10 parts · 10 chapters
Linux Kernel Internals
Every container, database and server you run in production sits on Linux. This course opens the kernel along the paths your code takes: a syscall entering, a thread being scheduled, a page faulting in, a write reaching disk, a packet arriving. Each part ends with the /proc files and tools that show that path on a live machine.
Ten parts: the kernel map; the system call path; scheduling from CFS to EEVDF; memory management; the VFS and the page cache; the block layer and I/O schedulers; the networking stack from NIC to socket; cgroups and namespaces as the kernel half of containers; loadable modules and drivers; and how to read the kernel source and follow a change through its mailing lists.
syscallsFrom the syscall instruction to the handler and back.
schedulerRun queues, virtual runtime, EEVDF, priorities and cgroups.
memoryPage tables, page faults, reclaim, the OOM killer.
filesVFS objects, the page cache, writeback, fsync.
networkNAPI, sk_buff, TCP, socket buffers.
isolationNamespaces and cgroups: containers are just processes.
00
The Kernel Map
Subsystems and the source tree
1 ch · ~8 min01The System Call Path
Following read() through the kernel
1 ch · ~8 min02Scheduling: CFS and EEVDF
Who runs next
1 ch · ~8 min03Memory Management
Pages, faults, reclaim and the OOM killer
1 ch · ~8 min04The VFS and the Page Cache
Files in memory
1 ch · ~8 min05The Block Layer
From bio to device
1 ch · ~8 min06The Networking Stack
Receive, transmit, and where packets drop
1 ch · ~8 min07cgroups and Namespaces
The kernel half of containers
1 ch · ~8 min08Modules and Drivers
A minimal module and a character device
1 ch · ~8 min09Reading the Source
A reading plan
1 ch · ~8 minBuilt on C and OSUses C and Systems Programming for the language and Operating Systems for the concepts; Systems Performance and Containers build on it.