ARC-301 · Processor Architecture · Advanced

x86-64 Systems Programming — full syllabus

The x86-64 architecture from a systems perspective: privilege levels, paging, and the mechanisms the kernel is built on.

Duration4 full days in person · 8 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 12,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Kernel and low-level engineers who work on or debug x86 platforms and need the architecture's mechanisms — privilege, paging, interrupts — precise rather than approximate.

Prerequisites

Course outline

Day 1 — Privilege and the legacy underneath

  • Privilege rings 0-3 and what actually uses them
  • Segmentation remnants and the flat model; GDT, LDT and TSS in 64-bit mode
  • Model-specific registers and CPUID feature detection
  • Errata: how to read them and decide if they affect you
  • Mapping the ring transitions the kernel depends on

Day 2 — Paging

  • Four- and five-level page tables and the walk
  • Page table entry format and flags: NX, accessed/dirty, global
  • TLBs, PCIDs and the cost of invalidation
  • Huge pages at the hardware level
  • Walking a live process's tables in a QEMU guest

Day 3 — Interrupts and exceptions

  • The IDT and the exception model
  • Local APIC and I/O APIC
  • MSI/MSI-X delivery and interrupt remapping
  • From device raise to handler: the delivery path end to end
  • Timing the entry and exit path

Day 4 — The system call path and the platform

  • syscall/sysret and the fast system call path versus int 0x80
  • The vDSO and why gettimeofday avoids the kernel
  • Mitigations visible at this level (KPTI and friends) and their measured cost
  • Reading the SDM critically
  • Putting it together with perf and ftrace

Hands-on labs

  1. Lab: detect CPU features with CPUID from a small program and cross-check against /proc/cpuinfo and the SDM
  2. Lab: walk a live process's four-level page tables in a QEMU guest and decode the PTE flags by hand
  3. Lab: measure syscall overhead and the cost of KPTI with a getpid microbenchmark under perf stat
  4. Lab: trace an interrupt from device raise to handler with ftrace and /proc/interrupts, then steer it with IRQ affinity
  5. Lab: read one published erratum for a real CPU and determine whether your test machine is affected

Capstone project

Build an evidence dossier on how the kernel uses the architecture on a real machine: a hand-decoded page-table walk, a measured syscall and interrupt path cost with and without mitigations, and a CPUID feature and errata report for the specific silicon — every statement cited to a register dump, a counter or a manual section.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
11 Oct – 14 Oct 20264 full days RiyadhIn person · KAFD Conference Centre 12 of 14 —SAR 12,000
18 Oct – 21 Oct 20264 full days Kuwait CityIn person · Al Hamra Tower 7 of 14 —KWD 990
25 Oct – 28 Oct 20264 full days MuscatIn person · Knowledge Oasis Muscat 12 of 14 —OMR 1,230
25 Oct – 3 Nov 20268 half-days Gulf bandLive online · 09:00–13:00 GMT+3 12 of 20 —US$2,300
26 Oct – 29 Oct 20264 full days OttawaIn person · Kanata North Tech Park 7 of 14 —CAD 4,350
2 Nov – 5 Nov 20264 full days TorontoIn person · MaRS Discovery District 12 of 14 —CAD 4,350
2 Nov – 11 Nov 20268 half-days Europe bandLive online · 09:00–13:00 CET 17 of 20 —US$2,300
9 Nov – 12 Nov 20264 full days LondonIn person · Shoreditch Works 7 of 14 GBP 2,250until 10 OctGBP 2,500
9 Nov – 18 Nov 20268 half-days Americas bandLive online · 13:00–17:00 ET 6 of 20 US$2,070until 10 OctUS$2,300
16 Nov – 19 Nov 20264 full days BerlinIn person · Factory Görlitzer Park 12 of 14 EUR 2,650until 17 OctEUR 2,940

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.