Skip to content

Topic archive

Linux

An open-source operating system ecosystem known for its flexibility, developer tooling, and widespread use on servers, cloud platforms, embedded devices, and workstations.

115 articles
Linux 19 Sep 2026 5 min read

timerfd Reads Count Periodic Expirations

A periodic timer can expire several times before a busy event loop gets CPU time again. Linux timerfd does not compress that delay into a bare “timer fired” notification. A successful read() returns an unsigned 64-bit count of expirations accumulated since the timer was armed or since the preceding successful read. That counter changes the semantics of delayed timer handling. Readiness says at least one expiration is pending; the value read from the descriptor says how many periods elapsed.

Linux 19 Sep 2026 5 min read

systemd Unit File Search Paths and Override Precedence

A systemd service file does not have to live in /etc/systemd/system. The system manager searches several directories for unit files, and the directory matters because the search order defines which definition wins when the same unit name exists in more than one place. For an administrator-managed service, /etc/systemd/system is usually the appropriate location. Distribution packages normally install units under /usr/lib/systemd/system, while /run/systemd/system is used for runtime configuration that disappears after reboot. This separation lets local configuration override vendor defaults without editing files owned by the package manager.

Linux 19 Sep 2026 4 min read

signalfd Converts Linux Signals into File-Descriptor Events

A conventional POSIX signal can interrupt a thread at almost any instruction boundary and transfer control to a signal handler. That asynchronous control flow imposes strict limits on handler code and complicates programs whose main control plane already runs through epoll, poll, or select. Linux signalfd() provides a different delivery interface. A process blocks selected signals in the normal signal mask, creates a signalfd for that set, and receives pending signals by reading structured signalfd_siginfo records from the descriptor. The signal remains a signal at the kernel interface; only its consumption moves into ordinary file-descriptor I/O.

Linux 19 Sep 2026 5 min read

seccomp User Notifications Move Selected System Calls to a Supervisor

seccomp User Notifications Move Selected System Calls to a Supervisor A seccomp filter can do more than allow a system call or reject it in the kernel. When a filter returns SECCOMP_RET_USER_NOTIF, Linux can suspend the calling thread and deliver a description of that attempted system call to a user-space supervisor. The mechanism creates an interposition boundary around selected calls. It is useful when a less-privileged process needs an operation mediated by another process, such as a container manager handling a call that the container cannot perform directly. The boundary is deliberately narrower than a general security-policy engine: notification state can race with mutable target memory, and the kernel documentation warns against treating the supervisor’s inspection as an authorization primitive.

Linux 19 Sep 2026 4 min read

Random Hex Is Not a Hash: Generating Cryptographic Random Values on Linux

A command such as openssl rand -hex 32 is often described as generating a “random hash.” The output certainly looks like a SHA-256 digest: 64 hexadecimal characters. But no hash operation has happened. OpenSSL generated 32 random bytes and encoded them as hexadecimal. That distinction matters. A hash function transforms input into a fixed-size digest. A cryptographically secure random number generator produces unpredictable bytes. If the requirement is a token, session secret, API credential, nonce, or other fresh random value, the random bytes are the important part. Hashing them afterward usually adds no useful unpredictability.

Linux 19 Sep 2026 6 min read

process_madvise Applies Memory Advice Across Process Boundaries

A process can consume memory on behalf of work that is coordinated elsewhere. Linux process_madvise() lets that external coordinator apply selected virtual-memory advice to ranges in the target process without injecting code into it. The target is identified by a pidfd, while the ranges are supplied as an array of struct iovec. That arrangement separates memory-policy decisions from the code that owns the mapping. A runtime manager, service supervisor, or memory controller can request reclaim-oriented or prefetch-oriented treatment for another process, subject to kernel support and permission checks. The system call does not transfer ownership of the mapping, freeze the target, or make its address space stable.

Linux 19 Sep 2026 6 min read

pidfd_getfd Duplicates a Live Descriptor Across Process Boundaries

A process can acquire a new descriptor that refers to the same open file description as a descriptor already held by another process, without asking that target process to send it. Linux provides this operation through pidfd_getfd(). The resulting descriptor is local to the caller, but the kernel object behind it is shared with the target descriptor. That distinction matters because a descriptor number is only an entry in one process’s descriptor table. The open file description carries state such as the current file offset and file status flags. Duplicating across a process boundary therefore transfers access to an existing kernel file instance rather than reopening the pathname or constructing an independent instance.

Linux 19 Sep 2026 5 min read

PID File Descriptors Give Linux a Stable Handle for Process Lifecycle Events

A numeric PID can name one process now and a different process later. Linux PID file descriptors change that boundary: a pidfd is a file descriptor that refers to a task, so process operations can remain attached to the intended kernel object instead of repeating a lookup by numeric PID. This distinction matters in supervisors, service managers, container runtimes, and other software that observes process lifecycles. A PID is useful for naming, but it is not a durable capability. A pidfd can participate in file-descriptor APIs and can be retained across the interval between identifying a process and acting on it.

Linux 19 Sep 2026 6 min read

PAGEMAP_SCAN Batches Page-Table State into Address Ranges

A large virtual address range may contain only a small number of page-state transitions. Reading one pagemap entry for every virtual page exposes that state at page granularity, but it also makes user space inspect a long sequence of entries. Linux PAGEMAP_SCAN moves the filtering into the kernel and reports matching spans as struct page_region records. The interface is an ioctl() on /proc/PID/pagemap. A request supplies an address interval, category predicates, a return mask, and an output vector. The kernel walks page tables and emits contiguous regions whose selected page properties match the request. This changes the shape of page-table inspection from a stream of per-page values into a filtered range query.

Linux 19 Sep 2026 6 min read

openat2 Constrains Path Resolution at the Kernel Boundary

A pathname that begins inside a trusted directory can resolve somewhere else before open() returns. Parent components, symbolic links, magic links, mount points, and concurrent namespace changes all participate in Linux pathname lookup. Checking a string before opening it therefore does not establish where the kernel will finish resolution. Linux openat2() places restrictions inside the lookup operation itself. A caller supplies a directory file descriptor, ordinary open flags, and a resolve policy in struct open_how. The kernel then applies those constraints while walking every relevant path component. This moves a security boundary from pre-validation of pathname text into the operation that actually resolves the pathname.

Linux 19 Sep 2026 5 min read

openat2 Constrains Linux Path Resolution at the Open Boundary

A pathname can change meaning while a process is resolving it. Directory renames, symbolic links, mount points, and .. components can redirect lookup away from the directory a program intended to treat as its boundary. Linux openat2() attaches resolution policy to the lookup itself. Its struct open_how contains a resolve bit mask, so the kernel can reject a path when resolution violates a caller-selected constraint instead of relying only on checks performed before open().

Linux 19 Sep 2026 4 min read

memfd Seals Constrain Shared-Memory Mutation After Handoff

A memfd_create() descriptor names an anonymous file whose storage lives in memory-backed filesystem infrastructure. By itself, descriptor handoff does not freeze that object: a process retaining suitable access can still write bytes, truncate the file, or extend it. Linux file seals add kernel-enforced restrictions that can make selected mutations fail after the producer declares the object complete. This changes shared-memory handoff from a convention into a state transition enforced at the file object.

Linux 19 Sep 2026 4 min read

MADV_FREE Marks Anonymous Pages for Lazy Reclaim

MADV_FREE does not immediately replace a private anonymous page with zeros. It marks eligible pages as disposable, allowing Linux to reclaim them later. Until reclaim actually occurs, existing bytes can remain observable. A write before reclaim cancels the disposable state for the affected page. That timing makes MADV_FREE distinct from advice that immediately changes the process-visible state of a range. It is a lazy reclamation contract: the application declares that old contents are expendable, while the kernel chooses when physical memory is recovered.

Linux 19 Sep 2026 5 min read

io_uring Multishot Requests Persist Across Completion Events

A normal io_uring request has a simple lifetime: userspace submits one SQE and eventually receives one CQE. Multishot operations change that relationship. One submitted request can remain active in the kernel and produce several completion queue entries as matching events occur. That persistence changes completion handling from a one-CQE-per-request assumption into an explicit lifecycle protocol. The decisive state is carried by IORING_CQE_F_MORE: when the flag is present, the originating request can produce another completion; when it is absent, that multishot request has terminated.

Linux 19 Sep 2026 6 min read

Idmapped Mounts Remap Ownership Without Rewriting Inodes

The same inode can appear with different ownership through two mount points without any recursive chown(). Linux idmapped mounts attach an ID mapping to a mount, so VFS ownership presentation and permission checks can translate user and group IDs for that view while the ownership stored by the filesystem remains unchanged. This property separates persistent inode metadata from the identity view exposed at a particular mount. It is especially useful when a filesystem tree must be shared with a container whose user namespace maps IDs differently from the host.

Linux 19 Sep 2026 4 min read

How Linux Maps an ESP32 USB-UART Bridge to /dev/ttyUSB0 on Fedora

An ESP32 development board connected through a CH341 USB-to-UART bridge does not appear on Fedora as a Windows-style COM port. Linux binds the USB interface to a serial driver and exposes a character device such as /dev/ttyUSB0. A working connection can produce this kernel message: usb 5-1: ch341-uart converter now attached to ttyUSB0 That line confirms USB enumeration, binding to the ch341 serial driver, and creation of ttyUSB0. The path used by a flasher or serial monitor is therefore /dev/ttyUSB0.

Linux 19 Sep 2026 5 min read

eventfd Turns Kernel Notifications into Pollable Counters

A Linux process can signal work through a file descriptor without moving a byte stream between producer and consumer. eventfd() creates a kernel-maintained 64-bit counter whose readiness can be observed by poll(), select(), or epoll. A write adds to the counter; a read consumes its accumulated state according to the descriptor mode. That shape makes eventfd different from a pipe. A pipe preserves a sequence of bytes. An eventfd preserves counter state. When the application needs a wakeup edge plus a compact amount of accumulated state, that distinction removes buffering and framing that a byte stream would otherwise require.

Linux 19 Sep 2026 5 min read

Configure Wi-Fi on Ubuntu Server Without Guessing the Netplan Backend

A Netplan Wi-Fi block can be syntactically valid and still be wrong for a particular Ubuntu Server. The two values that cannot safely be copied from an example are the interface name and the renderer. A configuration that names wlp2s0 assumes the machine actually has an interface with that name. Setting renderer: networkd assumes the installation is intended to use systemd-networkd; for Wi-Fi, that backend also relies on wpa_supplicant. Other installations may already be managed by NetworkManager.

Linux 19 Sep 2026 5 min read

close_range Makes File-Descriptor Cleanup a Single Linux Operation

A process preparing to execute another program often needs a simple boundary: descriptors 0, 1, and 2 remain available, while every higher descriptor must disappear. Repeating close() over a guessed numeric limit or enumerating /proc/self/fd turns that boundary into a userspace scan. Linux close_range() expresses the interval directly. The kernel applies one operation to every open file descriptor from first through last, inclusive. With flags, the same interface can isolate a shared descriptor table or mark the interval close-on-exec instead of closing it immediately.

Linux 19 Sep 2026 4 min read

CLONE_INTO_CGROUP Places a Child in Its Target cgroup at Creation

CLONE_INTO_CGROUP Places a Child in Its Target cgroup at Creation A process created in one cgroup and moved to another has a short but real interval in the original cgroup. During that interval, accounting, resource controls, and freezer state come from the initial placement rather than the destination. Linux provides CLONE_INTO_CGROUP so clone3() can place the child in a cgroup v2 target as part of process creation. This changes the placement boundary. Instead of creating a task and repairing its cgroup membership afterward, the caller identifies the destination before the child exists.

Linux 18 Sep 2026 5 min read

userfaultfd Turns Page Faults into Userspace Events

A thread can fault on a virtual address and remain blocked while another userspace thread or process decides what page state should make that access continue. userfaultfd provides this boundary by turning selected page faults into messages on a file descriptor and pairing those messages with ioctls that resolve the fault. The mechanism does not replace the kernel page-fault machinery. It inserts userspace control at registered ranges and fault classes, while the kernel still owns page tables, fault blocking, and the transition that makes the page usable again.

Linux 18 Sep 2026 4 min read

timerfd Counts Expirations Through Descriptor I/O

A periodic timerfd does not require one userspace wakeup for every timer expiration. If several expirations occur before the descriptor is read, Linux accumulates them and returns the count in one 8-byte integer. That behavior makes timer state fit the same readiness model used for sockets, pipes, and other descriptors. It also gives delayed event loops explicit information about missed periods rather than collapsing several expirations into one notification. Expiration state becomes readable descriptor data timerfd_create() creates a timer object and returns a file descriptor referring to it. The selected clock defines the timer’s time base. Common choices include CLOCK_MONOTONIC, CLOCK_REALTIME, and CLOCK_BOOTTIME.

Linux 18 Sep 2026 5 min read

Seccomp User Notifications Delegate Selected System Calls to a Supervisor

A seccomp filter can stop a selected system call before execution and turn it into a request on a listener file descriptor. The calling thread remains blocked while a userspace supervisor examines the notification and returns a result. This creates a mediation boundary that is narrower than tracing every system call and more dynamic than encoding every decision directly in classic BPF. The mechanism is SECCOMP_RET_USER_NOTIF. A filter returns that action for operations that require external mediation. A filter installed with SECCOMP_FILTER_FLAG_NEW_LISTENER yields a listener file descriptor, and a supervisor uses seccomp notification ioctls on that descriptor.

Linux 18 Sep 2026 4 min read

process_madvise Applies Memory Reclaim Advice Across Process Boundaries

process_madvise() can make one Linux process request memory-management action for virtual-address ranges owned by another process. The target is identified by a pidfd, while an iovec array names the target ranges. This separates memory-policy decisions from the process whose mappings receive the advice. The interface is useful for controllers that already have external knowledge about workload state. A runtime manager can mark inactive memory cold or request page reclamation without injecting code into the managed process. That capability is bounded by permission checks, supported advice values, and partial-progress semantics.