Part 0 · 1 chapters · ~8 min

The Kernel Map

What a kernel does, monolithic versus microkernels, the source tree layout (kernel, mm, fs, net, drivers, arch), user space and kernel space, contexts (process, interrupt, softirq), kernel threads, releases and stable trees, and where to look on a live system (/proc and /sys).

1

Subsystems and the source tree

directorywhat lives there
kernel/scheduler (kernel/sched), signals, fork, timers, cgroups
mm/page allocator, slab, page cache, reclaim, OOM killer
fs/VFS and file systems (ext4, xfs, btrfs, proc)
net/sockets, TCP/IP, netfilter
block/block layer and I/O schedulers
drivers/device drivers: the largest directory
arch/per-architecture code: entry, interrupts, page tables
code
uname -r                       # running kernel version
cat /proc/version              # build details
ps -eo pid,comm | grep '\['    # kernel threads appear in brackets: [kworker/0:1], [ksoftirqd/0], [kswapd0]
ls /sys/class/net              # devices and their attributes are files under /sys

Execution contexts: kernel code runs in process context (on behalf of a syscall, may sleep), hardirq context (an interrupt handler, must be quick, cannot sleep) or softirq context (deferred work such as network receive processing). Many kernel bugs are code that sleeps in the wrong context.

THE KERNEL MAP
subsystems between your process and the hardware
user spaceyour process, libc, runtimessystem call interfaceentry, dispatch, returnprocess, memory, file and network subsystemsscheduler, mm, VFS, netdriversblock, network, GPU, USB: most of the codearchitecture codex86, arm64: interrupts, page tables, entryhardware
swipe the figure sideways, or tap expand for full screen
1/4
one big program
Linux is a monolithic kernel: scheduler, memory manager, file systems, network stack and drivers run in one address space with full privileges, as one program.
monolithic, one address spacefast, no isolation between parts