---
title: 'Linux Kernel: Learning Along a Single Program Execution'
url: https://doc.liz6.com/en/linux-kernel/00-learning-path
locale: en
area: linux-kernel
tags:
- Linux kernel
date: 2026-09-12
modified: 2026-09-12
description: For readers who can read C pointers, structures, and basic concurrent code, and can compile and run small programs in Linux. First understand user-space processes, file descriptors, and system calls; if lacking, follow the [Systems Programming Learning Path](../systems-programming/00-learning-path.md) first. Kernel versions affect structures and paths; record the version used when reading source code, and do not treat any field as a permanent interface.
---

# Linux Kernel: Learning Along a Single Program Execution

For readers who can read C pointers, structures, and basic concurrent code, and can compile and run small programs in Linux. First understand user-space processes, file descriptors, and system calls; if lacking, follow the [Systems Programming Learning Path](../systems-programming/00-learning-path.md) first. Kernel versions affect structures and paths; record the version used when reading source code, and do not treat any field as a permanent interface.

## What you will build

Explain the kernel's responsibilities around "starting a program, accessing memory, reading files, blocking and waking up," and support your explanation with a reproducible observation.

## Required reading and checkpoints

1. [task_struct and Process Lifecycle](01-process-management/01-task-struct-and-process-lifecycle.md) → [Virtual Memory: Understanding Page Tables, Page Faults, and TLBs from a Single Memory Access Instruction](02-memory-management/01-virtual-memory.md).

   Start from process startup and the first access to a page of memory. Self-check: Distinguish between virtual addresses, page table mappings, page faults, and the stored data itself; be able to point out the relationship between process state and executing threads.

2. [VFS: From Pathnames to Open Files](03-file-system/01-VFS.md) → [Block Device Layer](07-block-device-layer/01-block-device-layer.md).

   Trace an open/read/close of a small program, separating path lookup, open files, caching, and device requests. Self-check: Repeated reads do not necessarily trigger new device I/O; you must explain which layer hit based on observations.

3. [Locking Mechanisms and Memory Ordering](05-synchronization-mechanisms/01-locking-mechanisms.md) → [eBPF Basics](08-ebpf-and-observability/01-ebpf-basics.md) → [Debugging and Testing](11-kernel-development-and-build/02-debugging-and-testing.md).

   First identify shared objects, lifecycles, and execution contexts, then select observation tools. Self-check: What is the difference between one wait and one busy-wait; why can't the number of observed calls directly prove lock correctness.

## Optional branches

Read [RCU](05-synchronization-mechanisms/02-RCU.md) after lifecycle and memory ordering; for containers, follow [namespaces](12-containers-and-primitives/01-namespaces.md) and [cgroup](12-containers-and-primitives/02-cgroup.md); for networking, follow [Protocol Stack Overview](06-network-subsystem/01-network-protocol-stack-overview.md). Drivers, DMA, KVM, and power management are entered based on actual problems, not as prerequisites for the first program.

## Completion task

Deliver a small program that opens and reads a file twice, the runtime environment and kernel version, system call or trace output, and an explanation from user-space to kernel. Write at least one conclusion stating "this output alone cannot prove." For performance issues, refer to [Queueing Theory](../theory/03-queueing-theory/index.md), first distinguishing between resource utilization and queueing wait.

On the first read, it is allowed to skip long proofs and implementation details, but you must complete the self-checks for each phase. When you encounter "knowing the terminology but unable to explain the results," return to the current example, change one condition, and then proceed to the next article; there is no need to read the entire directory first.
