STO-201 · Storage & Filesystems
VFS Internals
The abstraction every filesystem implements: inodes, dentries, the page cache and the locking around them.
Who this course is for
Kernel and storage engineers who need to understand — or modify — the layer every filesystem plugs into: the object model, the caches and the locking that make files behave like files.
Prerequisites
Course outline
Day 1 — The four core objects
- struct super_block, inode, dentry and file: who owns what
- The operations tables (file, inode, superblock, address_space) and how dispatch works
- Filesystem registration and mount: register_filesystem to fill_super
- The inode cache and icache lookup
- Guided source walk: one full open() path through fs/
Day 2 — Path resolution and the page cache
- Path walk: namei, link_path_walk and the RCU-mode fast path
- The dcache: positive and negative entries, d_lookup and invalidation
- struct address_space and the page cache: readahead, fault, write_begin/write_end
- Writeback from the VFS side: dirty tagging and the writeback queues
- Observing it live with ftrace and eBPF probes on VFS functions
Day 3 — Mounts, namespaces and locking
- The mount tree: vfsmount, struct mount, bind mounts and propagation (shared/slave/private)
- Mount namespaces and what containers actually inherit
- The locking rules: i_rwsem, d_lock and lock ordering across objects
- Classic VFS race windows and the bugs they produce
- Where filesystems get it wrong: reviewing a real upstream fix
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: trace open() to the filesystem's ->lookup and ->open with ftrace function graphs and annotate the object lifetimes
- Lab: hammer path resolution, watch dcache behaviour via /proc/sys/fs and eBPF, then stress negative dentries and measure the cost
- Lab: observe page-cache behaviour with cachestat and fadvise experiments, then force writeback under controlled dirty limits
- Lab: build mount-propagation scenarios (shared/slave/private) and predict — then verify — what a mount in one namespace does to another
Capstone project
Produce a VFS behaviour dossier for one real code path of your choice (a deeply nested open, a write through the page cache, or a cross-namespace bind mount): a source-level walk, an ftrace/eBPF timeline, the locks held at each stage, and one paragraph on what would break if a specific locking rule were violated — every claim reproducible from your scripts.
What you leave with
- A durable mental model of the superblock/inode/dentry/file object graph
- dcache and page-cache observability with /proc, ftrace and eBPF
- Mount namespace and propagation behaviour you can predict
- The VFS locking rules, learned from the code and from the races they prevent
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Kernel and storage engineers who need to understand — or modify — the layer every filesystem plugs into: the object model, the caches and the locking that make files behave like files. It sits at advanced level within the Storage & Filesystems track.
What do I need to know already?
Specific prerequisites for this course: Solid C and kernel module build experience (KRN-110 level); Kernel source navigation (KRN-101 level); KRN-230 (kernel locking) recommended. We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 18 Oct – 20 Oct 20263 full days | RiyadhIn person · KAFD Conference Centre | 9 of 14 | — | SAR 9,000 | |
| 25 Oct – 27 Oct 20263 full days | Kuwait CityIn person · Al Hamra Tower | 4 of 14 | — | KWD 740 | |
| 25 Oct – 27 Oct 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 9 of 14 | — | OMR 920 | |
| 1 Nov – 8 Nov 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 7 of 20 | — | US$1,750 | |
| 2 Nov – 4 Nov 20263 full days | OttawaIn person · Kanata North Tech Park | 4 of 14 | — | CAD 3,260 | |
| 9 Nov – 11 Nov 20263 full days | TorontoIn person · MaRS Discovery District | 9 of 14 | CAD 2,930until 10 Oct | ||
| 9 Nov – 11 Nov 20263 full days | LondonIn person · Shoreditch Works | 4 of 14 | GBP 1,680until 10 Oct | ||
| 9 Nov – 16 Nov 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 12 of 20 | US$1,580until 10 Oct | ||
| 9 Nov – 16 Nov 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 17 of 20 | US$1,580until 10 Oct | ||
| 16 Nov – 18 Nov 20263 full days | BerlinIn person · Factory Görlitzer Park | 9 of 14 | EUR 1,990until 17 Oct |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Storage & Filesystems
STO-1013 days
Block Layer & I/O Schedulers
How an I/O request travels from the filesystem to the device, and what the scheduler does to it on the way.
Practitioner-taught
SAR 7,880Next 15 Nov
STO-1103 days
NVMe & NVMe-oF
NVMe as a protocol and as a driver, including fabrics for disaggregated storage.
Practitioner-taught
SAR 9,000Next 25 Oct
STO-1203 days
Device Mapper & LVM
Composing block devices: linear, striped, snapshot, thin provisioning, crypt and cache targets.
Practitioner-taught
SAR 7,880Next 11 Oct
STO-2103 days
ext4 & XFS Internals
The on-disk layout and operational behaviour of the two filesystems most production Linux runs on.
Practitioner-taught
SAR 9,000Next 15 Nov
STO-2204 days
Writing a Filesystem from Scratch
Implement a small but real filesystem, which is the fastest way to genuinely understand the VFS.
Practitioner-taught
SAR 13,500Next 1 Nov