KRN-220 · Linux Kernel Core · Practitioner

Virtual Memory & Page Tables — full syllabus

Address spaces, page tables, faults and mappings — the machinery behind every memory access your program makes.

Duration4 full days in person · 8 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 10,500 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Systems developers and debuggers who want the machinery behind every pointer their program dereferences — address spaces, page tables, faults and mappings, read at the source.

Prerequisites

Course outline

Day 1 — The address space

  • mm_struct, vm_area_struct and the maple tree
  • Address space layout: stack, heap, mmap region and the kernel half
  • Reading /proc/<pid>/maps and smaps against the structures
  • VMA merge and split behaviour
  • mmap_lock and who contends for it

Day 2 — Page tables and large pages

  • Page table levels and the walk, step by step
  • Page table entry bits that matter: present, dirty, accessed, NX
  • Huge pages and Transparent Huge Pages: always/madvise/never and khugepaged
  • TLB organisation and why walks are expensive
  • Measuring walk and miss cost with perf

Day 3 — Page faults

  • The page fault handler end to end
  • Minor vs major faults and what each costs
  • Copy-on-write mechanics and the COW fault path
  • Demand paging, readahead and the file-backed path
  • Accounting: RSS, PSS, USS and why the numbers disagree

Day 4 — Mappings and cost at scale

  • mmap, munmap and mprotect internals
  • Page cache interaction with mapped files
  • TLB shootdowns and IPI storms on large systems
  • mmap_lock contention and what current kernels do about it
  • Capstone workshop

Hands-on labs

  1. Lab: map a process's VMAs from /proc/<pid>/maps and smaps and reconcile them with page-table data from pagemap
  2. Lab: force minor, major and COW faults deliberately and count each class with perf and /proc/<pid>/stat
  3. Lab: benchmark THP on and off for a fault-heavy workload and watch khugepaged collapse pages
  4. Lab: observe TLB shootdown IPIs under munmap-heavy load and measure their cost
  5. Lab: follow an mmap of a file from syscall to page-cache page with ftrace

Capstone project

Build a complete evidence pack for one application's memory behaviour: its VMA map, a fault-class breakdown, page-size usage, RSS/PSS accounting, and the two changes — mapping strategy and THP policy — that measurably reduce its fault and shootdown cost, each backed by a measurement you can reproduce.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 25 Nov 20264 full days RiyadhIn person · KAFD Conference Centre 5 of 14 SAR 9,450until 23 OctSAR 10,500
29 Nov – 2 Dec 20264 full days Kuwait CityIn person · Al Hamra Tower 10 of 14 KWD 780until 30 OctKWD 870
29 Nov – 2 Dec 20264 full days MuscatIn person · Knowledge Oasis Muscat 5 of 14 OMR 970until 30 OctOMR 1,080
6 Dec – 15 Dec 20268 half-days Gulf bandLive online · 09:00–13:00 GMT+3 13 of 20 US$1,800until 6 NovUS$2,000
7 Dec – 10 Dec 20264 full days OttawaIn person · Kanata North Tech Park 10 of 14 CAD 3,430until 7 NovCAD 3,810
7 Dec – 16 Dec 20268 half-days Europe bandLive online · 09:00–13:00 CET 18 of 20 US$1,800until 7 NovUS$2,000
14 Dec – 17 Dec 20264 full days TorontoIn person · MaRS Discovery District 5 of 14 CAD 3,430until 14 NovCAD 3,810
14 Dec – 17 Dec 20264 full days LondonIn person · Shoreditch Works 10 of 14 GBP 1,960until 14 NovGBP 2,180
14 Dec – 23 Dec 20268 half-days Americas bandLive online · 13:00–17:00 ET 7 of 20 US$1,800until 14 NovUS$2,000
21 Dec – 24 Dec 20264 full days BerlinIn person · Factory Görlitzer Park 5 of 14 EUR 2,320until 21 NovEUR 2,580

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.