Glossary
All 192 terms used in the course. The explanations are deliberately short, one sentence each. They are a reminder for someone who has already read the module, not a replacement for it: follow the link to the module for the details.
Nothing found. Try part of the word.
I. Foundations
- operating system
- A program that manages the hardware and gives every application the same way to use it. module 1
- kernel
- The part of the OS that runs with full privileges and controls the hardware directly. module 1
- application
- A program written for the user rather than for maintaining the system itself. module 1
- hardware
- The physical part of the machine: processor, memory, disks, device controllers. module 1
- multitasking
- The ability of a system to run several tasks as if they were going at the same time. module 1
- multiprogramming
- Keeping several programs in memory so the processor does not sit idle while one of them waits. module 1
- time-sharing
- A mode in which each user gets the processor in turn for a short interval. module 1
- batch processing
- Running jobs in batches, with no human involved while the work is being done. module 1
- real-time system
- A system where it matters not only what gets done but also by when. module 1
- embedded system
- A computer inside a device that does one job and has no familiar interface. module 1
- CPU
- The device that executes program instructions. module 2
- kernel mode
- A processor mode in which all instructions are allowed and all memory is accessible. module 2
- user mode
- A restricted processor mode in which ordinary programs run. module 2
- protection ring
- A processor privilege level; of the four x86 rings, modern systems use two. module 2
- interrupt
- A signal from a device that makes the processor set aside its current work and deal with it. module 2
- exception
- An event caused by the instruction itself, such as division by zero or access to a missing page. module 2
- trap
- A deliberate exception a program uses to ask the kernel for a service. module 2
- interrupt handler
- Kernel code that runs in response to an interrupt. module 2
- interrupt vector
- A table that maps each interrupt number to the address of its handler. module 2
- hardware timer
- A device that interrupts the processor at regular intervals and so hands control back to the kernel. module 2
- MMU
- The processor unit that translates virtual addresses into physical ones and checks access rights. module 2
- cache
- Fast memory next to the processor where recently used data settles. module 2
- cache line
- The smallest chunk the cache exchanges with memory, usually 64 bytes. module 2
- DMA
- Transferring data between a device and memory without involving the processor. module 2
- core
- A separate processing unit inside the processor. module 2
- cache coherence
- Keeping the caches of different cores in agreement so that all of them see the same value for a memory cell. module 2
- NUMA
- An architecture where each processor has its own memory and reaches other processors' memory noticeably more slowly. module 2
- system call
- The way to ask the kernel to do something the program is not allowed to do itself. module 3
- ABI
- An agreement on registers, alignment and calling format at the machine-code level. module 3
- monolithic kernel
- A kernel in which all subsystems run in a single address space. module 3
- microkernel
- A kernel that keeps the bare minimum inside and moves drivers and services out to user space. module 3
- hybrid kernel
- A kernel that is monolithic by design but has some of its services moved outside. module 3
- unikernel
- An image in which the application and the pieces of kernel it needs are built into a single program. module 3
- kernel module
- A piece of kernel code that can be loaded and unloaded on a running system. module 3
- user space
- The memory and code of ordinary programs, from which kernel structures are out of reach. module 3
- kernel space
- The memory and code of the kernel, which programs have no direct access to. module 3
- context switch
- Replacing one running process with another, saving and restoring their state. module 3
II. Unix and Linux
- POSIX
- A set of standards for system calls and utilities shared by Unix-like systems. module 4
- distribution
- A ready-made bundle of a kernel, a set of programs and a way to keep them updated. module 4
- shell
- A program that reads commands and runs other programs for you. module 4
- free software
- Programs you are allowed to study, modify and pass on. module 4
- open source
- A development model in which the source code is available to everyone. module 4
- bootloader
- A program that finds the kernel on disk and hands control to it. module 5
- GPT
- The modern format for describing disk partitions, without the limits of MBR. module 5
- MBR
- The old partition format stored in the first sector of the disk. module 5
- initramfs
- A temporary in-memory file system with the drivers needed to reach the real root. module 5
- init system
- The first process in the system, which starts all services and supervises them. module 5
- unit
- A description of an object managed by systemd, such as a service, mount, socket or timer. module 5
- target
- A group of units describing the state the system should be brought to. module 5
- daemon
- A background service that runs without a terminal and without a user around. module 5
III. Processes and Concurrency
- process
- A running program together with its own memory, open files and permissions. module 6
- process image
- The contents of a process's memory: code, data, heap and stack. module 6
- process control block
- The kernel structure that holds everything the kernel knows about a process. module 6
- process state
- A mark of what the process is doing right now: running, waiting, finished. module 6
- ready
- The process could run, but the processor is busy with someone else. module 6
- running
- The process is occupying a processor core right now. module 6
- blocked
- The process is waiting for an event and has no use for the processor until it happens. module 6
- child process
- A process created by another process. module 6
- parent process
- The process that created this one and is expected to collect its exit code. module 6
- zombie process
- The process has already exited, but its entry remains until the parent collects the result. module 6
- orphan process
- A process whose parent exited first; the system's first process adopts it. module 6
- signal
- A short asynchronous message sent to a process by the kernel or by another process. module 6
- process group
- A set of processes that the terminal can signal in one go. module 6
- scheduler
- The part of the kernel that decides who runs next and for how long. module 7
- scheduling
- Dividing processor time among the tasks that compete for it. module 7
- preemptive scheduling
- The scheduler can take the processor away from a task without asking. module 7
- non-preemptive scheduling
- A task gives up the processor only when it decides to. module 7
- time quantum
- The interval a task runs before it may be preempted. module 7
- ready queue
- The tasks that are waiting for the processor and for nothing else. module 7
- waiting time
- How long a task spent in the queue without running. module 7
- turnaround time
- The time from a task's arrival to its completion. module 7
- response time
- The time from a task's arrival to the moment it first gets the processor. module 7
- throughput
- How many tasks the system manages to complete per unit of time. module 7
- CPU affinity
- Binding a process to particular cores so it does not lose a warm cache. module 7
- starvation
- A task never gets the processor because others keep getting ahead of it. module 7
- aging
- Gradually raising the priority of a task that has been waiting too long. module 7
- thread
- A separate line of execution inside a process; all threads share one memory. module 8
- multithreading
- Running several threads in one process. module 8
- user-level thread
- A thread the kernel does not know about; a library inside the program switches it. module 8
- kernel-level thread
- A thread the kernel sees and schedules on equal terms with processes. module 8
- thread pool
- Threads created in advance that take tasks from a shared queue. module 8
- event loop
- A single thread that handles ready events one by one instead of blocking on each of them. module 8
- coroutine
- A function that can be paused and resumed without holding a whole thread during the pause. module 8
- thread-local storage
- Variables of which each thread has its own copy. module 8
- race condition
- The result depends on which thread got there first. module 9
- critical section
- A piece of code that no more than one thread may be in at a time. module 9
- mutual exclusion
- A guarantee that only one party at a time accesses a shared resource. module 9
- mutex
- A lock held by one thread while the others sleep on it. module 9
- semaphore
- A counter of permits that blocks a thread when no permits are left. module 9
- binary semaphore
- A semaphore with exactly one permit. module 9
- counting semaphore
- A semaphore that lets a preset number of threads in. module 9
- condition variable
- A way to sleep until a condition holds and be woken up when it does. module 9
- spinlock
- A lock on which a thread does not sleep but spins in a loop and checks again. module 9
- atomic operation
- An operation that other threads see either fully done or not started. module 9
- compare-and-swap
- Atomically replace a value provided it has not changed since it was last read. module 9
- memory barrier
- A point across which the processor and the compiler may not reorder memory accesses. module 9
- memory model
- The rules for the order in which threads see each other's writes to memory. module 9
- deadlock
- Several threads hold resources and wait for each other, now forever. module 9
- priority inversion
- An important task waits for a minor one because the minor one holds the lock it needs. module 9
- lock-free
- An algorithm in which stopping one thread does not stop the rest. module 9
- bounded-buffer problem
- The classic problem of a producer and a consumer sharing a queue of finite size. module 9
- dining philosophers problem
- The classic deadlock problem where each worker needs two resources at once. module 9
- readers-writers problem
- The classic access problem where reading can be done together but writing only alone. module 9
IV. Memory
- logical address
- The address the program sees. module 10
- physical address
- The address the memory chip itself sees. module 10
- address space
- All the addresses available to a process, together with what lies behind them. module 10
- address translation
- Converting a logical address into a physical one on every memory access. module 10
- base register
- The start of a process's memory region under contiguous allocation. module 10
- limit register
- The size of a process's region; an access beyond the limit raises an exception. module 10
- contiguous allocation
- A scheme in which a process occupies one solid piece of memory. module 10
- internal fragmentation
- Space lost inside an allocated block. module 10
- external fragmentation
- There is enough free memory, but it is scattered in small pieces. module 10
- compaction
- Moving occupied blocks to gather the free space into one place. module 10
- paging
- Splitting memory into equal-sized pages that can go into any free frames. module 11
- page
- A fixed-size block of virtual memory, usually 4 KiB. module 11
- frame
- A block of physical memory the same size as a page. module 11
- page table
- The mapping of pages to frames, separate for each process. module 11
- multi-level page table
- A table split into levels so it does not need an entry for every address in the space. module 11
- inverted page table
- One entry per frame instead of one entry per page in every process. module 11
- hashed page table
- Looking up the frame by a hash of the page number. module 11
- TLB
- A small cache of ready-made address translations inside the processor. module 11
- TLB miss
- The cache has no ready translation, so the page table has to be walked. module 11
- huge page
- A 2 MiB or 1 GiB page, meaning fewer table entries and fewer TLB misses. module 11
- segmentation
- Dividing memory into parts by content: code, data, stack. module 11
- segment table
- A description of the start and length of each segment of a process. module 11
- virtual memory
- Each process sees its own address space, larger than the physical memory available. module 12
- page fault
- The process accessed a page that is not in memory right now; the kernel brings it in. module 12
- demand paging
- A page is brought into memory only when it is actually accessed. module 12
- page replacement
- Choosing which page to evict when there are no free frames left. module 12
- valid-invalid bit
- A mark in the page table saying whether the page is in memory right now. module 12
- copy-on-write
- A shared page is copied only when someone writes to it. module 12
- working set
- The pages a process is using during the current period of its work. module 12
- thrashing
- The system spends almost all its time moving pages instead of doing useful work. module 12
- swapping
- Evicting pages to disk to free up physical memory. module 12
- swap file
- The place on disk where evicted pages go. module 12
- page cache
- Memory where the kernel keeps data already read from disk, in case it is needed again. module 12
- memory allocator
- Code that hands out pieces of memory to a program and keeps track of free space. module 12
- OOM killer
- The kernel picks a process and kills it when memory has run out for good. module 12
V. Storage and I/O
- I/O
- Exchanging data between a program and the world outside the processor. module 13
- block device
- A device accessed in equal-sized blocks and in any order. module 13
- character device
- A device read as a stream of bytes in sequence, with no random access. module 13
- device driver
- Kernel code that knows how to talk to a particular piece of hardware. module 13
- polling
- Checking a device's status periodically instead of waiting for an interrupt from it. module 13
- buffering
- Accumulating data in memory so the device is bothered less often. module 13
- blocking I/O
- The call does not return until the data is ready. module 13
- non-blocking I/O
- The call returns immediately, even if there is no data yet. module 13
- I/O multiplexing
- A single wait on many descriptors at once instead of a thread for each. module 13
- sector
- The smallest unit a disk can address. module 14
- LBA
- Sequential numbering of disk blocks with no reference to the disk's geometry. module 14
- disk scheduling
- The order in which pending requests are sent to the device. module 14
- FTL
- SSD firmware that hides block erasure behind the familiar disk interface. module 14
- wear leveling
- Spreading writes across cells so they wear out evenly. module 14
- striping
- Spreading data across several disks for speed. module 14
- mirroring
- The same contents on two disks at once. module 14
- parity
- Redundant data used to rebuild the contents of a lost disk. module 14
- logical volume
- A partition built from the space of several physical disks and independent of their boundaries. module 14
- snapshot
- The state of a volume frozen at a given moment, which stays available despite later changes. module 14
- file system
- A way to lay out files and directories across the blocks of a device and find them again later. module 15
- VFS
- A kernel layer that gives all file systems a common interface. module 15
- inode
- A record with a file's metadata and the list of its blocks; the file name is not in it. module 15
- file descriptor
- A number by which a process refers to a file it has opened. module 15
- hard link
- One more name for the same inode. module 15
- symbolic link
- A file that contains the path to another file. module 15
- mounting
- Attaching a file system to a directory in the shared tree. module 15
- mount point
- The directory in which the contents of an attached file system become visible. module 15
- journaling
- Writing down intentions in advance so that consistency can be restored after a crash. module 15
- extent
- A contiguous range of blocks described by a single record instead of a list. module 15
- permissions
- Who may read a file, write to it and execute it. module 15
- ACL
- Permissions for specific users on top of the usual owner, group and others. module 15
VI. Isolation and Security
- authentication
- Confirming that you are who you say you are. module 16
- authorization
- Checking whether you are allowed to do what you are asking for. module 16
- DAC
- The permissions on a file are set by its owner. module 16
- MAC
- The permissions are set by a system policy, and the file owner cannot bypass it. module 16
- capability
- A single one of root's privileges, granted to a process without all the others. module 16
- privilege escalation
- Gaining more privileges than you are entitled to. module 16
- ASLR
- Placing memory regions at random locations each time a program starts. module 16
- stack canary
- A check value placed before the return address; if it gets corrupted, it gives away an overflow. module 16
- sandbox
- A restricted environment in which a program is allowed exactly what it needs. module 16
- threat model
- A list of whom and what you are actually protecting against. module 16
- virtualization
- Running an entire operating system as a program on top of another one. module 17
- hypervisor
- A layer that creates virtual machines and divides the real hardware among them. module 17
- guest OS
- An operating system running inside a virtual machine. module 17
- host
- The machine on which virtual machines or containers run. module 17
- paravirtualization
- The guest system knows it is virtual and calls the hypervisor directly. module 17
- namespace
- A mechanism that shows a process only part of the system's resources instead of all of them. module 17
- cgroup
- A mechanism for limiting and accounting resources for a group of processes. module 17
- container
- A process in its own namespaces and under cgroup limits; it shares the kernel with the host. module 17
- container image
- A set of file system layers from which a container is started. module 17
- tracing
- Observing events inside a running system without stopping it. module 18
- confidential computing
- Protecting data while it is being processed, including from the owner of the hardware. module 18
- hard real-time
- A missed deadline means the system has failed. module 18
- soft real-time
- A missed deadline degrades quality but does not break the system. module 18