Advanced Operating Systems

Academic Year 2026/2027 - Teacher: GAETANO PATTI

Expected Learning Outcomes

Knowledge and understanding

Upon completion of the course, students will have acquired advanced knowledge of the mechanisms through which a modern operating system shares, isolates and controls the hardware resources of a computer: virtualization and the memory management on which it relies; the Linux kernel mechanisms that make it possible to build containers, a lighter-weight alternative to virtualization; device drivers, which manage access to the hardware; the extended Berkeley Packet Filter (eBPF) technology, which allows the kernel's functionality to be safely extended with programs loaded from user space; and resource management in real-time systems, where scheduling and access to shared resources must guarantee that the timing constraints of the supported applications are met. Students will also be able to understand the design issues underlying each mechanism, the advantages and limitations of the different solutions, and their impact on system performance and timing predictability.

Applying knowledge and understanding
By the end of the course, students will be able to: configure and run virtual machines; build an isolated execution environment (container) using kernel primitives and limit its resources; design, compile, load and test a kernel module implementing a device driver with an interface to the user space; write and run an eBPF-based program in the kernel; develop a real-time application and compare its timing behavior on a microcontroller and on a general-purpose system.

Making judgements
On completion of the course, students will be able to choose, with justification, the most suitable technology for a given requirement (emulation, virtualization, partitioning, container-based isolation or a dedicated system), and to discuss its advantages, limitations and implications for timing predictability. This ability is developed through the exercises carried out during the course and through the final project, which requires students to justify their design choices.

Communication skills
By the end of the course, students will have acquired the technical terminology of advanced operating systems and will be able to clearly present the design choices made, the advantages and limitations of the adopted solutions, and the results obtained, to both specialist and non-specialist audiences.

Learning skills
By the end of the course, students will be able to continue their studies independently, starting from the official documentation of the operating systems studied, manufacturers' manuals and the scientific literature in the field. The readings assigned during the course and the completion of the final project specifically contribute to this objective.

Course Structure

The course is mainly based on lectures and exercise sessions, which include exercises worked out by the lecturers. The course also includes practical exercises carried out by the students (hands-on sessions), which are also held in the University's computer labs. The lecturers supervise the students' work, providing the necessary explanations and teaching support.

The teaching methods described above make it possible to achieve the intended learning objectives, which include the acquisition of knowledge and the ability to apply it.

Should the course be delivered in blended or remote mode, the necessary changes to the above may be introduced in order to comply with the programme planned and set out in the syllabus.

Required Prerequisites

Prerequisites required to successfully reach the course goals:

  1. C programming: pointers and pointer arithmetic, structures, dynamic memory allocation, function pointers, use of the compiler and of a build system;
  2. concepts of process and thread, process states, context switching;
  3. hands-on use of a GNU/Linux command-line environment and of the main POSIX system calls for process management;
  4. concurrent programming with POSIX threads: thread creation and synchronization, mutexes, critical sections;
  5. inter-process communication mechanisms and sockets;
  6. computer architecture: memory hierarchy, interrupts, registers, I/O devices, multiprocessor architectures;
  7. basic concepts of virtual memory (paging, page faults) and virtualization (difference between type 1 and type 2 hypervisors, paravirtualization, container-based isolation).

Attendance of Lessons

Attendance is strongly recommended.

Detailed Course Content

Asterisks (*) indicate the minimum skills.

Virtualization and hypervisors. General concepts and virtualizability requirements. Emulation, dynamic binary translation, paravirtualization, hardware extensions. Case study: KVM. Criteria for choosing among emulation, virtualization and partitioning (*).

Memory management. Physical memory management in Linux and its impact on timing predictability (*). Address translation, the TLB and its invalidation, address spaces in virtual machines.

Linux mechanisms for containers. Namespaces: model and system calls; cgroups. Comparison between containers and virtual machines in terms of isolation (*).

Kernel-mode driver development. Kernel modules: life cycle, out-of-tree build, loading and unloading, with practical examples. Design issues of a device driver: a design example and the interface to user space (*).

eBPF (extended Berkeley Packet Filter). Life cycle of an eBPF program. The verifier and the security model. Maps, program types and choice of the attach point. Development workflow with libbpf, required privileges, cost and limitations of the technology (*).

Resource management in real-time systems. General concepts, predictability. Design issues: scheduling, access to shared resources. Case studies (*).

Textbook Information

For the part on virtualization and memory management:

  • A. S. Tanenbaum, H. Bos, Modern Operating Systems, 5th ed., Pearson, 2023, ISBN: 9781292459660.

For the part on kernel-mode drivers:

  • J. Madieu, Linux Device Driver Development, 2nd ed., Packt Publishing, 2022, ISBN: 9781803240060.

For the part on containers and eBPF:

  • L. Rice, Container Security, 2nd ed., O'Reilly, 2025, ISBN: 9798341627703.
  • L. Rice, Learning eBPF, O'Reilly, 2023, ISBN: 9781098135126.

For the part on resource management in real-time systems:

  • G. C. Buttazzo, Hard Real-Time Computing Systems, 4th ed., Springer, 2023, ISBN: 9783031454127.

Supplementary documentation and material, lecture notes and exercise sheets prepared by the lecturers, available on STUDIUM in the course area.


AuthorTitlePublisherYearISBN
A. S. Tanenbaum, H. BosModern Operating Systems, 5th ed.Pearson20239781292459660 
J. MadieuLinux Device Driver Development, 2nd ed.Packt Publishing20229781803240060
L. RiceContainer Security, 2nd ed.O'Reilly20259798341627703
L. RiceLearning eBPFO'Reilly20239781098135126
G. C. ButtazzoHard Real-Time Computing Systems, 4th ed.Springer20239783031454127

Course Planning

 SubjectsText References
1Virtualization and hypervisors. General concepts and virtualizability requirements. Emulation, dynamic binary translation, paravirtualization, hardware extensions. Case study: KVM. Criteria for choosing among emulation, virtualization and partitioning.Tanenbaum: Chapter 7. Further readings assigned during the course. Lecture notes by the lecturers available on STUDIUM.
2Memory management. Physical memory management in Linux and its impact on timing predictability. Address translation, the TLB and its invalidation, address spaces in virtual machines.Chapters 3 and 7. Official Linux kernel documentation. Lecture notes by the lecturers available on STUDIUM.
3Linux mechanisms for containers. Namespaces: model and system calls; cgroups. Comparison between containers and virtual machines in terms of isolation.Rice: Container Security. Official Linux kernel documentation. Lecture notes by the lecturers available on STUDIUM.
4Kernel-mode driver development. Kernel modules: life cycle, out-of-tree build, loading and unloading, with practical examples. Design issues of a device driver: a design example and the interface to user space.Madieu. Official Linux kernel documentation. Lecture notes by the lecturers available on STUDIUM.
5eBPF (extended Berkeley Packet Filter). Life cycle of an eBPF program. The verifier and the security model. Maps, program types and choice of the attach point. Development workflow with libbpf, required privileges, cost and limitations of the technology.Rice, Learning eBPF. Gregg. Official Linux kernel documentation. Lecture notes by the lecturers available on STUDIUM.
6Resource management in real-time systems. General concepts, predictability. Design issues: scheduling, access to shared resources. Case studies.Buttazzo. Lecture notes by the lecturers available on STUDIUM.

Learning Assessment

Learning Assessment Procedures

The exams are scheduled in agreement with the CdS, in compliance with the procedures established by the academic calendar. Registration through the University portal is required.

The exam consists of an individual final project and an oral interview in which the student discusses the project. The assessment covers the entire course syllabus.

The project is individual; it is assigned and prepared during the course and consists in the development and documentation of a project that applies the topics covered in the course. The project is not graded separately. It forms the basis of the exam discussion and is intended to allow the lecturers to assess, during the interview, the student's design skills and knowledge of the topic addressed.

In the oral interview, the student presents the project, explaining the design choices and their rationale, the advantages and limitations of the adopted solution and any results obtained. The interview then extends to the topics related to the project and to the other topics covered during the course. The assessment criteria are the relevance of the answers, the correctness and depth of the content, the ability to justify design choices and to identify their advantages and limitations, the ability to provide concrete examples, the appropriate use of technical language and clarity of presentation.

The assessment may also be carried out online, should conditions require it.

To guarantee equal opportunities and in compliance with current legislation, interested students may request a personal meeting in order to plan any compensatory and/or dispensatory measures, based on the educational objectives and their specific needs. Students may also contact the CInAP (Centro per l'integrazione Attiva e Partecipata – Services for Disabilities and/or Specific Learning Disorders) contact person of their Department (https://www.cinap.unict.it/content/referenti).

Examples of frequently asked questions and / or exercises

Conditions under which an architecture can be virtualized, and their practical consequences

Emulation, dynamic binary translation, paravirtualization and hardware extensions: differences and areas of application

Criteria for choosing among emulation, virtualization and partitioning, given an application requirement

Namespaces and cgroups: the form of isolation each mechanism provides and its limitations

Comparison between containers and virtual machines in terms of isolation

Main design issues of a device driver and criteria for addressing them

Life cycle of an eBPF program, role of the verifier and security model of the technology

Sources of unpredictability in general-purpose operating systems

Timing constraints and their nature

Real-time scheduling algorithms and the related schedulability analysis

Issues related to access to shared resources in a real-time system