<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Projects on Giovanni Nicosia</title>
    <link>https://giovanninicosia.dev/projects/</link>
    <description>Recent content in Projects on Giovanni Nicosia</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Fri, 27 Mar 2026 00:00:00 +0200</lastBuildDate>
    <atom:link href="https://giovanninicosia.dev/projects/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Reproducible TRNG Integration in a RISC-V SoC</title>
      <link>https://giovanninicosia.dev/projects/thesis/</link>
      <pubDate>Fri, 27 Mar 2026 00:00:00 +0200</pubDate>
      <guid>https://giovanninicosia.dev/projects/thesis/</guid>
      <description>&lt;p&gt;This master&amp;rsquo;s thesis was developed in the context of the &lt;strong&gt;VE-HEP&lt;/strong&gt; (Versatile Hardware Execution Platform) project, a research initiative aimed at building a flexible and secure RISC-V-based SoC. The core contribution is the integration of a physical True Random Number Generator (TRNG) — designed following the &lt;strong&gt;OpenTRNG&lt;/strong&gt; open-source framework — directly into the SoC&amp;rsquo;s peripheral bus.&lt;/p&gt;&#xA;&lt;p&gt;The TRNG IP is exposed to the processor via an &lt;strong&gt;APB3 wrapper&lt;/strong&gt; written in SpinalHDL, with a well-defined register map that allows firmware to configure the entropy source, read raw samples, and monitor health-test status. A lightweight C firmware driver was implemented to exercise the peripheral and validated end-to-end through functional simulation. The hardware description was also cross-verified at the Verilog netlist level to ensure correctness after synthesis.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ESCAPE Seminars — QR Attendance System</title>
      <link>https://giovanninicosia.dev/projects/escape-qr/</link>
      <pubDate>Fri, 06 Mar 2026 00:00:00 +0100</pubDate>
      <guid>https://giovanninicosia.dev/projects/escape-qr/</guid>
      <description>&lt;p&gt;The &lt;strong&gt;ESCAPE Seminars&lt;/strong&gt; attendance system was built to automate registration and presence tracking for a seminar series at Politecnico di Torino. Attendees authenticate using their &lt;strong&gt;institutional PoliTO credentials&lt;/strong&gt; through a SAML2 flow backed by a &lt;strong&gt;Keycloak&lt;/strong&gt; Identity Provider, ensuring that only enrolled students can register — without storing passwords in the application.&lt;/p&gt;&#xA;&lt;p&gt;The backend is a &lt;strong&gt;Django REST API&lt;/strong&gt; connected to a &lt;strong&gt;PostgreSQL&lt;/strong&gt; database. Upon successful authentication, the system generates a unique QR code for each session and user pair. Organizers can scan codes in real time via a dedicated endpoint, and an admin dashboard provides attendance summaries, CSV exports, and per-seminar statistics.&lt;/p&gt;</description>
    </item>
    <item>
      <title>eBPF Vulnerability Testing Suite</title>
      <link>https://giovanninicosia.dev/projects/ebpf-vulns/</link>
      <pubDate>Thu, 25 Sep 2025 00:00:00 +0200</pubDate>
      <guid>https://giovanninicosia.dev/projects/ebpf-vulns/</guid>
      <description>&lt;p&gt;This project is a structured testing suite that demonstrates real-world security vulnerabilities in &lt;strong&gt;eBPF and XDP&lt;/strong&gt; kernel programs, mapping each finding to coding rules defined in &lt;strong&gt;ISO/IEC TS 17961&lt;/strong&gt; (C Secure Coding Rules). The suite covers issues such as out-of-bounds memory access, uninitialized map values, integer overflows in packet offset calculations, and verifier bypass patterns.&lt;/p&gt;&#xA;&lt;p&gt;Each test case ships as a pair of intentionally vulnerable and patched C programs, loadable into the kernel via &lt;code&gt;bpftool&lt;/code&gt;. The test environment is isolated inside a &lt;strong&gt;KVM/QEMU&lt;/strong&gt; virtual machine to prevent any risk of destabilising the host kernel during verifier stress tests and deliberately crashing probes.&lt;/p&gt;</description>
    </item>
    <item>
      <title>PoliTO Students — Open Resources for Students</title>
      <link>https://giovanninicosia.dev/projects/polito-students/</link>
      <pubDate>Wed, 18 Jun 2025 00:00:00 +0200</pubDate>
      <guid>https://giovanninicosia.dev/projects/polito-students/</guid>
      <description>&lt;p&gt;&lt;strong&gt;PoliTO Students&lt;/strong&gt; is a GitLab organization that collects and publishes open-source lecture notes, exercise sheets, and study guides for courses at Politecnico di Torino. All documents are written in LaTeX or Typst and built automatically on every push via &lt;strong&gt;GitLab CI/CD pipelines&lt;/strong&gt;, with the resulting PDF artifacts published to &lt;strong&gt;GitLab Pages&lt;/strong&gt; and made freely available to all students.&lt;/p&gt;&#xA;&lt;p&gt;Each document repository packages its own build toolchain as a &lt;strong&gt;Nix derivation&lt;/strong&gt;, ensuring that the exact same compiler versions and font sets are used both locally and in CI. Contributors can enter a ready-to-use shell with &lt;code&gt;nix develop&lt;/code&gt; or &lt;code&gt;devenv shell&lt;/code&gt; without installing anything system-wide, and the CI runners consume the same derivation for byte-for-byte reproducible PDFs.&lt;/p&gt;</description>
    </item>
    <item>
      <title>NixOS System Configuration</title>
      <link>https://giovanninicosia.dev/projects/nix-config/</link>
      <pubDate>Wed, 25 Oct 2023 00:00:00 +0200</pubDate>
      <guid>https://giovanninicosia.dev/projects/nix-config/</guid>
      <description>&lt;p&gt;This repository is a &lt;strong&gt;Nix Flake&lt;/strong&gt; that manages the complete, declarative configuration of all my personal machines — development workstations and a homelab server — from a single, version-controlled source of truth. Each host is defined as a NixOS configuration module that composes shared profiles (desktop environment, development tools, security hardening) with host-specific settings, making it straightforward to keep multiple machines consistent or diverge them intentionally.&lt;/p&gt;&#xA;&lt;p&gt;The homelab server runs a set of self-hosted services deployed as &lt;strong&gt;NixOS containers&lt;/strong&gt;, isolated from each other and from the host. Networking between containers and to the outside is managed through a &lt;strong&gt;VPN&lt;/strong&gt; (WireGuard), with firewall rules derived directly from the NixOS configuration. Secrets such as API keys, database passwords, and VPN private keys are encrypted at rest using &lt;strong&gt;SOPS&lt;/strong&gt; (Secrets OPerationS) and decrypted at activation time, so no plaintext secrets ever land in the Nix store.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
