KRN-110 · Linux Kernel Core

Modules & the Kernel Build System

Kbuild, module loading, symbol resolution and the module lifecycle from insmod to rmmod.

Foundation 3 days in person6 half-days online Max 14 in person

Who this course is for

Developers writing or maintaining out-of-tree kernel modules — driver and BSP engineers who need Kbuild, symbol resolution and the load/unload lifecycle to be routine rather than mysterious.

Prerequisites

Solid CKRN-102 or equivalent build experienceAbility to build and boot a kernel in QEMU

Course outline

Day 1 — Kbuild from the outside

  • Kbuild makefiles: obj-m, obj-y, ccflags-y and per-object flags
  • In-tree vs out-of-tree builds: M=, KDIR and the kernel build directory contract
  • A first module: the boilerplate and what module_init/module_exit expand to
  • Build artifacts explained: .ko, .mod.c, modules.order, Module.symvers

Day 2 — Loading, symbols and the lifecycle

  • insmod, modprobe, rmmod and what each really does
  • Module reference counting and why rmmod fails
  • Symbol resolution: EXPORT_SYMBOL, EXPORT_SYMBOL_GPL and symbol namespaces
  • Module parameters (module_param) with permissions and sysfs exposure
  • Dependencies, depmod and modules.dep

Day 3 — Shipping modules that survive upgrades

  • vermagic and module versioning
  • Module signing and interaction with lockdown mode
  • Tainting: what taints the kernel and how to read /proc/sys/kernel/tainted
  • DKMS and rebuild-on-upgrade strategies
  • The unstable kernel ABI: what breaks on upgrades and how to design for it

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: build an out-of-tree module against a kernel tree, load it in QEMU and observe init/exit through dmesg
  2. Lab: export a symbol from one module and consume it from another; watch resolution in /proc/kallsyms and Module.symvers
  3. Lab: add module parameters with sysfs exposure and change behaviour at load time and runtime
  4. Lab: provoke a reference-count rmmod failure and diagnose it; then sign a module and load it under signature enforcement

Capstone project

Package a small two-module project the way a vendor would have to ship it: Kbuild files, an exported-symbol contract inside a namespace, documented module parameters exposed through sysfs, signed modules, and a short note on what will break at the next kernel upgrade — load-tested end to end on a freshly booted kernel.

What you leave with

  • Fluent out-of-tree Kbuild usage
  • Correct EXPORT_SYMBOL, namespace and module-parameter discipline
  • A working model of the load/unload lifecycle and reference counting
  • Practical answers on signing, tainting and kernel-upgrade breakage

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Developers writing or maintaining out-of-tree kernel modules — driver and BSP engineers who need Kbuild, symbol resolution and the load/unload lifecycle to be routine rather than mysterious. It sits at foundation level within the Linux Kernel Core track.

What do I need to know already?

Specific prerequisites for this course: Solid C; KRN-102 or equivalent build experience; Ability to build and boot a kernel in QEMU. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
15 Nov – 17 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 3 of 14 SAR 6,080until 16 OctSAR 6,750
22 Nov – 24 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 8 of 14 KWD 500until 23 OctKWD 560
29 Nov – 1 Dec 20263 full days MuscatIn person · Knowledge Oasis Muscat 3 of 14 OMR 620until 30 OctOMR 690
29 Nov – 6 Dec 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 13 of 20 US$1,170until 30 OctUS$1,300
30 Nov – 2 Dec 20263 full days OttawaIn person · Kanata North Tech Park 8 of 14 CAD 2,200until 31 OctCAD 2,450
7 Dec – 9 Dec 20263 full days TorontoIn person · MaRS Discovery District 3 of 14 CAD 2,200until 7 NovCAD 2,450
7 Dec – 14 Dec 20266 half-days Europe bandLive online · 09:00–13:00 CET 18 of 20 US$1,170until 7 NovUS$1,300
7 Dec – 14 Dec 20266 half-days Americas bandLive online · 13:00–17:00 ET 7 of 20 US$1,170until 7 NovUS$1,300
14 Dec – 16 Dec 20263 full days LondonIn person · Shoreditch Works 8 of 14 GBP 1,260until 14 NovGBP 1,400
14 Dec – 16 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 3 of 14 EUR 1,490until 14 NovEUR 1,660

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Linux Kernel Core

KRN-1013 days Kernel Architecture & Source Navigation A guided tour of the kernel tree: how it is organised, how subsystems relate, and how to find the code you need. Foundation Practitioner-taught SAR 6,750Next 18 Oct KRN-1022 days Building & Configuring the Kernel Configure, build, install and boot a kernel you compiled yourself, and understand what the thousands of config options actually do. Foundation Practitioner-taught SAR 4,500Next 18 Oct KRN-2014 days Process Lifecycle & Scheduling How processes are created, scheduled and destroyed, and how scheduling decisions show up as latency in your application. Practitioner Practitioner-taught SAR 10,500Next 8 Nov KRN-2103 days CFS to EEVDF Internals The fair scheduler in depth, the move to EEVDF, and what changed for latency-sensitive workloads. Advanced Practitioner-taught SAR 9,000Next 18 Oct KRN-2112 days CPU Isolation & Affinity Taking CPUs away from the kernel for latency-critical work: isolcpus, nohz_full, RCU offload and the gotchas. Advanced Practitioner-taught SAR 6,000Next 25 Oct KRN-2204 days Virtual Memory & Page Tables Address spaces, page tables, faults and mappings — the machinery behind every memory access your program makes. Practitioner Practitioner-taught SAR 10,500Next 22 Nov KRN-2213 days Allocators: Buddy, Slab, vmalloc How the kernel allocates memory at every scale, and how allocator behaviour surfaces as fragmentation and latency. Advanced Practitioner-taught SAR 9,000Next 22 Nov KRN-2223 days Memory Pressure, OOM & cgroup v2 What happens when memory runs out: reclaim, swap, the OOM killer, and cgroup v2 limits that throttle silently. Advanced Practitioner-taught SAR 9,000Next 22 Nov KRN-2303 days Kernel Locking Primitives Every locking primitive the kernel offers, when each is correct, and the deadlocks that follow from choosing wrong. Practitioner Practitioner-taught SAR 7,880Next 8 Nov KRN-2313 days RCU in Depth Read-copy-update from first principles: grace periods, publish-subscribe, and why RCU is everywhere in the kernel. Advanced Practitioner-taught SAR 9,000Next 8 Nov KRN-2323 days Memory Barriers & the Kernel Memory Model The hardest correctness topic in the kernel: reordering, barriers, and reasoning about concurrent code that actually holds. Expert Practitioner-taught SAR 10,120Next 8 Nov