ARC-301 · Processor Architecture
x86-64 Systems Programming
The x86-64 architecture from a systems perspective: privilege levels, paging, and the mechanisms the kernel is built on.
Who this course is for
Kernel and low-level engineers who work on or debug x86 platforms and need the architecture's mechanisms — privilege, paging, interrupts — precise rather than approximate.
Prerequisites
Course outline
Day 1 — Privilege and the legacy underneath
- Privilege rings 0-3 and what actually uses them
- Segmentation remnants and the flat model; GDT, LDT and TSS in 64-bit mode
- Model-specific registers and CPUID feature detection
- Errata: how to read them and decide if they affect you
- Mapping the ring transitions the kernel depends on
Day 2 — Paging
- Four- and five-level page tables and the walk
- Page table entry format and flags: NX, accessed/dirty, global
- TLBs, PCIDs and the cost of invalidation
- Huge pages at the hardware level
- Walking a live process's tables in a QEMU guest
Day 3 — Interrupts and exceptions
- The IDT and the exception model
- Local APIC and I/O APIC
- MSI/MSI-X delivery and interrupt remapping
- From device raise to handler: the delivery path end to end
- Timing the entry and exit path
Day 4 — The system call path and the platform
- syscall/sysret and the fast system call path versus int 0x80
- The vDSO and why gettimeofday avoids the kernel
- Mitigations visible at this level (KPTI and friends) and their measured cost
- Reading the SDM critically
- Putting it together with perf and ftrace
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: detect CPU features with CPUID from a small program and cross-check against /proc/cpuinfo and the SDM
- Lab: walk a live process's four-level page tables in a QEMU guest and decode the PTE flags by hand
- Lab: measure syscall overhead and the cost of KPTI with a getpid microbenchmark under perf stat
- Lab: trace an interrupt from device raise to handler with ftrace and /proc/interrupts, then steer it with IRQ affinity
- Lab: read one published erratum for a real CPU and determine whether your test machine is affected
Capstone project
Build an evidence dossier on how the kernel uses the architecture on a real machine: a hand-decoded page-table walk, a measured syscall and interrupt path cost with and without mitigations, and a CPUID feature and errata report for the specific silicon — every statement cited to a register dump, a counter or a manual section.
What you leave with
- A precise model of rings, paging and the IDT/APIC machinery
- The ability to walk and decode x86-64 page tables
- Measured costs for syscalls, interrupts and mitigations
- SDM and errata reading habits that transfer to any x86 platform
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Kernel and low-level engineers who work on or debug x86 platforms and need the architecture's mechanisms — privilege, paging, interrupts — precise rather than approximate. It sits at advanced level within the Processor Architecture track.
What do I need to know already?
Specific prerequisites for this course: C and assembly reading ability; Linux systems programming experience; ARC-101 and ARC-102 or equivalent architecture grounding. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 4 full days with hardware on your desk, capped at 14. Online is 8 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 11 Oct – 14 Oct 20264 full days | RiyadhIn person · KAFD Conference Centre | 12 of 14 | — | SAR 12,000 | |
| 18 Oct – 21 Oct 20264 full days | Kuwait CityIn person · Al Hamra Tower | 7 of 14 | — | KWD 990 | |
| 25 Oct – 28 Oct 20264 full days | MuscatIn person · Knowledge Oasis Muscat | 12 of 14 | — | OMR 1,230 | |
| 25 Oct – 3 Nov 20268 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 12 of 20 | — | US$2,300 | |
| 26 Oct – 29 Oct 20264 full days | OttawaIn person · Kanata North Tech Park | 7 of 14 | — | CAD 4,350 | |
| 2 Nov – 5 Nov 20264 full days | TorontoIn person · MaRS Discovery District | 12 of 14 | — | CAD 4,350 | |
| 2 Nov – 11 Nov 20268 half-days | Europe bandLive online · 09:00–13:00 CET | 17 of 20 | — | US$2,300 | |
| 9 Nov – 12 Nov 20264 full days | LondonIn person · Shoreditch Works | 7 of 14 | GBP 2,250until 10 Oct | ||
| 9 Nov – 18 Nov 20268 half-days | Americas bandLive online · 13:00–17:00 ET | 6 of 20 | US$2,070until 10 Oct | ||
| 16 Nov – 19 Nov 20264 full days | BerlinIn person · Factory Görlitzer Park | 12 of 14 | EUR 2,650until 17 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Processor Architecture
ARC-1013 days
CPU Pipelines & Microarchitecture
How a modern out-of-order core fetches, schedules and retires instructions, and why that determines the performance ceiling of your code.
Practitioner-taught
SAR 6,750Next 18 Oct
ARC-1023 days
Cache & Memory Hierarchy
The cache hierarchy from L1 to main memory, and the access patterns that decide whether your workload is fast or memory-bound.
Practitioner-taught
SAR 6,750Next 18 Oct
ARC-1102 days
SIMD & Vector Processing
Data-parallel execution on CPUs: AVX-512, NEON and SVE, and how to get the compiler to actually use them.
Practitioner-taught
SAR 5,250Next 15 Nov
ARC-2012 days
NUMA & Multi-Socket Systems
Non-uniform memory access, node topology discovery, and the placement decisions that quietly cost you throughput.
Practitioner-taught
SAR 5,250Next 8 Nov
ARC-2103 days
PCIe & System Interconnects
The fabric between CPU, memory and devices: PCIe generations, topology, and the bandwidth you actually get.
Practitioner-taught
SAR 7,880Next 25 Oct
ARC-3024 days
Arm64 Systems Programming
AArch64 for systems engineers: exception levels, translation regimes and the memory model that trips up x86 developers.
Practitioner-taught
SAR 12,000Next 18 Oct
ARC-3033 days
RISC-V Systems Programming
RISC-V privileged architecture for engineers arriving from x86 or Arm, including the state of the software ecosystem.
Practitioner-taught
SAR 9,000Next 18 Oct