10 parts · 10 chapters

Linux Kernel Internals

Every container, database and server you run in production sits on Linux. This course opens the kernel along the paths your code takes: a syscall entering, a thread being scheduled, a page faulting in, a write reaching disk, a packet arriving. Each part ends with the /proc files and tools that show that path on a live machine.

Ten parts: the kernel map; the system call path; scheduling from CFS to EEVDF; memory management; the VFS and the page cache; the block layer and I/O schedulers; the networking stack from NIC to socket; cgroups and namespaces as the kernel half of containers; loadable modules and drivers; and how to read the kernel source and follow a change through its mailing lists.

the kernel map · the system call path · scheduling (CFS to EEVDF) · memory management · VFS and the page cache · the block layer · the networking stack · cgroups and namespaces · modules and drivers · reading the sourcesenior → staff · backend, infrastructure and SRE engineers
syscallsFrom the syscall instruction to the handler and back.
schedulerRun queues, virtual runtime, EEVDF, priorities and cgroups.
memoryPage tables, page faults, reclaim, the OOM killer.
filesVFS objects, the page cache, writeback, fsync.
networkNAPI, sk_buff, TCP, socket buffers.
isolationNamespaces and cgroups: containers are just processes.
Built on C and OSUses C and Systems Programming for the language and Operating Systems for the concepts; Systems Performance and Containers build on it.