Operating Systems · Module 1 — Foundations: What an OS Actually Does
User mode vs kernel mode, and system calls
Imagine every program could talk to the disk directly. One bug in a half-finished student project could overwrite Aisha's whole filesystem. One nosy program could read the browser's saved passwords straight out of RAM.
Sign in to track your score
Aisha hits Ctrl+S in her code editor. matrix.c, 12 KB, needs to reach the SSD.
But the editor is not allowed to touch the SSD. Not "should not" physically cannot. The CPU will refuse the instruction.
So how does the file get saved?
The editor asks. And that asking is one of the two ways the OS ever gets to run.
Why & what
Why the restriction exists. Imagine every program could talk to the disk directly. One bug in a half-finished student project could overwrite Aisha's whole filesystem. One nosy program could read the browser's saved passwords straight out of RAM.
Good manners cannot prevent this. Programs are not trustworthy. So the protection is built into the CPU itself.
The mode bit. The CPU has a single bit that says which mode it is in.
- User mode — ordinary programs run here. Certain instructions are blocked. If the editor tries one, the CPU refuses and kills it.
- Kernel mode — the OS runs here. Every instruction is allowed.
The blocked ones are called privileged instructions: talking to devices, changing the memory map, switching off the timer.
Contrast it plainly:
- User mode: can compute, can use its own memory, cannot touch hardware.
- Kernel mode: can do all of that, plus everything else.
The system call. A system call is a program's request to the kernel to do something it cannot do itself. Examples: read, write, open, fork, exit.
It is not an ordinary function call. An ordinary call jumps to another address in the same program, in the same mode. A system call deliberately triggers a trap a controlled, built-in interruption that flips the CPU into kernel mode and jumps to a fixed address the kernel chose in advance.
That last part matters. The program does not choose where in the kernel it lands. If it could, it would just jump into the middle of the kernel and skip the permission checks.
How it works
Follow the editor (PID 2210) reading matrix.c:
- The editor asks. It puts the number for read and the details of what it wants into CPU registers, then executes the trap instruction.
- The mode bit flips. The CPU switches to kernel mode and jumps to the kernel's fixed entry point. The editor's own progress is saved first.
- The kernel checks. Does matrix.c exist? Is Aisha allowed to read it? Is the memory the editor pointed at really its own? Any "no" and the call fails safely.
- The kernel does the work. It fetches the 12 KB from the SSD and copies it into the editor's memory.
- Back to user mode. The mode bit flips back, the editor resumes on its next line, holding the data. Round trip: about 2 microseconds.

Common confusion
"printf is a system call." It is not. printf is a library function in your own program. It formats your text, and then it makes the real system call, write. Library functions are free. System calls are not.
"A system call is expensive, so it must be slow." Relative, not absolute. An ordinary function call costs a few nanoseconds. A system call costs about 2 microseconds roughly a thousand times more. That is why programs buffer output instead of making one call per character.
"Mode switch and context switch are the same thing." This is the most commonly missed distinction in this module.
- Mode switch the same program keeps the CPU, but the CPU changes privilege level. The editor is still the program running.
- Context switch — the CPU is taken away from one program and handed to a different one. The editor stops; the compiler starts. Module 2 covers it.
Every context switch involves a mode switch. Most mode switches do not involve a context switch.
Interview angle
Two questions come up constantly.
"Why do we need two modes?" Answer with the consequence, not the definition: without them, any program could touch any hardware or any other program's memory, so a single bug or a single malicious app could destroy the whole system. The mode bit makes the protection a hardware guarantee rather than a promise.
"What is the difference between a system call and a function call?" Name three differences: a system call changes privilege mode, it enters the kernel at a fixed address the caller cannot pick, and it costs roughly a thousand times more.
- 1.
The editor executes an instruction that talks straight to the SSD controller. What happens?
- 2.
Which pair correctly describes a system call?