Part 0 · 1 chapters · ~8 min
The Kernel Map
What a kernel does, monolithic versus microkernels, the source tree layout (kernel, mm, fs, net, drivers, arch), user space and kernel space, contexts (process, interrupt, softirq), kernel threads, releases and stable trees, and where to look on a live system (/proc and /sys).
1
Subsystems and the source tree
| directory | what lives there |
|---|---|
| kernel/ | scheduler (kernel/sched), signals, fork, timers, cgroups |
| mm/ | page allocator, slab, page cache, reclaim, OOM killer |
| fs/ | VFS and file systems (ext4, xfs, btrfs, proc) |
| net/ | sockets, TCP/IP, netfilter |
| block/ | block layer and I/O schedulers |
| drivers/ | device drivers: the largest directory |
| arch/ | per-architecture code: entry, interrupts, page tables |
code
uname -r # running kernel version cat /proc/version # build details ps -eo pid,comm | grep '\[' # kernel threads appear in brackets: [kworker/0:1], [ksoftirqd/0], [kswapd0] ls /sys/class/net # devices and their attributes are files under /sys
Execution contexts: kernel code runs in process context (on behalf of a syscall, may sleep), hardirq context (an interrupt handler, must be quick, cannot sleep) or softirq context (deferred work such as network receive processing). Many kernel bugs are code that sleeps in the wrong context.
THE KERNEL MAP
subsystems between your process and the hardware
swipe the figure sideways, or tap expand for full screen
1/4
one big program
Linux is a monolithic kernel: scheduler, memory manager, file systems, network stack and drivers run in one address space with full privileges, as one program.
monolithic, one address spacefast, no isolation between parts