SEC-210 · Kernel Security

Stable, LTS & Vendor Tree Hygiene

Working with the upstream stable process and keeping a vendor tree that does not rot.

Practitioner 2 days in person4 half-days online Max 14 in person

Who this course is for

Engineers maintaining a long-lived product kernel who want the tree to stay close enough to upstream that security fixes remain cheap.

Prerequisites

git and kernel build experienceSome exposure to maintaining out-of-tree patchesSEC-201 recommended for the backporting side

Course outline

Day 1 — The stable machine

  • How the stable and LTS process works: cadence, rules, review and the AUTOSEL story
  • What stable-queue and stable-rc trees are and how to consume them
  • Choosing an LTS base for a product: lifetime math and the cost of an odd choice
  • Planning the migration to the next LTS before you are forced into it
  • Reading a stable release: what got in, what got dropped and why

Day 2 — Keeping your tree rebaseable

  • Inventorying local patches: board support, drivers and the 'temporary' hacks from three years ago
  • Upstream-first as policy: what it buys, what it costs and how to argue for it
  • Structuring local patches to rebase cleanly: topic branches, series files and quarantine
  • Tooling for divergence: range-diff, patch tracking and drift reporting
  • Deciding what to keep, what to upstream and what to drop at the next rebase

Hands-on labs

Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach

  1. Lab: Follow a stable release from -rc to final and catalogue what changed for your subsystem set
  2. Lab: Compute an LTS selection for a stated product lifetime and defend the choice
  3. Lab: Inventory a supplied vendor-style tree: classify every local patch as upstreamable, rebaseable or droppable
  4. Lab: Measure divergence from upstream with range-diff and produce a drift report with recommendations
  5. Lab: Rebase a small local patch series onto a newer stable point release and resolve what breaks

Capstone project

Produce a hygiene plan for a supplied vendor tree: an LTS base recommendation with lifetime math, a classified inventory of local patches with an upstream/drop/rebase decision for each, a measured divergence report and a concrete plan for the next LTS migration.

What you leave with

  • Working knowledge of the stable/LTS cadence and how to consume it
  • A defensible LTS-selection method with lifetime math
  • A local-patch inventory and classification practice
  • Divergence-measurement tooling you can run on your own tree the same week

How it runs

Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.

Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.

Questions

Who is this course for?

Engineers maintaining a long-lived product kernel who want the tree to stay close enough to upstream that security fixes remain cheap. It sits at practitioner level within the Kernel Security track.

What do I need to know already?

Specific prerequisites for this course: git and kernel build experience; Some exposure to maintaining out-of-tree patches; SEC-201 recommended for the backporting side. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.

Can this run privately for my team?

Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.

What is the difference between in-person and online?

In person is 2 full days with hardware on your desk, capped at 14. Online is 4 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.

Do you invoice companies?

Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 19 Oct 20262 full days RiyadhIn person · KAFD Conference Centre 12 of 14 —SAR 5,250
18 Oct – 19 Oct 20262 full days Kuwait CityIn person · Al Hamra Tower 7 of 14 —KWD 430
25 Oct – 26 Oct 20262 full days MuscatIn person · Knowledge Oasis Muscat 12 of 14 —OMR 540
1 Nov – 4 Nov 20264 half-days Gulf bandLive online · 09:00–13:00 GMT+3 8 of 20 —US$1,000
2 Nov – 3 Nov 20262 full days OttawaIn person · Kanata North Tech Park 7 of 14 —CAD 1,900
2 Nov – 3 Nov 20262 full days TorontoIn person · MaRS Discovery District 12 of 14 —CAD 1,900
2 Nov – 5 Nov 20264 half-days Europe bandLive online · 09:00–13:00 CET 13 of 20 —US$1,000
9 Nov – 10 Nov 20262 full days LondonIn person · Shoreditch Works 7 of 14 GBP 980until 10 OctGBP 1,090
9 Nov – 12 Nov 20264 half-days Americas bandLive online · 13:00–17:00 ET 18 of 20 US$900until 10 OctUS$1,000
16 Nov – 17 Nov 20262 full days BerlinIn person · Factory Görlitzer Park 12 of 14 EUR 1,160until 17 OctEUR 1,290

Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.

More in Kernel Security

SEC-1012 days Reading Kernel CVEs Assessing whether a kernel CVE actually affects you, which is usually a different question from whether it is severe. Practitioner Practitioner-taught SAR 5,250Next 11 Oct SEC-1103 days Exploit Mitigations & Hardening The mitigations available in a modern kernel, what each actually stops, and what they cost. Advanced Practitioner-taught SAR 9,000Next 8 Nov SEC-1202 days Attack Surface Reduction Making the kernel smaller and less reachable, which beats mitigating attacks you could have made impossible. Advanced Practitioner-taught SAR 6,000Next 25 Oct SEC-2013 days Multi-Branch Backporting Taking an upstream fix and applying it correctly across several maintained branches — the core skill of a vendor security team. Advanced Practitioner-taught SAR 9,000Next 1 Nov SEC-2202 days Building an Advisory Workflow The process around the engineering: intake, assessment, communication and evidence, on a deadline. Practitioner Practitioner-taught SAR 5,250Next 15 Nov SEC-3013 days LSM, SELinux & AppArmor Mandatory access control on Linux: how the LSM framework works and how to write policy that is actually enforced. Advanced Practitioner-taught SAR 9,000Next 22 Nov SEC-3102 days Landlock & Kernel Lockdown Newer confinement mechanisms: unprivileged sandboxing with Landlock and restricting root with lockdown. Advanced Practitioner-taught SAR 6,000Next 8 Nov SEC-3203 days Integrity: IMA/EVM & dm-verity Measuring and verifying what runs on the system, from block device to individual file. Advanced Practitioner-taught SAR 9,000Next 18 Oct