BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//talks.osfc.io//osfc-2026//speaker//ZSRFRM
BEGIN:VTIMEZONE
TZID:Europe/Berlin
BEGIN:DAYLIGHT
DTSTART:20250917T000000
TZNAME:CEST
TZOFFSETFROM:+0200
TZOFFSETTO:+0200
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20251026T030000
RDATE:20261025T030000
TZNAME:CET
TZOFFSETFROM:+0200
TZOFFSETTO:+0100
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260329T030000
RDATE:20270328T030000
TZNAME:CEST
TZOFFSETFROM:+0100
TZOFFSETTO:+0200
END:DAYLIGHT
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:[Open Mic] Don’t Trust the Claim: Reproducible Firmware Evidence
  with WedgeBench - Keith Gariepy
DTSTART;TZID=Europe/Berlin:20260917T145000
DTEND;TZID=Europe/Berlin:20260917T151000
DTSTAMP:20260924T222509Z
UID:pretalx-osfc-2026-E8TZTM@talks.osfc.io
DESCRIPTION:“It passed on my laptop.” What can the next maintainer act
 ually verify?\n\nWedgeBench is an open-source workflow that turns bounded 
 malformed-input parser tests into reproducible\, machine-checkable evidenc
 e. It combines a deterministic corpus\, thin target adapters\, structured 
 artifacts\, and validation.\n\nI’ll walk through the go-tcg-storage refe
 rence integration\, deliberately alter a copy of the evidence\, and show t
 he validator rejecting the mismatch. We’ll examine what PASS establishes
 —and why it does not certify firmware safety\, authenticate the author\,
  or validate physical hardware.\n\nThis complements fuzzing\; it does not 
 replace it. You’ll leave with a public workflow to try and a concrete pa
 ttern for maintainer handoffs. Bring your skepticism: challenge the assump
 tions\, find a mutation the validator should reject but accepts\, or nomin
 ate the next real target.\n\nDon’t trust the claim. Run the workflow.
LOCATION:Main Room // Grote Zaal
URL:https://talks.osfc.io/osfc-2026/talk/E8TZTM/
END:VEVENT
END:VCALENDAR
