Pengutronix at the Open Source Firmware Conference 2026
This year's Open Source Firmware Conference took place from September 15th to 17th at Pakhuis de Zwijger in Amsterdam. Marco Felsch and I attended for Pengutronix and had three talks between us:
- Setting Boundaries: Securing overlooked OP-TEE attack vectors (Marco, Day 1)
- barebox and the Last Nasal Demon Riders (me, Day 1)
- Runtime Access Control in the Bootloader (me, Day 3)
The program's focus was in the eye of the beholder: the firmware people we talked to were convinced this edition was mostly about bootloaders, while we bootloader people were convinced it was rather about BMCs. We didn't find out if any BMC people thought it was too much other firmware, but if they do, then there was apparently something for everyone. :-)
Below are some of the talks that stuck with us. See the full schedule for more.
Day 1
The morning got off to a strong start with Sahaj Sarup's Memory-Mapped FPGA Peripherals on Zephyr. He described his quest to memory-map an FPGA into a microcontroller running Zephyr via the FMC and QSPI controllers. I love talks like this.
Marco and I had our talks later that day. Marco's talk made the point that running OP-TEE in the Secure World is not the same as running it securely: loading it takes careful coordination between several firmware stages as there is no shortage of creative alternative ways to try to circumvent memory protections. His work on closing these gaps resulted in patches across TF-A, OP-TEE and barebox.
For my first talk that week, I nerded out about one particular kind of fix: the ones whose commit message opens with a compiler version, followed by a disassembly with a fat arrow pointing at where programmer intent and code generation diverge. The slides collect the caveats we ran into writing bare metal C for barebox.
The talk that drew the most questions that day was the 17:20 slot, Agentic AI Software Debugging in OpenBMC by Jia Chunhui. I have been pondering LLM use for anomaly detection for a while: I have been logging all my interactive Labgrid use for the last three years. With that history at hand, it's possible to see how things like the dmesg output changes across kernel versions, provided you know what to look for. A local LLM with the right harness might just be able to spot such discrepancies on its own.
Day 2
The second day moved a bit away from BMCs and closer to our home turf of SoC bring-up and boot chains.
Bringing up Linux on a memory-safe CHERI RISC-V system by Alice Ziuziakowska was a gentle introduction to CHERI. Jorge Ramirez-Ortiz brought up a fully open TrustZone stack on Qualcomm's QCM6490, from TF-A at EL3 through OP-TEE to U-Boot and Linux at EL2, all built from source. For customers who don't use the evaluation kits, however, documentation and custom board memory designs are still out of reach. Hopefully not for long as these are some quite cool SoCs.
There was an impromptu session on GNU poke by Mohammad-Reza Nabipoor. We look at a lot of hexdumps at Pengutronix and flip our fair share of bits, so this one piqued our interest right away. I am still thinking about how to best use it live on the hardware instead of only on files. Apparently one can instantiate custom I/O spaces for that, maybe something to hook up to barebox RATP.
Simon Glass looked beyond EFI, which was designed in the 1990s for a closed-source world and brings a lot of complexity that, he argues, open source systems don't need. I wouldn't want to force shim on anybody not needing it either, but I could imagine our future projects booting Linux through its EFI stub even if nothing else changes. Keeping the MMU enabled across the handover and physical ASLR? Yes, please.
Jiji Freya Daniel Maslowski made a good case in Boot Chains and Build Systems for why build systems should describe how the components on a SoC interact.
Mate Kukri closed the day with native raminit for Bay Trail and how he reverse engineered the vendor blob by tracing its execution.
After that, the hallway track moved onto two boats for a cruise through Amsterdam's canals.
Day 3
The last day was a mix of lightning talks and open mic slots as well as a parallel workshop track. One of the lightning talks was mine, on barebox security policies (slides). These let a single bootloader image adapt to the development, factory and field stages of a device instead of shipping a zoo of nearly identical images. Security Policies were still in the making when I spoke about bootloader security at last year's ELC-E and Linux Security Summit, both also in Amsterdam, and are now upstream.
We also took part in the Arm SystemReady Workshop. The topic is gaining relevance for us: since v2026.01.0, barebox can act as EFI firmware instead of only running without EFI or under EFI. A future goal would be to designate an upstream platform in barebox as EFI reference platform and get it to pass ARM's Architecture Compliance Suite for the Embedded Base Boot Requirements with Device Tree.
Wrap-up
The conference was well organized and the venue was a nice place to spend three days in. We met nice people, ate well and had interesting conversations with attendees throughout.
OSFC has been alternating between Europe and the US, with last year's edition held in Sunnyvale, CA. We will probably not be there for the next one, even though we hear the US editions are more coreboot-y and therefore likely closer to our day-to-day. We are, however, looking forward to it presumably returning to Europe in 2028.
Further Readings
Secure Boot on Rockchip RK3588
The Rockchip RK3588 SoC provides hardware features to verify the integrity and legitimacy of firmware running on a device. I presented how to enable Rockchip Secure boot with barebox at the Embedded Recipes conference 2026 in Nice. This blog post goes into more details on how Secure Boot works on the RK3588, how to enable Secure Boot in barebox, and what to take into consideration when integrating it into devices.
Girls' Day 2026
Unter dem Motto "Open Source - Open Future!" waren im Rahmen des Girls' Day am 23. April 2026 vier junge Frauen bei Pengutronix zu Gast. Zu Beginn gab es eine kurze Vorstellung von Pengutronix und natürlich die Antwort auf die Frage, was eigentlich dieses Embedded ist.
Pengutronix auf den Chemnitzer Linux Tagen 2026
Wir freuen uns, auch in diesem Jahr bei den Chemnitzer Linux Tagen dabei sein zu können. Wie jedes Jahr sind die CLT eine willkommene Gelegenheit, Freunde zu treffen und sich über Linux, Open Source und den Rest der Welt auszutauschen. Auch in diesem Jahr stellen wir uns mit einem eigenen Stand vor und freuen uns, vier Vorträge zum Vortragsprogramm beitragen zu können.
Pengutronix auf der embedded world 2026
Meet us at the embedded world 2026 in Nuremberg. Like every year you'll find us in hall 4, booth 4-261. As usual, we will be showing demonstrators on current topics at our exhibition stand. In addition, we are again inviting you to the RAUC and Labgrid community meetup.
Pengutronix bei der Embedded Testing 2026
Pengutronix ist in diesem Jahr wieder Partner der der Embedded Testingu nd ist dort sowohl mit einem Stand als auch mit einem Vortrag vertreten. Die Embedded Testing findet am 24. und 25. Februar 2026 in Unterhaching bei München statt.Pengutronix at FOSDEM and OE Workshop 2026
On January 31st and Febuary 1st 2026 it is once again time for waffles, Belgian beer and Open Source: FOSDEM will take place at ULB in Brussels. With over 8k hackers, FOSDEM is the biggest and most important Open Source conference in Europe. One other event riding the wave of FOSDEM is the the OpenEmbeddedWorkshop. The full list of co-located events is here. We are participating in both FOSDEM and OE Workshop and are looking forward to many interesting discussions with developers of different Open Source software components – be it the Linux kernel, Yocto, Labgrid, Debian, and others...
Pengutronix at SPS in Nuremberg
After some years of absence, Pengutronix is back at the SPS 2025 in Nuremberg. You will find us in hall 6, booth 6-350C. We are looking forward to connecting with old and new friends, partners and customers. As usual, we will be showcasing demonstrators on current topics at our exhibition stand.
Bringing Barebox into OE-Core (Yocto)
This blog post chronicles the multi-year journey to get Barebox accepted into OE-Core—from the early attempts to the eventual success in October 2024. Along the way, we’ll explore the technical hurdles we faced, the community discussions that shaped the process, and the improvements we added to both OE and Barebox.DSA in Barebox
The v2022.05.0 Release of barebox introduced initial support for the Distributed Switch Architecture (DSA) Framework. DSA is originally a subsystem from the Linux Kernel, which exposes the individual ports of a network switch IC as virtual network interfaces.
Wir haben doch etwas zu verbergen: Schlüssel mit OP-TEE verschlüsseln
Moderne Linux Systeme müssen häufig zwecks Authentifizierung bei einer Cloud- basierten Infrastruktur oder einer On-Premise Maschine eigene kryptografische Schlüssel speichern. Statt der Verwendung eines Trusted Platform Modules (TPM), bieten moderne ARM Prozessoren die TrustZone-Technologie an, auf deren Basis ebenfalls Schlüssel oder andere Geheimnisse gespeichert werden können. Dieses Paper zeigt die Nutzung des Open Portable Trusted Execution Environments (OP- TEE) mit der Standardkonformen PKCS#11 Schnittstellen und i.MX6 Prozessoren von NXP als Beispiel.