Operating Systems

System Calls; Dual Mode Operation; Process Management

C-CAT

System Calls

What are System Calls?

System calls provide the interface between user programs and the operating system kernel.

When a program needs OS services (file I/O, process creation, memory allocation), it makes a system call.

Categories of System Calls

CategoryExamples
Process Controlfork(), exec(), exit(), wait(), getpid()
File Managementopen(), read(), write(), close(), unlink(), stat()
Device Managementioctl(), read(), write() (for devices)
Information Maintenancegetpid(), alarm(), sleep(), time()
Communicationpipe(), socket(), send(), recv(), shmget()

System Call Flow

User Program
    |
    | calls  printf("hello") → internally calls write()
    |
    ↓
std C library (write() wrapper)
    |
    | System Call Instruction (int 0x80 / syscall)
    ↓
KERNEL (system call handler)
    |
    | sys_write() → device driver → I/O
    ↓
Returns to user program

Dual Mode Operation

What is Dual Mode?

The CPU operates in two modes to protect the OS from user programs:

ModeAlso CalledPrivilege
User ModeUnprivileged modeLimited instructions; cannot directly access hardware
Kernel ModeSupervisor/System modeAll instructions; full hardware access

Mode Switching

User Program executes → User Mode
     |
     | System Call or Interrupt
     ↓
Kernel Mode (OS handles request)
     |
     | Return from system call
     ↓
User Mode (program resumes)

Mode bit:

  • 0 = Kernel Mode
  • 1 = User Mode

Privileged vs Non-Privileged Instructions

Instruction TypeUser ModeKernel Mode
I/O operationsNot allowedAllowed
Memory managementNot allowedAllowed
Interrupt controlNot allowedAllowed
Normal arithmeticAllowedAllowed
Function callsAllowedAllowed

Process Management

What is a Process?

A process is a program in execution — an active entity.

Program vs Process:

FeatureProgramProcess
StatePassive (on disk)Active (in memory)
ResourcesNone (static file)CPU, memory, I/O
NumberOne copy on diskMultiple processes can run from same program
Examplenotepad.exe fileRunning instance of Notepad

Process in Memory

+------------------+   High address
|      Stack       |   ← Function calls, local variables (grows down)
|        ↓         |
|                  |
|        ↑         |
|       Heap       |   ← Dynamic memory (malloc, new)
+------------------+
|    BSS Segment   |   ← Uninitialized global/static variables
+------------------+
|    Data Segment  |   ← Initialized global/static variables
+------------------+
|    Text Segment  |   ← Program code (instructions)
+------------------+   Low address

Process Creation

In Unix/Linux:

pid_t child_pid = fork();  // Creates child process (copy of parent)
if (child_pid == 0) {
    // This is the child process
    exec("new_program");   // Replace with different program
} else {
    wait(NULL);            // Parent waits for child to finish
}

Process hierarchy — Process Tree:

init (PID 1)
├── systemd
│   ├── sshd
│   │   └── bash (user session)
│   │       └── vim
│   └── cron
│       └── backup_script.sh
└── kthreadd (kernel threads)

Continue learning

Related notes

Put this topic into timed practice

Open mock tests when you want full-exam pacing, or keep drilling in practice mode.