KRN-220 · Linux Kernel Core

Virtual Memory & Page Tables

Address spaces, page tables, faults and mappings — the machinery behind every memory access your program makes.

Practitioner 4 days in person8 half-days online Max 14 in person

Who this course is for

Systems developers and debuggers who want the machinery behind every pointer their program dereferences — address spaces, page tables, faults and mappings, read at the source.

Prerequisites

Solid CUserspace mmap/malloc experienceKRN-101-level source navigation

Course outline

Day 1 — The address space

  • mm_struct, vm_area_struct and the maple tree
  • Address space layout: stack, heap, mmap region and the kernel half
  • Reading /proc/<pid>/maps and smaps against the structures
  • VMA merge and split behaviour
  • mmap_lock and who contends for it

Day 2 — Page tables and large pages

  • Page table levels and the walk, step by step
  • Page table entry bits that matter: present, dirty, accessed, NX
  • Huge pages and Transparent Huge Pages: always/madvise/never and khugepaged
  • TLB organisation and why walks are expensive
  • Measuring walk and miss cost with perf

Day 3 — Page faults

  • The page fault handler end to end
  • Minor vs major faults and what each costs
  • Copy-on-write mechanics and the COW fault path
  • Demand paging, readahead and the file-backed path
  • Accounting: RSS, PSS, USS and why the numbers disagree

Day 4 — Mappings and cost at scale

  • mmap, munmap and mprotect internals
  • Page cache interaction with mapped files
  • TLB shootdowns and IPI storms on large systems
  • mmap_lock contention and what current kernels do about it
  • Capstone workshop

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: map a process's VMAs from /proc/<pid>/maps and smaps and reconcile them with page-table data from pagemap
  2. Lab: force minor, major and COW faults deliberately and count each class with perf and /proc/<pid>/stat
  3. Lab: benchmark THP on and off for a fault-heavy workload and watch khugepaged collapse pages
  4. Lab: observe TLB shootdown IPIs under munmap-heavy load and measure their cost
  5. Lab: follow an mmap of a file from syscall to page-cache page with ftrace

Capstone project

Build a complete evidence pack for one application's memory behaviour: its VMA map, a fault-class breakdown, page-size usage, RSS/PSS accounting, and the two changes — mapping strategy and THP policy — that measurably reduce its fault and shootdown cost, each backed by a measurement you can reproduce.

What you leave with

  • A source-level model of mm_struct, VMAs and page tables
  • Fault diagnosis with perf, /proc and pagemap
  • THP and page-cache tuning guided by evidence
  • Shootdown and mmap_lock cost awareness for large systems

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Systems developers and debuggers who want the machinery behind every pointer their program dereferences — address spaces, page tables, faults and mappings, read at the source. It sits at practitioner level within the Linux Kernel Core track.

What do I need to know already?

Specific prerequisites for this course: Solid C; Userspace mmap/malloc experience; KRN-101-level source navigation. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 4 full days with hardware on your desk, capped at 14. Online is 8 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
22 Nov – 25 Nov 20264 full days RiyadhIn person · KAFD Conference Centre 5 of 14 SAR 9,450until 23 OctSAR 10,500
29 Nov – 2 Dec 20264 full days Kuwait CityIn person · Al Hamra Tower 10 of 14 KWD 780until 30 OctKWD 870
29 Nov – 2 Dec 20264 full days MuscatIn person · Knowledge Oasis Muscat 5 of 14 OMR 970until 30 OctOMR 1,080
6 Dec – 15 Dec 20268 half-days Gulf bandLive online · 09:00–13:00 GMT+3 13 of 20 US$1,800until 6 NovUS$2,000
7 Dec – 10 Dec 20264 full days OttawaIn person · Kanata North Tech Park 10 of 14 CAD 3,430until 7 NovCAD 3,810
7 Dec – 16 Dec 20268 half-days Europe bandLive online · 09:00–13:00 CET 18 of 20 US$1,800until 7 NovUS$2,000
14 Dec – 17 Dec 20264 full days TorontoIn person · MaRS Discovery District 5 of 14 CAD 3,430until 14 NovCAD 3,810
14 Dec – 17 Dec 20264 full days LondonIn person · Shoreditch Works 10 of 14 GBP 1,960until 14 NovGBP 2,180
14 Dec – 23 Dec 20268 half-days Americas bandLive online · 13:00–17:00 ET 7 of 20 US$1,800until 14 NovUS$2,000
21 Dec – 24 Dec 20264 full days BerlinIn person · Factory Görlitzer Park 5 of 14 EUR 2,320until 21 NovEUR 2,580

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Linux Kernel Core

KRN-1013 days Kernel Architecture & Source Navigation A guided tour of the kernel tree: how it is organised, how subsystems relate, and how to find the code you need. Foundation Practitioner-taught SAR 6,750Next 18 Oct KRN-1022 days Building & Configuring the Kernel Configure, build, install and boot a kernel you compiled yourself, and understand what the thousands of config options actually do. Foundation Practitioner-taught SAR 4,500Next 18 Oct KRN-1103 days Modules & the Kernel Build System Kbuild, module loading, symbol resolution and the module lifecycle from insmod to rmmod. Foundation Practitioner-taught SAR 6,750Next 15 Nov KRN-2014 days Process Lifecycle & Scheduling How processes are created, scheduled and destroyed, and how scheduling decisions show up as latency in your application. Practitioner Practitioner-taught SAR 10,500Next 8 Nov KRN-2103 days CFS to EEVDF Internals The fair scheduler in depth, the move to EEVDF, and what changed for latency-sensitive workloads. Advanced Practitioner-taught SAR 9,000Next 18 Oct KRN-2112 days CPU Isolation & Affinity Taking CPUs away from the kernel for latency-critical work: isolcpus, nohz_full, RCU offload and the gotchas. Advanced Practitioner-taught SAR 6,000Next 25 Oct KRN-2213 days Allocators: Buddy, Slab, vmalloc How the kernel allocates memory at every scale, and how allocator behaviour surfaces as fragmentation and latency. Advanced Practitioner-taught SAR 9,000Next 22 Nov KRN-2223 days Memory Pressure, OOM & cgroup v2 What happens when memory runs out: reclaim, swap, the OOM killer, and cgroup v2 limits that throttle silently. Advanced Practitioner-taught SAR 9,000Next 22 Nov KRN-2303 days Kernel Locking Primitives Every locking primitive the kernel offers, when each is correct, and the deadlocks that follow from choosing wrong. Practitioner Practitioner-taught SAR 7,880Next 8 Nov KRN-2313 days RCU in Depth Read-copy-update from first principles: grace periods, publish-subscribe, and why RCU is everywhere in the kernel. Advanced Practitioner-taught SAR 9,000Next 8 Nov KRN-2323 days Memory Barriers & the Kernel Memory Model The hardest correctness topic in the kernel: reordering, barriers, and reasoning about concurrent code that actually holds. Expert Practitioner-taught SAR 10,120Next 8 Nov