Skip to content

Open Source

My upstream work centers on firmware that boots servers and devices, the protocols they use to prove what they are running, and getting software to run well on new hardware. Everything below is merged upstream; each item links to the change itself.

Boot firmware

u-root (LinuxBoot)

u-root is the Go userland that LinuxBoot uses to replace UEFI’s boot stage with Linux. I added RISC-V support to its kexec path.

Android Generic Bootloader (AOSP libbootloader)

Fixes to the documented QEMU flows for GBL, each one a command that failed as written on a current distribution:

Platform security

DMTF libspdm

libspdm is DMTF’s reference implementation of SPDM, the protocol devices use to authenticate and establish secure sessions with the platform.

  • Fix key update rollback for Specula cluster A.1 and A.3 — a failed KEY_UPDATE could leave a session with half-updated keys and no way back. The fix marks the backup valid before deriving new keys and rolls back every failure arm, with unit tests that fail against the old code.

LLM inference on RISC-V

llama.cpp

Matrix kernels for the SpacemiT X60’s IME matrix extension:

Android kernel

Documentation fixes in the Android Common Kernel (kernel/common), for the binder, dma-buf, dma-heap and UFS interfaces:

Systems tools

  • elfuse (7 merged) — runs Arm64 and x86-64 Linux ELF binaries on macOS. My changes bring its Linux syscall emulation closer to the kernel: futex refusals, CLONE_THREAD exit signalling, AT_EMPTY_PATH, deferred stack unmapping.
  • codetrial (6 merged) — a live technical interview simulator.
  • frama-c-mcp (3 merged) — an MCP server that gives AI agents the Frama-C formal verification tools.
  • shecc — a regression test for the self-hosting, educational C compiler.
  • sse2neon — dropped a <fenv.h> dependency that leaked FE_* macros into every includer.

Documentation