`/proc` as the Process Interface
/proc is not a directory of files. Nothing under it is stored anywhere, and nothing you cat was
/proc is not a directory of files. Nothing under it is stored anywhere, and nothing you cat was
The central Linux idiom derived from scratch, after which kobjects, the VFS, and the device model all become readable at once.
exec() is the complement to fork(), in the precise sense of doing the
fork()'s contract sounds absurd the moment you say it out loud: duplicate this entire process,
The Virtual Address Space described the layout a process's pointers
What the kernel brings up and in what order, and why driver initialisation order is a level rather than a list.
Mounting the real root, the three constantly-confused ways to change it, and what makes PID 1 special.
The kernel's unit of scheduling — not the two hundred fields, the twelve that matter, grouped by concern.
Every allocation decision in the kernel eventually comes down to one distinction: physically
A Debian VM for the labs that need systemd and real block devices, then an honest account of which labs WSL2 can and cannot run.
A static BusyBox, a directory skeleton, and an /init packed into an initramfs — early user space made concrete instead of magical.
Every address a program uses is invented. 0x400000 in one process and 0x400000 in another refer to
"We do not break user space" is usually quoted as a slogan. Treated as an engineering constraint it is
A syscall has no calling convention of its own. It borrows one — the same general-purpose registers a
atomict, the operation families, the ordering each does and does not carry, and why refcountt exists separately.
GRUB 2, systemd-boot, and direct EFI stub boot — and the four things any boot loader must do.
The canonical QEMU invocation every later lab reuses, explained flag by flag.
From defconfig to a bootable image, including the debug options that make the rest of this section's labs possible.
C++ has no built-in package manager. Third-party tools fill this gap. The two dominant options are vcpkg (Microsoft, integrates tightly with CMake and Visual Studio) and Conan (JFrog, cross-platform, more configuration power). Both work on Windows and Linux.
The pinned kernel for this section, v6.18, does not run CFS as its fair-class scheduler — it runs
Everything earlier in this folder schedules tasks. A container, a service, or a user session is a
The decision table, six worked selections, and the cost hierarchy from an uncontended atomic to cross-NUMA ping-pong.
There is a rule that sounds like bureaucracy and is not: the kernel may never dereference a user
A task's identity is not one number. There are four user IDs, four group IDs, a supplementary group
Attaching a debugger to the virtual CPU, loading vmlinux symbols, and walking live kernel structures — the highest-leverage skill in this section.
Busy-wait delays, sleeping delays, and the guarantee every one of them lacks.
The Page Fault Handler named doanonymouspage() and dowppage() as
The method has to come before any tool. "The application is janky" is not a scheduling problem until you
Same kernel, different packaging: what genuinely varies between distributions and the much longer list of things that do not.
x86-64 from 16-bit entry through protected mode and early page tables into long mode, and the far simpler arm64 equivalent.
CFS and Virtual Runtime ended on a specific complaint: CFS had exactly one
Embedded software runs on hardware that was never meant to run much of anything: a few hundred
C has no exceptions, no try/catch, and no automatic unwinding. The kernel has instead settled on one
A process's exit status has to survive the process, because POSIX gives the parent the right to ask
Why "never break user space" and "break modules freely" are a consistent pair of positions rather than hypocrisy.
lockdep and what it proves, KCSAN for data races, and a real splat read line by line.
What the firmware does before anything Linux exists, and why UEFI made boot loaders simpler and boot debugging harder.
struct page describes one 4 KiB frame of physical memory, and there is one struct page for every
Every handoff between pressing the power button and a login prompt, with the artefact each stage passes to the next.
Cloning or downloading the pinned kernel, what the repository costs in disk and time, and a first orientation pass through the tree.
Every term below links to the one page that owns and genuinely defines it, so "where did this come from" always has an answer. The list covers folders 00–10 so far and grows as later folders land — a term you expect but can't find here probably belongs to a page that hasn't been written yet.
What a handler may not do, why each rule follows from the context, and the pressure that creates the rest of the folder.
The Entry Path told the syscall half of the entry
Every convention this section uses, with a live example of each. The prose explaining the folder
A TLB holds a fixed number of entries, and its reach — the amount of address space it can translate
Every widely-held wrong belief this section corrects, gathered in one place and linked to the
Why a root filesystem needs a root filesystem, and how the chicken-and-egg is broken.
The layout of a compressed kernel image, and why vmlinux, vmlinuz, and bzImage are three different things.
/proc/interrupts read column by column, MSI-X vectors per queue, and why pinning an interrupt near its consumer matters.
How a configuration symbol becomes a compiled object, and how to read past the CONFIG_ ifdefs that are everywhere.
Intrusive lists, hlists, red-black trees, xarrays, and IDRs — why intrusive containers, and what they cost.
Loading, unloading, parameters, dependency resolution, taint, and building a module out of tree.
/sys is not a directory tree someone laid out by hand. It is generated, at runtime, from an in-kernel
End to end in the QEMU lab: define it, wire the table, rebuild, boot, call it, and watch it in
One event, three instruments, and the point of running all three is not redundancy — it is
There is a layer most C programmers forget is there. Almost nobody calls the kernel directly — they
How Linux actually works, from the boundary between a command you type and the kernel that
Where the kernel genuinely goes lock-free, and an honest account of why most kernel code should not.
Why a plain access is not safe, what each barrier actually orders, and why this is the page arm64 changes the most.
Where Linux sits in the architecture taxonomy, why, and the honest cost: a driver bug is a kernel bug.
Sleeping locks that spin first, owner tracking, and why semaphores are now rare.
Node-local allocation by default, the policies that override it, and when NUMA effects are a red herring.
Translation is a size problem before it's anything else. A flat table mapping every 4 KiB page of a
Eliminating sharing rather than protecting it, and what that costs in preemption discipline.
Every operating systems course spends a lecture on System V message queues and semaphores, and almost no
When the kernel is executing on behalf of a task — running a system call, handling a fault, walking a
What does nice -n 5 actually buy a process? Not a percentage, and not a guarantee — and, despite the
"Running" is the rarest state a task is in. Look at any real machine, at any moment, and almost every
The API, the ordering it encodes, and the rules that make RCU misuse silently fatal rather than loudly wrong.
Readers that take no locks and pay nothing, writers that publish a new version and defer reclamation until every reader has left.
Why a reader-writer lock is often slower than a plain one, and where rw_semaphore is genuinely the right answer.
The word misleads, so the definition has to come first: real-time does not mean fast. It means
The Page Allocator hands out pages until it can't. A system that only
A kernel has no garbage collector and no scope-based destruction — nothing frees an object automatically
Every page in this section declares its prerequisites in front matter, and the build fails on a
How does one scheduler support real-time tasks, deadline tasks, ordinary tasks, and the idle task all at
The chain of trust from firmware keys to a signed kernel and signed modules, and what it does and does not protect against.
Lockless readers with a retry loop, the constraints that puts on a reader, and the canonical use in timekeeping.
Signals are the oldest asynchronous notification mechanism in UNIX — older than threads, older than
The Page Allocator deals in 4 KiB units. The kernel allocates `struct
The load balancer lives in a permanent tension. Moving a runnable task onto an idle CPU puts otherwise
The fixed set, why it is fixed, the budget that stops it starving everything else, and the si column in top.
Busy-waiting and when it is right, the queued implementation, and the absolute rule against sleeping while holding one.
Swap has an undeserved reputation. It is not "what happens when a machine runs out of memory" — it is
Socket activation, journald, and unit supervision, then the playbook for a machine that will not finish booting.
Units, the separation of dependency from ordering, targets instead of runlevels, and the transaction computed at every boot.
The model, its serialisation guarantee, the problems that deprecated it, and what to use instead.
The whole handoff sequence in one diagram, with the exact artefact passed at each step and where each one lives on disk.
A context switch is both smaller and larger than people think. The part with a name — saving one
Some of what happens between the SYSCALL instruction and dosyscall64 is done by the CPU, because
The seven hardware capabilities every Linux mechanism rests on, each linked to the Computer Science page that owns it.
How an Interrupt Reaches the Kernel ended at
How parameters reach the kernel, how they are parsed, and the dozen worth knowing — the most useful boot debugging tool there is.
Freestanding C with no libc, no floating point, a tiny stack, GCC extensions in daily use, and the annotations sparse checks.
Two worlds separated by one hardware-enforced door, and why every mechanism in this section is shaped by that door.
Why QEMU is the spine of every lab here, what to install on the host, and what each lab host badge means.
Where your data actually is at each moment between write() returning and the bytes reaching the device, and what fsync changes.
docker run de-mystified: a container is a process started with unusual arguments, and here is every one of them.
Wire to socket and back again, through the DMA ring, NAPI, GRO, netfilter, routing, and TCP.
An ordinary first touch of freshly allocated memory, traced from the CPU exception to the instruction re-executing — the normal case, not an error.
By the time this code runs, every allocation path has already failed, reclaim has already been asked and
Every other allocator in the kernel — slab, vmalloc, the page cache, the stack allocator — ultimately
This is the single most consequential piece of Linux memory management, and the one most misread by
The Life of a Page Fault told this story shallowly, as
Every top-level directory in a line, the four that matter expanded, and a lookup table from question to location.
Behind a grand-sounding interface is a mundane mechanism: the syscall number is an index, that index
What the periodic tick was doing, what turning it off moves elsewhere, and CPU isolation for latency-sensitive work.
Page Tables and the Walk established that a translation costs up to
Some "system calls" are not system calls. clock_gettime is called millions of times a second by
A pointer on x86-64 is a 64-bit value, but the address space it names is not a 64-bit space. Implementing
A quick primary handler plus a schedulable thread, and why PREEMPT_RT makes nearly every handler threaded.
Linux has no separate thread object: a thread is a task that shares its address space, files, and signal
How a clocksource is chosen, what each CLOCK* actually measures, and the lockless read path behind clockgettime.
The timer wheel's deliberate imprecision, hrtimers with real deadlines, and which one a driver should choose.
Watching a syscall and changing what it does are completely different mechanisms with completely
How to actually answer "how much memory is this using", and why every simple answer to that question is wrong.
A system call is not a function call into the kernel. It is a deliberate, hardware-mediated
This is the catalogue page. Kernel bugs — the ones that end in an oops, a silent corruption, or a security
Twenty mechanisms, named and linked, between a keystroke and a directory listing on your screen.
Kernel, GNU, and distribution pulled apart, plus the two design commitments that still constrain everything: a stable user-space ABI and no stable module ABI.
"The scheduler" is not one algorithm answering one question. It answers three: which runnable task
The scope of this section, what it deliberately leaves out, and what "understanding Linux" means in practice.
Four independent sources of concurrency and the context matrix that determines every locking choice in the folder.
Deferred work in process context, so it may sleep — plus the cancel-versus-free lifetime bug everyone writes once.
There is a gap between "the write returned" and "the data is safe", and most data-loss incidents live