When a C program calls printf("Hello"), the standard library buffers the text and invokes the write() system call (x86_64 syscall number 1). The CPU traps to kernel mode, copies the buffer to the display device driver, and returns to user space.
// Direct Linux System Call via assembly / C syscall wrapper
#define _GNU_SOURCE
#include <unistd.h>
#include <sys/syscall.h>
int main() {
const char msg[] = "Direct write() system call\n";
// Invokes syscall #1 (SYS_write) passing stdout file descriptor 1
syscall(SYS_write, 1, msg, sizeof(msg) - 1);
return 0;
}Visual representation of control loops, memory layout, and execution flow for OS Architecture, Dual-Mode & System Calls.
User application calls a standard library API (e.g., fopen(), read()) in unprivileged User Mode (Ring 3).
The CPU executes the SYSCALL (or INT 0x80) instruction, switching the hardware privilege level from Ring 3 to Ring 0 (Kernel Mode) and swapping to the per-process kernel stack.
The kernel reads the system call number from CPU register (e.g., RAX on x86_64) and dispatches execution to the corresponding handler in the sys_call_table array.
The kernel validates user buffer pointers, executes requested I/O or memory operation, places the return code into RAX, and invokes SYSRET to restore User Mode.
| Feature / Dimension | Monolithic Kernel (e.g., Linux, Windows NT) | Microkernel (e.g., seL4, QNX, Minix) |
|---|---|---|
| Kernel Space Scope | Scheduler, Memory, VFS, Network Stack, and Device Drivers all run in Ring 0. | Only minimal IPC, low-level scheduling, and memory mapping run in Ring 0. |
| Execution Speed | Fast direct function calls inside shared kernel address space. | Slower due to heavy message-passing (IPC) context switches between user servers. |
| Crash Resilience & Security | A bug or panic in a third-party device driver can crash the entire OS. | Crashed driver restarts as an isolated user process; kernel remains intact. |
| Extensibility | Loadable Kernel Modules (LKMs) can be inserted dynamically into Ring 0. | Modules run as standard user-space daemons with fine-grained capabilities. |
Detailed answers, interviewer pro tips, key takeaway summaries, and code examples formulated for technical rounds.
✅ Correction: printf() and malloc() are C standard library functions. printf() buffers text and calls write(), while malloc() manages a user-space memory pool and only calls brk()/sbrk() or mmap() when more memory is needed.
✅ Correction: User code cannot arbitrarily change CPU privilege flags. It can only execute predefined gateway instructions (SYSCALL/SYSENTER), where hardware strictly enforces jumping to verified kernel entry vectors.
Dual-Mode Operation splits CPU privilege into Ring 3 (User) and Ring 0 (Kernel), bridged securely by System Call trap gateways.