Agent skill

Kernel Internals

by mohitmishra786 in mohitmishra786/low-level-dev-skills

Linux kernel internals skill for scheduler, memory, and VFS subsystems.

MITAuto-check: notes

Install Kernel Internals

skills CLI
$ npx skills add mohitmishra786/low-level-dev-skills --skill kernel-internals -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mohitmishra786/low-level-dev-skills kernel-internals --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mohitmishra786/low-level-dev-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/kernel/kernel-internals .claude/skills/kernel-internals && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kernel-internals
GitHub stars
253
Token cost
~1.8k tokens
SKILL.md length
478 words
Files
1
Skills in repo
138
Repo updated
First seen
Licence
MIT

At a glance

Linux kernel internals skill for scheduler, memory, and VFS subsystems.

  • Works in 9 steps: Scheduler — CFS and EEVDF → EEVDF specifics → Memory subsystem — buddy allocator → …
  • Analyzing CFS/EEVDF scheduling
  • SKILL.md covers Purpose, When to Use, Workflow and Common Problems, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Kernel Internals is an agent skill from mohitmishra786/low-level-dev-skills. Linux kernel internals skill for scheduler, memory, and VFS subsystems. Use when analyzing CFS/EEVDF scheduling, buddy/SLUB allocators, page cache, memory zones, OOM killer, or interpreting /proc/meminfo. Activates on queries about kernel scheduler, vruntime, SLUB, vmalloc, page cache, or OOM killer.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Linux. The repository describes itself as: A curated suite of AI agent skills for systems and low-level programming with C/C++, Rust, and Zig toolchains, covering compilers, debuggers, profilers, build systems…. The licence is MIT.

When your agent uses it

  • Analyzing CFS/EEVDF scheduling
  • Buddy/SLUB allocators
  • Interpreting /proc/meminfo

Example prompts

  • “/kernel-internals”

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Scheduler — CFS and EEVDF
  2. EEVDF specifics
  3. Memory subsystem — buddy allocator
  4. SLUB allocator
  5. Highmem
  6. VFS layer
  7. Page cache and readahead
  8. /proc/meminfo interpretation
  9. OOM killer

What it can do on your machine

Read from SKILL.md and the folder at commit bdc5847. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash and c).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kernel Internals loads about 1.8k tokens when it runs. Until then it costs about 80 tokens; SKILL.md has 478 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~80
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:146
    sync && echo 3 | sudo tee /proc/sys/vm/drop_caches
  • NoteRuns commands with sudoSKILL.md:202
    echo -1000 | sudo tee /proc/<pid>/oom_score_adj

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mohitmishra786/low-level-dev-skills at commit bdc5847, republished under its MIT licence (© mohitmishra786). 478 words, ~1,753 tokens.

Download SKILL.mdSave it as .claude/skills/kernel-internals/SKILL.md (or your agent's skills folder).
name
kernel-internals
description
Linux kernel internals skill for scheduler, memory, and VFS subsystems. Use when analyzing CFS/EEVDF scheduling, buddy/SLUB allocators, page cache, memory zones, OOM killer, or interpreting /proc/meminfo. Activates on queries about kernel scheduler, vruntime, SLUB, vmalloc, page cache, or OOM killer.

Kernel Internals

Purpose

Guide agents through Linux kernel internals: the CFS and EEVDF schedulers, runqueues and vruntime, the buddy allocator and SLUB, vmalloc vs kmalloc, VFS dentry/inode/file objects, page cache and readahead, memory zones, OOM killer heuristics, and /proc/meminfo interpretation.

When to Use

  • Diagnosing scheduling latency or unfair CPU distribution
  • Understanding kmalloc failures vs vmalloc for large kernel allocations
  • Analyzing page cache behavior and readahead effectiveness
  • Interpreting /proc/meminfo during memory pressure
  • Debugging OOM killer victim selection
  • Reading kernel source in kernel/sched/, mm/, or fs/

Workflow

1. Scheduler — CFS and EEVDF

Linux uses EEVDF (Earliest Eligible Virtual Deadline First) for CFS-class scheduling. EEVDF was merged as an option in 6.6 (2023); the gradual CFS→EEVDF transition completed in 6.12 (Nov 2024). On older 6.6–6.11 kernels, verify which scheduler is active. Core concepts (runqueues, vruntime/lag) carry over:

Per-CPU runqueue (struct rq)
├── cfs_rq — fair-class tasks sorted by vruntime/deadline
├── rt_rq  — real-time tasks (FIFO/RR)
└── dl_rq  — SCHED_DEADLINE tasks

Key metrics:

bash
# Task scheduling info
chrt -p <pid>
cat /proc/<pid>/sched

# Runqueue latency (scheduler debugging)
cat /sys/kernel/debug/sched/debug  # requires debugfs

# Trace scheduler events
perf sched record -a -- sleep 5
perf sched latency

vruntime — virtual runtime tracking CPU time consumed; lower vruntime = more eligible for CPU.

bash
# CFS tunables
sysctl kernel.sched_latency_ns
sysctl kernel.sched_min_granularity_ns
sysctl kernel.sched_wakeup_granularity_ns
2. EEVDF specifics

EEVDF picks the task with the earliest eligible virtual deadline, improving latency fairness for short time-slice tasks. Tasks with positive lag are eligible; the scheduler selects the earliest virtual deadline among eligible tasks.

bash
# Check kernel version (EEVDF transition complete in 6.12+)
uname -r

# Scheduler documentation
# docs.kernel.org/scheduler/sched-eevdf.html
3. Memory subsystem — buddy allocator

Physical pages allocated in power-of-two order (order 0 = 4KB, order 1 = 8KB, ...).

ZONE_DMA / ZONE_DMA32 / ZONE_NORMAL / ZONE_MOVABLE
└── free_area[MAX_ORDER] — buddy lists per order
bash
# Buddy allocator stats
cat /proc/buddyinfo

# Per-zone page counts
cat /proc/zoneinfo | head -80
4. SLUB allocator

Default kmalloc backend — per-CPU caches (slabs) for common sizes.

bash
# SLUB debug (requires CONFIG_SLUB_DEBUG)
cat /sys/kernel/slab/*/objects 2>/dev/null | head

# kmalloc size classes visible in /proc/slabinfo
cat /proc/slabinfo | head -20
APIUse when
kmalloc(size, GFP_KERNEL)≤ ~128KB (arch-dependent), physically contiguous
kzalloc(size, flags)Zeroed kmalloc
vmalloc(size)Large, virtually contiguous (may be physically fragmented)
get_free_pages()Direct page allocation
c
// Kernel module allocation example
void *buf = kmalloc(4096, GFP_KERNEL);
if (!buf)
    return -ENOMEM;
kfree(buf);
5. Highmem

On 32-bit or specific configs, ZONE_HIGHMEM holds pages not permanently mapped in kernel virtual address space. On 64-bit x86/arm64, essentially all RAM is in ZONE_NORMAL.

bash
grep -i highmem /proc/zoneinfo
6. VFS layer
Path lookup: /home/user/file.txt
├── dentry cache (dcache) — directory entry tree
├── inode — metadata (permissions, size, ops)
└── file — per-open-file state (offset, flags)
bash
# Mounted filesystems
cat /proc/mounts

# Inode/dentry cache pressure
sysctl vm.vfs_cache_pressure   # higher = reclaim caches sooner

# File descriptor usage
ls /proc/<pid>/fd | wc -l
7. Page cache and readahead
bash
# Drop caches (testing only — destructive to perf)
sync && echo 3 | sudo tee /proc/sys/vm/drop_caches

# Readahead tuning
blockdev --getra /dev/sda
blockdev --setra 4096 /dev/sda

# Per-file cache status
cat /proc/<pid>/smaps_rollup

Page cache pages appear as Cached in meminfo. Dirty pages await writeback.

Show full SKILL.md (192 more words)Show less
8. /proc/meminfo interpretation
bash
cat /proc/meminfo
FieldMeaning
MemTotalTotal usable RAM
MemFreeCompletely unused pages
MemAvailableEstimate of allocatable memory (includes reclaimable cache)
CachedPage cache + tmpfs
BuffersBlock device metadata cache
SwapTotal / SwapFreeSwap space
DirtyPages pending writeback
AnonPagesAnonymous (heap/stack) pages
SlabKernel object cache
SReclaimableReclaimable slab
SUnreclaimKernel structures (not easily reclaimed)
Memory pressure diagnosis
├── MemAvailable low + Cached high → page cache reclaim candidate
├── AnonPages high + SwapFree low → OOM risk
├── Slab huge → kernel object leak; check /proc/slabinfo
└── Dirty high → slow writeback; check I/O scheduler
9. OOM killer
bash
# OOM score per process (higher = more likely victim)
cat /proc/<pid>/oom_score
cat /proc/<pid>/oom_score_adj   # -1000 to 1000, admin adjustment

# OOM events in kernel log
dmesg | grep -i "out of memory"
journalctl -k | grep -i oom

OOM killer selects based on oom_score considering memory usage, child processes, and oom_score_adj. Protect critical daemons:

bash
# Protect process from OOM (requires root)
echo -1000 | sudo tee /proc/<pid>/oom_score_adj

Common Problems

SymptomCauseFix
kmalloc: allocation failedFragmentation or size too largeUse vmalloc; reduce pressure; GFP_ATOMIC only when needed
High iowait, low MemAvailablePage cache thrashingIncrease RAM; tune vfs_cache_pressure
OOM kills wrong processHigh memory user with low adjSet oom_score_adj; use cgroups memory.max
Scheduling unfairnessRT tasks starving CFSCheck chrt; isolate CPUs with isolcpus
SLUB corruptionUse-after-free in moduleEnable KASAN; audit with slub_debug
Slow file readsReadahead too smallIncrease readahead; check backing device
  • skills/kernel/device-drivers — char/platform drivers using these subsystems
  • skills/kernel/kernel-debugging — ftrace, kgdb for internals investigation
  • skills/low-level-programming/linux-kernel-modules — LKM development basics
  • skills/kernel/kernel-testing — KUnit for subsystem unit tests
  • skills/profilers/linux-perf — perf sched and memory profiling
  • skills/observability/ebpf — trace scheduler and memory events from userspace

© mohitmishra786, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/kernel/kernel-internals of mohitmishra786/low-level-dev-skills.

Open the folder on GitHubat commit bdc5847

Compare with similar skills

Kernel Internals next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kernel Internals compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kernel Internals this skillmohitmishra786/low-level-dev-skills253—~1.8kAutomated safety check: NotesMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT
Upgrade Browserflutter/flutter179k—~1.1kAutomated safety check: PassBSD-3-Clause
K8s Security PoliciesCybereason-Public/owLSM28012 repos~2kAutomated safety check: PassGPL-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Upgrade Browser

    flutter/flutter

    Upgrade browser versions (Chrome or Firefox) in the Flutter Web Engine and/or Framework tests.

    179k GitHub stars~1.1k tokensUpdated today
    MobileAuto-check passed
  • K8s Security Policies

    Cybereason-Public/owLSM

    Comprehensive guide for implementing NetworkPolicy, PodSecurityPolicy, RBAC, and Pod Security Standards in Kubernetes.

    280 GitHub starsUsed in 12 repos~2k tokens
    Backend & APIsAuto-check passed
  • Apple Container Test Runner

    RustPython/RustPython

    Runs RustPython tests inside a Linux container built with Apple's container CLI, so macOS users can compare Linux results with their local ones.

    22k GitHub stars~467 tokensUpdated today
    Testing & QAAuto-check passed

More from mohitmishra786/low-level-dev-skills

All 138 skills in this repo
  • ARM and AArch64 Assembly

    mohitmishra786/low-level-dev-skills

    Guides reading and writing AArch64 and ARM Thumb assembly: compiler output, inline asm, registers, the AAPCS calling convention and NEON or SVE basics.

    253 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • RISC-V Assembly Guide

    mohitmishra786/low-level-dev-skills

    Reference for RISC-V assembly on RV32 and RV64: register names and calling convention, extension naming, GCC and Clang inline asm, and QEMU with GDB debugging.

    253 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • x86-64 Assembly Reference

    mohitmishra786/low-level-dev-skills

    Explains x86-64 registers, the System V AMD64 calling convention, and how to read compiler-generated or inline assembly.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Bazel for C and C++

    mohitmishra786/low-level-dev-skills

    Guides your agent through Bazel for C/C++ projects: BUILD files, Bzlmod dependencies, toolchain registration, remote execution, dependency queries and sandbox debugging.

    253 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Binary Hardening

    mohitmishra786/low-level-dev-skills

    Binary hardening skill for security-hardened C/C++ builds. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed
  • Binutils

    mohitmishra786/low-level-dev-skills

    GNU binutils skill for binary manipulation and analysis. An agent skill from mohitmishra786/low-level-dev-skills.

    253 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about Kernel Internals

What does Kernel Internals do?

Linux kernel internals skill for scheduler, memory, and VFS subsystems. Kernel Internals is an agent skill from mohitmishra786/low-level-dev-skills. Linux kernel internals skill for scheduler, memory, and VFS subsystems.

When should I use Kernel Internals?

Kernel Internals fits situations like: analyzing CFS/EEVDF scheduling; buddy/SLUB allocators; interpreting /proc/meminfo.

How do I install Kernel Internals in Claude Code?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-internals -a claude-code`. Or copy the skill folder (skills/kernel/kernel-internals in mohitmishra786/low-level-dev-skills) into .claude/skills/kernel-internals in your project. Claude Code loads it when a task matches its description.

How do I install Kernel Internals in Codex?

Run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-internals -a codex`. Or copy the skill folder (skills/kernel/kernel-internals in mohitmishra786/low-level-dev-skills) into .agents/skills/kernel-internals in your project. Codex loads it when a task matches its description.

Can I use Kernel Internals in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mohitmishra786/low-level-dev-skills --skill kernel-internals -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kernel-internals, .gemini/skills/kernel-internals, .github/skills/kernel-internals and .opencode/skills/kernel-internals in your project.

What does Kernel Internals need to run?

SKILL.md names no scripts, command-line tools or credentials: Kernel Internals is instructions for the agent only.

Does Kernel Internals access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kernel Internals safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Kernel Internals use?

Kernel Internals is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kernel Internals use?

About 1.8k tokens (SKILL.md is roughly 7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kernel Internals?

Skills that share tags, products or a category with Kernel Internals: Configuring Horizon (coollabsio/coolify, 63k stars), Engine Whats New (flutter/flutter, 179k stars), Openclaw Live Updater (openclaw/openclaw, 392k stars) and Upgrade Browser (flutter/flutter, 179k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kernel Internals?

mohitmishra786 (a GitHub user) maintains it in mohitmishra786/low-level-dev-skills, which has 253 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on June 27, 2026.

Source: mohitmishra786/low-level-dev-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.