PQC is, but want to learn what it means for your project - you've always wanted to ask that one question about post-quantum cryptography, but haven't found the right person to ask - you are running a distribution's package signing infrastructure, or maintain a package that implements a network protocol</p>

Error recovery at boot with MicroOS and systemd-bless-boot (en)

<p><strong>openSUSE MicroOS</strong> is a <em>snapshot-based</em>, <em>immutable</em> operating system that features <em>automatic updates</em> and <em>recovery</em>.<br /> <a href="https://github.com/openSUSE/health-checker"><strong>health-checker</strong></a> is the system tool responsible for handling <strong>automatic recovery</strong> and <strong>rollbacks</strong>, and it comes installed by default. It was recently rewritten to support both <strong>systemd-boot</strong> and <strong>grub2-bls</strong>, utilizing <em>systemd-bless-boot</em> and <a href="https://systemd.io/AUTOMATIC_BOOT_ASSESSMENT/"><em>Automatic Boot Assessment</em></a>.</p> <p>In this talk, we will provide a brief explanation of the <strong>Boot Loader Specification (BLS)</strong>, which is supported by both <strong>systemd-boot</strong> and <strong>grub2-bls</strong>. Next, we will explain <em>Automatic Boot Assessment</em>, describe how it is used by <strong>health-checker</strong>, and show how it can be used to check the <em>system status at boot</em> and act accordingly.</p>

ParticleOS, from Fedora to Feast: Stirring Traditional Distros into Immutable Delights (en)

<p>How to successfully brew a Linux immutable image, with bells and whistles</p> <ul> <li>take a <a href="https://github.com/systemd/particleos">ParticleOS recipe</a> 📜</li> <li>generously pour in packages from a traditional distribution like <a href="https://www.fedoraproject.org/">Fedora</a> 🫗</li> <li>add a pinch of <a href="https://microsoft.github.io/ipe/">security policies for code integrity</a>, build time and boot time customizations to taste 🧂</li> <li>amalgamate them together with <a href="https://systemd.io/">systemd</a> 👩🏻‍🍳</li> <li>stir vigorously with <a href="https://github.com/systemd/mkosi">mkosi</a> 🥣</li> <li>bake until crispy in the <a href="https://openbuildservice.org/">Open Build Service</a> ♨️</li> <li>allow time to cool in your <a href="https://download.opensuse.org/repositories/system:/systemd/">CDN</a> 🥧</li> </ul> <p>Creating a (truly!) immutable distribution with a strong security posture and a chain of trust that starts in the hardware and ends in userspace is no longer a job that requires an entire team and starting from first principles. With the power of tooling and infrastructure provided by the <a href="https://systemd.io">systemd project</a>, anyone can customize, build and deploy at scale and securely starting from your preferred traditional package-based distribution.</p> <p>This talk will go over all the tooling and infrastructure available to achieve this, from systemd to mkosi, from UEFI Secure Boot and dm-verity to the Integrity Policy Enforcement LSM, from OBS to systemd-sysupdate, from systemd-repart to systemd-firstboot, and show a working example and how to reproduce and customize it.</p>

Forging Fedora Project’s Future With Forgejo (en)

<p>Fedora Project is undergoing significant infrastructure changes that affect everyone from distribution users to individual contributors - that is migrating from Pagure to Forgejo as its primary Git forge for both source code and package sources. Our talk chronicles the journey from the early days of collective debating between GitLab and Forgejo with Fedora Council, through the ongoing migration of thousands of repositories with Fedora Infrastructure.</p> <p>While the initiative began due to the need to move away from Pagure, it gradually evolved into one that also aimed at fixing the long-standing pain points faced with workflows. We got the opportunity to streamline the processes that made sense about a decade back and have since then, slowly started getting in the way of contribution. This also allowed us to contribute back to the Forgejo upstream with the features that would end up benefitting all.</p> <p>Our findings serve as a blueprint for other distribution maintainers facing similar infrastructure decisions with maintaining their collaborative applications and services. They can take advantage of Fedora Project's learnings on building compatibility bridges, CI/CD workflow modernization, granular permission models, existing toolchain integration and comprehensive documentation - to ensure a sustainable approach to their significant infrastructure changes.</p> <h2>Target audience</h2> <ul> <li>Distribution developers and maintainers working on their infrastructure</li> <li>Contributors and collaborators seeking ideas to improve platforms</li> <li>Project engineers and managers maintaining access control on namespaces</li> <li>Anyone interested in large-scale multi-functional Git hosting solutions</li> </ul> <h2>Resources</h2> <ul> <li>Fedora Moves Towards Forgejo - Fedora Magazine https://fedoramagazine.org/fedora-moves-towards-forgejo-a-unified-decision/</li> <li>Announcing the Soft Launch of Fedora Forge - Fedora Community Blog https://communityblog.fedoraproject.org/announcing-the-soft-launch-of-fedora-forge/ </li> <li>Forging Fedora’s Future with Forgejo - Fedora Community Blog https://communityblog.fedoraproject.org/forging-fedoras-future-with-forgejo/ </li> <li>Git Forge Initiative - Fedora Council - Fedora Wiki https://fedoraproject.org/wiki/Initiatives/Git_Forge_Initiative_2025 </li> <li>Dist Git Move - Advanced Reconnaissance Crew - Read The Docs https://fedora-arc.readthedocs.io/en/latest/dist-git-move/index.html</li> <li>Dist Git Comparison - Advanced Reconnaissance Crew - Read The Docs https://fedora-arc.readthedocs.io/en/latest/dist-git-comparison/index.html</li> </ul>

32 years of Debian: how a do-ocracy keeps evolving (en)

<p>In August 2025, Debian turned 32 — or, for those who prefer other bases, 0b100000 in binary, or 0x20 in hexadecimal. An impressive age for a community-driven distribution that continues to power much of the Free Software world.</p> <p>By the time of FOSDEM, I will have served nearly two years as Debian Project Leader. In this talk, I’ll share insights from that experience: how Debian works as a do-ocracy, what helps it thrive, and where collaboration sometimes meets friction.</p> <p>I’ll reflect on what I set out to achieve, what we managed to accomplish, and the challenges of coordinating a large, globally distributed project run entirely by volunteers. The talk will also explore how Debian adapts to change — in technology, community dynamics, and expectations — while staying true to its core values.</p> <p>https://www.debian.org</p>

Bringing WebAssembly to constrained devices with Rust: Runtimes, tooling, and real-world tradeoffs (en)

<p>In this talk, we will share the insights we gained while building Myrmic, our open-source Rust middleware for distributed systems, with a particular focus on our microcontroller firmware that enables running WebAssembly on resource-constrained targets such as Nordic and ESP devices. Our entire stack is Rust-based—from Embassy firmware and the embedded HAL to the Wasm toolchain and the runtimes themselves. We will outline the requirements that running Wasm in <code>no_std</code> environments imposes on runtimes, particularly in the context of distributed systems with constrained devices. We will then share our experience with Rust-native runtimes such as wasmtime, wasmi, and tinywasm and with embedding WAMR into Rust firmware, focusing on how each runtime aligned with these requirements and the modifications or integration work needed to support our use case. We will also discuss how we structure and compile our Wasm modules, and the trade-offs we make between developer ergonomics, code portability, and the memory footprint of the resulting binaries. The goal of this talk is to provide practical lessons for Rust developers, highlight gaps in today’s embedded-Wasm tooling, and point out opportunities for new open-source contributions.</p> <p>Links to relevant projets: - wasmtime (https://github.com/bytecodealliance/wasmtime) - wamr (https://github.com/bytecodealliance/wasm-micro-runtime) - wasmi (https://github.com/wasmi-labs/wasmi) - tinywasm (https://github.com/explodingcamera/tinywasm) - A link to Myrmic is not yet available since it will be open-sourced early 2026</p>

Rust meets cheap bare-metal RISC-V (en)

<p>With the Rust embedded-hal v1.0 now released almost two years ago, Rust is really ready for bare metal embedded deployments. This talk will look at cheap RISC-V MCUs like the CH32V003 featuring (RPi Pico or Teensy style for less than EUR 1.30) and show you hands-on how you may develop your embedded system using bare metal Rust. From zero to main, using probe-rs for flashing and debugging, IDE integration thereof and some tricks like successfully using no-std for the tiniest footprint possible.</p>

RustBoy: A Rust journey into Game Boy dev (en)

<p>Tired of the endless “search, copy, paste, test” routine, last year’s FOSDEM helped me break out of that loop thanks to two unexpected sparks: Rust and retrogaming. In this talk, I’ll share how discovering Rust and the Game Boy homebrew scene rekindled my passion for creating software bare metal, bringing back the artistic and playful side of programming. We’ll explore the current state of the Rust ecosystem for GB, GBC, and GBA development — from compilers and minimalist engines to demo ROMs and the ongoing work bridging these two worlds.</p> <p><strong>Links</strong> https://github.com/ffex/rust-boy</p>

Async Rust in Godot 4: Leveraging the engine as a runtime (en)

<p><a href="https://github.com/godotengine/godot">Godot 4</a>’s built-in async support for GDScript has long been a powerful feature - but what about Rust? In February 2025, I implemented async support for Godot’s Rust bindings (<a href="https://github.com/godot-rust/gdext"><code>godot-rust</code></a>), enabling Rust developers to write async code without introducing external runtimes. </p> <p>In this talk, I’ll walk you through the architecture: how we adapted Godot’s async execution (already designed for GDScript) to work with Rust’s <code>Future</code> and <code>async</code> abstractions, and how we minimized cost by reusing the engine’s existing event loop and task scheduler. We’ll dive into the implementation details - including how Godot-specific futures are constructed, polled, and scheduled - and discuss the challenges we faced when implementing <code>async</code> while interacting with the engine's C++ code over FFI on potentially multiple threads. </p> <p>This talk will be especially valuable for developers interested in embedding async logic godot and other game engines or understanding how async can be made “engine-native” rather than externally bolted on.</p>

Common Expression Language (CEL) in Rust (en)

<p>The Common Expression Language (<a href="https://cel.dev">CEL</a>) is an expression language that’s fast, portable, and safe to execute in performance-critical applications. The <a href="https://github.com/cel-rust/cel-rust/">CEL crate</a> provides a parser and interpreter for the language that emerged from Google, but never provided an implementation for Rust. Given its traits, CEL is the perfect match for any Rust project that requires some sort of expression evaluation. We'll cover why that is the case and where these needs emerged from, then dive into the state of the Rust port of the interpreter, covering some of the challenges met along the way, like reviving the Rust runtime for <a href="https://github.com/antlr4rust/antlr4">antlr4</a>.</p>

Calling JIT-compiled Roto scripts from Rust (en)

<p>Roto is a statically-typed and compiled scripting language for Rust applications that integrates very tightly with Rust. To achieve that integration, it needs to interface directly with Rust types and functions. Implementing that boundary turned out to be quite tricky! We had many obstacles to overcome, such as Rust providing very few mechanisms for reflection and not providing a stable ABI by default. This talk will explain how Rust-Roto boundary works and the tricks we have to pull along the way. You can expect lots of unsafe code, deep dives into the Rust Reference and coercions from slices to function pointers.</p>

Clickhouse’s C++ and Rust journey (en)

<p>Full rewrite from C++ to Rust or gradual integration with Rust libraries? For a large C++ codebase, only the latter works, but even then, there are many complications and rough edges. In my presentation, I will describe our experience integrating Rust and C++ code and some weird and unusual problems we had to overcome.</p>

Profiling Rust applications with Parca (en)

<p>This talk introduces <a href="parca.dev">Parca</a>, a general-purpose CPU, GPU and memory profiler for Linux. The main unique feature of Parca is the fact that unwinding happens in an eBPF program, and so is low-overhead enough to be constantly running in production: it doesn't require building with frame pointers or copying large sections of the stack between memory spaces. The primary mode of visualization in the Parca UI is the flame graph.</p> <p>Rust-specific features in Parca include:</p> <p>(1) For those projects that use jemalloc, memory profiling via <a href="https://github.com/polarsignals/rust-jemalloc-pprof">rust-jemalloc-pprof</a> (2) "Custom labels" feature for associating arbitrary application-relevant tags with stack traces (for example: allowing the user to filter profiles by trace ID or any other value they choose to instrument).</p>

Building performance-critical Python tools with Rust: Lessons from production (en)

<p>Python dominates web development, but they often comes with performance and scaling issues. Recently, the Python ecosystem has seen massive performance gains from projects written in Rust, such as <code>uv</code> and <code>ruff</code>. But what other projects are out there to help Python scale thanks to Rust? At Cloudsmith, we achieved 2x throughput on our 10-year-old Django monolith by integrating Rust-based tools and contributed features back upstream</p> <p>We'll look at a number of projects that helped us start bringing Rust into our stack. We'll go over our methodology: establishing performance baselines through load testing, identifying bottlenecks, and scaling issues. We integrated existing Rust-based tools with minimal code changes and tuned application server configuration for maximum throughput, consolidating infrastructure and reducing operational complexity.</p> <p>We'll also share our experience contributing observability features upstream to Granian, ensuring production-ready monitoring that benefits the entire community.</p> <p>You'll leave with actionable strategies for modernising legacy services using existing Rust tools, understanding when this approach makes sense, and maintaining production reliability throughout the transition.</p>

Ty: Adventures of type-checking Python in Rust (en)

<p><a href="https://docs.astral.sh/ty/">Ty</a> is a fast Python type checker and language server. Ty is built with Rust, and there are a lot of interesting technical challenges involved in making it a useful tool.</p> <p>Building a Python type checker is a hard task; however, the design of Ty provides a joyful developer experience for contributors. In this talk, we will look at how the Ty codebase is structured to make development simple, and what design choices make it pleasant to work on.</p> <p>We will cover:</p> <ul> <li> <p>How Ty goes from a Python program to a diagnostic, and what parts are most important if you want to contribute.</p> </li> <li> <p>Data layout and ownership model of structs in Rust.</p> </li> <li> <p>Salsa solves challenge of incremental type checking across many files.</p> </li> <li> <p>Tooling for tests, snapshot testing during development and type checking open source projects in CI.</p> </li> </ul>

Rust in Mercurial: The wider benefits (en)

<p>From its timid introduction to the <a href="https://mercurial-scm.org">Mercurial Version Control System</a> back in 2017 to its more than 50k lines of code today, Rust has enabled a wide range of improvements, some of which we wager would have been impossible if not for Rust.</p> <p>This talk shows how we reach far beyond the obvious point of "Rust runs faster than Python". It discusses aspects like maintainability, dependency management, API re-designs, opportunities for more advanced algorithms, on disk data-structures, safe parallelism, etc.</p> <p>We present our rare perspective of working on a 20 year-old codebase with half-a-million lines of Python code, in a software niche with quite extreme goals. Mercurial aims to provide instant-feeling commands with short lived processes for a local database of tens of millions of revisions for millions of files with fully distributed replication.</p>

Taming Git complexity with Rust and Gitoxide (en)

<p>Git's internal design is both elegant and notoriously complex. Building reliable tooling on top of it means dealing with purpose-built data structures, performance trade-offs, and years of historical quirks.</p> <p>In this talk, we’ll explore how Rust, together with Gitoxide[0], makes it possible to create fast, correct, and ergonomic version-control tooling. We’ll look at how Rust’s ownership model and type system help avoid whole classes of errors, and how Gitoxide exposes a safe and composable interface to the raw Git data structures.</p> <p>Using some real-world examples, we’ll walk through: - How Git stores its data and why interacting with it is non-trivial - How the Gitoxide APIs to make this tractable - Patterns for building high-level Git workflows - A short demo of how these pieces come together in the GitButler CLI</p> <p>Attendees will come away with a deeper understanding of Git’s inner workings, practical insights into using Gitoxide, and perhaps ideas for creating next-gen developer tooling using Rust.</p> <p>[0] https://github.com/GitoxideLabs/gitoxide</p>

Rust Coreutils in Ubuntu: Yes, we rewrote /bin/true in Rust — Here’s what really happened (en)

<p>Ubuntu’s plan to “carefully but purposefully oxidise” the distro has given us the perfect playground to see what really happens when you swap decades-old GNU coreutils for their shiny Rust equivalents. Spoiler: everything relies on way more weird flags than you think — and significantly more than the internet’s finest armchair kernel engineers believe.</p> <p>In this talk, I’ll share the fun, the sharp edges, and the truly unexpected lessons from bringing Rust Coreutils (https://github.com/uutils/coreutils ) into Ubuntu: which obscure behaviours scripts secretly depend on, how packaging Essential tools can turn one missing corner-case into a boot failure, what benchmarks actually taught us (as opposed to what Reddit said they would), and how tools like oxidizr (https://github.com/jnsgruk/oxidizr ) let us safely flip between GNU and Rust without breaking the universe.</p> <p>Along the way, we’ll look at some of the best online troll predictions — the “Rust will destroy Linux”, “this is rewriting for the sake of CVs”, and “it will be 100× slower forever” genre — and compare them with what happened in the real world. Some were wrong, some were surprisingly insightful, and some were… educational, in their own way.</p> <p>If you’re curious about modernizing the Linux system, if you enjoy data-driven myth-busting, or if you simply want field notes from the frontier of “C → Rust” rewrites, this session is for you. Links:</p> <p>Ubuntu “oxidising” initiative: https://discourse.ubuntu.com/t/carefully-but-purposefully-oxidising-ubuntu/56995</p> <p>uutils/coreutils: https://github.com/uutils/coreutils</p>

Rethinking network services: Freedom and modularity with Rama (en)

<p>Modern networking software often forces developers to choose between rigid, off-the-shelf frameworks and the painstaking effort of building everything from scratch. Rama takes a different path. It’s a modular Rust framework that lets you move and transform packets across the network stack, without giving up control, safety, or composability.</p> <p>In this talk, I’ll explore together with the audience how Rama’s philosophy of layers, services, and extensions turns network programming into a flexible and enjoyable experience. You’ll see how its building blocks span multiple layers of abstraction. From transport and TLS up to HTTP, and a lot more in between. All while you can still easily plug in your own logic or replace existing components. It also shows how you can build network stacks that aren't possible anywhere else, and all without a sweat. For example socks5 over TLS. Why not.</p> <p>Through practical examples, we’ll look at how Rama empowers developers to build everything from proxies and servers to custom network tools, while still benefiting from Rust’s performance and safety guarantees. Whether you’re curious about programmable networking, Rust’s async ecosystem, or just want to build things your own way, this talk will show you how Rama helps you do it, all with elegance and confidence.</p> <p>More information about rama itself can be found at https://ramaproxy.org/, which is developed and maintained by https://plabayo.tech/, a FOSS, consulting and commercial technology (small family) company from Ghent.</p> <p>https://github.com/plabayo/rama</p>

Random seeds and state machines: An approach to deterministic simulation testing in Rust (en)

<p>Deterministic simulation testing (DST) is a method that explores as many random execution paths of a system as possible, injects random failures, and lets developers reproduce the exact same execution path on failure given an initial random seed. This testing approach shakes out many difficult to find bugs before they reach production and greatly increases developer confidence in system correctness when making new changes.</p> <p>DST was first popularized by the FoundationDB team, and is slowly finding its way into the testing arsenal of many products like TigerBeetle, Resonate, and more recently, Turso’s rewrite of SQLLite in Rust. This talk will cover how we implemented DST of our distributed storage system at Polar Signals by modelling our core components as state machines and why this was the right choice for us over other approaches that use deterministic async runtimes (e.g. https://github.com/madsim-rs/madsim).</p> <p>Come learn more about DST and how it can help you write better and more resilient software!</p>

Syd: Writing an application kernel in Rust (en)

<p><a href="https://gitlab.exherbo.org/sydbox/sydbox/">Syd</a> (sydbox-3) is an application kernel written in Rust. This talk is a tour of its runtime architecture and the Rust that makes it portable. We’ll walk through the threads and their roles: <code>syd_main</code> (startup, namespaces, policy load, lock), <code>syd_mon</code> (lifecycle, seccomp-notify plumbing), a CPU-sized pool of <code>syd_emu</code> workers (syscall brokering), <code>syd_ipc</code> (UNIX-socket control when <a href="https://man.exherbo.org/syd.2.html#ipc"><code>lock:ipc</code></a> is enabled), <code>syd_int</code> (timers/alarms), and <code>syd_aes</code> (<strong>AF_ALG</strong> crypto for <a href="https://man.exherbo.org/syd.7.html#Crypt_Sandboxing">Crypt sandboxing</a>, plus helpers <code>syd-pty</code> and <code>syd-tor</code>. Implementation highlights: minimal unsafe at the syscall edge; per-thread isolation with <code>unshare(CLONE_FS|CLONE_FILES)</code> and per-thread <em>seccomp</em>(2); <a href="https://man.exherbo.org/syd.7.html#Syscall_Argument_Cookies">syscall-argument cookies</a>; forced <strong>O_CLOEXEC</strong> and <a href="https://man.exherbo.org/syd.7.html#Force_Randomized_File_Descriptors">randomized FDs</a>; deterministic "last-match-wins" policy; and <em>mseal</em>(2) sealing on <code>lock:on</code>. Portability is first-class: one codebase for Linux ≥ 5.19 with proper multi-arch support (x86-64/x86/x32, arm64/armv7, ppc64{b,l}e, riscv64, s390x, loongarch64), ILP32/LP64 awareness, and MSRV 1.83+. You’ll leave with concrete patterns for building a thread-isolated, multi-arch syscall broker in Rust.</p>

[CANCELED] Carving JSON in heap dumps (en)

<p>There are lots of carving tools out there, but surprisingly there's no open-source one for carving JSON objects. <a href="https://www.reportersunited.gr/en/">Reporters United</a>, a network of investigative reporters in Greece, wrote <a href="https://github.com/reportersunited/json-carver"><code>json-carver</code></a> as part of our investigation into the <a href="https://www.theregister.com/2025/08/10/telemessage_archive_online/?td=readmore">Telemessage leaks</a>. <a href="https://github.com/reportersunited/json-carver"><code>json-carver</code></a> is a FOSS tool written in Rust, that can recover JSON objects from any binary stream, even partially-corrupted ones.</p> <p>We'll discuss the role of this tool in our investigation, compare its accuracy and speed against <code>strings(1)</code>, and show how to use this tool in any of your future investigations.</p>

Bugbane: Simplifying consensual Android forensics (en)

<p>Bugbane is an open-source Android application that simplifies consensual forensics by building on Amnesty TechLab's Mobile Verification Toolkit (MVT). Bugbane makes MVT's capabilities accessible to everyone through a user-friendly interface, allowing users to self-test in just a few minutes without needing a second device. It also enables periodic data acquisitions, supporting the analysis of past acquisitions with updated IoCs in an "acquire-now, detect-later" workflow. Bugbane reliably extracts and decodes key artifacts like installed apps, backups, and system logs, and allows users users to export AndroidQF-compatible age-encrypted archives.</p> <p>The goal is to expand access and usage, helping users and supporting organizations work more efficiently, and reaching a broader audience, including less-technical individuals and communities currently outside civil-society support. In the longer term, Bugbane aims to strengthen the collection of open threat intelligence that can be shared with researchers, analysts, and civil-society organizations.</p> <ul> <li>https://github.com/osservatorionessuno/bugbane</li> <li>https://osservatorionessuno.org/blog/2025/09/bugbane-simplifying-consensual-android-forensics/</li> </ul>

Automate all the things! Using Puma to automate UI actions in Android applications (en)

<p>In this talk, we will introduce PUMA (Programmable Utility for Mobile Automation), an open-source Python tool developed by the Netherlands Forensic Institute. PUMA streamlines mobile app automation by allowing users to define high-level actions—like sending messages or searching in apps—without manual UI scripting. PUMA is designed for ease-of-use and reproducibility, making it ideal for testing, research, and workflow automation. We’ll explore PUMA’s architecture, key features, and practical applications, from forensic purposes like generating reference datasets, educational purposes like how to validate your application, to personal use cases like automating repetitive tasks. Whether you’re a developer, tester, or automation enthusiast, discover how PUMA can save time, reduce errors, and unlock new possibilities in mobile automation. https://github.com/NetherlandsForensicInstitute/puma</p>

How the **** do I do that? Making 300+ forensic parsers easily accessible (en)

<p>Fox-IT's Dissect has a huge collection of features and parsers, but what does it take to maintain those and, more importantly, make them easily usable and accessibly to analysts? Wondered how we made recursive hypervisor analysis a hell of a lot easier? Or why it's so ridiculously easy to build custom tools on top of Dissect? Join us as we take you on a tour of some of the features of Dissect, as well as the challenges that come with maintaining it.</p>

Dangerzone: Bleach your documents (en)

<p>Activists and whistleblowers often handle sensitive documents that can incriminate both the exposed parties and themselves for acquiring or distributing the material. To move forward with their revelations, they must ensure they leave no identifiable trail. Enter <a href="https://dangerzone.rocks/">Dangerzone</a>, an open-source tool that sanitizes suspicious documents and removes incriminating metadata in the process.</p> <p>This talk covers metadata removal: concrete examples of how metadata has been used to de-anonymize authors and distributors, the limitations of current tools, and the challenges posed by adversaries who can apply advanced watermarking and tracing techniques to documents.</p>

Investigating Security Incidents with Forensic Snapshots in Kubernetes (en)

<p>The absence of forensics data can be just as dangerous as the presence of malicious activity. While traditional digital forensics focuses on artefacts located on storage devices, containerized environments like Kubernetes introduce new challenges for collection of digital evidence from compromised applications, where malware now routinely leaves no traces. In this talk, we are going to explore how to collect, preserve, and analyse forensic snapshots with transparent checkpointing methods while maintaining a chain of custody to investigate security incidents. We will also discuss techniques for automation in real-world scenarios and best practices for capturing and analysing malicious activity in compromised containers.</p>

I spent my summer reverse engineering ESXi VMFS, you? (en)

<p>Someone on the internet told me I was wrong. Or, well, that my code was wrong. And a totally normal response to that is to spend over a month reverse engineering proprietary kernels and kernel modules.</p> <p>How did we get here? Well, once upon a time I was fed up with all the bugs in vmfs-tools and vmfs6-tools, so I wrote my own VMFS implementation. Except that I took a lot of shortcuts, and in doing so I inherited some of the same bugs! Fast forward to 2025, and those bugs are finally catching up to me.</p> <p>Join me as I go over the excruciating process of gathering decade old ESX(i) installation media, hunting for debug symbols, and trying to piece together how VMFS <em>actually</em> works. Oh, and fix that bug, of course.</p>

Your function signature here please. (en)

<p>Software reverse engineering is a very useful tool in digital forensics. Not only can it tells us a lot about the inner workings of the software of interest, it can also lead us to quirks and even vulnerabilities not even available in the source (e.g. compiler quirks). With enough effort it even turns proprietary implementations into open-source, what's not to like?</p> <p>Of course, with a technique this powerful, there will always be downsides. Reverse engineering large binaries can be a monumental task. Where a few kB's of storage seem tiny, a few kB's of code can be huge if you have to reverse it all. A secondary problem to this, is that all this work is quite hard to reuse in the future. Binary code can differ, even with the same source, purely based on compiler options. SRE tools change, making your scripts obsolete. Decompilers change, making your signatures obsolete and so on. </p> <p>We present an open-source machine learning model, server and Ghidra plugin for creating function signatures from aarch64 assembly. These function signatures can be stored and compared to a database of known functions to easily reuse all the blood, sweat and tears you put into reversing that library that has since been updated twice.</p> <p>All code is of course open source and available at https://github.com/NetherlandsForensicInstitute/asmtransformers</p>

Designing attestations UI: The Security and Safety of OSS package supply chain (en)

<p>After working on a 12+ week project looking at how to express in the varied UI's of three package repositories (npm, pypi and RubyGems) we can now see more clearly what developers, across skill and knowledge levels, use in package repository pages to make a decision on the security of an OSS located on a registry. These decisions are critical for better understanding trust, value, social proof and the knowledge of secure practices across developers and helps answer the question: how much do developers know about the security of their software supply chain?</p> <p>This talk will cover: 1. The essential user research findings from the project, 2. How user research informed the UI style guide design build 3. What gaps and opportunities are here to continue design in the SBOM, Attestations and securing software repositories topics.</p> <p>https://github.com/ossf/wg-securing-software-repos/tree/main/docs/attestations-style-guide</p>

The UI Layer of Security: What could go wrong? (en)

<p>We spend enormous amounts of time and money auditing code for security holes. Whole industries are built around it. But for all that effort, we rarely look at the part of the system that is actually clicking the buttons and interpreting the warnings. The person with Dorito dust on their fingers and a coffee ring permanently branded on their desk, someone just trying to get things done in a tool that may or may not be helping them make safe decisions. A surprising number of real-world security failures happen not because the code is flawed, but because the interface leaves too much room for dangerous misunderstandings.</p> <p>Drawing on our work at Ura with security-critical and open source projects, this talk explores how the user experience itself can introduce or amplify security risks and why these issues often slip through traditional code-focused reviews. We will look at memorable examples of user-driven failures, outline common UX surfaces where security risks emerge, and show why auditing the human side of the system is just as critical as auditing the code.</p>

Designing For Trust and Safety In the Age of Predatory Technology (en)

<p>What does safety look like in the age of Grok, misinformation, doxxing, and technology company founders imposing their own views of safety, surveillance, and ethics on their platforms? As a former trust and safety employee of the Wikimedia Foundation, and online gender based violence expert with over a decade of experience, this talk will cover new design patterns, best practices, and product tooling to help achieve safety, security and foster trust for all types of communities online, but especially marginalized and vulnerable ones. This talk will reference ongoing research on Designing for Safety, a current project of the speaker's, and builds on notable work in the Trust and Safety field from research by Pen America, NDI, the Web Foundation, the Integrity Institute and others. Parts of the talk will focus on how open source design can be a part of the solution space for creating safety, and how transparency, security and privacy should be leveraged for safety online. This talk will also reference actionable design insights, UX, UI, new types of product design, and design related policy that could be implemented all for safety.</p>

Gephi Lite: We Built a Data Visualization Tool, But We Couldn't Design It (en)

<p><strong>Gephi Lite</strong> is a web-based open-source network visualization tool built by a three-person engineering team. After two years of development, we had a functional application—and a nagging feeling that our interface wasn't working for users. The problem: we lacked the skills to diagnose what was wrong, let alone fix it. So we brought in <strong>Arthur Desaintjan</strong>, a design intern, to help us figure it out.</p> <p>In this talk, we'll share how we approached design at a pivotal moment in our project's life—first by stepping back to clarify what Gephi Lite should really be, then by running user interviews that revealed just how far our assumptions were from reality. We'll walk through the specific findings that surprised us, the design decisions that followed, and what small open-source teams can learn from our experience about investing in design when you don't have designers.</p> <h5>Resources</h5> <ul> <li><a href="http://gephi.org/lite">The project's website</a></li> <li><a href="https://lite.gephi.org/">The web application</a></li> <li><a href="https://www.ouestware.com/2025/07/31/gephi-lite-new-design-en/">Arthur's blog post about this journey</a></li> </ul>

Design Systems in Open Source (en)

<p>Design systems evolved the process by which UI graphics are made, full with automation and deep integration. However, Open Source communities were left out of this bandwagon as most of the applications providing these capabilities were for pay or very limited for users.</p> <p>Fortunately, a new wave of design system applications, led by PenPot, has made an appearance with a bold strategy and Open Source at its core. As such, KDE Plasma saw an opportunity to build something unique to develop the Plasma desktop faster and with higher fidelity to user experience standards.</p> <p>This is the talk about the journey and current state of implementation at the KDE Plasma Deskop. In this talk we discuss graphics, colors, typography, graphical components and much more. How the journey took us from a limited application for pay to a fully Open Source system.</p>

You Don’t Need to Be a Designer to Design: Fixing UX in Open Source (en)

<p>Open source thrives on contributions from developers, testers, and community builders, but design often gets left behind. With far fewer dedicated designers in FOSS than in the commercial tech world, usability issues go unaddressed, and end users feel the friction. The good news: you don’t need a design degree or a new job title to make a difference. In this talk, I’ll show how any contributor can use simple, practical design methods to identify and solve UX issues in their favorite open source projects. I’ll try to break down “design” into simple steps anyone can try, noticing where people get stuck, asking the right questions, sketching ideas on paper, and trying them out with friends or community members. No special skills or software needed: just curiosity and a willingness to make things easier for others. If you’ve ever thought, “I see the problem, but I’m not a designer” - this talk will give you the mindset and tools to step up and become one.</p>

Understanding developer needs - User research in Forgejo (en)

<p>Understanding your users should be an important step of software development. In recent years, many end-user facing FLOSS communities integrated at least some aspects of design into their development. Unfortunately, most developer-centric projects still haven't started to even think about it.</p> <p>This talk concludes two years of user research in Forgejo, a Git-backed software forge and collaboration platform. Forgejo can be self-hosted or used on a public instance like Codeberg.org to create software together, from sharing and reviewing code to tracking user problems, doing project management and doing design work.</p> <p>Key points include:</p> <ul> <li>Surprise: False assumptions we made about our users.</li> <li>Challenge: Understanding complex and technical use cases.</li> <li>Bad-practices: Why "Feature Requests" and the common workflow to create software might actually be a terrible idea.</li> <li>Some ideas: Scaling user research beyond the team of one.</li> </ul>

Use eye tracking to figure out usability issues, the open source way (en)

<p>The talk considers usage of eye trackers to track usability issues in FLOSS. The use of consumer-grade hardware eye trackers is considered for cases when there is an SDK for Linux available, and when there is not. A webcam-based software eye tracking approach is considered as well and compared with hardware eye tracking using illustrative examples. Visualization of short-term and long-term eye tracking data series is explained with sample code for Graphviz and GNU Octave. Examples of eye tracking heatmaps and their usage scenarios are discussed, as well as using mouse heatmaps as supplementary data.</p>

Crystal: A language for humans and computers (en)

<p>Crystal focuses on developer happiness while still providing strong safety guarantees. It goes to great lengths to make complex concepts easy to use, taking away a lot of complexity. For example, static typing and compilation to native code make it intrinsically type safe and blazingly fast. Yet built-in type inference makes most type annotations unnecessary, resulting in easy to read and clean code. It feels like a dynamic language. Crystal’s runtime allows the programmer to write I/O operations as if they were blocking, but they're actually non-blocking under the hood.</p>

Building a minimal cross-platform terminal UI library (en)

<p>Terminal UI libraries often rely on heavy dependencies (e.g., curses) or platform-specific hacks. Lua’s minimal standard library makes this even harder—how can we provide a portable, lightweight solution? In this talk we’ll explore terminal.lua (built on top of luasystem): a minimal, cross-platform terminal UI library for Lua designed to provide essential terminal primitives without external dependencies like curses. The work presented here includes developments made during its participation in GSoC 2025, as well as improvements made afterwards.</p> <p>Lua intentionally keeps its standard library small, so handling terminals requires defining the true minimum set of capabilities needed for Unix, macOS, and Windows — while keeping the API simple, consistent, and predictable. The talk begins by outlining the problem: how to handle terminals portably and transparently in a lightweight language by creating a level playing field. We’ll then walk through the minimal core implemented in luasystem and how terminal.lua builds a higher-level layer on top.</p> <p>We’ll discuss:</p> <p>Low-level:</p> <ul> <li>Bridging differences between Unix/POSIX and Windows</li> <li>UTF-8/Unicode handling (including double-width characters such as emojis)</li> <li>Non-blocking async keyboard input in single-threaded Lua</li> <li>Querying the terminal (e.g., retrieving cursor position)</li> </ul> <p>Higher-level:</p> <ul> <li>Representing terminal state (color, cursor position/shape/visibility)</li> <li>Basic layouting and color handling</li> </ul> <p>Projects:</p> <ul> <li><a href="https://github.com/lunarmodules/luasystem">LuaSystem</a> — a C library exposing the absolute bare minimum terminal and system primitives needed to let Lua build a UI layer on top: https://github.com/lunarmodules/luasystem</li> <li><a href="https://github.com/lunarmodules/terminal.lua">terminal.lua</a> — the “proof of the pudding”: a pure-Lua UI library that demonstrates what can be built cleanly and portably when sticking to those minimal primitives: https://github.com/lunarmodules/terminal.lua</li> </ul>

BLUE - A generic build-system crafted entirely in Guile (en)

<p><strong>BLUE</strong> is an acronym for <strong>Build Language User Extensible</strong>. It is a functional declarative build-system fully written in Guile.</p> <p>As opposed to other build-systems, BLUE works as a library that can be used by projects to manage their builds. It is entirely self-contained and <em>can</em> be embedded into existing projects. It provides an optional clean and extensible CLI and extension points for external tools.</p> <p>BLUE aims to reduce frictions from the build-system by providing a rich extensible API with clear error messages and documentation.</p>

Modern Development Tools and Practices for GNU Guile (en)

<p>Ever wondered what is so special about Lisp's REPLs? Curious how to debug your Guile project or write tests? Lost in all the tools and libraries and not sure which to use or how? We've got you covered.</p> <p>Today we will go through the fundamental tools needed for efficient Guile development. This will work for your personal Guix config, Guix itself, a new fancy Guile library, or Your Next Big Thing. We will go step by step from a simple project stub to a fully functional application covered with tests, and along the way we will learn about:</p> <ul> <li>REPLs and highly interactive development environments</li> <li>Ares/Arei Guile IDE</li> <li>How to deal with exceptions and stack traces</li> <li>Testing in the Scheme ecosystem and a new testing library, suitbl</li> <li>Whether tests and TDD work with the REPL</li> <li>Whether you need a debugger and how to use it</li> </ul> <p>Links:</p> <ul> <li><a href="https://www.gnu.org/software/guile/libraries/">Guile</a> and <a href="https://srfi.schemers.org/">SRFI</a> libraries</li> <li><a href="https://git.sr.ht/~abcdw/guile-ares-rs">Guile Ares</a> :: Guile IDE backend (suitbl library lives here)</li> <li><a href="https://git.sr.ht/~abcdw/emacs-arei">Arei</a> :: Emacs frontend for Guile IDE</li> <li><a href="https://trop.in">trop.in</a> :: Andrew Tropin's personal page and blog</li> </ul>

Guile development outside of Emacs (en)

<p>Those looking to get started with Scheme often find that they need to first learn Emacs. This is for good reason: pretty much all other editors have lacked the basic features to make Scheme a comfortable language to use. Over the past year, I've been developing my own VS Code extension to make programming Scheme without Emacs a reality. This talk explores what exists today, covering both my own extension, other tooling, and what's left for us to do as a community to make Scheme a first-class citizen in all editors.</p>

Wastrel: WebAssembly Without the Runtime (en)

<p><a href="https://codeberg.org/andywingo/wastrel">Wastrel</a> is a new ahead-of-time compiler from WebAssembly to native binaries. It has all the features, tail calls, garbage collection (via <a href="https://github.com/wingo/whippet">Whippet</a>), and exception handling included. In this talk we show how Wastrel can run on vanilla C programs compiled using the <a href="https://wasi.dev/">WASI</a> toolchain with best-in-class performance, as well as running Scheme programs compiled using <a href="https://codeberg.org/spritely/hoot">Hoot</a>. We discuss how Wastrel build on Hoot's WebAssembly support library and compare the speed of Scheme programs in the browser versus Wastrel versus native Guile.</p>

Lisp is clay: the power of composable DSLs (en)

<p><a href="https://en.wikipedia.org/wiki/Lisp_(programming_language)">Lisp</a> is often decried for being hard to read and having too little syntax. This talk argues that the parentheses are not the point, but the uniform structure is! Lisp is like clay: a medium which is versatile for building many shapes and sculpting beautiful new technical visions. Christine Lemmer-Webber makes an argument that lisp's power comes from composable DSLs, and that this power is what gives projects like <a href="https://guix.gnu.org/">Guix</a> and <a href="https://spritely.institute/">Spritely</a> much of their strength.</p>

Functional reactive programming with propagators (en)

<p>Functional reactive programming (FRP) is a declarative programming paradigm that is most commonly used in interactive applications where imperative, event-driven, callback-laden code quickly becomes overwhelming and difficult to reason about. The reduction in cognitive overhead comes at a price, however. Popular reactive systems are limited to one-way data flow (a directed acyclic graph) which limits the types of problems these systems can solve elegantly. Fortunately, a way to remove this limitation has been known for over 15 years! Alexey Radul's 2009 PhD thesis "Propagation Networks: A Flexible and Expressive Substrate for Computation" tells us how. In this talk, I'll use Guile Scheme to demonstrate how an FRP system built on the propagator model allows for cyclic dependencies without user-visible glitches whilst keeping implementation complexity low.</p>

Guix Container Images - and what you can do with them (en)

<p>This talk will describe work on creating and publishing Guix container images, and what you can do with them. Images are bootstrapped from Debian images and built on GitLab shared runners for amd64 and arm64, with ppc64el and riscv64 work in progress. The images are tested for regression, and automatically uploaded to the GitLab container registry and to Docker Hub. We will also talk about what these images can be used for, with examples of long-term reproducible tarball artifacts for official releases of GNU Libtasn1, InetUtils, Libidn2 and SASL. We will also go into limitations involving security trade-offs for reducing guix-daemon privileges, and the interaction between GitLab shared runners, user namespaces and other security complications.</p>

Language support in Meilisearch (en)

<p>Meilisearch (https://www.meilisearch.com/) is a popular Open-Source search engine written in Rust that boasts more than 50k stars on GitHub, focusing on performance and ease-of-use. Meilisearch is designed to be available worldwide, which requires supporting multiple languages through word tokenization. But, how difficult is it to segment and normalize words? And, how different this process can be depending on the Language?</p> <p>Meilisearch core maintainers share how they handled language support, the difficulties they faced, and the solution they found.</p>

Implementing Block-Max Pruning in Rust: Faster Learned Sparse Retrieval for Modern Search (en)

<p>Learned sparse retrieval models such as SPLADE, uniCOIL, and other transformer-based sparse encoders have become popular for delivering neural-level relevance while preserving the efficiency of inverted indexes. But these models also produce indexes with statistical properties radically different from classic BM25: longer queries, compressed vocabularies, and posting lists with unusual score distributions. As a result, traditional dynamic pruning algorithms like WAND and Block-Max WAND often fail to exploit their full potential.</p> <p>This talk presents Block-Max Pruning (BMP) from a systems and Rust-engineering perspective. We will walk through how BMP restructures query processing by partitioning document space into small, contiguous blocks and maintaining lightweight, on-the-fly score upper bounds that guide safe or approximate early termination.</p> <p>The talk is aimed at developers building retrieval engines, Rust-based data systems, or ML-powered search pipelines who want to push sparse retrieval performance further. Attendees will leave with a clear understanding of how BMP works, why learned sparse models require new pruning strategies, and how to integrate these ideas into modern, high-performance Rust codebases.</p> <p>Code and resources: BMP GitHub repository: https://github.com/pisa-engine/BMP/ Paper (SIGIR 2024): https://www.antoniomallia.it/uploads/SIGIR24.pdf</p>

Deriving Maximum Insight: Open-Source Graph-Enhanced RAG for Complex Question Answering (en)

<p>Traditional QA pipelines—even those using baseline RAG—struggle with complex reasoning tasks such as multi-hop inference, contradiction detection, entity linking, temporal consistency, and large-scale cross-document understanding. These limitations become critical in domains like investigative journalism, scientific research, and legal analysis, where answers depend on relationships spread across many documents rather than isolated text chunks.</p> <p>This talk will demonstrate how open-source knowledge-graph–based approaches can overcome these challenges by enabling structured retrieval, multi-hop reasoning, richer context assembly, and corpus-level summarization. We will explore several open-source frameworks used today to build graph-enhanced RAG systems and compare them across practical criteria: extraction quality, response latency, hardware requirements, maintenance complexity, and suitability for different problem types.</p> <p>Attendees will leave with a clear, practical understanding of how to select and apply graph-based RAG techniques to extract deeper insight from large unstructured datasets.</p> <p>Frameworks we're going to consider: - MS GraphRAG (MIT license) - https://github.com/microsoft/graphrag - LlamaIndex KG (MIT license) - https://github.com/run-llama/llama_index - KAG/OpenSPG (Apache-2.0 license) - https://github.com/OpenSPG/KAG</p>

OpenSearch v3: A New Era of Search Innovation - From Neural Sparse ANN to Agentic Workflows and everything in-between (en)

<p>OpenSearch v3 major release that was introduced in the past year represents a significant leap forward in open source search technology, delivering breakthrough innovations across neural search, AI-driven search experiences and performance optimization. This talk explores the major features that define the 3.x releases and their impact on modern search applications.</p> <p>We'll dive into differentiating capabilities like scalable Neural Sparse ANN Search using the SEISMIC algorithm, and the new Search Relevance Workbench for metric-driven relevance evaluation. Discover how system-generated Search Pipelines eliminate configuration overhead, automatically building Vector Search pipelines at query runtime and UI editor for AI Search workflow set up.</p> <p>The release brings industry-standard search features including MMR, ColBERT’s late interaction, RRF, radial search, and one of the most popular pre-trained spare encoder model in HuggingFace positioning OpenSearch alongside leading search platforms. Performance innovations deliver dramatic improvements: Memory-Optimized and Disk-based Vector Search with efficient FAISS execution, star-tree indexes for multi-field aggregations, 2x storage savings through derived source, and reader/writer separation for independent index/search scaling and resiliency. Real-time data processing enables continuous query execution for streaming results, and ability to build vector indices remotely using GPUs, while QueryInsights helps monitor cluster’s search query performance.</p> <p>Finally, we'll showcase Agentic Search capabilities—from Natural Language Agent Search to native AI agents with persistent memory, workflow UI editors for non-technical users to set up AI Search flows, and OpenSearch MCP integration with Claude code, Gemini CLI and other AI assistants to interact with OpenSearch.</p> <p>This is your opportunity to hear from the OpenSearch maintainers and ambassadors about the latest and greatest in the project. Attendees will leave understanding how OpenSearch v3 addresses the full spectrum of modern search challenges: Neural and Vector Search, Search quality measurement, performance at scale, and the future of AI-powered Search experiences.</p>

Multi-Vector embeddings revolution? or evolution? (en)

<p>What are multi-vector embeddings? How do they differ from regular embeddings? And how can you build an AI-powered OCR system in under 5 minutes without paying a fortune for infrastructure? If you're curious for answers, join me! I'll break down ColBERT embeddings, explore how MUVERA compression is revolutionizing the way we work with multi-vectors, and show you how to leverage it all to build an AI-powered OCR system on resource constrained devices such as Raspberry Pi.</p> <p>Weaviate DB: https://github.com/weaviate/weaviate Multi-Vector vision embeddings demo: https://github.com/antas-marcin/weaviate-multi-vector-example</p>

Multi-Stage Retrieval in Elasticsearch - Present and Future (en)

<p>Search in Elasticsearch keeps evolving, from traditional BM25 keyword retrieval to multi-stage search that combine lexical, vector, and language-model-driven intelligence. In this talk, we’ll explore how Elasticsearch APIs enable developers to build hybrid search systems that mix classical scoring, dense vector search and semantic reranking in a single coherent workflow.</p> <p>We’ll use ES|QL, Elasticsearch’s new query language, and show how constructs like FORK, FUSE, RERANK, COMPLETION, and full-text functions let you build multi-stage pipelines in a simple query.</p> <p>We’ll discuss where ML models and LLMs fit into the retrieval stack, from embedding generation to on-the-fly augmentation and semantic rerankers. </p> <p>Finally, we’ll look at future directions for search.</p> <p>If you want a practical and forward-looking view of how search is evolving in Elasticsearch—and how to put multi-stage retrieval to work—this session is for you.</p>

The state of Go (en)

<p>What is new since Go 1.25. In this talk we'll bring you up to date with all upcoming changes to the Go language and the community! Go 1.26 will be released in February 2026, we will be taking a look to all upcoming features as well as give an update on important changes in Go 1.235 This includes traditionally updates about the language, tooling, libraries, ports and most importantly the Go Community.</p>

Modularizing a 10-Year Monolith: The Architecture, the People, and the Pain (en)

<p>Most Go codebases begin as straightforward layered monoliths, but years of growth often turn those layers into a web of hidden coupling, unclear ownership, and hard-to-predict side effects. Small changes start requiring deep context, and compile and test times slowly creep up, turning routine work into risky work. Rewrites promise a clean slate but rarely succeed in practice. What the Go community lacks are real examples of large open source Go projects that have successfully evolved toward a modular monolith.</p> <p>This talk presents a major open source Go project in the middle of that evolution. It covers how we are moving from a decade-old layered architecture toward a modular design while continuing to ship features to multiple production environments that teams actively depend on every day. This is not theory. This is architectural change in a live system, with real contributors, long CI pipelines, social constraints, and legacy assumptions embedded throughout the code.</p> <p>What began as an investigation into slow build and test times exposed deeper problems: oversized packages, uncontrolled dependencies, unclear boundaries, and an architecture that no longer matched how engineers actually reasoned about the system. We walk through familiar pain points in large Go monoliths, including tight coupling, long feedback cycles, and frequent merge conflicts, and explain why these problems persist even in well-intentioned codebases. You’ll see where our early attempts stalled, how architectural changes regressed quietly over time, why good ideas alone were not enough, and how steady, incremental refactoring helped us regain control without freezing development. Architecture only works when people agree to carry it together.</p> <p>Whether you are working on a fast-growing Go project or maintaining a mature production system, this talk will give you concrete techniques and mental models for evolving your architecture safely. You’ll leave with a clearer understanding of how to introduce boundaries that hold, align ownership with code, and make a large system feel smaller, safer, and easier to change, so teams can move faster without needing to hold the entire system in their heads.</p>

Brewed for Speed: How Go’s Green Tea GC Works (en)

<p>Go’s runtime has always prided itself on efficient, low-latency garbage collection. But modern hardware brings new challenges. More cores, bigger caches, and heavier workloads. In this talk, we’ll start by exploring how Go’s current garbage collector and memory allocator work together to manage memory. Then we’ll dive into the new GreenTea GC, an experimental redesign that cleans memory in groups (“spans”) instead of object-by-object. You’ll learn how it works, why it matters, and what this “span-based” approach could mean for your Go programs in the future.</p> <p>I'll be exploring the Go source code: https://go.dev</p>

Inside Reflection (en)

<p>Reflection is a form of metaprogramming that often feels like magic — letting you inspect and manipulate your code at runtime. But there's no magic here at all — just clever engineering that makes your programs simpler and more flexible.</p> <p>In this talk, we'll take a look at how reflection actually works under the hood in Go. We'll explore how types and values are represented at runtime, what really happens when you call <code>reflect.ValueOf</code> or <code>reflect.TypeOf</code>, and how the compiler keeps this dynamic capability simple, yet powerful in its implementation.</p> <p>After this talk, reflection will look a little less mysterious — and a lot more elegant.</p>

Understanding Why Your CPU is Slow: Hardware Performance Insights with PerfGo (en)

<h2>The Problem</h2> <p>Go's pprof tells you <em>where</em> your CPU time is spent, but not <em>why</em> the CPU is slow. Is it cache misses? Branch mispredictions? These hardware-level performance characteristics are invisible to pprof but critical for optimisation.</p> <h2>The Solution</h2> <p>perf-go bridges this gap by leveraging Linux's <code>perf</code> tool and CPU Performance Monitoring Units (PMUs) to expose hardware performance counters for Go programs. It translates perf's low-level observations into pprof's familiar format, giving Go developers hardware insights without leaving their existing workflow.</p> <h2>What You'll Learn</h2> <p>In this talk, we'll: - Demonstrate the limitations of pprof for understanding performance bottlenecks - Show how perf-go exposes CPU cache behaviour, branch prediction, and memory access patterns - Walk through real benchmarks where we identify and fix cache-line contention issues - Explore how hardware counters can guide improvements that pprof alone wouldn't reveal</p> <h2>Target Audience</h2> <p>Go developers who want to optimise performance-critical code and understand the "why" behind their bottlenecks. Basic familiarity with profiling concepts helpful but not required.</p>

Concurrency + Testing = synctest (en)

<p>Go 1.25 introduced <code>testing/synctest</code>, a package that brings deterministic scheduling and control over concurrency during tests. For developers who struggle with flaky tests, hidden data races, or hard-to-reproduce timing issues, synctest offers a powerful solution: it lets you run concurrent code in a bubble, so you can efficiently explore interleavings, force edge cases, and prove correctness.</p> <p>In this talk, we’ll explore the motivation behind synctest, and dive into the testing patterns it enables. We’ll walk through practical examples of converting existing tests to use synctest. The session includes a demo illustrating how synctest can turn an intermittently failing test into a deterministic one, and surface bugs that traditional tests might miss.</p> <p>Whether you build concurrent systems, maintain production Go services, or simply want more reliable tests, this talk will give you a solid understanding of what synctest brings to Go—and how you can start using it today.</p>

gomodjail: library sandboxing for Go modules (en)

<p>Open source is under attack. Most notably the xz/liblzma backdoor incident (CVE-2024-3094) has shown how even trusted and widely adopted libraries can be compromised. Also, since February 2025, the Go language community has been observing an enormous amount of malicious Go modules being published with fake GitHub stars and very plausible contents.</p> <p>This session introduces gomodjail, an experimental tool that “jails” Go modules by applying syscall restrictions using seccomp and symbol tables, so as to mitigate potential supply chain attacks and other vulnerabilities. In other words, gomodjail provides a "container" engine for Go modules but in finer granularity than Docker containers, FreeBSD jails, etc.</p> <p>gomodjail focuses on simplicity; a security policy for gomodjail can be applied just by adding <code>// gomodjail:confined</code> comment to the <code>go.mod</code> file of the target program.</p> <p>The session will discuss its design, implementation details, limitations (e.g., support for modules that use "unsafe" pointers or reflections), and the plan to improve its robustness and performance.</p> <p>Repository: https://github.com/AkihiroSuda/gomodjail</p>

Resilient file uploading with Go (en)

<p>File uploads are a ubiquitous and fundamental part of modern applications. While simple at first, they become increasingly challenging as file sizes grow. Users expect reliable data transfers, even when uploading multi-gigabyte files over unreliable mobile networks.</p> <p>Conventional file uploads over HTTP fail unrecoverably when the underlying connection is interrupted. Resumable uploads, on the other hand, allow an application to continue uploading a file exactly where it left off. This preserves previously transferred data and greatly improves the user experience.</p> <p><a href="https://github.com/tus/tusd">Tusd</a> is an open-source file-upload server written in Go that makes it easy to add resumable uploads to any application - even those written in languages other than Go.</p> <p>This talk explores why Go is a natural fit for such use cases. In particular, we dive into how contexts help coordinate concurrent, long-running HTTP requests, how the net/http package provides fine-grained control over request handling, and how Go’s tooling assists in testing various failure scenarios.</p> <p>Additional links: - Tus homepage: https://tus.io/ - Tusd upload server: https://github.com/tus/tusd</p>

Profile-Guided Optimization (PGO) in Go: current state and challenges (en)

<p>Profile-Guided Optimization (PGO) is a well-known compiler optimization technique that brings runtime statistics about how an application is executed to the Ahead-of-Time (AoT) compilation model, which is quite recently added to the Go compiler. However, this technique is not widely used nowadays.</p> <p>In this talk, I want to discuss the current PGO state in the Go ecosystem. During my work on the <a href="https://github.com/zamazan4ik/awesome-pgo">Awesome PGO</a> project, I gathered a lot of interesting data points and insights about various PGO issues and discussed many related quirks with different stakeholders like end-users, maintainers, and application developers. We will talk about:</p> <ul> <li>PGO state across Go compilers</li> <li>PGO awareness across the Go industry</li> <li>PGO tooling issues</li> <li>Strengths and weaknesses of PGO modes for different use cases in real-world</li> <li>Top blockers for PGO adoption</li> <li>And many other things!</li> </ul> <p>I believe that after the talk more people will be aware of PGO, aware of usual PGO blockers, and know more about how to avoid these limitations in practice.</p> <p>Target audience: performance-oriented Go users and Go compiler engineers</p>

How to Instrument Go Without Changing a Single Line of Code (en)

<p>Zero-touch observability for Go is finally becoming real. In this talk, we’ll walk through the different strategies you can use to instrument Go applications <strong>without changing a single line of code</strong>, and what they cost you in terms of overhead, stability, and security.</p> <p>We’ll compare several concrete approaches and projects:</p> <ul> <li><strong>eBPF-based auto-instrumentation</strong>, using OpenTelemetry’s Go auto-instrumentation agent: </li> <li><a href="https://github.com/open-telemetry/opentelemetry-go-instrumentation">https://github.com/open-telemetry/opentelemetry-go-instrumentation</a> </li> <li><a href="https://opentelemetry.io/docs/zero-code/obi/">https://opentelemetry.io/docs/zero-code/obi/</a> </li> <li><strong>Compile-time manipulation</strong>, using tools that rewrite or augment Go binaries at build time, such as: </li> <li><a href="https://github.com/alibaba/opentelemetry-go-auto-instrumentation">https://github.com/alibaba/opentelemetry-go-auto-instrumentation</a> </li> <li><strong>Runtime techniques</strong>, including agents, shared-library injection, and binary trampolines, as used in OpenTelemetry’s Go “Autosdk” work: </li> <li><a href="https://opentelemetry.io/docs/zero-code/go/autosdk/">https://opentelemetry.io/docs/zero-code/go/autosdk/</a> </li> <li><strong>USDT (User Statically-Defined Tracing) probes</strong>, exploring how to add or generate USDT probe points for Go services (at build time or via injection) so that external tooling (eBPF, DTrace-style tools, etc.) can consume high-level events without source changes.</li> </ul> <p>Beyond what exists today, we’ll look at how ongoing work in the Go runtime and diagnostics ecosystem could unlock cleaner, safer hooks for future auto-instrumentation, including:</p> <ul> <li><code>runtime/trace</code> and diagnostics primitives: </li> <li><a href="https://pkg.go.dev/runtime/trace">https://pkg.go.dev/runtime/trace</a> </li> <li><a href="https://go.dev/doc/diagnostics">https://go.dev/doc/diagnostics</a> </li> <li>Proposals such as Go “flight recording” (Issue #63185): </li> <li><a href="https://github.com/golang/go/issues/63185">https://github.com/golang/go/issues/63185</a></li> </ul> <p>Throughout the talk, we’ll use <strong>benchmark results and small, realistic services</strong> to compare these strategies along three axes:</p> <ul> <li>Performance overhead (latency, allocations, CPU impact) </li> <li>Robustness and upgradeability across Go versions and container images </li> <li>Operational friction: rollout complexity, debugging, and failure modes</li> </ul> <p>Attendees will leave with a clear mental model of <strong>when to choose eBPF, compile-time rewriting, runtime injection, or USDT-based approaches</strong>, how OpenTelemetry’s Go auto-instrumentation fits into that picture, and where upcoming runtime features might take us next. The focus is strongly practical and open-source: everything shown will be reproducible using publicly available tooling in the Go and OpenTelemetry ecosystems.</p>

Making of GoDoctor: an MCP server for Go development (en)

<p>This session will explore the development of GoDoctor, a Model Context Protocol server designed to improve the experience of coding with AI agents. This is not a product presentation, GoDoctor is actually a playground to test different types of tools applied to coding with LLMs, and in this talk I will focus on the different experiments I made and reporting on both successes and failures. The ultimate goal is to understand what works and what doesn’t for improving code generation for Go projects.</p>

Systems Programming: Lessons from Building a Networking Stack for Microcontrollers (en)

<p>Developing Go for micocontrollers with 32kB of RAM requires a big shift in thinking, moreso if you are trying to get a complete networking stack with Ethernet, TCP/IP, HTTP to run on said device.</p> <p>Over the past years we've learned how to minimize memory usage and make programs run performantly on these small devices by adopting patterns common in the embedded industry, some of which make working with Go a even better experience than the norm.</p> <p>This talk explores the tried and tested "Embedded Go" programming patterns we've found to work and make developing in Go a pleasure, no matter the hardware context: - Avoiding pointers to structs within structs: rethinking the Configure() method - Zero-value programming - Eliminating heap allocations during runtime - Reusing slice capacity - Bounded memory growth on your program - Safe pointer-to-slice with generational index handles</p>

Extending sqlc: augmented generation of repositories in Go (en)

<p>This talk explores how to bridge sqlc (SQL-compiler)'s type-safe generated queries with a clean service architecture using Crush coding agent. It is open source and built entirely in Go.</p> <p>Sqlc generates strongly typed database access, but using its structs directly can couple business logic to schema details. Crush can automate the creation of repository layer on top of sqlc-generated artifacts. Repositories work with domain entities, orchestrate transactions while preserving compile-time type safety.</p> <p>In this talk, Crush leverages augmented generation (reference implementation + custom command or skills) to keep the produced code consistent and idiomatic. It also generates tests first, using testify/suite, testcontainers-go, gofakeit and go-cmp, then refines repositories code until tests pass.</p> <p>The result is a practical Go-based workflow that reduces boilerplate, ensures consistency across repositories, and demonstrates how open source LLM tooling can enhance real-world Go development — without sacrificing simplicity or type safety.</p>

My old trains have a second life, with TinyGo! (en)

<p>In the 1970s, model trains were a popular hobby. Thanks to low production costs, anyone could afford a small HO gauge layout. The system was simple: a train, a motor, 12V DC in the track, and off you go!</p> <p>Fifty years later, we took our trains out of the attic with a big idea in mind: to convert them to digital. With some Seeed Studio, Bluetooth, and TinyGo, we managed to get a functional railway network, were we can manage speed, direction, and lights of each train individually.</p>

Go Around The World Without Wires (en)

<p>In this next edition of the "Go Wireless" saga, we will take Go to new heights...</p>

Go Lightning Talks (en)

<p>Come speak! As every edition the last hour of the Go Devroom will be open for 5 minute lightning talks. The CfP for this will open shortly before the event and close 90 minutes before the session starts.</p>

Welcome to the Community Devroom! (en)

<p>The Community Devroom co-organizers will welcome attendees and give an overview of the day’s sessions.</p>

There are No Adults in the Room: Learning how to Grow Up as a Team (en)

<p><strong><em>What happens when your project grows up faster than you do?</em></strong></p> <p>The dynamics of the FOSS world allow for young and passionate developers to make real, lasting contributions; sometimes in places where they would otherwise never be taken seriously. As <a href="https://www.theregister.com/2022/10/26/rolling_rhino_reboot"><em>The Register</em> put it</a>, Rhino Linux was started by a "<em>teen dream team</em>". We had a bold, fast-paced start that threw us headfirst into the world of Linux maintainership. But while we shared the common goal of 'growing and improving' the distribution, our individual visions often diverged.</p> <p>Being taken seriously has its burdens, too. It's easy to get in over your head - to lose direction, burn out, or stop communicating altogether - especially when there are no adults in the room to offer guidance. We banded together by chance, and had to discover our own limits through trial and error. Saying '<em>no</em>' isn't easy, especially under the internal pressure to keep delivering at a steady pace, when everyone is deeply passionate about the project.</p> <p>FOSS is no stranger to ever-shifting team dynamics, or to developers biting off more than they can chew; challenges that are only accentuated when all involved are still growing up. It's easy to lose sight of when to step back, and when to recognize the need to scale. As we have come to learn, if you want to be a systems maintainer, you need to maintain your own systems, too.</p> <p>Join us as we retrace the human side of <a href="https://rhinolinux.org">Rhino Linux</a> - how we learned to build a team as young developers, what this project taught us about maturity, communication, and sustainability, and the lessons we hope others like us can take from our journey.</p>

Accessible Sovereignty: Why the Four Freedoms Depend on Inclusion (en)

<p>The four essential freedoms defined by the Free Software Foundation — freedom 0: the freedom to run the software; freedom 1: the freedom to study and change it; freedom 2: the freedom to redistribute; freedom 3: the freedom to distribute modified versions — are widely cited as the foundation of free software. https://www.gnu.org/philosophy/free-sw.en.html#four-freedoms</p> <p>But what does “freedom” mean when people with disabilities cannot meaningfully use, extend, and share software? Digital sovereignty is hollow unless the tools and communities respect accessibility. If a user interface or workflow excludes a segment of users, then the right to “run” or “modify” the software is in practice restricted.</p> <p>This talk argues that accessibility (in code, UI, documentation, communities) is not an optional add-on — it is essential for the exercise of the four freedoms, and thus for true digital sovereignty. We will explore how CMS projects can embed accessibility into their governance, workflows and contributions so that every user can exercise the freedoms of use, study, share and collaborate.</p> <p>It is great to see GitHub making significant efforts to improve their accessibility, and that of the tools that they give to the community. https://accessibility.github.com/</p> <p>https://github.blog/open-source/social-impact/our-pledge-to-help-improve-the-accessibility-of-open-source-software-at-scale/</p> <p>We will cover: • How exclusion of users with disabilities limits freedom of software use and modification. • The link between accessibility and community inclusivity: if you cannot participate fully, you cannot help shape the software. • Practical steps for CMS ecosystems (Drupal, WordPress, etc) to make accessibility a governance norm rather than a compliance afterthought. • A call to action: build tools, policies and default workflows so that accessibility becomes part of the infrastructure of freedom.</p>

Neurodiversity in tech: how to build, mentor and motivate every mind (en)

<p>Open source communities thrive when every contributors can participate fully and safely. Neurodivergent contributors bring unique strengths such as pattern detection, hyperfocus, creativity, and non-linear problem-solving. But they also face invisible barriers that can limit their access and growth. This talk explores practical scenarios for fostering neuroinclusive communities from onboarding and mentorship to culture-building and leadership. Attendees will leave with lessons they can apply in their teams, projects, and meetups and welcome every mind within their communities.</p>

Companies vs. Foundations: Who Should Steer Your Open Source Project? (en)

<p>In the last several years, a number of open source companies have attracted significant attention after announcing license changes. Not surprisingly, these shifts sparked backlash from open source enthusiasts, prompting some to create community-driven forks under open source foundations.</p> <p>Now there is growing skepticism toward (single) company backed open source projects, with many arguing that open source projects should be run by neutral foundations to prevent future bait-and-switch tactics. But is foundation backing really the answer?</p> <p>Drawing on over a decade of experience in both open source foundations and companies, Fatih and Ray will compare foundation-backed and company-backed projects across key areas such as governance, roadmap planning, community, and funding. They’ll explore real-world examples of successful—and not-so-successful—projects in both models.</p> <p>Finally, Fatih and Ray will discuss why funding models should be just one of several factors in assessing the long-term viability of open source projects. They’ll offer a holistic approach for evaluating open source projects, helping developers and decision-makers make informed choices about which projects to adopt, support, or contribute to.</p>

A decade of lessons from Apache Incubator release votes (en)

<p>Ten years, 1,600 release votes, and a clear lesson: open collaboration works. Discover how Apache Incubator projects turned release reviews from rule-checking into mentoring, and what this decade of data reveals about building healthier open source communities. Description: What can we learn from a decade of release votes in open source communities? From 2015 to 2025, over 1,600 Apache Incubator release vote threads showed how project collaboration and growth have changed. In this talk, I’ll share practical lessons from analysing votes across more than 160 projects. You’ll see how better documentation, mentoring, and automation changed a stressful compliance process into a positive learning experience. You’ll learn about the changes: fewer rejections, quicker reviews, and a shift from a strict to a more collaborative tone. I’ll also discuss how release cadence reflects community health and what early warning signs to watch for before a project slows down. Whether you’re a maintainer, mentor, or contributor, you’ll come away with ideas to improve release workflows and help build stronger, more confident communities.</p>

Downstream Mindset vs Upstream Communities (en)

<p>As open source became mainstream, companies started to allow or even encourage their employees to get involved upstream and even started to open source their projects. Having more people being paid to work on open source software sounds great at first. However, when people don’t get the education and support to integrate upstream work and mindset into their daily work the open source projects, and eventually the boarder ecosystem, suffer.</p> <p>This phenomenon affects everyone from single-vendor projects to diverse communities, and from small projects to large communities, and eventually contributes to maintainer shortage and burnout. Addressing this is the responsibility of both individuals and corporations. So, where should they start?</p> <p>This presentation will outline the different ways how corporate mindset and priorities harm open source projects today, including tasks and responsibilities in open source projects that fall short and obstacles that maintainers face on a daily basis. Attendees will learn what individuals can do to improve their own and their communities’ experience. Last, but not least, the talk will provide tools to educate employers about why and how maintaining key open source dependencies is strategic for a successful business strategy.</p>

The CRA isn't coming for your open source community (en)

<p>Many open source contributors, maintainers, and communities are anxious about the Cyber Resilience Act (CRA) and its potential impact on open source. It’s easy to feel that these obligations aimed at commercial vendors will somehow end up falling on volunteer maintainers, community projects, and the broader open source ecosystem. But that's not the whole story.</p> <p>Thanks to strong, coordinated advocacy from the community, the European Commission actually understands the open source ecosystem far better than many believe. The CRA not only clarifies where responsibility lies—squarely on the vendors who profit from open-source components, as it should—but also introduces meaningful tools to improve sustainability, including the new attestation program, which has real potential to channel support back into the ecosystem.</p> <p>A well-designed law, however, doesn’t mean there will be no impact.</p> <p>Drawing on direct involvement in the CRA implementation process through the ORC WG and the CRA Expert Group, Tobie will walk through how these changes will affect open source communities in practice, why the underlying structure of the CRA makes sense, and how the open source communities can position themselves to benefit from it if they so wish to deliver more secure software more sustainably.</p>

The Synthetic Senior: Rethinking Free Software Mentorship in the AI Era (en)

<p>AI-assisted contributors can now produce patches that appear senior at first glance: fast, polished, and surprisingly complex. But many of these contributions arrive without the context, intent, or architectural understanding that maintainers rely on during review. This emerging pattern — the rise of the “Synthetic Senior” — is reshaping expectations around mentorship, review culture, and long-term project sustainability.</p> <p>Maintainers face a growing dilemma: welcoming new contributors while navigating an influx of high-volume, low-context PRs that demand deep review time. Traditional mentorship doesn't scale to this volume, and without new guardrails, it’s a recipe for burnout. While platforms, including GitHub, iterate on systemic solutions to filter this noise, communities need immediate, practical strategies to protect their maintainers today.</p> <p>Drawing on discussions with seasoned maintainers and data from AI tooling pilots across open source foundations, this talk offers community-centered strategies for adapting to the AI era without losing what makes FOSS resilient. We’ll explore:</p> <ul> <li><strong>Demonstrating comprehension:</strong> Contribution workflows that encourage understanding rather than pure generation, helping contributors show they can maintain what they propose. </li> <li><strong>Helpful friction:</strong> How small, intentional barriers can surface genuine contributors and reduce maintainer fatigue. </li> <li><strong>Self-serve onboarding:</strong> Using automation and pre-flight checks to move the first-pass review back to contributors. </li> <li><strong>Healthy boundaries:</strong> Re-establishing norms around closing contributions that lack necessary context, while keeping the door open for genuine contributors.</li> </ul> <p>This session isn’t about banning AI. It is about building the guardrails that protect human mentorship and keep free software communities healthy.</p>

From Gatekeepers to Partners: How Developer Relations Transforms Security Tool Adoption (en)

<p>Security tools don’t always fail to catch on because the tech is flawed. They more likely fail because the human connection is missing. When developers are treated like compliance checkers instead of collaborators, the result is frustration, pushback, and ultimately, insecure software.</p> <p>This talk invites security folks to move from gatekeeping to enablement, and makes the case that the missing ingredient isn’t better code, it’s better relationships.</p> <p>Developer Relations can be the spark that turns security tools from roadblocks into superpowers. By meeting developers where they are, offering context instead of noise, and partnering rather than policing, DevRel brings security into the conversation early and often, raising adoption rates and strengthening security across the open source ecosystem.</p>

From Vibrant to Silent: Has the Community Lost Its Voice? (en)

<p>Has the once vibrant and much-loved cloud-native community lost its spark? What was once an ecosystem fueled by collaboration and curiosity now feels increasingly defined by Slack channels, swag drops, and conference booths.</p> <p>Despite an explosion of meetups, and events, audiences are thinning. Community fatigue is real and vendor influence often overshadows genuine grassroots participation.</p> <p>Contribution activity has slowed, and several once-thriving open-source projects are experiencing a contributor drought. End-user organizations and sponsors that once championed community contributions are now scaling back, leaving critical projects struggling to sustain.</p> <p>This talk takes a candid look at the past, present, and possible future of the open source community. Through data and insights from a few popular OSS projects we’ll explore the patterns behind this shift and what it means for the sustainability of open collaboration in the years ahead.</p>

Headscale & Tailscale: The complementary open source clone (en)

<p>Headscale began as a learning project to work out “what was needed” to re-implement a Tailscale control server and unexpectedly exploded in popularity in the self-hosted and open source community as a home-labbers alternative to Tailscale. </p> <p>Headscale has a vibrant community, about 6000 members in our Discord community and our Github repo has more stars than Tailscale’s open source client, but who's counting. </p> <p>Three years ago I was hired as a member of technical staff at Tailscale, spending half of my time contributing and driving Headscale, ensuring the future of the project. </p> <p>Headscale is a clone of Tailscale’s closed-source SaaS control plane, and it would be easy to consider it a competitor. Tailscale supporting Headscale this way is an unusual arrangement and sometimes raises eyebrows with "the internet". </p> <p>It turns out that letting Headscale be autonomous and trusting it to run its own community complements Tailscale in a variety of ways. It helps people stay in the ecosystem. Homelabbers and self-hosted will use it at home, but bring Tailscale to work. Sometimes it even solves problems Tailscale can not.</p> <p>Of course, it has not only been smooth sailing, and being a paid contributor has caused a lot of skepticism with some users fearing an “embrace, extend, extinguish” strategy, fueling conspiracy theories about our roadmap.</p> <p>In this talk, I will share how the projects exist in symbiosis, the challenges of being a paid contributor, and how the stability of a corporate payroll has enabled Headscale to reach its current scale.</p>

How the OpenSSL community was built on Heartbleed (en)

<p>Before April 2014, <a href="https://openssl-library.org/">OpenSSL</a> was a backwater open source project with fewer than 10 regular contributors and 1 1/2 maintainers. Meanwhile its code had become a pillar of secure communication and data privacy in the industry. This was an unstable situation that was exposed when the <a href="https://en.wikipedia.org/wiki/Heartbleed">Heartbleed bug</a> became global news.</p> <p>The way the OpenSSL project responded to this crisis was informed by the principles of open source. Jon Ericson, the Community Manager for the <a href="https://openssl-foundation.org/">OpenSSL Foundation</a>, explains how a security bug ignited community growth and how the open source community provides ongoing stability to the OpenSSL project.</p>

What happens if someone breaks the rules? (en)

<p>Nearly every tech event has a Code of Conduct these days, but too often it’s treated as boilerplate, or as a box to tick. But what happens when someone breaks it? Like incident response, success depends on rehearsal, not documentation.</p> <p>In this talk we’ll share practical lessons from over a decade of experience running events like DevOpsDays, Cloud Native Days and PostgreSQL conferences. How to set the stage for a safe event, talk through potential incidents, and what conversations will need to be had with different stakeholders.</p> <p>Most importantly, it’s hard to build trust, but easy to lose trust. We will cover how to openly and iteratively develop your community’s Code of Conduct.</p>

Self-Raising Lazarus: All Contributors and how Open Source can Rise Again (en)

<p><a href="https://allcontributors.org/">All Contributors</a> is a project which helps us recognise all the types of contributions that build our open source communities and make them flourish. It defines a specification for acknowledging community members' work, whatever they contribute, as well as tools for easy management and presentation of this information. All Contributors is used by a wide range of communities, particularly those where key contributors are not well recognised by metrics more easily extracted from version control history.</p> <p>Recently these communities noticed signs of poor health in All Contributors. When the website went offline, a group of users were <a href="https://github.com/orgs/the-turing-way/discussions/4245">catalysed in to action</a>. Coordinated by <a href="https://www.leahwasser.com/">Leah Wasser</a> (pyOpenSci Executive Director &amp; Founder, PSF Fellow) they committed to adopting the project and forming a new, sustainable team of maintainers.</p> <p>With the context of All Contributors, I will tell a story of the decline and rise of an open source project. There will be a scattering of challenges maintainers face such as, burnout, technical debt, and lottery factor. However, it is also a hopeful story about how open source software can play critical roles, cultivate deep affection from its users, and, with community support, rise again.</p>

Building on Success: Sustainability of Open Source (en)

<p>Open source is suffering from its own success. Our community solved problems with minimal attention from the rest of the world for almost 30 years, slowly becoming the foundation of nearly every piece of software critical to everyday life. Now with increasing regulation around the world, evolving cybersecurity requirements, and changing corporate participation and funding, how do we ensure the ecosystem's continued success? The things that have worked for the first decades will not be the things that keep us going. We will look at sustainability not only as a funding problem, but also from the perspectives of global policy movement, security, and other intertwined issues that face open source in the coming years.</p>

Burnout in Open Source: A Structural Problem We Can Fix Together (en)

<p>I'm a psychology researcher that has been moved by the extent of burnout in Open Source, and I've written what I believe to be the most comprehensive report to date on burnout among OSS developers. I reviewed the academic literature, conducted a qualitative analysis of online discussion in the OSS community, and interviewed OSS developers. I identified 6 factors that contribute to developer burnout: difficulty getting paid, workload and time commitment, maintenance work as unrewarding, toxic community behaviour, hyper-responsibility and pressure to prove oneself. I recommend 4 structural changes to address developer burnout: pay OSS developers, foster a culture of recognition and respect, grow the community and advocate for maintainers.</p>

The AI Shockwave in Open Source Communities: How AI Is Reshaping the Foundations of Open Source Communities (en)

<p>Open source communities depend on a steady influx of newcomers who ask questions, seek help, and build relationships. Future heroes have to start somewhere as newbies. But across the ecosystem, those early engagement signals are dropping—sometimes sharply. Generative AI is changing how people learn, troubleshoot, and participate.</p> <p>This talk synthesizes new research and real-world data to explore how AI is reshaping contributor pipelines—and what open source projects can do to adapt before downstream participation suffers.</p>

Backtraces for embedded Linux C and C++ programs (en)

<p>When a Python program crashes, a backtrace is printed — often enough to pinpoint and fix the issue. When a C or C++ program crashes on an embedded Linux system, however, nothing appears by default — except perhaps the dreaded “Segmentation fault” message. Unfortunately, there’s no simple --enable-backtrace option to enable human-readable backtraces at build time. Even worse, generating useful backtraces involves many subtle factors, and there’s no comprehensive resource that explains how to get them right.</p> <p>This lack of clear information arises because backtraces depend on numerous variables: your hardware architecture, operating system, distribution, compiler, build configuration, and the specific tools used to unwind the stack.</p> <p>In this talk, I’ll demystify how backtraces actually work and explore the key concepts behind them. I’ll also show how to leverage libunwind and minidebuginfo to obtain reliable backtraces on ARMv7 and ARMv8 systems, within the context of a Yocto-based embedded Linux distribution.</p>

From C to Rust on the ESP32: A Developer’s Journey into no_std (en)

<p>Rust is rapidly reshaping how we build reliable software — including in areas once dominated by C. But what does it really look like to bring Rust into an existing embedded codebase? This talk shares the hands-on experience of migrating a working ESP32 firmware from C to no_std Rust, highlighting what Rust changes, what it improves, and where the bumps in the road are.</p> <p>Starting from a hobby project — a wireless arcade button used in a multiplayer blind test game (https://github.com/neon-beat) — we will explore the practical steps of developing Rust firmware on the ESP32, from toolchain setup and hardware abstraction to system architecture and debugging strategies. Along the way, we’ll discuss the key differences from traditional Rust development, the challenges faced in a no_std environment, and how the embedded Rust ecosystem and community helped the project move forward.</p> <p>Whether you’re an embedded developer curious about Rust, someone evaluating the risks and benefits of adopting it in production, or simply interested in real-world migration stories, this talk aims to provide actionable insights, lessons learned, and a realistic view of what transitioning from C to Rust on micro controllers really looks like.</p>

Ariel OS - The Embedded Rust Software Stack for Microcontroller-based Internet of Things (en)

<p>Ariel OS is a new RTOS for microcontrollers written fully in Rust. It supports popular hardware architectures (Cortex-M, ESP, RISC-V) and popular boards from vendors such as Espressif, Nordic, Raspberry Pi and ST. Ariel OS is built on top of Embassy and the embedded-hal traits, adding various OS functionalities and a multi-core capable scheduler. Ariel OS further aims to integrate the best of the available embedded Rust ecosystem to provide a seamless, batteries-included experience for microcontroller firmware development. Ariel OS is open source with dual Apache 2.0 / MIT license, available on GitHub</p> <p>In this talk we demonstrate how easy it is to use Ariel OS on microcontroller-based hardware and how the different features help to quickly get a project up and running. We overview the OS and walk through creating a firmware for a common board, thus showcasing the features that make Ariel OS development unique and appealing</p> <ul> <li>https://www.ariel-os.org</li> <li>https://github.com/ariel-os/ariel-os/</li> <li>https://ariel-os.github.io/ariel-os/dev/docs/book/</li> <li>https://embassy.dev/</li> <li>https://github.com/rust-embedded/embedded-hal</li> </ul>

The Ultimate Office Chair: Hacking a BMW Comfort Seat with an ESP32 (en)

<p>What happens when you mix German luxury engineering with a bit of DIY spirit? You get the world’s most over-engineered office chair.</p> <p>This talk dives inside a BMW comfort seat — so when you get home in your 7-series, you can feel right at home in the same seat at your desk. Packed with ECUs, motors, pumps, heaters, ambient lighting and airbags, we’ll explore how it all works, how the seat communicates over CAN, j1850 CRCs, some quirks, and how an ESP32 can take control of everything from massage and lumbar support to heating and cooling, obviously all hooked up to homeassistant.</p> <p>The hope is that this talk will inspire others to reuse car parts in interesting and wonderful ways. We'll also discuss slightly easier things like integrating an idrive controller or gearshifter which are much more common but rarely explained in detail how and why they work the way they do compared to a more complex device like a seat.</p>

Build Once, Trust Always: Single-Image Secure Boot with barebox (en)

<p>Secure-boot projects often end up with a zoo of nearly-identical bootloader images for development, factory, and field use with each variant adding more risk.</p> <p>This showcase illustrates how to avoid this entirely: one bootloader image that adapts securely to each lifecycle stage using fuse-based state transitions, device-bound unlock tokens, and policy-driven access control.</p> <p>With barebox and OP-TEE, we’ll show how these mechanisms enforce secure operation while still allowing controlled debugging and recovery, without ever maintaining multiple images.</p>

ARM SCP firmware porting (en)

<p>Contemporary embedded SoCs increasingly act as a network of specialized CPU cores, some dedicated to user applications, other dedicated to real time tasks, others to security. All those cores still share one set of critical peripherals, which require resource access coordination. This is increasingly implemented by making all cores talk to a dedicated core called SCP, the System Control Processor, using SCMI protocol. The SCP is responsible for coordinating access to critical resources, clock, reset, power domain, and so on. An open source firmware, SCP-firmware, can be used on the SCP to offer the SCMI services. This talk explains how to implement a port of SCP-firmware to an SCP core, what is the architecture of SCP-firmware, its initialization process, its driver or module model, how the ordering of module start up is achieved, how to implement UART and mailbox driver modules, and finally how SCMI server services are bound to modules and exposed to other cores. This is illustrated by an example code from existing SCP-firmware port to contemporary SoC.</p> <p>LINKS: - ARM SCP firmware https://gitlab.arm.com/firmware/SCP-firmware - SCMI specification v4.0 https://developer.arm.com/documentation/den0056/f</p>

Tamper-resistant factory data from the bootloader (en)

<p>Secure-boot chains in embedded systems have largely converged on common building blocks like FIT, dm-verity or UKIs.</p> <p>The bootloader is anchored in hardware trust, then verifies an operating system image, and the chain continues, eventually covering the application.</p> <p>But there is a gap when it comes to adding unit-specific bits of information, such as per-device configuration, hardware calibration, or MAC addresses needed early in boot.</p> <p>In this segment, I present the TLV framework recently added to the barebox bootloader, to which I contributed signature support. It allows device-specific key-value pairs to become part of the secure-boot chain from early on, providing the system with authenticated, replay-protected per-unit data.</p> <p>This short presentation discusses - factory data and its relevance to a secure-boot chain - the barebox implementation using a signed Tag-Length-Value format - when and how to prevent interchange of TLV blobs across units - integration of the new feature</p>

Snagboot: vendor-agnostic, open-source and developer-friendly recovery and reflashing tool (en)

<p>Most modern embedded SoCs provide a ROM-based recovery mechanism to bootstrap an unflashed device or revive a system whose bootloader has failed. Unfortunately, these mechanisms are typically vendor-specific, poorly documented, and supported only non-standard, sometimes closed, tools. Engineers end up juggling different utilities for each SoC family, with varying user interfaces and commands.</p> <p>Snagboot addresses this fragmentation. It is a vendor-agnostic, fully open-source recovery and reflashing tool written in Python, with support for TI, NXP, Microchip, ST, Broadcom, Amlogic, and Xilinx platforms (and Rockchip on the way). Through its components snagrecover, snagflash, and snagfactory, Snagboot offers a unified workflow for recovery, reflashing, and factory programming. This talk will give a concise introduction to how Snagboot works and where it fits in the bring-up and manufacturing process.</p>

sbom-cve-check: Lightweight open-source CVE analysis tool for your embedded systems (en)

<p>With embedded devices now everywhere, from home appliances to industrial systems, it is vital to regularly check them for CVEs so that any known vulnerabilities in software components can be identified and addressed before they lead to security risks.</p> <p>Regularly monitoring these CVEs will be mandatory in various cases to comply with the EU Cyber Resilience Act (CRA), which pushes the industry toward more accountable and proactive security in embedded systems.</p> <p>We present <strong>sbom-cve-check</strong>: a new automated vulnerability-analysis tool based on an SBOM, without requiring access to the original build systems. The SBOM is initially obtained from build systems such as Yocto or Buildroot.</p> <p><strong>sbom-cve-check</strong> supports SBOMs in SPDX2 or SPDX3 formats, and CycloneDX compatibility is planned. The tool aims to be an efficient replacement for the cve-check logic currently available in Yocto. It pulls from several databases, including NVD and the CVE List, and supports multiple annotation formats such as OpenVEX and Yocto’s custom format. <strong>sbom-cve-check</strong> currently supports the following export formats: SPDX3, CSV, and Yocto’s cve-check output format.</p> <p>The tool is provided under the GPLv2 license, and contributions are of course welcome :)</p>

Longer-Term Support releases for Buildroot (en)

<p>Last year, Buildroot, the embedded Linux image build system, extended its Long-Term Support (LTS) release channel to three years, up from one year previously. This has been made possible through the Buildroot LTS Sponsorship program, which funds developer time for ongoing open-source maintenance rather than relying solely on maintainers' free time.</p> <p>In this talk, we will walk through the Buildroot contribution and release process, and explain how LTS branches are maintained. We will discuss: - When and why should you use a Buildroot LTS release ? - What can you expect from LTS releases ? - How the “LTS stewards” coordinate, analyze security issues and collaborate with upstream Buildroot maintainers - The challenges and lessons learned during the first year of the program - How to submit your contributions so they can be easily integrated in LTS releases - Why should you or your company sponsor the LTS program ?</p>

Illuminating the Frame: Enhancing Flash Control in V4L2 (en)

<p>Beyond mobile use cases, flash control is increasingly important in industrial imaging applications. Precise timing is essential for tasks such as barcode scanning and machine vision. However, controlling camera flashes in embedded Linux systems has long been (and still is) a hardware-specific challenge that is often only supported by the downstream drivers.</p> <p>This talk presents the current efforts to improve flash and strobe control in the Linux kernel, with a focus on the V4L2 subsystem. It begins with an overview of flash timing concepts and their key components, followed by an introduction to the existing V4L2 controls and the latest extensions under development. These enhancements aim to standardize flash behavior across platforms and pave the way for a clean and robust user-space integration.</p>

libcamera software ISP status update (en)

<p>Many recent Windows (on ARM and x86) laptops have replaced the standard UVC USB camera module with a raw MIPI camera-sensor using a CSI receiver and ISP in the CPU to process the raw data into an image (and on smartphones this has been the norm for ages).</p> <p>Supporting these cameras under Linux is an ongoing challenge. At FOSDEM 2024 a solution using a software ISP running on the CPU was presented as a solution to get these cameras to work with a fully opensource stack.</p> <p>This talk will look at where we are at now, 2 years later, highlights:</p> <ul> <li>GPU acceleration</li> <li>FOSS sensor calibration setup and color correction using CCMs</li> <li>Lens shade correction</li> <li>Linux distributions shipping softISP MIPI camera support OOTB</li> </ul>

Raw to Real and Green to Great: Open Source Camera Tuning for Linux Devices with libcamera (en)

<p>When you first power up a new camera sensor, the images often look green, noisy, and far from realistic. Getting from that raw output to a natural, high-quality image is a complex process known as camera tuning, and until recently, it’s been an opaque and proprietary part of the imaging pipeline.</p> <p>This talk introduces the fundamentals of open source camera bring-up and tuning, using tooling provided by the libcamera project to illustrate the process. Through real examples, we’ll look at what early images from a new sensor look like, and how they improve through calibration and tuning steps. We’ll cover the basic equipment and workflow needed to get started, and highlight community efforts to create an open repository of tuning data for phones, laptops, tablets, and embedded libcamera powered Linux devices.</p>

No Line Like Mainline: Update On The Fully Mainline Software Stack For Rockchip SoCs (en)

<p>Users wanting to run mainline Linux on ARM64 often face a familiar set of trade-offs: the hardware is too expensive, hard to find, outdated, or doesn’t support mainline at all. But this is starting to change, and Rockchip is one of the SoC vendors hitting the sweet spot.</p> <p>Find out why Rockchip hardware, and Rockchip as a company, has been doing particularly well when it comes to mainline Linux support. This talk provides an overview of the available Rockchip hardware and the current state of the mainline software landscape around them. We will then highlight what the community has sucessfully upstreamed in 2025, and look at what's still baking in the developers' ovens.</p> <p>The talk assumes the audience is already convinced that using the mainline kernel rather than vendor BSPs is the way to go. Beyond that, both veteran kernel hackers who are curious about hardware they're unfamiliar with, as well as people looking to get their feet wet in Linux kernel development, are welcome to attend.</p>

Add Support for New Boards to Mainline Linux, U-Boot and Yocto (en)

<p>In the course of the past months, Michael has added or expanded support for new ARM and RISC-V boards to the Linux kernel (6.19+), to Yocto BSP layers and hopefully before FOSDEM 2026, to the U-Boot bootloader.</p> <p>This turned out to be much easier than expected, thanks to the availability of device drivers for most hardware blocks, and thanks to the possibility to reuse code (especially Device Tree) for already supported boards.</p> <p>So, if you have hardware sitting idle or working suboptimally because of quick and dirty vendor kernels and BSPs, join this talk and learn how to let the mainline Linux kernel, U-Boot and appropriate Yocto Project layer fully support your board. This should enable other contributors to get involved, and make it much easier for community projects to adopt such hardware too.</p>

The Year in Embedded Security (en)

<p>The embedded ecosystem is evolving rapidly, and keeping track of the most important developments has become increasingly difficult, especially outside of our current main interests. Over the past year,there have been important changes in the state of regulation, cryptography, tooling and software supply chain practices. In this talk, Marta will present a curated overview of the key trends that marked the year across both Linux and RTOS-based platforms.</p> <p>The session will highlight the impact of the EU Cyber Resilience Act on embedded development, recent progress in post-quantum cryptography, the growing influence of AI-assisted tooling, and notable changes in compilers and hardening features. It will also cover the state of vulnerability reporting, examples of high-impact security issues affecting embedded systems, and the maintainership challenges that arise as long-standing maintainers get closer to reaching retirement.</p> <p>All topics will be supported with concrete references to articles, software releases and conference talks, giving attendees a clear and actionable picture of where embedded security is heading and what to pay attention to in the coming year.</p>

Pixel on life-support, upgrading from Android 12 to Android 16 (en)

<p>For those who care about software upgrades, Android phones have long been sold with two to three years of software support at best. This situation left a lot of devices running an out-of-date system, with the consequence of exposing users to security issues and premature obsolescence.</p> <p>This presentation takes the case of the Google Pixel 4a (and a couple of other old Pixel phones) to discuss the issue and to show how it has been updated from Android 13 to Android 16 successfully, using Evolution X custom ROM project, thus extending the device lifetime beyond what was commercially offered by the manufacturer.</p>

MicroPythonOS: the best of Android, now on Microcontrollers. AppStore, OTA Updates, Touch Screen, Camera and much more! (en)

<p>MicroPythonOS is the first modern graphical operating system that's addressing the need for a complete, out-of-the-box OS for resource-constrained hardware such as microcontrollers.</p> <p>It takes heavy inspiration from Android and iOS, with an easy to use appstore, a beautiful LVGL-based touchscreen and button UI with lots of widgets, gestures, theme support, wifi manager and over-the-air updates.</p> <p>The software stack is fully open-source. This openness stands in contrast to the increasingly restrictive policies of traditional mobile ecosystems, which are increasingly becoming a walled-garden with tight controls on app distribution, content, and monetization.</p> <p>The OS currently targets the ESP32 family, but it can run on anything that supports MicroPython, including the RP2350. It can also run as a regular desktop application, fullscreen or windowed, which makes app development super short cycle, and debugging much easier.</p> <p>Hardware support currently includes WiFi, Bluetooth, many Intertial Measurement Units, Camera's, Touch Screens, IO Expanders, Displays, as well as low-level ADC pins, GPIO pins, I2C chips etc.</p>

Fluorite - console-grade game engine in Flutter (en)

<p>Fluorite is a new open-source 3D game engine built in Flutter. It allows developers to leverage the Flutter &amp; Dart ecosystem to write game logic, and to integrate it with Flutter’s rich UI toolkit to build stunning interactive experiences across the board.</p> <p>At the same time, all the complexity is hidden away behind its highly-efficient C++ ECS core, ensuring performance and portability across mobile, desktop, embedded and console platforms.</p> <p>By integrating Filament, Google’s 3D rendering engine, Fluorite delivers best-in-class PBR rendering performance and quality, enabling high-fidelity creative workflows.</p> <p>In this intermediate-level session for Flutter and game developers, we will demonstrate Fluorite's tech demos and the code behind them, as well as illustrate how to set up 3D scenes and assets, and leverage Flutter widgets in your game UI. We’ll compare Fluorite’s approach against existing solutions, highlighting how its Dart-first architecture streamlines iteration with Hot Reload, multi-platform support, Widget Inspector, and the full pub.dev ecosystem.</p>

Welcome to the SBOMs and Supply Chains devroom! (en)

<p>Welcome to another year of the SBOM devroom, now also including more general Supply Chain topics!</p> <p>The organizers will introduction the topics and the structure of the devroom.</p>

The day in a life of a SBOM (en)

<p>The growing use of Software Bill of Materials (SBOMs) has introduced a new challenge with six different types exist (Design, Source, Build, Analysed, Deployed, and Runtime). As each type captures component information at a unique point in the development lifecycle, it is no longer sufficient to say that you want an SBOM' you need the right one which meets your use case. So how do you determine which SBOM type is the right fit for your specific use case?</p> <p>This session attempts to provide the answer through the use of the creation of a sample application moving through the entire development pipeline, demonstrating precisely how the SBOM's content evolves from an initial Design SBOM to a final Runtime SBOM captured within a runtime environment. It will demonstrate the critical information that can be gained at each stage, the specific use cases that each SBOM type enables, and the practical challenges that still need to be overcome to create reliable, high-quality SBOMs.</p>

When One Product Has Three SBOMs: Lessons from Embedded Vulnerability Management (en)

<p>Modern embedded products are no longer single-processor devices. A typical architecture combines a Linux-based main system, one or more microcontrollers running RTOS workloads, and cloud-side processing also running on Linux. Each of these components produces its own SBOM - often using different formats, tooling, and levels of detail.</p> <p>But what happens when you need to use all of them together for vulnerability management?</p> <p>This talk shares a real-world journey of attempting to aggregate and analyse SBOMs across heterogeneous parts of an embedded product. We will walk through the practical challenges encountered: incompatible SBOM formats, ambiguous identifiers, conversion tools that fail in unexpected ways, and friction between ecosystem assumptions and embedded reality. The goal is to highlight what currently works, what does not, and what the community could improve to make multi-SBOM workflows feasible for embedded systems.</p> <p>Attendees will leave with concrete insights, pitfalls to avoid, and a clearer picture of the current limits of SBOM-based vulnerability management in complex (but totally common) embedded architectures.</p>

Contextual SBOMs and impact on vulnerability management (en)

<p>Various tools producing SBOMs for pre-built artifacts, such as container images, usually provide only a flat list of components - packages, libraries, RPMs, and binaries - without explaining where any of them originated. But why does this origin information matter, and how can we obtain it?</p> <p>To simply introduce the concept, imagine your build ecosystem as a bakery: the built container is the loaf of bread, and your SBOM is the ingredient label on the package. While customers only see a flat list of ingredients, bakers actually care about where each one came from, because they are responsible for the quality and safety of the final product. The same applies to components in a Containerfile. As the "building factory", we need to know the provenance of every package, library, and binary - not just that it exists, but whether it came from a base image, a builder stage, or was installed directly in the final Containerfile. This provenance information, captured in a Contextual SBOM, is essential for effective vulnerability management. Once an issue appears, understanding vulnerability origin determines whether we must update a base or builder images, update a Containerfile-installed package, or rethink the build process entirely. </p> <p>In this talk, we will show how we transform a plain, flat SBOM into a structured, layered Contextual SBOM, and what benefits this brings. We will demonstrate how contextual provenance helps us identify vulnerabilities faster and more reliably, and how it improves our overall vulnerability-management workflow.</p> <p>Key Topics: - Limitations of traditional SBOMs: Why flat, non-contextual SBOMs fall short in containerized build environments where content origin is unclear - Introducing Contextual SBOM: An overview of contextual SBOMs and how they enrich component data with provenance - Differentiation base image vs. installed content: distinguishing inherited base-image content from software added directly in the Containerfile - Tracing builder-stage content: Identification and attributing content copied from builder stages in multistage builds to final image - Using Contextual SBOMs in vulnerability management: How provenance-aware SBOMs accelerate triage, clarify responsibility, and improve remediation decisions</p> <p>This talk is ideal for security professionals, compliance officers, compliance auditors, developers and anyone involved in the supply chain aspects of software.</p> <p>Relevant repositories: https://github.com/konflux-ci/mobster https://github.com/konflux-ci/capo</p>

Beyond SBOM: Integrating VEX into Open Source Workflows (en)

<p>When a new CVE surfaces in an open-source dependency, teams face an immediate question: Do we really need to update? Is the vulnerability <strong>eploitable</strong>? In practice, nearly 90% of reported issues never affect the consuming application, but identifying the critical 10% is far from trivial. Reachability analysis offers a path forward by tracing vulnerable functions from the upstream component through multi-hop call graphs to determine whether the affected code is ever invoked downstream.</p> <p>Despite its value, reachability analysis is notoriously difficult to automate. Most organizations still rely on manual investigation, while existing SCA tools frequently fall short, leaving teams uncertain and prompting unnecessary upgrades.</p> <p>This talk presents a concrete case study from Apache Hadoop and Solr, illustrating how accurate reachability analysis can prevent wasted effort, reduce noise, and focus attention on the vulnerabilities that truly matter. The reachability of vulnerabilities will be analyzed using the Open Source VEX Generation Toolset project.</p>

From Passive Data to Active Defense: Supply Chain Policy-as-Code with Conforma (en)

<p>The modern software supply chain is no longer suffering from a lack of data. Between SBOMs, SLSA provenance, and vulnerability scans, DevOps teams are drowning in attestations. However, a critical gap remains: the ability to aggregate this diverse evidence and enforce consistent, automated security decisions. Simply having an SBOM does not secure your pipeline; verifying its content against a trusted policy does.</p> <p>In this talk, we introduce <strong>Conforma</strong>, an open-source tool designed to address the enforcement gap in supply chain security. We will move beyond static documentation and demonstrate how to implement an automated, blocking Policy Gate that enforces integrity before deployment.</p> <p>Attendees will learn how to transition from passive observation to active enforcement using <strong>Policy-as-Code</strong>. We will demonstrate how Conforma acts as a central engine that ingests various security artifacts, including SBOMs, in-toto attestations, and vulnerability reports, to evaluate them against strict policies.</p> <p>To provide a detailed look at the tool's capabilities, we will showcase two concrete policy checks: <strong>SBOM Content Hygiene</strong> and <strong>SLSA Provenance</strong>.</p> <p>Attendees will leave with a clear understanding that supply chain data is only as valuable as the policies that enforce it. They will learn how Conforma automates this verification, turning a passive collection of attestations into an active, enforceable defense system.</p> <p>Conforma: https://conforma.dev/ SLSA Provenance: https://slsa.dev/spec/v1.1/provenance In-toto: https://in-toto.io/</p>

CRA-Ready SBOMs: A Practical Blueprint for High-Quality Generation (en)

<p>As one of the co-leaders of the CISA working group on <a href="https://github.com/SBOM-Community/SBOM-Generation">SBOM Generation</a> and a contributor to its accompanying <a href="https://github.com/SBOM-Community/SBOM-Generation/blob/main/whitepaper/Draft-SBOM-Generation-White-Paper-Feb-25-2025.pdf">whitepaper</a>, I’ve spent the last few years deep in the trenches of SBOM creation. With the EU’s Cyber Resilience Act (CRA) raising the bar for software transparency and lifecycle security, the need for <em>reliable, high-quality</em> SBOMs has never been more urgent.</p> <p>In this talk, I’ll present a practical blueprint for SBOM generation that goes beyond minimal compliance and helps projects prepare for the expectations emerging from the CRA and similar regulatory frameworks. The model breaks SBOM creation into four clear phases:</p> <ul> <li><strong>Authoring</strong> – producing the initial SBOM from a lockfile</li> <li><strong>Augmenting</strong> – resolving gaps and adding metadata to meet increasingly strict transparency requirements that SBOM generation tools can't do</li> <li><strong>Enriching</strong> – improve the quality of the SBOM using open data sets</li> <li><strong>Signing</strong> – provide attestation to ensure the SBOM can be trusted</li> </ul> <p>I’ll discuss the technical considerations behind each phase, common pitfalls, and how these practices help projects avoid the compliance gaps many teams are now discovering as the CRA timeline approaches.</p> <p>To ground everything in reality, I’ll demo a fully open-source workflow built with the <a href="https://github.com/sbomify/github-action/">sbomify action</a>, a tool from <a href="https://sbomify.com">sbomify</a> that runs in GitHub Actions or any CI environment, enabling CRA-ready SBOM pipelines without proprietary tooling.</p>

Deutsche Bahn's Approach to Large-Scale SBOM Collection and Use (en)

<p>500,000 SBOMs -- that's the scale of Deutsche Bahn's software supply chain. We will show how we extend our automated collection of Source, Build, Artifact, and Runtime SBOMs from both internal systems and external suppliers, and how we make this data usable. Doing this, we understand that SBOMs are not a tool by themselves but a supporting method for various use-cases. To facilitate them, we heavily rely on FOSS tools, enriched with own logic to fit into our enterprise architecture. You love diagrams? We have them!</p> <p>But tools and clever ideas aren't enough. We need people to integrate them into pipelines and continuously monitor the quality of the resulting SBOMs and derived findings. We depend on cooperation from operators of related internal services. And we also need support from our governance stakeholders. Join this session to hear about our journey, where we stand today, and what lies ahead.</p> <p><em>Note: This talk is a follow-up to the session <a href="https://fosdem.org/2026/schedule/event/ZSWH3N-deutsche-bahn-supply-chain-cra-strategy/">Software Supply Chain Strategy at Deutsche Bahn</a> that puts an emphasis on the overall strategy and organizational implementation.</em></p>

How public administrations are shifting their software supply chain paradigms – and why now (en)

<p>The open-source ecosystem, and quite prominently the Cloud Native Computing Foundation (CNCF), have matured to the point where proprietary vendors are increasingly challenged in the areas of keeping up with formalities and documentation, historically one of their key advantages. Innovations such as OCI attestations and Vulnerability Exploitability eXchange (VEX) go beyond metadata – they have the potential to fundamentally change how software is procured and evaluated. This talk explores the concept of shared responsibility in software security and quality, focusing on practical initiatives in Germany, including the container ecosystem, the openCode platform and its Badge Programme: transparent standards, verifiable provenance, and community-driven approaches can strengthen digital sovereignty, improve supply chain security, and reshape the way public sector organisations adopt and reuse software.</p>

LibreOffice and Collabora Online - how we managed to automate SBOM generation for a large legacy project (en)

<p>This is a case study of how we managed to analyse &amp; subsequently automate the SBOM generation for a very large, legacy code base. Come and hear about our journey to lift the LibreOffice-family open source projects into modern software supply chain management times, including some war stories about particularly obnoxious dependencies, as well as what tools (standard, as well as home-grown) we're using for that.</p>

SBOMs for Embedded Firmware: The Zephyr RTOS Case Study (en)

<p>SBOMs for embedded systems are harder than for typical apps: vendor HALs, out-of-tree modules, binary blobs... accurately capturing what <em>actually</em> ended up in the binary image deployed on your product is crucial for addressing future CVEs with confidence, as well as to comply with regulations such as CRA.</p> <p>In this talk, I’ll show how Zephyr RTOS integrates SPDX-based SBOM generation into its CMake build system, and how we’re exploring SPDX 3 to describe things that aren’t just source code — build configuration, AI/ML artifacts, etc. — so that SBOMs for Zephyr-based products reflect the real security and compliance surface of the device, not just the code that was compiled.</p>

Forget SBOMs, use PURLs (en)

<p>SBOMs have become the poster child of supply chain security. Everyone's generating them, regulators are demanding them, and compliance tools are built around them. But, the same package gets identified differently across tools, ecosystems, and standards. You end up with multiple SBOMs for the same software that can't be correlated, cross-referenced, or meaningfully compared - or actionable for vulnerability exploitability and remediation.</p> <p>Package-URLs (PURLs: https://github.com/package-url/purl-spec) solve the identification problem to make SBOMs actually useful. A PURL provides a universal, standardized identifier for any package across any ecosystem. This simple spec makes supply chain tooling interoperable, enabling vulnerability databases, compliance tools, and SBOM generators to speak the same language about packages, regardless of source.</p> <p>This talk covers the latest PURL developments that are making it essential infrastructure: validation tools, expanded ecosystem support including AI/ML model identifiers, growing adoption in major security tools and databases, integration into SBOM standards like SPDX and CycloneDX, and community-driven efforts to standardize package identification across the entire supply chain landscape. We'll show real examples where PURLs enable cross-ecosystem vulnerability tracking, make SBOM validation actually possible, and simplify compliance workflows by providing a common identifier system everyone can use.</p> <p>The title is provocative, but the reality is complementary: SBOMs describe your software's composition, PURLs make those descriptions machine-readable and universally meaningful. You'll leave understanding how PURLs are becoming critical infrastructure for supply chain security, why major projects and ecosystems are adopting PURL, and how to integrate PURLs into your own tooling and compliance automation workflows.</p>

How to create the SBOM for the Linux kernel (en)

<p>This presentation will explain how we built a tool that can create an SBOM for a Linux kernel build that describes the generated artifacts, the source files included and the build relations between them as an SPDX3 document. This is deduced from kernel specific build outputs. In our journey we overcame several hurdles and we want to share what we learned.</p>

What is new in SPDX 3.1 which is now a Living Knowledge Graph (en)

<p>SPDX 3.1 is transforming from a flat bill of material scheme to a knowledge graph” that now covers hardware, supply-chain security and safety tests, and the 130+ crypto algorithms that are used on your data. The AI/Dataset profile added three must-have lines for every smart assistant—AI Agent, Prompt, and RAG so you can see exactly how your AI system (Basiic AI, GenAI and Agentic AI) was created </p> <p>SPDX has also added a SPDX crypto lalgorithm list which is similar to the methodology and process that was used for the SPDX License list. There are over 130 algorithms that have been reviewed by the SPDX Working group</p> <p>Demonstrate some newly available SPDX SBOM tools that can automate creating SBOM for existing AI system. </p> <p>In this talk we will: 1. Show the ontology and how a single spdx:Element can simultaneously be: hw:Chip (Hardware ) da:Requirement (Design-Assurance) crypto:Algorithm (Cryptology) sc:TransportEvent (Supply-Chain) 2. Show how to query the knowledge graph to: “Return every AI model that was trained on dataset x deployed on a hardware y whose root-of-trust implements one of the 130 curated cryptographic algorithms, and that passed a functional-safety test required by CRA.” 3. Show how the new classes in AI/Dataset profile and relationship can document an Agentic AI system<br /> 4. Demonstrate how for CRA, ISO 42001, and FDA : where each regulation asks a different question, but all questions can be seen as graph walk(s).</p>

A semantic framework for modelling and analysing supply chains through SBOMs (en)

<p>We will present a multi-layered semantic structure for modelling and examining software supply chains using Software Bills of Materials (SBOMs), and a case study of its application to analyse CERN's computing services.</p> <p>Contemporary software ecosystems depend significantly on FOSS components, but SBOMs only offer standalone snapshots of elements, missing integrated perspectives on organisational context, vulnerability propagation, and internal software behaviour. This study integrates Semantic Web technologies, graph-based dependency modelling, and function-level structural analysis to overcome these limitations. At the organisational level, diverse SBOMs, survey data, licensing details, and vulnerability records are integrated into an ontology-based knowledge graph, facilitating expressive queries and automated reasoning throughout varied software landscapes. At the project level, the Vulnerability-Dependency Graph (VDGraph) model integrates SBOM dependency details with vulnerability information from Software Composition Analysis(SCA) tools, aiding the analysis of how vulnerabilities spread through dependency chains. Ultimately, at the code level, function-call graphs described by node centrality metrics and Graph Attention Network (GAT) embeddings reflect the structural significance of functions within an application, providing insights on how updates in dependencies might influence internal behaviour.</p> <p>Created during an internship at CERN’s Open Source Program Office, this framework offers a complete, scalable method for understanding, managing, and safeguarding intricate software supply chains within large and heterogeneous organisations. The framework has been put in practice to perform an analysis of CERN's computing ecosystem during 2025.</p>

Bringing Functional Safety to the SBOM: Automating Compliance with the SPDX Safety Profile (en)

<p>Functional safety is crucial for open-source components used in safety-critical domains like automotive, medical, and industrial control. However, the current practice for managing the Safety Case—the collection of documents (requirements, tests, analyses, and evidence) proving compliance with standards like IEC 61508 or ISO 26262—is manual, chaotic, and inefficient. These artifacts are often fragmented across proprietary lifecycle systems, spreadsheets, or PDFs, leading to broken traceability and overwhelming manual effort in the supply chain. This talk introduces the SPDX Functional Safety Profile, a critical extension built on the upcoming SPDX 3.1 specification. We will demonstrate how this profile moves the entire Safety Case into a single, standardized, and machine-readable exchange format. The profile achieves this by introducing new classes beyond the SPDX Core: - REQUIREMENT: Capturing functional, non-functional, and design needs. - VERIFICATION: Defining specifications for tests, reviews, and analyses. - EVIDENCE: Storing test reports, build logs, and compliance evidence. Attendees will learn how to use machine-readable relationships to trace requirements through the V-Model, connecting code, design documents, and test results automatically. This profile is the key to building an automated, auditable, and tool-agnostic safety documentation pipeline, finally delivering the ability to exchange comprehensive Safety SBOMs across complex, multi-party supply chains.</p>

C/C++ Build-time SBOMs with pkgconf (en)

<p>Build-time SBOMs for traditional C/C++ applications have historically been difficult to generate. To improve this situation, we have been extending <a href="https://github.com/pkgconf/pkgconf">pkgconf</a> to support generating high-quality build-time SBOMs, as the pkg-config database already understands all of the build dependency relationships needed for a build-time SBOM. This talk is intended to be a walk through using the new pkgconf 3.x SBOM tools to generate a high quality build-time SBOM for a project.</p>

Enhancing Swift’s Supply Chain Security: Build-time SBOM Generation in Swift Package Manager (en)

<p>A Software Bill of Materials (SBOM) provides a detailed inventory of software components in an artifact. SBOMs allow developers to improve the supply chain security of their Swift projects by analyzing direct and transitive dependencies for vulnerabilities. Currently, Swift Package Manager (SwiftPM) lacks built-in SBOM support, and developers must rely on third-party tools that can under- or over-represent package dependencies in a project, leading to a lack of critical information or too much noise.</p> <p>This talk focuses on an in-development feature to integrate SBOM generation directly into the Swift toolchain. As a result of this upcoming integration, developers will be able to create industry-standard CycloneDX or SPDX SBOMs as part of their build, without additional configuration. We will delve into the design in which SwiftPM employs the resolved modules graph to generate accurate SBOMs that capture both package and product dependencies, and optionally incorporates SwiftBuild build system’s build graph to align the SBOM with build-time conditions.</p> <p>Listeners will be introduced to the basics of SwiftPM, learn more about the upcoming SBOM generation design that leverages SwiftPM’s existing graph structures, and have the opportunity to provide feedback before the feature is released.</p>

Generating SBoMs for BuildStream projects (en)

<p><a href="https://buildstream.apache.org/">BuildStream</a> is a software integration tool that allows building software aggregated from multiple sources in a single pipeline to produce a final output. This final output could be a container image, an operating system image or anything that you can write a plugin for.</p> <p>In this talk, I present <a href="https://gitlab.com/BuildStream/buildstream-sbom/">buildstream-sbom</a>. It's a tool that extracts information from a BuildStream project and uses it to generate an SPDX-formatted SBoM. I also discuss the issues that I had translating from BuildStream concepts to SPDX.</p>

Intro to the Decentralized Internet & Privacy devroom (en)

<p>The Internet landscape is evermore on it’s steadfast course towards surveillance and centralization. Video content and streaming out of CDNs now account for half of all global traffic; splinternets are now a thing, from China to South Korea, from Russia to Iran; mandatory backdoors on communication platforms are just around the conner with EU’s Chat Control. In this scenario, where most Internet connected devices have become tools of imprisonment rather than liberation, reviving the old Internet ethos of peer-to-peer (P2P) and private communication is of uttermost importance.</p> <p>This is the revival of the <a href="https://fosdem.org/2026/schedule/track/decentralized-internet-and-privacy/">Decentralized Internet and Privacy Devroom</a> at <a href="https://fosdem.org/2026/">FOSDEM 2026</a>.</p> <p>The devroom and the program is coordinated by <a href="https://decentral.community/">decentral.community</a> and <a href="https://riat.at">RIAT</a>.</p>

Bringing Decentralization to Your Doorstep: 5 Years in Browsers (en)

<p>Can we make the web more decentralized and more private without asking users to switch browsers? For the past five years, the IPFS ecosystem has pioneered multiple approaches to this challenge. This talk shares hard-won lessons about what works—and what doesn't.</p> <p>We'll cover three parallel strategies: (1) pushing for native protocol support in major browsers, (2) driving adoption of critical cryptographic building blocks (such as Ed25519 into WebCrypto API, a three-year standards journey led by Igalia that just succeeded in Chrome 137), and (3) using existing browser capabilities in novel ways.</p> <p>The work emerged from IPFS's needs, but the benefits extend far beyond one protocol. Ed25519 in browsers now helps decentralized identity systems, local-first apps, and any protocol needing trustless verification — all without developers bundling their own cryptography libraries.</p> <p>The talk will be practical and honest: What takes three years versus three months? How do you fund unglamorous infrastructure work? When should you work around browser limitations versus push for standards changes? Attendees will leave with actionable insights for pushing privacy and decentralization into mainstream web infrastructure, plus a preview of what's coming next.</p> <p>Links: - ipfs.io - https://blogs.igalia.com/jfernandez/2025/08/25/ed25519-support-lands-in-chrome-what-it-means-for-developers-and-the-web/</p>

Re-decentralizing the web platform with Wasm GC (en)

<p>The massive size of browser engines has concentrated power over the web platform into a few large corporations. Creating a new browser engine that is sufficiently featureful to be an alternative to the Big Three is practically impossible. But what if we could shrink the footprint of a browser's core? What if a browser was little more than a WebAssembly (Wasm) runtime and nearly everything else was an extension? By breaking up the monolith we would have a chance to re-decentralize control over the web. This talk will explore what a modular web platform might look like with Wasm at its core, with a focus on how Wasm GC enables the mission-critical feature of safely sharing resources amongst components.</p>

Reclaiming the Web: Surfing the Internet on Torrents (en)

<p>In recent decades, the internet has increasingly become centralized, shifting from its hacker-driven origins into a cartel of advertising companies. It won't get better if we allow these same companies to drive the design of the web browsers and their protocols.</p> <p>Within hacker communities, many solutions have been developed to mitigate centralization, but their adoption has been limited, often because they require specialized expertise to be operated safely.</p> <p>In this talk I'll introduce you to a new open-source project that aims to provide an accessible alternative by building a web browser that is able to fetch web content using the BitTorrent protocol in tandem with the Tor network.</p> <p>We will dive into the ethical, security, and privacy trade-offs at play when designing such an alternative web.</p> <p>The IvI Project: https://ivi.eco</p> <p>Historically, peer-to-peer communication has been at the heart of the internet since its early days, reaching its peak in the late 90s when the web truly became a platform for sharing knowledge and art. For a moment it felt like we could exchange freely with anyone else. Unfortunately, that did not last long: legal restrictions, centralization and the emergence of commercial streaming services did eventually reshape the internet.</p> <p>But the peer-to-peer spirit did not die. Over times many tools have been developed to try to keep the web decentralized and open. They are all contributing to forge a vision in which the internet network must be owned and operated by its users.</p> <p>The project "IvI" that I'm introducing to you tries to bring those pieces together in a way that makes it accessible to anyone: a web browser that streams web content using BitTorrent while guarding privacy using the Tor network. It allows people in different parts of the world to help each other access content freely, even when local internet providers or policies impose restrictions on torrenting.</p> <p>Rebuilding the web using this model allow us to mitigate the risks of mass surveillance and censorship by design. Though seeding activity is public, the decentralized nature of the network makes it difficult to trace who is accessing what, or from where. It also builds solidarity into the web itself: users helping users across borders through open technology... but it does also raise complex ethical questions.</p> <p>When users set up their "Akoopa" browser, they will have the choice to operate under a public or private (cloaked) profile.</p> <p>By choosing a public profile, the node will communicate with the BitTorrent mainline DHT, it participates as an active node in traditional BitTorrent swarms. But here's the twist: a public node also exposes itself using an onion service which is only advertised to peers running the IvI stack. On the other hand, all the HTTP browsing traffic goes through Tor, effectively preventing websites (or their advertisers) from correlating the torrenting activity.</p> <p>Alternatively, by choosing a private profile, all communications will go through Tor. This means that the node can not directly communicate with BitTorrent mainline DHT. Instead, it relies on the overlay network of public IvI nodes to proxy its requests. In such situation it can participate only passively with the traditional BitTorrent nodes, but it is actively supported by the other IvI nodes in the swarm.</p> <p>With this design in mind, and a carefully hardened BitTorrent client implementation which is respectful of Tor bandwidth and exit policies, we should be able to work around the issues traditionally encountered when torrenting with Tor.</p> <p>This initiative is not commercial, not governmental; it is just a community effort to reclaim the web’s original spirit. It’s a simple idea that poses this question: What if we delivered the web itself through torrents? The technology exists; now it’s about putting it together and doing so collectively to figure out how to make it work for everyone.</p>

In defence of GnuPG: Key Sovereignty in an Age of Digital Feudalism (en)

<p>For over a decade, critiques of OpenPGP and GnuPG have resurfaced in cycles: too complex, too fragile, too old, unfriendly, too “cryptonerd.” Modern messaging apps, "forward-secrecy-by-default" protocols, and crypto tools are frequently presented as decisive reasons to abandon GPG altogether. Yet these arguments often rely on a deeper and more troubling assumption: that ordinary users cannot and should not be expected to understand or control their own cryptographic identity.</p> <p>This talk challenges that premise.</p> <p>GnuPG is not merely another encryption tool; it is one of the few remaining technologies that give individuals total sovereign control over their cryptographic keys and consequently, over their digital identity. In an era increasingly shaped by "digital feudalism", where platforms dictate the limits of user agency under the guise of convenience, GPG represents a radically different model: federation instead of walled gardens, user-owned keys instead of opaque key escrow, and a trust model that distributes power horizontally rather than concentrating it in corporate or governmental authorities.</p> <p>This presentation revisits the popular criticisms such as complexity, usability, lack of forward secrecy, the Web of Trust, aging cryptographic primitives and examines which reflect genuine limitations and which reflect a shift in cultural expectations shaped by centralized, app-centric design. It also highlights the unique strengths of GPG: asymmetric communication without a central provider, universal applicability far beyond email, a single identity usable across code-signing, backup encryption, SSH, authentication, and fully offline communication.</p> <p>Finally, it explores the broader political and social context: why long term key ownership matters, why revocability and inspectability are essential freedoms, and why privacy cannot be sustainably outsourced to corporations whose incentives are misaligned with user autonomy. While modern protocols like Signal and Matrix bring important innovations, none yet replace the core promise of OpenPGP that cryptographic self determination remains possible.</p> <p>This talk argues that dismissing GPG as "too hard" risks conceding our digital agency to systems designed to keep users passive. In a world where ideas outlive the apps that package them, GPG’s foundational idea (users should own their keys) remains not only relevant, but indispensable.</p>

NymVPN: The First Real-World Decentralized Noise-Generating Mixnet for Anonymity (en)

<p>Nym is the first decentralized noise-generating mixnet to provision real-world network anonymity to Internet users even against nation-state adversaries. The aim here is to supersede existing VPNs in order to fight increasingly more powerful authoritarianism and surveillance. Unlike traditional centralized VPNs that can be de-anonymized by a global passive adversary - like the NSA - based on their traffic patterns, Nym adds noise (“cover traffic”) to existing Internet communications. Similar to Tor, Nym routes each packet separately over a decentralized network of servers, but unlike Tor, mixes traffic and adds noise at each hop. It has both a “fast” and “anonymous” mode. The “fast” mode features speeds comparable to centralized VPNs using the same decentralized network as the mixnet, but without mixing. We will also explore the effect on anonymity of fine-tuning cover traffic, mix delays, and the rate of the Poisson distribution. We'll briefly overview upcoming features on censorship-resistance and postquantum cryptographic security on the network-level Via the SDK, the Nym mixnet remains free to use by hackers to build the next generation of privacy infrastructure.</p>

Liberate Your User Data with zkTLS: Verifiable HTTPS Using TLSNotary (en)

<p>TLS has secured the internet for decades, but it has a major limitation: because TLS relies on symmetric encryption, data cannot simply be shared with a third party. As a result, most Web data remains locked inside centralized silos. HTTPS provides authenticity and confidentiality, but not verifiable provenance, leaving applications to rely on screenshots, scraped HTML, or centralized access control mechanisms such as OAuth.</p> <p>zkTLS changes this. Using MPC-TLS and zero-knowledge techniques, zkTLS allows a client to produce cryptographically verifiable proofs and attestations of real HTTPS sessions. This makes previously inaccessible user data portable, trustworthy, and reusable across applications. Importantly, zkTLS places the user in control: the user decides what to disclose, without exposing secrets (e.g. authentication tokens) or revealing unnecessary fields in a response.</p> <p>In this talk, we will: * explain how zkTLS works at a protocol level (MPC-TLS, transcript commitments, zero-knowledge) * present real-world use cases * discuss security and trust assumptions * demonstrate TLSNotary running in the browser, generating proofs from private HTTPS requests</p> <p>Attendees will see how zkTLS provides a practical path toward user-controlled data provenance, enabling open innovation on top of the world’s existing HTTPS infrastructure.</p>

Namecoin and Tor as a Public Key Infrastructure (en)

<p>Public certificate authorities in TLS are a security liability from both a censorship and MITM perspective. Conceptually, DNSSEC's idea of tying PKI to domain names should be a better replacement -- except that in the DNS, relying on the names means trusting the registrars, registries, and ICANN. But what if we had <em>self-authenticating</em> domain names? Could we build a PKI on top of those? Could such a PKI work with unmodified mainstream web browsers like Chromium, Firefox, and Tor Browser?</p> <p>We've done exactly that. Namecoin (a blockchain naming system providing the .bit TLD) and Tor (an anonymity network providing the .onion TLD) provide the self-authenticating domain names. This talk covers how we made the PKI. Topics to be discussed include:</p> <ul> <li>Why public certificate authorities are dangerous.</li> <li>Prior work on using DNS as a PKI (and why it's less useful for us than you might think).</li> <li>How we creatively used API's to get mainstream TLS implementations to use Namecoin to validate TLS certificates.</li> <li>Why you might want to use TLS with Tor onion services (and why onion service encryption might not be as secure as you think).</li> <li>How we generalized Namecoin TLS to work with Tor onion services.</li> <li>How we made TLS implementations that don't support Ed25519 work anyway with Tor onion services (which rely on Ed25519).</li> <li>How we can use TLS with Namecoin without putting a TLSA record on the blockchain (for better scalability).</li> <li>How Namecoin's smart contract functionality (allowing multisig and timelocks to control updating a name) interacts with PKI use cases.</li> <li>How we generalized Namecoin and Tor PKI to work with non-TLS protocols.</li> <li>How revocations can be handled securely.</li> <li>How we ensured anonymity (including Tor stream isolation) despite TLS implementations not providing API's for this.</li> </ul>

Gosling: Build Anonymous, Secure, and Metadata- Resistant Peer-to-Peer Applications using Tor Onion Services (en)

<p>Gosling is a Tor onionservice-based protocol and Rust reference-implementation which allows developers to build privacy-preserving p2p applications with the following properties: - persistent authenticated peer identity - end-to-end encrypted - anonymity - metadata resistance - decentralisation - real-time communication</p> <p>This talk will go over the complexities involved in combining all of these properties (with a focus on metadata resistance) and describe how Gosling solves these problems.</p>

Half-time recap & precap for Decentralized Internet devroom (en)

<p>Short summary of what happened until now and details about the main topics for the afternoon session.</p>

Radicle: Peer-to-Peer Code Collaboration (en)

<p>Today, much of the open-source ecosystem depends on a few centralized code forges, even though modern version control systems are designed with fully distributed collaboration in mind. This creates questionable dependencies with regards to governance and supply-chain security. In this talk, we explore an alternative: <a href="https://radicle.xyz/">Radicle</a>, a decentralized, peer-to-peer, open source, code collaboration stack built on Git, that empowers developers to work together while staying sovereign.</p> <p>Unlike traditional, centralized code forges (such as GitHub or GitLab) that can impose censorship, Radicle ensures that each user retains control over their data, interactions, and collaboration, free from corporate influence. This aligns with broader movements toward decentralization, open-source software, and the democratization of internet services.</p> <ul> <li>We describe the Radicle gossip protocol, peer discovery, and secure data replication through cryptographic verification.</li> <li>We share plans for future development of the network.</li> </ul> <p>Attendees gain a comprehensive understanding of Radicle’s technical architecture, its practical benefits for decentralized code collaboration, and how it contributes to a more autonomous and resilient future for open-source development.</p> <p>Find out more: - <a href="https://radicle.xyz/faq">FAQ of the project (radicle.xyz)</a> - <a href="https://www.youtube.com/watch?v=tsVa53SPIHc"><em>How we built a gossip layer and CRDT on top of Git</em> by Alexis Sellier at GitMerge 2024 (youtube.com)</a> - <a href="https://radicle.xyz/2024/09/10/radicle-1.0.0.html">Release Notes for 1.0.0 (radicle.xyz)</a> - <a href="https://radicle.xyz/2024/12/05/radicle-1.1.0.html">Release Notes for 1.1.0 (radicle.xyz)</a> - <a href="https://radicle.xyz/2025/06/02/radicle-1.2.0.html">Release Notes for 1.2.0 (radicle.xyz)</a> - <a href="https://radicle.xyz/2025/08/12/radicle-1.3.0.html">Release Notes for 1.3.0 (radicle.xyz)</a> - <a href="https://radicle.xyz/2025/09/04/radicle-1.4.0.html">Release Notes for 1.4.0 (radicle.xyz)</a> - <a href="https://radicle.xyz/2025/09/30/radicle-1.5.0.html">Release Notes for 1.5.0 (radicle.xyz)</a> - <a href="https://radicle.zulipchat.com">radicle.zulipchat.com</a></p> <p><em>Free your code!</em></p>

Peergos: Capability-Based Access Control for an Encrypted Web (en)

<p>We introduce Peergos, a peer-to-peer protocol for end-to-end encrypted storage, social networking, and application hosting built on top of libp2p. Peergos combines cryptographic identity, content addressing, and decentralized access control into a unified protocol where users fully control their data, identity, and applications without relying on trusted servers.</p> <p>Instead of treating encryption as an add-on, Peergos integrates cryptographic capabilities directly into its data model: files, directories, social data, and application state are all encrypted and access-controlled by default. We will explain the design of Peergos’ capability-based access control, how key rotation and sharing work in practice, and how identity portability is achieved without central authorities.</p> <p>We will also introduce the Peergos application sandbox, which allows untrusted applications to operate over private user data without exposing plaintext or keys. This enables privacy-preserving apps such as social feeds, collaborative editing, and backups to run directly on encrypted storage.</p> <p>The talk will include live demos and a discussion of performance trade-offs, limitations, and open problems in decentralized encrypted systems, including search, discovery, and offline access.</p> <p>More info: https://peergos.org</p> <p>https://book.peergos.org</p> <p>https://github.com/peergos/peergos</p>

OCapN: The secure, decentralized protocol of the future (en)

<p><a href="https://ocapn.org">OCapN</a> (Object Capability Network) is a secure messaging protocol designed for the next generation of distributed applications. It leverages the capability security model (if you don't have it, you can't use it) to provide secure, peer-to-peer functionality with ergonomics that resemble ordinary programming. It has a rich set of features including promise pipelining, network transport agnosticism, error handling across networks, distributed acyclic garbage collection, and third-party handoffs providing powerful ways to share references with any peer. This talk will provide a tour of the protocol and show how it makes distributed, peer-to-peer development easier.</p>

iroh p2p connections (en)

<p>iroh is a library to establish direct connections between two peers, wherever they are on the internet. It takes care of using different transports and holepunching as needed, to reliably establish connectivity. To the application a normal QUIC connection is presented. The aim is to be a connection layer for p2p, providing greater user agency.</p> <p>Once there is a QUIC connection between two peers other network protocols can be run on top. iroh encouranges mixing and matching custom protocols as the application needs them. Two such building blocks maintained by the same team are iroh-gossip and iroh-blobs, implementations of gossip and verified streaming.</p> <p>After explaining how the core iroh system works and what applications need to understand the idea of how iroh encourages modular protocols will be described and iroh-gossip and iroh-blobs building blocks will be presented briefly as part of this.</p>

NextGraph: E2EE decentralized platform & framework (en)

<p>NextGraph is a protocol, a framework, and a platform that supports development of Local-First, decentralized, secure and private apps.</p> <p>By combining the best of the local first world (Yjs, Automerge CRDT libraries), a graph database, DID (decentralized identifiers) for users and documents, and end-to-end encryption plus encryption at rest, we provide an SDK that offers all the requirements of portability, interoperability and security needed today for a true alternative to Big Tech platforms and products.</p> <p>In this talk, we would like to dive into details of implementation of the E2EE sync protocol, the specifics of an encrypted sync protocol for CRDTs, the cryptographic capabilities that enable decentralized access control, and our 2-tier overlay network based on a pub/sub. Our philosophy is "zero single point of failure". With that in mind, we completely got rid of dependencies on DNS, and only rely on IP. Our broker can be and should be self-hosted, and forms a federation of decentralized servers.</p> <p>The protocol and SDK can be used to develop any kind of app, including messenger, productivity tools, editors, and social networks. All apps developed with our SDK can be built to webapp, Linux, Android, iOS, macOS and Win, thanks to the use of Tauri. All our codebase is in Rust, and MIT/Apache 2.0 of course. We recently released a new ORM mechanism that does all the heavy lifting of managing the database. Developers just need to declare the schema they want to use, and then objects are directly mapped to reactive components in React, Svelte, VueJS, via proxies and signals.</p>

Walkaway Stack: Radical, infrastructure-independent peer-to-peer systems (en)

<p>The Walkaway-Stack describes a peer-to-peer system where applications remain functional even if the underlying "event delivery" infrastructure changes. This enables seamless transitions between different network types—whether moving from a "connected" Internet stack to a "connectionless" mesh network, or from radio protocols to sneakernets, and vice versa. In this way, applications are decoupled from the underlying network, giving users the autonomy to choose their preferred infrastructure.</p> <p>In this presentation, I'll explore the space more broadly—examining why it's so exciting, why it's not fully solved yet, and where things currently stand. Hopefully, this will also reveal a theoretical overlap between "mesh protocols" and "overlay networks," which may actually be more closely related than we realize.</p> <p><strong>Background</strong></p> <p>This lecture will be a compressed version of the "p2p lecture series" I've been then running bi-weekly in our community space "offline" in Berlin.</p>

Reticulum-rs: Porting the Trustless Mesh from Python to Rust (en)

<p>Reticulum is a cryptography-based networking stack designed for resilient, decentralised mesh communication without central coordination, source addresses, or trusted infrastructure. While the reference implementation in Python demonstrates the architecture’s strengths, running it on mobile and embedded systems revealed major performance bottlenecks: high latency, limited throughput, and heavy CPU overhead, especially on Android devices. This led us to re-implement Reticulum in Rust, a language whose safety guarantees and mature cryptographic ecosystem enable a fundamental architectural redesign rather than a direct port.</p> <p>This talk presents Reticulum-rs, a modern async Rust implementation that eliminates circular dependencies, clarifies module boundaries, and enables components such as links, channels, and transport to be reasoned about and tested independently. We will discuss the concurrency model required for a fully distributed mesh, the challenges in rewriting a large cross-linked system in a type-safe language, and the roadmap toward embedded Rust and no_std targets for future low-power hardware. Finally, we introduce early applications built on the new stack, including a peer-to-peer VPN and MAVLink bridge operating over Reticulum, outlining how a high-performance Rust core unlocks new use cases across mobile mesh, and distributed robotics domains.</p>

qaul.net - Internet Independent Wireless Mesh Communication App (en)

<p>qaul is a P2P mesh communication app, with a strong focus on privacy and usability. Every user is identified via their self-sovereign cryptographic identity.</p> <p>It not only communicates P2P, but builds a mesh network, interconnecting multiple communication such as BLE (Bluetooth Low Energy), Local Area Networks, and Internet overlay links.</p> <p>The messaging app has an automated user discovery, end-to-end encrypted direct messaging and group chats for text, voice-messages and files, as well as public communication channels.</p> <p>https://qaul.net</p>

Multi-relay chat messaging & cryptographic identities with Delta Chat and Chatmail relays (en)

<p>During the past year, Delta Chat has been working on multi-relay chat messaging - you are no longer restricted to one server hosting your identity and transmitting your messages. Instead, the decentralized chatmail relay network transmits your messages, while your identity remains on your devices only, through the cryptographic key.</p> <p>In this talk we go into the technical details of multi-relay. We show how we migrate the ecosystem to this new approach, and how it can be introduced without taking away the seamless messaging experience from users.</p> <ul> <li>Delta Chat website: https://delta.chat</li> <li>Chatmail relay documentation: https://chatmail.at/doc/relay/</li> </ul>

Closing of the Decentralized Internet devroom (en)

<p>Recap of the main topics and news about what's next with the decentral.community</p>

Escape the Maze! - Program a Game in Snap! (en)

<p>Let's program an interactive maze game in Snap! This beginners workshop is open for children of all ages interested in learning how to make their own video games. We'll explore how to animate sprites, navigate them through a maze, prevent them from passing through walls, and make them reach the next level.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Create a Critter (en)

<p>Workshop: Create a Critter. Margaret Low. Audience: children aged 9 and up. Create your own finger puppet using turtlestitch. TurtleStitch is a block based language, that runs in the browser. Use turtlestitch to create the outline for your finger puppet. It’ll then be stitched by a digital embroidery machine onto two layers of felt, and you can then decorate it, adding eyes, hair, etc.</p> <p>www.turtlestitch.org Tutorial: https://warwick.ac.uk/turtlestitch/project_2._finger_puppet.pdf</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Play robot football: program a CoCube with MicroBlocks (en)

<p>Score! Your goal will be to teach a CoCube robot how to "shoot a soccer ball into the net".</p> <p>You'll first learn the basics: how to program a https://www.cocubefun.com/ using https://microblocks.fun.</p> <p>Then you'll apply your new programming skills to shoot, and score!</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Make a controller for your game (en)

<p>In this workshop you'll create a little game that works in your computer, plus a physical controller -like the ones in gaming consoles- that you'll use to control the game you've made.</p> <p>To program the video game and the controller we are going to use two different blocks-based programming languages: Snap! and MicroBlocks.</p> <p>Snap! is a live, blocks-based language that delves into advanced programming concepts and is suitable for a rigorous introduction to computer science. MicroBlocks is also a live blocks-based programming language that runs on microcontrollers and is ideal to get started with electronics and physical computing.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Flowers and stars (en)

<p>A short talk to get you started in coding your own flowers and stars, which can be embroidered!</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Create your own art (Mondriaan or Picasso) with coding in p5.js (en)

<p>Create your own art like Mondriaan or Picasso with coding in p5.js. An online scripting site where you can put in circle's, square's, lines etc in different colours to create a pattern. You will start off with some examples so you know how this scripting coding works. Then you can make your own.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Exploring GCompris - an educational software (en)

<p>GCompris is an educational software with more than 100 educational activities, some of which are game oriented. Here you will hear some of the history as well as the prevalence of the application. Come and discover GCompris, and what it has to offer. This workshop is most suitable for children up to age 10. Having GCompris installed before the workshop is recommended. You can use either a mobile phone or a computer.</p> <p>https://gcompris.net/</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Learn Python programming using Hedy (en)

<p>Hedy is a programming language that aims to teach textual programming to kids. Hedy's unique approach involves gradual changes in the syntax of the programming language, so students are not overloaded with information right away. This devroom is aimed at students from 9 to 12 years old, but anyone with a desire to start learning programming (or teaching) with text based language is welcome. You'll need your own laptop (no installs needed, Hedy is webbased) and reading- and basic typing skills (or someone to help you read and type). No prior programming experience is needed. When you have finished all 16 levels of Hedy, you know the basics of Python.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Train and Deploy Machine Learning Models with MIT App Inventor (en)

<p>MIT App Inventor is an intuitive, visual programming environment that allows everyone – even children – to build fully functional apps for Android phones, iPhones, and Android/iOS tablets. Those new to MIT App Inventor can have a simple first app up and running in less than 30 minutes. In this workshop, participants will train their own convolutional neural network (CNN) to play the game peek-a-boo. We will then play with the model on tablets/phones using an app built with MIT App Inventor.</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop and a phone.</p>

Music by Coding (en)

<p>Sonic Pi is a free code-based music creation and performance tool. It is Powerful for professional musicians and DJs, Expressive for composition and performance. It is also accessible for blind and partially sighted people and is simple for computing and music lessons. Learn to code creatively by composing or performing music in an incredible range of styles from Classical &amp; Jazz to Hip hop &amp; EDM. Free for everyone with a friendly tutorial. https://sonic-pi.net/</p> <p>Unless stated otherwise, FOSDEM Junior workshops are intended for children aged 7 to 17. Don't forget to bring your own laptop.</p>

Welcome to the Confidential Computer Devroom (en)

<p>Welcome to the 7th iteration of the Confidential Computing devroom! In this welcome session, we will give a very brief introduction to confidential computing and the devroom, and we will give an honorable mention to all the folks that contributed to this devroom, whether they are presenting or not.</p>

Securing the Linux Boot Process with COCONUT-SVSM (en)

<p>Hardware extensions for confidential computing establish a strict trust boundary between a virtual machine and the host hypervisor. From the guest’s perspective, any interaction crossing this boundary must be treated as untrusted and potentially malicious. This places significant hardening demands on guest operating systems, especially around firmware interfaces, device drivers, and boot components.</p> <p>This talk explores how COCONUT-SVSM can act as a trusted proxy between the hypervisor and the Linux guest, restoring trust in key firmware and memory-integrity interfaces. By offloading sensitive interactions to the SVSM, we can simplify guest OS hardening and provide a more secure boot process for confidential VMs.</p>

Restartable confidential guests on QEMU hypervisor - where is the challenge? (en)

<p>Currently QEMU hypervisor based confidential guests on SEV-SNP, SEV-ES and TDX are not at-par with other non-confidential guests in terms of restartability. For these confidential guests, once their initial state is locked-in and its private memory pages, CPU register states are encrypted, its state is finalized and it cannot be changed. This means, in order to restart a confidential guest, a new confidential guest context must be created in KVM and CPU registers, private memory pages re-encrypted with a different key. Today, this means that upon restart, the old QEMU process terminates and the only way to achieve a reset is to instantiate a new guest with a new QEMU process on these systems.</p> <p>Resettable confidential guests are important for reasons beyond bringing them at par with non-confidential guests. For example, they are a key requirement for implementation of the F-UKI idea [1][2]. This talk will describe some of the challenges we have faced and our experiences in implementing SEV-ES, SEV-SNP and TDX guest reset on QEMU. A demo will be shown that reflects the current state of progress of this work. A link for the demo video will also be shared. This will be mostly a QEMU centric presentation so we will also describe some fundamental concepts of confidential guest implementation in QEMU. </p> <p>WIP patches based on which the demo will be shown are here [3][4][5]. These patches are posted in the qemu-devel mailing list for review and inclusion into QEMU [6][7][8].</p> <ol> <li>KVM Forum 2024 presentation https://pretalx.com/kvm-forum-2024/talk/HJSKRQ/</li> <li>FOSDEM 2025 https://fosdem.org/2025/schedule/event/fosdem-2025-4661-introducing-fuki-guest-firmware-in-a-uki-for-confidential-cloud-deployments/</li> <li>https://gitlab.com/anisinha/qemu/-/commits/coco-reboot</li> <li>https://gitlab.com/anisinha/qemu/-/commits/coco-reboot-v2</li> <li>https://gitlab.com/anisinha/qemu/-/commits/coco-reboot-v3</li> <li>v1: https://lists.gnu.org/archive/html/qemu-devel/2025-12/msg01681.html</li> <li>v2: https://mail.gnu.org/archive/html/qemu-devel/2026-01/msg01946.html</li> <li>v3: https://mail.gnu.org/archive/html/qemu-devel/2026-01/msg05298.html</li> </ol>

Securing Memory Isolation in Texas Instruments Microcontrollers (en)

<p>In this talk, I will first introduce Intellectual Property Encapsulation, the confidential computing feature of Texas Instruments MSP430 microcontrollers, and multiple vulnerabilities we have found in it. Then, I will propose two methods of mitigating these vulnerabilities: first, a software-only solution that can be deployed on existing devices; second, a standard-compliant reimplementation of the hardware on an open-source CPU with more advanced security features and an extensive testing framework.</p> <p>Attacks and software mitigation: https://github.com/martonbognar/ipe-exposure Open-source hardware design and security testing: https://github.com/martonbognar/openipe</p>

OpenCCA: An Open Framework to Enable Arm CCA Research (en)

<p>Confidential computing is rapidly evolving with Intel TDX, AMD SEV-SNP, and Arm CCA. However, unlike TDX and SEV-SNP, Arm CCA lacks publicly available hardware, making performance evaluation difficult. While Arm's hardware simulation provides functional correctness, it lacks cycle accuracy, forcing researchers to build best-effort performance prototypes by transplanting their CCA-bound implementations onto non-CCA Arm boards and estimating CCA overheads in software. This leads to duplicated efforts, inconsistent comparisons, and high barriers to entry.</p> <p>In this talk, I will present OpenCCA, our open research framework that enables CCA-bound code execution on commodity Arm hardware. OpenCCA systematically adapts the software stack—from bootloader to hypervisor—to emulate CCA operations for performance evaluation while preserving functional correctness. Our approach allows researchers to lift-and-shift implementations from Arm’s simulation to real hardware, providing a framework for performance analysis, even without publicly available Arm CPUs with CCA.</p> <p>I will discuss the key challenges in OpenCCA's design and implementation. OpenCCA runs on an affordable Armv8.2 Rockchip RK3588 board ($250), making it a practical and accessible platform for Arm CCA research.</p> <p>I brought the opencca box, the RK3588 board along with tooling to flash firmware and power reset to FOSDEM. During the talk, we will attempt a live demo and boot a confidential VM on OpenCCA to run GPU workloads. This with the goal to showcase how OpenCCA can be used to explore systems research ideas on Arm CCA.</p>

Challenges of Remote Attestation for Confidential Computing Workloads (en)

<p>Confidential Computing poses a unique challenge of Attestation Verification. The reason is, Attester in Confidential Computing is infact a collection of Attesters, what we call as Composite Attester. One Attester is a Workload which runs in a CC Environment, while the other Attester is the actual platform on which the Workload is executed. The two Attesters have separate Supply Chains (one been the Workload Owner deploying the Workload) while the Platform is a different Supplier, say Intel TDX or Arm CC. Another deployment could be a Workload been trained on a GPU (via means of Integrated TEE) attached to a CPU, to create an end-to-end secure environment. How can one trust such a Workload, along with the CPU which is feeding the training data to it?? To trust a Composite Attester, through remote attestation one needs multiple Remote Attestation Verifiers, for example one coming from CPU Vendor the other from a GPU Vendor. How do the Verifiers coordinate? Are there topological patterns of coordination that can be standardized.</p> <p>The presentation will highlight the Work done in IETF Standards &amp; Open Source Project Veraison to highlight: 1. Composite Attesters 2. Remote Attestation though Multiple Verifiers 3. Open-Source Work done in Project Veraison to highlight how Composition of Attesters can be constructed in a standardized manner 4. Open Source Work done in Project Veraison to highlight how Multiple Verifiers can coordinate to produce a Combined Attestation Verdict for a Composite Attester.</p> <p>Please see the following links- https://datatracker.ietf.org/doc/draft-richardson-rats-composite-attesters/</p> <p>https://datatracker.ietf.org/doc/draft-deshpande-rats-multi-verifier/</p> <p>Composition of Attesters using Concise Message Wrappers: Golang Implementation: https://github.com/veraison/cmw <br /> Rust Implementation: https://github.com/veraison/rust-cmw</p> <p>Attestation results required for constructing compositional semantics: Golang Implementation: https://github.com/veraison/ear</p> <p>Rust Implementation: https://github.com/veraison/rust-ear</p> <p>Verification of Composite Attesters - Arm-CCA https://github.com/veraison/services</p>

Lesson from Cloud Confidential Computing Remote Attestation Sample (en)

<p>We have released the sample codes for remote attestation on cloud confidential computing services. I report the lessons learned from them. https://github.com/iisec-suzaki/cloud-ra-sample The samples cover multiple types of Trusted Execution Environments (TEEs): (1) Confidential VMs, including AMD SEV-SNP on Azure, AWS, and GCP, and Intel TDX on Azure and GCP; (2) TEE enclaves using Intel SGX on Azure; and (3) hypervisor-based enclaves using AWS Nitro Enclaves. As verifiers, the samples make use of both open-source attestation tools and commercial services such as Microsoft Azure Attestation (MAA). This talk aims to share these observations to support developers and researchers working with heterogeneous TEE environments and to help avoid common pitfalls when implementing remote attestation on cloud platforms.</p>

bare-sgx: A Bare-Metal C Runtime for Intel SGX Development with Minimal Trust (en)

<p>A decade after Intel SGX’s public release, a rich ecosystem of shielding runtimes has emerged, but research on API and ABI sanitization attacks shows that their growing complexity introduces new vulnerabilities. What is still missing is a truly minimal and portable way to develop enclaves.</p> <p>In this talk, we will introduce our recent work on "bare-sgx", a lightweight, fully customizable framework for building SGX enclaves directly on bare-metal Linux using only C and assembly. The initial code was forked from the Linux kernel's selftests framework and explicitly encouraged by prominent kernel developers. By interfacing directly with the upstream SGX driver, bare-sgx removes the complexity and overhead of existing SGX SDKs and library OSs. The result is extremely small enclaves, often just a few pages, tailored to a specific purpose and excluding all other unnecessary code and features. Therefore, bare-sgx provides a truly minimal trusted computing base while avoiding fragile dependencies that could hinder portability or long-term reproducibility.</p> <p>Although still young, bare-sgx aims to provide a long-term stable foundation for minimal-trust enclave development, reproducible research artifacts, and rapid prototyping of SGX attacks and defenses.</p>

Standardization and Open-source Implementation of Attested TLS for Confidential Computing (en)

<h2>Summary</h2> <p>Attested TLS is a fundamental building block of confidential computing. We have defended our position (cf. <a href="https://datatracker.ietf.org/doc/bofreq-fossati-tls-exported-attestation-expat/">expat BoF</a>) to standardize the attested TLS protocols for confidential computing in the <a href="https://www.ietf.org/">IETF</a>, and a new Working Group named <a href="https://datatracker.ietf.org/wg/seat/about/">Secure Evidence and Attestation Transport (SEAT)</a> has been formed to exclusively tackle this specific problem. In this talk, we present the design choices for standardization of attested TLS, namely pre-handshake attestation, intra-handshake attestation, and post-handshake attestation. We present the journey of standardization effort showing replay, diversion and relay attacks on pre-handshake attestation and intra-handshake attestation (see <a href="https://www.researchgate.net/publication/398839141_Identity_Crisis_in_Confidential_Computing_Formal_Analysis_of_Attested_TLS">paper</a> and <a href="https://github.com/CCC-Attestation/formal-spec-id-crisis">formal proof</a>). We finally present the post-handshake attestation <a href="https://datatracker.ietf.org/doc/draft-fossati-seat-expat/">candidate draft</a> for standardization to gather feedback from the community, so that it can be accommodated in the standardization. </p> <h2>Technical details</h2> <p>We propose a specification that defines a method for two parties in a communication interaction to exchange Evidence and Attestation Results using exported authenticators, as defined in <a href="https://datatracker.ietf.org/doc/html/rfc9261">RFC9261</a>. Additionally, we introduce the cmw_attestation extension, which allows attestation credentials to be included directly in the Certificate message sent during the Exported Authenticator-based post-handshake authentication. The approach supports both the passport and background check models from the <a href="https://datatracker.ietf.org/doc/rfc9334/">RATS architecture</a> while ensuring that attestation remains bound to the underlying communication channel.</p> <h2>WiP Implementation</h2> <p><a href="https://github.com/tls-attestation/attestation-exported-authenticators">WiP Implementation</a> uses the <a href="https://github.com/veraison/rust-cmw">veraison/rust-cmw</a> implementation of <a href="https://datatracker.ietf.org/doc/draft-ietf-rats-msg-wrap/">RATS conceptual messages wrapper</a>. It includes a test which demonstrates using it with QUIC (for transport) and Intel TDX (as confidential compute platform): <a href="https://github.com/tls-attestation/attestation-exported-authenticators/blob/main/tests/quic_tdx.rs">tests/quic_tdx.rs</a>.</p> <h2>Useful links</h2> <ul> <li>IETF SEAT WG: https://datatracker.ietf.org/wg/seat/about/</li> <li>Subscribe to SEAT WG mailing list: https://mailman3.ietf.org/mailman3/lists/seat.ietf.org/</li> <li>Spec: https://datatracker.ietf.org/doc/draft-fossati-seat-expat/</li> <li>Proposed for adoption at CCC Attestation SIG: https://github.com/CCC-Attestation/governance/issues/20</li> </ul>

Open source firmware for high assurance confidential infrastructure (en)

<p>This talk presents a practical approach to building a high‑assurance core infrastructure for home and small business environments, using modern open firmware on commodity server hardware.</p> <p>As AI workloads move from cloud to on‑premise, the need for trustworthy and attestable hardware platforms for running models and handling sensitive data becomes critical. But what does "trustworthy" actually mean at the hardware/firmware level, and can we realistically achieve it with today’s platforms?</p> <p>We will walk through how to build a system based on a modern AMD server board combined with open‑source firmware (coreboot[1] and OpenSIL[2]) to gain more control and transparency across the boot chain. We will discuss:</p> <ul> <li>How open firmware and silicon initialization enable a stronger supply chain transparency and verifiability</li> <li>How to establish, measure, and attest a minimal and understandable firmware and software stack</li> <li>How to combine this with AMD’s security and confidential computing features to protect workloads and keys</li> <li>Practical pitfalls when deploying such systems at home or in small organizations</li> </ul> <p>The goal is to show how open firmware can complement security and confidentiality computing features to create a platform you can actually inspect, reason about, and attest from top to bottom - rather than treating the hardware and firmware as opaque, trusted black boxes.</p> <p>[1] https://www.coreboot.org/ [2] https://github.com/openSIL/openSIL</p>

Open-Education in the OpenFlexure Project (en)

<p>As technology advances, the difference in cost and technical specifications between proprietary devices used in professional settings and education grows. We present the OpenFlexure Microscope, a locally manufacturable and 3D-printed, brightfield microscope as a solution to bridge the gap between teaching equipment and the devices medics are expected to use throughout labs around the world. The OpenFlexure Project develops all the hardware, software and documentation for education across all levels and disciplines. A locally manufacturable and affordable digital microscope allows pathologists to image and practice on local samples - something that is key to medical education - whilst also breaking down international barriers through collaborative initiatives such as the School of Open Pathology which seeks to connect pathologists around the world. High schools are becoming more invested in interdisciplinary projects across all age groups and the OpenFlexure Microscope gives students the opportunity to learn about biology, engineering, physics and computing science all in the same package. We have run workshops for high school science teachers around Glasgow, Scotland where we have shown them how to build the microscope and discussed challenges of integrating our microscope into a classroom environment.</p>

GNU Octave in education: an insight beyond engineering into statistics and data analysis (en)

<p>GNU Octave is programming language intended for numerical computations. Often quoted as the MATLAB open-source clone or alternative, Octave has been in constant development for more than three decades already. Hundreds of engineering departments worldwide and tens of thousands of student have benefited from this free and open source software. Traditionally, Octave has been primarily targeting engineering applications due to its advanced computational capabilities with multidimensional arrays. Complementary to the core Octave capabilities, there has been Octave Forge, which for a long time served numerous packages extending Octave functionality for various domain-specific engineering applications. Since 2022, there has been a shift towards expanding the Octave ecosystem beyond engineering applications. This coincided with the development of Octave Packages, a new package indexing system that facilitates the development and integration of Octave package within the Octave ecosystem. This shift is most prominent by the recent advancements of the statistics package as well as a number of other packages focused on data analysis and visualization. This talk aims at a concise presentation of the current state of the Octave ecosystem with a special attention to the educational aspects and its benefits for educators and students alike. The talk will focus on statistics and data analysis with GNU Octave, and discuss its educational benefits in these two widely popular fields. https://octave.org https://gnu-octave.github.io/packages/ https://github.com/gnu-octave/statistics https://github.com/pr0m1th3as/datatypes</p>

Processing: Creative Coding and the Future of Education (en)

<p><a href="https://processing.org/">Processing</a> is one of the most widely used open-source tools for creative coding and computer science education. Since its first release in 2001, it has helped millions of students, artists, and designers learn programming through visual and interactive projects. It has been used in classrooms, art installations, interactive media, and data visualization worldwide. Processing popularized the term <em>creative coding</em> and helped establish it as a field that bridges art, design, and computer science.</p> <p>The values that shaped Processing (accessibility, creativity, and democratization) remain essential, but the context has changed. Computer science education is dealing with rapid shifts in technology and society and today’s learners encounter a software ecosystem dominated by opaque but tantalizing systems and automation. This raises new questions: What does it mean to learn to code today? Can we re-imagine coding tools in a way that preserves learner agency, curiosity, and critical thinking? Could creative coding hold some of the answers?</p> <p>In this talk, we’ll share what we’re learning as stewards of Processing and how these efforts invite us to rethink creative coding’s role in the future of computer science education.</p> <p>More about Processing:</p> <ul> <li><a href="https://medium.com/processing-foundation/a-modern-prometheus-59aed94abe85">A Modern Prometheus. The History of Processing by Casey Reas and Ben Fry</a> </li> <li><a href="https://vimeo.com/60735314">Hello World! Processing - a documentary on creative coding</a> </li> <li><a href="https://eyeondesign.aiga.org/processing-the-software-that-shaped-creative-coding/">Processing: the Software that Shaped Creative Coding</a> </li> <li><a href="https://media.ccc.de/v/lgm25-upstream-2025-83647-the-state-of-processing-how-we-re-bringing-a-creative-coding-icon-back-to-life">The State of Processing: How We’re Bringing a Creative Coding Icon Back to Life - media.ccc.de</a></li> </ul>

Deep Learning Demystified - Having Fun with Neural Networks in Snap! (en)

<p>While "AI" is all the rage in current educational debates, the associated skills are mostly about prompting chat bots and generally becoming a productive user of commercial offerings. This talk will introduce new approaches to educate learners about the algorithms that make up modern AI systems, specifically neural networks, how to build them from scratch using free and open source materials, how to use them to diagnose data sets and enhance your personal projects, and how to form an informed critical and skeptical competence towards them.</p>

Learn Python with Execubot (en)

<p>Execubot (execubot.fr) is an open-source serious game designed to help students learn Python. It also offers a collaborative environment where both students and teachers can create and submit custom levels. Execubot can be used independently by learners or integrated into the classroom, with teacher-controlled settings that adapt the experience to specific learning objectives.</p>

Hedy - Textual programming made easy! (en)

<p>Hedy is an open-source programming language designed to make programming easier for children. It’s also easy for teachers without a technical background to adopt. Hedy bridges the gap between block-based tools like Scratch and text-based programming in Python.</p> <p>In this talk, we’ll explore how Hedy gradually introduces programming concepts in three stages: Basic, Advanced, and Expert. Across 16 levels, learners progress from simple print statements to fully functional Python code. We’ll share how teachers around the world use Hedy in classrooms, how our global translator community has made Hedy available in over 40 languages, and how open-source collaboration drives its continuous evolution.</p> <p>You will gain insight into Hedy’s design principles, pedagogical impact, and the challenges that come with developing an educational programming language. Whether you’re an educator, developer, or open-source contributor, come see how Hedy lowers the barriers to programming and inspires the next generation of coders!</p>