1
00:00:00,005 --> 00:00:02,002
- [Instructor] What is this Linux Kernel thing?

2
00:00:02,002 --> 00:00:04,002
Well, let's talk about it.

3
00:00:04,002 --> 00:00:06,009
The Kernel is a program, compiled program.

4
00:00:06,009 --> 00:00:08,005
The Kernel program has a name.

5
00:00:08,005 --> 00:00:09,009
That file has a name.

6
00:00:09,009 --> 00:00:15,002
The name is something like vmlinuz-<kernel version>.

7
00:00:15,002 --> 00:00:18,003
That program needs to be loaded into memory and run,

8
00:00:18,003 --> 00:00:21,001
and that operation is done by a boot loader.

9
00:00:21,001 --> 00:00:24,003
With Linux, we often have a boot loader called GRUB.

10
00:00:24,003 --> 00:00:27,002
So GRUB reads the kernel, file from disc,

11
00:00:27,002 --> 00:00:30,004
puts it in memory, and transfers control to it.

12
00:00:30,004 --> 00:00:33,001
The Kernel program, like other programs,

13
00:00:33,001 --> 00:00:36,000
actually has some command line parameters that you can set,

14
00:00:36,000 --> 00:00:37,007
and GRUB is responsible

15
00:00:37,007 --> 00:00:41,001
for passing those parameters to the Kernel.

16
00:00:41,001 --> 00:00:43,002
The Linux Kernel also has an API.

17
00:00:43,002 --> 00:00:45,003
It provides a programming interface.

18
00:00:45,003 --> 00:00:47,006
The functions that we can call from user space

19
00:00:47,006 --> 00:00:51,004
into the Kernel, we call system calls,

20
00:00:51,004 --> 00:00:53,004
but the Linux Kernel also provides

21
00:00:53,004 --> 00:00:56,001
virtual file systems, proc and sys,

22
00:00:56,001 --> 00:00:58,009
and the lesser known debugfs, for example.

23
00:00:58,009 --> 00:01:01,003
And through those virtual file systems,

24
00:01:01,003 --> 00:01:03,006
we can interact directly with the Kernel,

25
00:01:03,006 --> 00:01:05,004
getting information from the Kernel

26
00:01:05,004 --> 00:01:08,000
and changing things in the Kernel.

27
00:01:08,000 --> 00:01:10,007
And our system has device files.

28
00:01:10,007 --> 00:01:12,006
We interact with device drivers

29
00:01:12,006 --> 00:01:16,005
by doing operations on those device files.

30
00:01:16,005 --> 00:01:19,000
Those operations are standard system calls

31
00:01:19,000 --> 00:01:22,000
like read and write and open.

32
00:01:22,000 --> 00:01:23,006
The Kernel is a gatekeeper.

33
00:01:23,006 --> 00:01:25,006
The Kernel enforces privileges.

34
00:01:25,006 --> 00:01:29,002
In Linux, we call those privileges capabilities,

35
00:01:29,002 --> 00:01:31,002
and the Linux Kernel source code,

36
00:01:31,002 --> 00:01:34,002
it refers to the capabilities of a process

37
00:01:34,002 --> 00:01:36,009
to see if it's allowed to perform some sort

38
00:01:36,009 --> 00:01:39,003
of privilege operation.

39
00:01:39,003 --> 00:01:43,000
Linux Kernel also implements a number of security policies,

40
00:01:43,000 --> 00:01:46,008
the underlying mechanisms used by SE Linux

41
00:01:46,008 --> 00:01:48,009
and App Armor, for example.

42
00:01:48,009 --> 00:01:51,006
And finally, the Kernel provides controlled access

43
00:01:51,006 --> 00:01:54,002
to hardware and other resources.

44
00:01:54,002 --> 00:01:56,001
It wouldn't be safe to allow processes

45
00:01:56,001 --> 00:02:01,003
to willy-nilly access the disc at will, for example, no.

46
00:02:01,003 --> 00:02:03,007
The Kernel has to provide controlled access

47
00:02:03,007 --> 00:02:05,008
to make sure that things are done

48
00:02:05,008 --> 00:02:09,004
in an orderly and safe manner.

49
00:02:09,004 --> 00:02:11,001
The Kernel is modular.

50
00:02:11,001 --> 00:02:17,001
The Kernel itself, that vmlinuz file is relatively small.

51
00:02:17,001 --> 00:02:19,007
The Kernel image is sufficient to boot to user space

52
00:02:19,007 --> 00:02:22,002
to begin running the first process.

53
00:02:22,002 --> 00:02:24,001
Once we have that process

54
00:02:24,001 --> 00:02:25,008
and the ones that started,

55
00:02:25,008 --> 00:02:28,008
we can load additional functionality into the Kernel

56
00:02:28,008 --> 00:02:31,007
through the loadable Kernel module mechanism.

57
00:02:31,007 --> 00:02:34,001
The loadable module mechanism means

58
00:02:34,001 --> 00:02:36,009
we can just load the drivers that we need.

59
00:02:36,009 --> 00:02:38,001
We don't need to load drivers

60
00:02:38,001 --> 00:02:40,005
for hardware that's not present.

61
00:02:40,005 --> 00:02:43,003
We can also load additional sorts of functionality

62
00:02:43,003 --> 00:02:47,006
that's not drivers, but, say, for security or other things.

63
00:02:47,006 --> 00:02:51,000
We'll be looking at all of those in some detail.

