NET-110 · Kernel Networking · Advanced
Socket Layer & Protocol Handling — full syllabus
TCP and UDP implementation details that explain the behaviour you see on the wire.
Who this course is for
Engineers who own TCP/UDP services in production and need kernel-level explanations for retransmits, buffer stalls and latency that application metrics cannot provide.
Prerequisites
- NET-101 or equivalent packet-path knowledge
- Sockets programming experience in any language
- Comfort reading kernel source with guidance
Course outline
Day 1 — the socket layer and its memory
- Socket lifecycle: socket(), bind, connect/accept, close and the states in between
- Send and receive queues: where skbs wait and why
- Socket memory accounting: net.core and net.ipv4.*_mem knobs
- Buffer autotuning and when it stops helping
- Backpressure: what the kernel does when the application is slow
Day 2 — TCP under the hood
- The state machine as it appears on the wire
- Timers: retransmission, delayed ACK, keepalive, TIME_WAIT
- Loss recovery: fast retransmit, SACK and RTO computation
- Congestion control: CUBIC, BBR and the pluggable CC interface
- Loading and inspecting a congestion-control module
Day 3 — zero-copy paths and TCP observability
- sendfile and splice: what they save and what they cost
- MSG_ZEROCOPY semantics and its error queue
- io_uring for network I/O
- ss, tcp_diag and the TCP tracepoints
- Building a retransmit and latency view you can keep in production
Hands-on labs
- Lab: drive a connection into socket memory limits and watch ss -m, /proc and drop counters respond
- Lab: reproduce a loss event under tc netem and correlate tcpdump with TCP retransmit tracepoints
- Lab: benchmark CUBIC against BBR on an emulated WAN and explain the difference
- Lab: measure the CPU cost of copy vs sendfile vs MSG_ZEROCOPY on the same payload
- Lab: write a bpftrace tool charting per-connection retransmit and RTT distributions
Capstone project
Take a misbehaving TCP service from symptom to mechanism: using captures and a live system, you identify whether the cause is buffering, timers, congestion control or loss recovery, apply the fix, and deliver before/after evidence — captures, tracepoint data and the configuration or code change — that would survive an incident review.
What you leave with
- A mechanism-first method for diagnosing TCP behaviour
- Hands-on command of ss, tcp_diag, tracepoints and bpftrace for sockets
- Measured experience with CUBIC vs BBR under loss and delay
- A zero-copy decision framework: when sendfile, MSG_ZEROCOPY or io_uring is worth it
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 22 Nov – 24 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 9 of 14 | SAR 8,100until 23 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 4 of 14 | KWD 670until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 9 of 14 | OMR 830until 30 Oct | ||
| 6 Dec – 13 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 3 of 20 | US$1,580until 6 Nov | ||
| 7 Dec – 9 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 4 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 9 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 8 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | LondonIn person · Shoreditch Works | 4 of 14 | GBP 1,680until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 13 of 20 | US$1,580until 14 Nov | ||
| 21 Dec – 23 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 9 of 14 | EUR 1,990until 21 Nov |
Book a seat, or bring this course to your team
Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.
Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.