// the find
systerel/S2OPC
Mirror repository for open-source OPC-UA Toolkit designed with security and embedded devices in mind. Main repository is on gitlab:
S2OPC is a C implementation of an OPC UA client/server stack and PubSub, built for industrial and embedded targets where footprint and certifiability matter more than feature count. It suits teams that need an OPC UA server or client in C under Apache 2.0, with Systerel selling support on top. This GitHub repo is a mirror; the main project and its issue tracker live on GitLab.
The service logic is formally modelled in B, and the bsrc tree has machines for sessions, browse continuation points and subscription queues, so the formal work is in the repo rather than only in a slide deck. Verification is layered: Frama-C and TrustInSoft analysis, Coverity, sanitizer builds, libcheck unit tests, fuzzing, and interop runs against FreeOpcUa and open62541. The address space can be compiled into the binary through a Python generator that turns UANodeSet XML into C, so an embedded server doesn't need an XML parser at runtime. Build-time switches such as S2OPC_NANO_PROFILE, S2OPC_NODE_MANAGEMENT and S2OPC_EVENT_MANAGEMENT, plus a choice of mbedtls or CycloneCRYPTO, let you cut the feature set down to what a device needs.
The GitHub side is a mirror. Issues, merge requests and the compilation wiki are on GitLab, so anyone hitting a build problem or wanting to contribute has to leave GitHub to get anything done. Server coverage has real gaps: there is no TransferSubscriptions and no SetTriggering, HistoryRead is ReadRaw only and has to be implemented by the application, and the PubSub JSON encoding supports only a subset of types with no discovery. If you need subscription transfer after a reconnect or historical access, you will be writing that part yourself. Building it means assembling mbedtls 3.6 or later, Check, expat and a CMake toolchain by hand. The tested matrix in the README (Debian 11, Windows 10 with Visual Studio 2017) is dated, so expect to work out the dependency versions yourself. The UACTT compliance tool behind the OPC Foundation certification is restricted to corporate members, so outside users cannot rerun the suite the demo server passed.