Loading…
Xen Summit 2026
Type: Embedded / Safety clear filter
Tuesday, September 15
 

10:45am PDT

Enabling Mixed-Critical Automotive Workloads on R-Car Gen5 (X5H) with Xen
Tuesday September 15, 2026 10:45am - 11:15am PDT
As automotive platforms shift to centralized compute, the key challenge is consolidating mixed-critical workloads while ensuring isolation, predictability, and visibility into cross-domain interference.
This session presents a Xen-based implementation on Renesas R-Car Gen5 (X5H) using a Dom0-managed architecture to run Android IVI, Linux service/AI workloads, and real-time control with defined domain partitioning.
We cover system architecture, bring-up, and integration challenges, including CPU allocation and device assignment trade-offs. We also demonstrate on-device AI inference using LLaMA 3.2 and Qwen models in dedicated Xen domains, focusing on coexistence with IVI and real-time workloads.
Finally, we present a cross-domain observability framework using xentop and a custom dashboard, providiāng visibility into CPU usage and interference patterns. The session shares practical insights and measured behavior for deploying mixed-critical workloads on X5H
Speakers
avatar for Harunobu Kurokawa

Harunobu Kurokawa

Senior Manager, Renesas Electronics Corporation
He has been involved in automotive Linux development since 2013 and actively contributes to Linux Foundation projects, including Automotive Grade Linux (AGL). At Renesas, a semiconductor company, he leads embedded Linux development and promotes OSS adoption. Since joining the AGL... Read More →
avatar for Jahan Murudi

Jahan Murudi

Senior System Architect | Software-Defined Vehicles, Renesas Electronics
Building next-generation automotive platforms on R-Car Gen5 with expertise in Xen virtualization, embedded Linux, and software-defined vehicles. Enabling secure multi-domain architectures, AI/ML workloads, and NPU acceleration.
Driving innovation in LLM/VLM, performance optimization, and advanced IVI solutions... Read More →
Tuesday September 15, 2026 10:45am - 11:15am PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

11:15am PDT

Initial Evaluation of Xen on the Renesas R-Car X5H Automotive SoC
Tuesday September 15, 2026 11:15am - 11:45am PDT
Hypervisors are used in automotive SoCs to consolidate multiple operating systems and provide system isolation.
However, publicly available reports on Xen running on automotive Arm SoCs are still limited, especially regarding basic performance characteristics and evaluation setups.
Therefore, sharing practical evaluation methods and measurement considerations based on real hardware is important when considering the use of Xen in the automotive domain.

This session introduces an initial evaluation effort for Xen on the Renesas R-Car X5H, an automotive SoC featuring 32 Arm Cortex-A720AE cores.
Using a native Linux environment as a baseline, it discusses the evaluation setup, measurement conditions, benchmark design, and preliminary results available at the time of the presentation
The session also covers considerations during the setup of the evaluation environment, basic configuration topics such as CPU assignment and domain configuration, practical issues encountered during measurement, and areas for further investigation in future evaluations.
Speakers
avatar for Yuya Hamamachi

Yuya Hamamachi

Software Enginner, Renesas Electronics
Yuya Hamamachi is software engineer for R-Car SoC device, has been working for OSS related task, such as R-Car Gen3 Starterkit support, R-Car S4 Whitebox SDK development, R-Car V4H Sparrow Hawk BSP development, and R-Car X5H .
Tuesday September 15, 2026 11:15am - 11:45am PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

11:45am PDT

Xen in cars: what's next?
Tuesday September 15, 2026 11:45am - 12:15pm PDT
Renesas Electronics provides high-end System-on-Chips for cars, including cockpit systems and driver assistance systems.
Xen is the reference solution used on our chips.

Let's dive into the typical usecases that we intend to cover with Xen, what links we do with other community projects, and how we can push the stack forward in the safety-critical or real-time domains.

This talk will also cover the security properties that are expected by automakers and chipmakers, and what commonalities we can find with the cloud industry.
Speakers
avatar for Frédéric Ameye

Frédéric Ameye

Head of Software Architecture, Renesas Electronics
Frederic has been working as SW developer for more than 15 years, in opensource communities and large industrial setups (defense, medical, heavy industry, automotive). Now he is leading the software strategy of Renesas Electronics for the automotive market.
Tuesday September 15, 2026 11:45am - 12:15pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

12:15pm PDT

Beyond the Reference Board - Porting AGL SoDeV's Xen Multi-Domain Architecture from V4H to RPi5
Tuesday September 15, 2026 12:15pm - 12:45pm PDT
AGL SoDeV's Xen multi-domain architecture -- Dom0less, DomD, and DomA -- was designed and validated on the Renesas R-Car V4H (Sparrow Hawk), the AGL reference platform. This talk shares our experience porting that architecture to the Raspberry Pi 5, a low-cost, widely available board, to make SDV prototyping accessible beyond specialized automotive silicon.
We walk through the concrete challenges encountered: GPU virtualization, where virtio-gpu alone is insufficient and virgl is required for 3D acceleration under a Xen DomD-backed setup; securing virtio-mmio transport with Xen 4.18 grant tables in a driver-domain configuration; and resolving Android guest (DomA) boot failures rooted in autostart defaults, a config-variable regression, and GPT label mismatches after reflashing. We also cover Yocto/kernel alignment between the reference workspace and downstream RPi5 layers, both pinned to Scarthgap 5.0 LTS.
Beyond the fixes, we discuss what changes and what stays the same when porting a safety-oriented, automotive-grade Xen design from a reference SoC to commodity hardware -- and what that means for lowering the barrier to SDV experimentation and community contribution.
Speakers
avatar for Yuichi Kusakabe

Yuichi Kusakabe

Chief Architect / OSPO Tech Lead, Honda
Yuichi Kusakabe is the Chief Architect at Honda Motor Co., Ltd. , AGL(Automotive Grade Linux) member and COVESA(Connected Vehicle Systems Alliance) member since 2011 with over twenty years of Automotive and Open Source Software Experience.
Prior to joining Honda Motor he worked f... Read More →
Tuesday September 15, 2026 12:15pm - 12:45pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

4:00pm PDT

Thermal Management in the Xen hypervisor for Automotive: Challenges and a Hybrid Approach
Tuesday September 15, 2026 4:00pm - 4:30pm PDT
The automotive industry is rapidly increasing its demand for hardware virtualization and is increasingly interested in the Xen Hypervisor as a key solution. This shift toward highly integrated systems introduces new challenges, particularly in thermal management, which are critical concerns for the automotive industry.
Xen hypervisor currently lacks a standardized framework for system-level thermal control, unlike traditional single-OS systems such as Linux. Thermal management in virtualized environments requires coordinated control across multiple components, but responsibilities are distributed across multiple layers—from firmware to hypervisor and operating systems—while no single component has full system visibility or authority over global coordination, where system-level control becomes significantly more difficult.
In this session, we present key challenges focusing on this gap and share our perspective on possible architectural directions, including a hybrid control approach that combines centralized policy concepts with distributed control. Through the session, we aim to engage the Xen community and encourage further exploration toward practical and standardized solutions.
Speakers
avatar for Kevin Hilman

Kevin Hilman

CTO, BayLibre
Kevin is the co-founder and CTO of BayLibre, an embedded software consultancy focused on low-level systems software like Linux, Zephyr, and trusted firmware, as well as GCC and LLVM toolchains. Kevin's primary interest in Linux has been in the various subsystems related Power Management... Read More →
avatar for Takahiko Gomi

Takahiko Gomi

Principal Engineer, SoC Software Enablement for Automotive Systems, Renesas
Takahiko Gomi is a Principal Engineer working on SoC software enablement for automotive systems at Renesas. His work focuses on power and thermal management, system-level architecture, and virtualization technologies including Xen.
He is involved in defining software requirements... Read More →
Tuesday September 15, 2026 4:00pm - 4:30pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

4:30pm PDT

Xen in Automotive: Challenges and Lessons Learned Toward Safety Certification
Tuesday September 15, 2026 4:30pm - 5:00pm PDT
As next-generation automotive systems increasingly demand hardware virtualization, several automotive companies are interested in Xen Hypervisor as a key solution. Understanding what the automotive industry truly needs from Xen is a critical topic for the Xen Community.

In this session, we present nine categories of automotive requirements for Xen Hypervisor — Isolation, VM Lifecycle, Device Virtualization, Security, Scheduling, Performance, Development Environment, Power Management, and Functional Safety — these requirements come from
production projects at Renesas.

Among them, Safety stands out as the most prioritized requirement in automotive projects. We will present our 18-month Xen Safety qualification activities, our approach to functional safety (ISO 26262) for Xen, key technical challenges we have encountered, and our planned contributions to the Xen Community.
Speakers
avatar for Gaku Inami

Gaku Inami

Principal, Renesas Electronics
Gaku Inami is Principal for automotive SoC device, has designed and proposed system architecture with mainly using Open-Source Software since 2019, recently focusing on the system design of integrated ECU(SoC+MCU) for next generation.
avatar for Tu Thanh Nguyen

Tu Thanh Nguyen

Renesas Design Vietnam, Senior Staff
Senior Staff Software Engineer working on the Xen Hypervisor project, participating activities related to Xen qualification and compliance with ASIL B functional safety requirements.
Tuesday September 15, 2026 4:30pm - 5:00pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

5:00pm PDT

Securing Consolidated ICS Platforms with Xen - Meeting IEC 62443 Isolation Requirements
Tuesday September 15, 2026 5:00pm - 5:30pm PDT
Industry 4.0 and OT/IT convergence are consolidating industrial systems onto single-SoC multicore platforms that combine real-time control, safety monitoring, HMI, and cloud connectivity. This cuts cost and complexity, but sharing hardware between trusted and untrusted software makes cybersecurity isolation the central challenge: a compromise of one component must not open a path into another. IEC 61508 requires freedom from interference (FFI), yet on a connected platform that guarantee holds only if the isolation layer is secure first. This presentation shows how the Xen hypervisor meets the challenge—using its Type-1 architecture, strong VM isolation, and Flask/XSM framework to separate safety-critical workloads from less-trusted components. Built under a secure development lifecycle aligned with IEC 62443-4-1 and mapped to the 4-2 component requirements at Security Level 4 (SL 4), the same isolation that satisfies IEC 62443 underpins the IEC 61508 FFI argument—keeping safety and security separately evaluated on a shared mechanism. The talk also maps IEC 62443 requirements to the EU Cyber Resilience Act.
Speakers
avatar for Senthil Kumar Rajagopal

Senthil Kumar Rajagopal

Functional Safety and Cybersecurity Manager, Advanced Micro Devices Inc
A highly enthusiastic functional safety expert with a total of 25 years of professional experience in designing software systems, functional safety, and ensuring cybersecurity compliance for embedded software products. Currently, I serve as a Functional Safety and Cybersecurity Manager... Read More →
Tuesday September 15, 2026 5:00pm - 5:30pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany
 
Wednesday, September 16
 

9:00am PDT

Robots Among Us: a Least-Privilege Xen Architecture for Safe Humanoid Robots
Wednesday September 16, 2026 9:00am - 9:30am PDT
Humanoid robots are poised to become one of the defining technologies of the next decade, with explosive growth projected across applications from hazardous industrial work to elderly care. They are also emerging as a promising new frontier for embedded virtualization. A single robot must fuse safety-critical motion control, real-time sensor processing, and rich AI workloads onto one heterogeneous platform. Real-time is critical: a humanoid robot that misses a deadline can fall, or injure someone. Safety is also essential; Xen must split responsibilities into separate domains, each granted only the permissions it needs.

This presentation will show how these pieces come together into a virtualization architecture for humanoid robots. It will detail the permissions assigned to each domain, and explain why minimizing privilege is essential to both Safety and Security in a machine that shares physical space with people. We will also discuss how Xen enforces strict isolation and bounded latency across multiple architectures to make the next generation of humanoid robots safe, responsive, and dependable.
Speakers
avatar for Stefano Stabellini

Stefano Stabellini

Fellow, AMD
Stefano Stabellini is a Fellow at AMD, where he leads system software architecture and the virtualization team. Previously, at Aporeto, he created a virtualization-based security solution for containers and authored several security articles. As Senior Principal Software Engineer... Read More →
avatar for Jason Andryuk

Jason Andryuk

AMD, AMD
Senior Member of Technical Staff at AMD working on Xen.
Wednesday September 16, 2026 9:00am - 9:30am PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

9:30am PDT

Toward Reproducible OSS Reference Integration: Challenges in Automotive Xen-on-Arm BSP Integration
Wednesday September 16, 2026 9:30am - 10:00am PDT
Automotive SDV systems require multiple domains—IVI, instrument cluster, real-time, and service—to coexist on a single Arm SoC. Combining AGL, Zephyr, and Xen is a promising approach for OSS-based reference integration. The key challenge is turning this virtualized setup into a continuously buildable and reusable foundation.
In this talk, Kurokawa presents ongoing integration work with AGL, Zephyr, and Xen on an automotive Arm platform. He outlines key challenges, including Device Tree configuration, role separation among Dom0, the hardware domain, and driver domains, and VirtIO backend placement. A central question is how SoC-specific hardware should be assigned, shared, or abstracted across domains while maintaining consistency with BSP configurations.
He shares these challenges as practical feedback to the Xen community. Many are common issues as Xen expands into embedded and edge use cases. He discusses approaches in configuration, build, and testing, and provides actionable guidance for building maintainable OSS-based integration platforms.
Speakers
avatar for Harunobu Kurokawa

Harunobu Kurokawa

Senior Manager, Renesas Electronics Corporation
He has been involved in automotive Linux development since 2013 and actively contributes to Linux Foundation projects, including Automotive Grade Linux (AGL). At Renesas, a semiconductor company, he leads embedded Linux development and promotes OSS adoption. Since joining the AGL... Read More →
Wednesday September 16, 2026 9:30am - 10:00am PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

10:00am PDT

ARINC 653 on Xen: A Unikraft Safety Architecture
Wednesday September 16, 2026 10:00am - 10:30am PDT
This talk presents a safety-critical architecture built entirely on the open-source Xen hypervisor, Linux and Unikraft unikernel(s) as self-contained per-partition runtimes. We cover how this environment is a basis for implementing the ARINC 653 avionics standard, static configuration, and how a control domain pattern provides system management without Dom0 privileges. We discuss real challenges encountered — debug/trace without xl, scheduler extensions for fault tolerance scenarios, and device tree validation at boot — and identify areas where Xen community collaboration would accelerate safety-relevant capabilities.
Speakers
avatar for Matthew Weber

Matthew Weber

Chief Software Architect, The Boeing Company
Matthew Weber is the Chief Software Architect for Boeing Linux, leading certified Linux and hypervisor architectures across Boeing business units. He chairs the ELISA Aerospace Working Group, and sits on the governing boards of both the ELISA Project and the Xen Project. Matt holds... Read More →
Wednesday September 16, 2026 10:00am - 10:30am PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

1:45pm PDT

Xen Functional Safety Certification (an update)
Wednesday September 16, 2026 1:45pm - 2:15pm PDT
As AMD advances efforts to safety-certify the upstream Xen hypervisor, this presentation provides an update on the past year's progress and roadmap. Xen, a type-1 hypervisor with a self-contained codebase, continues to gain traction in automotive and industrial applications due to its robust isolation, security, and virtualization capabilities.

A central theme this year is reducing the certifiable code footprint through changes we intend to upstream in the near future. We apply several dead-code-elimination techniques, such as gating management hypercalls (`MGMT_HYPERCALLS`), adding AMD restricted-feature configurations (`AMD_RESTRICTED_*`), and enabling linker garbage collection of unused sections.

Alongside the code, we have formalized Xen's domain-facing behavior into requirements and architecture specification, both of which we plan to upstream as a shared, verifiable baseline for the community.

On verification, we will share tests spanning domain-based tests, a self-test framework, GDB fault-injection test framework, and QEMU qtest-based cases. Finally, we present the current structural coverage on Arm64 and x86_64, along with our roadmap to close the remaining gaps.
Speakers
avatar for Penny Zheng

Penny Zheng

Staff Software Engineer, AMD
Penny Zheng is s staff software engineer on AMD, focusing on virtualization on automotive scenario, especially for GPU virtualization.
Wednesday September 16, 2026 1:45pm - 2:15pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

2:15pm PDT

Flight-Grade Xen: DO-178C Reverse Engineering for an example in list.h
Wednesday September 16, 2026 2:15pm - 2:45pm PDT
What does the term “Low Level Requirement” (LLR) mean to Xen? This talk provides an update to the ongoing work of Xen’s Functional Safety Working Group in the form of a worked case study for a challenging example: list.h We will show

1) When we should use a technique called “requirements mapping” (to reuse requirements rather than invent them ourselves)
2) How to test the preprocessor macros and occasional static inline functions in our list.h example to satisfy the DO-178C’s LLR-to-verification “trace data” obligations
3) How to produce a subject matter expert (SME) to review list.h LLRs (i.e., for “necessary and complete LLR”), via a training course about its RCU algorithm and the requirements behind that algorithm.

We hope to engage the broader Xen community’s SMEs by focusing not on “FuSa” specifically, but more broadly on “How does Xen really work?”
Speakers
avatar for Mark Brown

Mark Brown

Parry Labs, Parry Labs
Mark Brown is the Director of Safety Critical Systems at Parry Labs. Parry Labs develops multiple types of soft-updatable modularity for vehicles and avionics, in order to promote a Modular Open Systems Approach (MOSA). Mark has worked with a range of operating systems, type-1 hypervisors... Read More →
Wednesday September 16, 2026 2:15pm - 2:45pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

2:45pm PDT

Safety Cases as Data: The SPDX Functional Safety Profile and Lessons from Zephyr
Wednesday September 16, 2026 2:45pm - 3:15pm PDT
Xen and Zephyr are walking parallel paths toward functional safety within the Linux Foundation, and both face the same problem: a safety case is a large, manually maintained argument that drifts the moment the design changes, and is hard to exchange between the projects, suppliers, and integrators who depend on it. This talk shares where Zephyr has gotten with a data-driven approach, and opens a conversation about what it could mean for Xen.
We start with SPDX 3.1's Functional Safety profile, which gives the safety case a machine-readable form: requirements and their refinement, verification activities, pass/fail evaluations, evidence, and assumptions of use, expressed as a graph that tools can produce, exchange, and check. We then show how Zephyr leverages it in practice—generating a "safety SBOM" from project content rather than assembling a safety case by hand, recomputing verdicts as code evolves, and detecting which evidence has gone stale.
Speakers
avatar for Nicole Pappler

Nicole Pappler

Senior Safety Expert, AlektoMetis.com
Nicole has worked in different projects developing safety relevant embedded software before starting as an independent assessor.
With now more than twenty years of experience in the industry, she supported several customers to show their compliance with safety, security and quality standards. Currently she is utilizing her experience regarding the development of highly reliable software to enable open source... Read More →
Wednesday September 16, 2026 2:45pm - 3:15pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

3:15pm PDT

Formal Methods for Xen's Safety and Security
Wednesday September 16, 2026 3:15pm - 3:45pm PDT
We will explore how different formal methods like model checking and theorem proving can be used to certify the correctness of Xen's working. We will also discuss the different benefits of a verified kernel, especially for embedded systems, and the various certifications.
Speakers
avatar for Thomas Courrege

Thomas Courrege

Student Researcher
Student at EPITA, a French engineering school, specializing in security, networks, and industrial systems, with a particular interest in formal methods and kernel verification.
Wednesday September 16, 2026 3:15pm - 3:45pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany

4:00pm PDT

Display Para-Virtualization
Wednesday September 16, 2026 4:00pm - 4:30pm PDT
In recent years, GPU para-virtualization on Xen has evolved to support increasingly complex automotive workloads. While prior work focused on graphics and compute virtualization, display para-virtualization introduces new challenges due to its interaction with hardware composition pipelines and real-time requirements. In this session, Ray presents his team’s latest work on display para-virtualization, focusing on Multi-Plane Overlay (MPO) virtualization and the Virtual Primary Plane (vPP). These mechanisms extend the VirtIO GPU model to enable guest VMs to utilize host display hardware. He explains how MPO virtualization exposes multiple display planes to guest VMs, allowing composition to be offloaded to hardware. The vPP abstraction provides a stable primary display surface, decoupling guest behavior from host specifics. He also discusses GPU recovery integration and outlines validation approaches and future directions.
Speakers
avatar for Ray Huang

Ray Huang

Principal Software Engineer, AMD
Ray Huang (Huang Rui) is a kernel developer and leads AMD Linux platform solution team that works on AMD CPU, APU, and GPU enabling. He works on multiple components in the Linux kernel including GPU kernel DRM graphic and CPU power management support. Recently, he and his team focus... Read More →
Wednesday September 16, 2026 4:00pm - 4:30pm PDT
HEADS office - Gold Room Einsteinring 30, 85609 Aschheim, Germany
 
Share Modal

Share this link via

Or copy link

Filter sessions
Apply filters to sessions.