STO-201 · Storage & Filesystems · Advanced

VFS Internals — full syllabus

The abstraction every filesystem implements: inodes, dentries, the page cache and the locking around them.

Duration3 full days in person · 6 half-days online
Cohortmax 14 in person · 20 online
Pricefrom SAR 9,000 in person · local pricing per city
Delivery35% principles · 20% guided investigation · 45% engineering studio

Who this course is for

Kernel and storage engineers who need to understand — or modify — the layer every filesystem plugs into: the object model, the caches and the locking that make files behave like files.

Prerequisites

Course outline

Day 1 — The four core objects

  • struct super_block, inode, dentry and file: who owns what
  • The operations tables (file, inode, superblock, address_space) and how dispatch works
  • Filesystem registration and mount: register_filesystem to fill_super
  • The inode cache and icache lookup
  • Guided source walk: one full open() path through fs/

Day 2 — Path resolution and the page cache

  • Path walk: namei, link_path_walk and the RCU-mode fast path
  • The dcache: positive and negative entries, d_lookup and invalidation
  • struct address_space and the page cache: readahead, fault, write_begin/write_end
  • Writeback from the VFS side: dirty tagging and the writeback queues
  • Observing it live with ftrace and eBPF probes on VFS functions

Day 3 — Mounts, namespaces and locking

  • The mount tree: vfsmount, struct mount, bind mounts and propagation (shared/slave/private)
  • Mount namespaces and what containers actually inherit
  • The locking rules: i_rwsem, d_lock and lock ordering across objects
  • Classic VFS race windows and the bugs they produce
  • Where filesystems get it wrong: reviewing a real upstream fix

Hands-on labs

  1. Lab: trace open() to the filesystem's ->lookup and ->open with ftrace function graphs and annotate the object lifetimes
  2. Lab: hammer path resolution, watch dcache behaviour via /proc/sys/fs and eBPF, then stress negative dentries and measure the cost
  3. Lab: observe page-cache behaviour with cachestat and fadvise experiments, then force writeback under controlled dirty limits
  4. Lab: build mount-propagation scenarios (shared/slave/private) and predict — then verify — what a mount in one namespace does to another

Capstone project

Produce a VFS behaviour dossier for one real code path of your choice (a deeply nested open, a write through the page cache, or a cross-namespace bind mount): a source-level walk, an ftrace/eBPF timeline, the locks held at each stage, and one paragraph on what would break if a specific locking rule were violated — every claim reproducible from your scripts.

What you leave with

Upcoming dates

DatesWhereSeatsEarly birdRegular
18 Oct – 20 Oct 20263 full days RiyadhIn person · KAFD Conference Centre 9 of 14 —SAR 9,000
25 Oct – 27 Oct 20263 full days Kuwait CityIn person · Al Hamra Tower 4 of 14 —KWD 740
25 Oct – 27 Oct 20263 full days MuscatIn person · Knowledge Oasis Muscat 9 of 14 —OMR 920
1 Nov – 8 Nov 20266 half-days Gulf bandLive online · 09:00–13:00 GMT+3 7 of 20 —US$1,750
2 Nov – 4 Nov 20263 full days OttawaIn person · Kanata North Tech Park 4 of 14 —CAD 3,260
9 Nov – 11 Nov 20263 full days TorontoIn person · MaRS Discovery District 9 of 14 CAD 2,930until 10 OctCAD 3,260
9 Nov – 11 Nov 20263 full days LondonIn person · Shoreditch Works 4 of 14 GBP 1,680until 10 OctGBP 1,870
9 Nov – 16 Nov 20266 half-days Europe bandLive online · 09:00–13:00 CET 12 of 20 US$1,580until 10 OctUS$1,750
9 Nov – 16 Nov 20266 half-days Americas bandLive online · 13:00–17:00 ET 17 of 20 US$1,580until 10 OctUS$1,750
16 Nov – 18 Nov 20263 full days BerlinIn person · Factory Görlitzer Park 9 of 14 EUR 1,990until 17 OctEUR 2,210

Book a seat, or bring this course to your team

Seats can be reserved online; private delivery runs on-site or live online, adapted to your stack.

Course page & booking

Questions about fit or prerequisites? Email hello@kernelsystems.academy. To save this syllabus, print this page to PDF from your browser.