SEC-201 · Kernel Security

Multi-Branch Backporting

Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team.

Advanced 3 days in person6 half-days online Max 14 in person

Who this course is for

Maintenance and security engineers carrying fixes across several product kernels at once — the daily work of a vendor kernel security team, taught from current vendor-side practice.

Prerequisites

Solid git: rebase, cherry-pick, range-diff and conflict resolutionAbility to build and boot-test a kernelC reading skills sufficient to follow a fix and its surrounding context

Course outline

Day 1 — Finding the real fix

  • Reading the upstream fix: what the patch does versus what the commit message claims
  • Fixes: tags, commit ancestry and following the prerequisite chain backwards
  • Refactors that precede the fix: when you need them and when you work around them
  • Stable rules and what 'must be in mainline first' means in practice
  • Reconstructing a multi-commit dependency graph for one CVE

Day 2 — Applying across diverged branches

  • Textual vs semantic conflicts: when git applies cleanly and is still wrong
  • Diverged-context strategies: renamed APIs, moved files and changed locking
  • Forward ports, backports and revert queues: keeping each branch's story straight
  • Equivalence checking: range-diff, side-by-side review and what reviewers actually check
  • Regression risk assessment: blast radius, test selection and what 'boot-tested' is worth

Day 3 — Running the patch matrix

  • Separating apply, build, boot and test status per branch — and tracking it
  • Targeted reproducers: writing the smallest test that proves the fix
  • Build matrices and smoke boots with QEMU
  • Patch provenance: upstream tags, changelogs and the audit trail
  • Rollback planning: revert queues and what you do when a backport breaks a customer

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Reconstruct the dependency chain behind a real security fix using git log, Fixes: tags and blame
  2. Lab: Resolve a textual conflict, then a semantic conflict git accepted silently — and catch the difference
  3. Lab: Backport a fix to an older branch and verify equivalence with range-diff and a targeted test
  4. Lab: Write a minimal reproducer that fails on the unpatched branch and passes after your backport
  5. Lab: Maintain an apply/build/boot/test matrix for one fix across three branches, with rollback notes

Capstone project

Backport a real security fix from mainline to an older product branch: deliver the ordered patch queue with provenance, conflict-resolution notes, an equivalence argument (range-diff plus a targeted reproducer), a build/boot/test matrix and a ready revert queue — the exact bundle a vendor security team hands to release engineering.

What you leave with

  • A dependency-reconstruction method that finds the whole fix, not the headline patch
  • Conflict-resolution judgement for textual vs semantic divergence
  • Equivalence-checking habits: range-diff plus targeted tests
  • A patch-matrix tracking format reusable on your own branches
  • Rollback and revert-queue discipline for when a backport goes wrong

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Maintenance and security engineers carrying fixes across several product kernels at once — the daily work of a vendor kernel security team, taught from current vendor-side practice. It sits at advanced level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: Solid git: rebase, cherry-pick, range-diff and conflict resolution; Ability to build and boot-test a kernel; C reading skills sufficient to follow a fix and its surrounding context. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
1 Nov – 3 Nov 20263 full days RiyadhIn person · KAFD Conference Centre 12 of 14 —SAR 9,000
8 Nov – 10 Nov 20263 full days Kuwait CityIn person · Al Hamra Tower 7 of 14 KWD 670until 9 OctKWD 740
15 Nov – 17 Nov 20263 full days MuscatIn person · Knowledge Oasis Muscat 12 of 14 OMR 830until 16 OctOMR 920
15 Nov – 22 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 10 of 20 US$1,580until 16 OctUS$1,750
16 Nov – 18 Nov 20263 full days OttawaIn person · Kanata North Tech Park 7 of 14 CAD 2,930until 17 OctCAD 3,260
23 Nov – 25 Nov 20263 full days TorontoIn person · MaRS Discovery District 12 of 14 CAD 2,930until 24 OctCAD 3,260
23 Nov – 30 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 15 of 20 US$1,580until 24 OctUS$1,750
23 Nov – 30 Nov 20266 half-days Americas bandLive online · 13:00–17:00 ET 4 of 20 US$1,580until 24 OctUS$1,750
30 Nov – 2 Dec 20263 full days LondonIn person · Shoreditch Works 7 of 14 GBP 1,680until 31 OctGBP 1,870
30 Nov – 2 Dec 20263 full days BerlinIn person · Factory Görlitzer Park 12 of 14 EUR 1,990until 31 OctEUR 2,210

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2102 days Stable, LTS & Vendor Tree Hygiene Working with the upstream stable process and keeping a vendor tree that does not rot. Practitioner Practitioner-taught SAR 5,250Next 18 Oct SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct