eBPF Explained: Safe, Programmable Observability in the Linux Kernel
Understand eBPF programs, verifier, maps, hooks, BTF and CO-RE, privileges and operational risks without treating kernel execution as a sandbox.
Conceptual, architectural explainers - how a subsystem actually works underneath.
Understand eBPF programs, verifier, maps, hooks, BTF and CO-RE, privileges and operational risks without treating kernel execution as a sandbox.
Build, inspect, sign, load and remove a minimal out-of-tree Linux module inside a disposable VM with matching kbuild artifacts and safe rollback.
Compare SELinux label policy and AppArmor profiles through enforcement, logging, safe policy changes, containers and a denial-first audit workflow.
Understand Linux namespace types, ownership, lifetime and composition, then inspect containers without mistaking an isolated view for security.
Compare APT/dpkg, DNF4/DNF5/RPM and Pacman workflows, trust, transactions, upgrades and recovery without mixing incompatible repositories.
Read procfs and sysfs safely across PID, user, mount and network namespaces; inspect volatile kernel state without leaking secrets or changing hardware.
Understand systemd unit loading, dependency and ordering graphs, service readiness, activation, credentials, sandboxing and forensic debugging.
Understand Linux VFS path lookup, dentries, inodes, open-file descriptions, mounts, page cache, permissions and safe resolution across filesystems.
How APFS's container/volume model, copy-on-write clones, and snapshots replaced HFS+ across every Apple platform starting in 2017.
How Apple Silicon's secure boot chain differs from Intel Macs, and the stages both go through to reach the login window.