STO-210 · Storage & Filesystems
ext4 & XFS Internals
The on-disk layout and operational behaviour of the two filesystems most production Linux runs on.
Who this course is for
Engineers who own production filesystem decisions — choosing between ext4 and XFS, tuning them, and performing the recovery when something corrupts at 3 a.m.
Prerequisites
Course outline
Day 1 — ext4 on disk and in memory
- Block groups, group descriptors and the superblock layout
- Extents vs block maps; the extent tree
- Directory indexing (htree) and inline data
- The journal (jbd2): ordered, writeback and journal modes and what each guarantees
- Inspection: dumpe2fs, debugfs, tune2fs and the ext4 sysfs knobs
Day 2 — XFS on disk and the fsync question
- Allocation groups and XFS's parallel layout
- B+trees everywhere: free space, inodes, extents and directories
- Delayed allocation and speculative preallocation
- The XFS log and log-force behaviour
- Crash consistency end to end: what fsync, fdatasync, O_SYNC and O_DIRECT really promise on both filesystems
- Inspection: xfs_info, xfs_db and xfs_io
Day 3 — Performance, repair and forensics
- Workload matching: small-file, large-file, metadata-heavy and parallel writers on both filesystems
- Fragmentation: causes, measurement and the defrag tools
- e2fsck vs xfs_repair: different philosophies, different failure modes
- Corruption forensics: reading a damaged filesystem with debugfs and xfs_db
- Backup and snapshot strategies consistent with each filesystem's guarantees
Hands-on labs
Labs follow the academy model — 35% principles, 20% guided investigation, 45% engineering studio. Every claim you make in a lab is backed by a trace, a counter or a measurement you captured yourself. How we teach
- Lab: dissect an ext4 image with dumpe2fs/debugfs and an XFS image with xfs_db — locate a file's extents and journal state by hand
- Lab: benchmark both filesystems with fio across small-file, large-file and fsync-heavy workloads and explain the divergence from the on-disk design
- Lab: compare ext4 journal modes under a crash-consistency workload and demonstrate what each mode loses on power failure
- Lab: corrupt-and-repair — damage a superblock, a journal and an inode table on expendable images, then recover with e2fsck/xfs_repair and verify the data
Capstone project
Run a full filesystem selection and recovery exercise: for a stated production workload you benchmark both candidates, write a one-page selection memo justified by your fio data and the crash-consistency guarantees, then recover a corrupted image of the winner to a verifiable state — checksums before corruption matching checksums after repair, or a precise statement of what was unrecoverable and why.
What you leave with
- On-disk literacy for both filesystems: debugfs and xfs_db without fear
- Journal/log modes and fsync semantics precise enough to design durability policies
- Benchmarks that map workload characteristics to allocation design
- A practised corrupt-and-repair drill for e2fsck and xfs_repair
How it runs
Every course follows the same model: 35% principles, 20% guided investigation, 45% engineering studio. You leave with working code, raw measurements and an evidence-based report — not a certificate of attendance. Read the methodology or see a full sample lesson.
Material is adapted to your kernel version, hardware and workload before a private delivery. For public cohorts, the environment is provided and configured.
Questions
Who is this course for?
Engineers who own production filesystem decisions — choosing between ext4 and XFS, tuning them, and performing the recovery when something corrupts at 3 a.m. It sits at advanced level within the Storage & Filesystems track.
What do I need to know already?
Specific prerequisites for this course: STO-201-level VFS knowledge or strong filesystem administration experience; Linux administration with loop devices and image files; Comfort reading C structs (on-disk layouts are read from source and headers). We confirm levels before the cohort starts and adapt if a group is stronger or weaker than expected.
Can this run privately for my team?
Yes. Any course runs on-site at your offices anywhere, or live online for a distributed team, with labs adapted to your hardware and codebase.
What is the difference between in-person and online?
In person is 3 full days with hardware on your desk, capped at 14. Online is 6 half-day sessions across about two weeks so you can keep working, capped at 20, with remote lab access.
Do you invoice companies?
Yes. Purchase orders are accepted and invoicing is available in USD, EUR, GBP, SAR and CAD.
Upcoming dates
| Dates | Where | Seats | Early bird | Regular | |
|---|---|---|---|---|---|
| 15 Nov – 17 Nov 20263 full days | RiyadhIn person · KAFD Conference Centre | 9 of 14 | SAR 8,100until 16 Oct | ||
| 22 Nov – 24 Nov 20263 full days | Kuwait CityIn person · Al Hamra Tower | 4 of 14 | KWD 670until 23 Oct | ||
| 29 Nov – 1 Dec 20263 full days | MuscatIn person · Knowledge Oasis Muscat | 9 of 14 | OMR 830until 30 Oct | ||
| 29 Nov – 6 Dec 20266 half-days | Gulf bandLive online · 09:00–13:00 GMT+3 | 5 of 20 | US$1,580until 30 Oct | ||
| 30 Nov – 2 Dec 20263 full days | OttawaIn person · Kanata North Tech Park | 4 of 14 | CAD 2,930until 31 Oct | ||
| 7 Dec – 9 Dec 20263 full days | TorontoIn person · MaRS Discovery District | 9 of 14 | CAD 2,930until 7 Nov | ||
| 7 Dec – 14 Dec 20266 half-days | Europe bandLive online · 09:00–13:00 CET | 10 of 20 | US$1,580until 7 Nov | ||
| 14 Dec – 16 Dec 20263 full days | LondonIn person · Shoreditch Works | 4 of 14 | GBP 1,680until 14 Nov | ||
| 14 Dec – 16 Dec 20263 full days | BerlinIn person · Factory Görlitzer Park | 9 of 14 | EUR 1,990until 14 Nov | ||
| 14 Dec – 21 Dec 20266 half-days | Americas bandLive online · 13:00–17:00 ET | 15 of 20 | US$1,580until 14 Nov |
Dates shown for the next few months. If nothing fits, tell us where and when — cohorts are added on demand, and private delivery can be scheduled any week.
More in Storage & Filesystems
STO-1013 days
Block Layer & I/O Schedulers
How an I/O request travels from the filesystem to the device, and what the scheduler does to it on the way.
Practitioner-taught
SAR 7,880Next 15 Nov
STO-1103 days
NVMe & NVMe-oF
NVMe as a protocol and as a driver, including fabrics for disaggregated storage.
Practitioner-taught
SAR 9,000Next 25 Oct
STO-1203 days
Device Mapper & LVM
Composing block devices: linear, striped, snapshot, thin provisioning, crypt and cache targets.
Practitioner-taught
SAR 7,880Next 11 Oct
STO-2013 days
VFS Internals
The abstraction every filesystem implements: inodes, dentries, the page cache and the locking around them.
Practitioner-taught
SAR 9,000Next 18 Oct
STO-2204 days
Writing a Filesystem from Scratch
Implement a small but real filesystem, which is the fastest way to genuinely understand the VFS.
Practitioner-taught
SAR 13,500Next 1 Nov