Skip to content

Glossary

All 192 terms used in the course. The explanations are deliberately short, one sentence each. They are a reminder for someone who has already read the module, not a replacement for it: follow the link to the module for the details.

I. Foundations

operating system
A program that manages the hardware and gives every application the same way to use it. module 1
kernel
The part of the OS that runs with full privileges and controls the hardware directly. module 1
application
A program written for the user rather than for maintaining the system itself. module 1
hardware
The physical part of the machine: processor, memory, disks, device controllers. module 1
multitasking
The ability of a system to run several tasks as if they were going at the same time. module 1
multiprogramming
Keeping several programs in memory so the processor does not sit idle while one of them waits. module 1
time-sharing
A mode in which each user gets the processor in turn for a short interval. module 1
batch processing
Running jobs in batches, with no human involved while the work is being done. module 1
real-time system
A system where it matters not only what gets done but also by when. module 1
embedded system
A computer inside a device that does one job and has no familiar interface. module 1
CPU
The device that executes program instructions. module 2
kernel mode
A processor mode in which all instructions are allowed and all memory is accessible. module 2
user mode
A restricted processor mode in which ordinary programs run. module 2
protection ring
A processor privilege level; of the four x86 rings, modern systems use two. module 2
interrupt
A signal from a device that makes the processor set aside its current work and deal with it. module 2
exception
An event caused by the instruction itself, such as division by zero or access to a missing page. module 2
trap
A deliberate exception a program uses to ask the kernel for a service. module 2
interrupt handler
Kernel code that runs in response to an interrupt. module 2
interrupt vector
A table that maps each interrupt number to the address of its handler. module 2
hardware timer
A device that interrupts the processor at regular intervals and so hands control back to the kernel. module 2
MMU
The processor unit that translates virtual addresses into physical ones and checks access rights. module 2
cache
Fast memory next to the processor where recently used data settles. module 2
cache line
The smallest chunk the cache exchanges with memory, usually 64 bytes. module 2
DMA
Transferring data between a device and memory without involving the processor. module 2
core
A separate processing unit inside the processor. module 2
cache coherence
Keeping the caches of different cores in agreement so that all of them see the same value for a memory cell. module 2
NUMA
An architecture where each processor has its own memory and reaches other processors' memory noticeably more slowly. module 2
system call
The way to ask the kernel to do something the program is not allowed to do itself. module 3
ABI
An agreement on registers, alignment and calling format at the machine-code level. module 3
monolithic kernel
A kernel in which all subsystems run in a single address space. module 3
microkernel
A kernel that keeps the bare minimum inside and moves drivers and services out to user space. module 3
hybrid kernel
A kernel that is monolithic by design but has some of its services moved outside. module 3
unikernel
An image in which the application and the pieces of kernel it needs are built into a single program. module 3
kernel module
A piece of kernel code that can be loaded and unloaded on a running system. module 3
user space
The memory and code of ordinary programs, from which kernel structures are out of reach. module 3
kernel space
The memory and code of the kernel, which programs have no direct access to. module 3
context switch
Replacing one running process with another, saving and restoring their state. module 3

II. Unix and Linux

POSIX
A set of standards for system calls and utilities shared by Unix-like systems. module 4
distribution
A ready-made bundle of a kernel, a set of programs and a way to keep them updated. module 4
shell
A program that reads commands and runs other programs for you. module 4
free software
Programs you are allowed to study, modify and pass on. module 4
open source
A development model in which the source code is available to everyone. module 4
bootloader
A program that finds the kernel on disk and hands control to it. module 5
GPT
The modern format for describing disk partitions, without the limits of MBR. module 5
MBR
The old partition format stored in the first sector of the disk. module 5
initramfs
A temporary in-memory file system with the drivers needed to reach the real root. module 5
init system
The first process in the system, which starts all services and supervises them. module 5
unit
A description of an object managed by systemd, such as a service, mount, socket or timer. module 5
target
A group of units describing the state the system should be brought to. module 5
daemon
A background service that runs without a terminal and without a user around. module 5

III. Processes and Concurrency

process
A running program together with its own memory, open files and permissions. module 6
process image
The contents of a process's memory: code, data, heap and stack. module 6
process control block
The kernel structure that holds everything the kernel knows about a process. module 6
process state
A mark of what the process is doing right now: running, waiting, finished. module 6
ready
The process could run, but the processor is busy with someone else. module 6
running
The process is occupying a processor core right now. module 6
blocked
The process is waiting for an event and has no use for the processor until it happens. module 6
child process
A process created by another process. module 6
parent process
The process that created this one and is expected to collect its exit code. module 6
zombie process
The process has already exited, but its entry remains until the parent collects the result. module 6
orphan process
A process whose parent exited first; the system's first process adopts it. module 6
signal
A short asynchronous message sent to a process by the kernel or by another process. module 6
process group
A set of processes that the terminal can signal in one go. module 6
scheduler
The part of the kernel that decides who runs next and for how long. module 7
scheduling
Dividing processor time among the tasks that compete for it. module 7
preemptive scheduling
The scheduler can take the processor away from a task without asking. module 7
non-preemptive scheduling
A task gives up the processor only when it decides to. module 7
time quantum
The interval a task runs before it may be preempted. module 7
ready queue
The tasks that are waiting for the processor and for nothing else. module 7
waiting time
How long a task spent in the queue without running. module 7
turnaround time
The time from a task's arrival to its completion. module 7
response time
The time from a task's arrival to the moment it first gets the processor. module 7
throughput
How many tasks the system manages to complete per unit of time. module 7
CPU affinity
Binding a process to particular cores so it does not lose a warm cache. module 7
starvation
A task never gets the processor because others keep getting ahead of it. module 7
aging
Gradually raising the priority of a task that has been waiting too long. module 7
thread
A separate line of execution inside a process; all threads share one memory. module 8
multithreading
Running several threads in one process. module 8
user-level thread
A thread the kernel does not know about; a library inside the program switches it. module 8
kernel-level thread
A thread the kernel sees and schedules on equal terms with processes. module 8
thread pool
Threads created in advance that take tasks from a shared queue. module 8
event loop
A single thread that handles ready events one by one instead of blocking on each of them. module 8
coroutine
A function that can be paused and resumed without holding a whole thread during the pause. module 8
thread-local storage
Variables of which each thread has its own copy. module 8
race condition
The result depends on which thread got there first. module 9
critical section
A piece of code that no more than one thread may be in at a time. module 9
mutual exclusion
A guarantee that only one party at a time accesses a shared resource. module 9
mutex
A lock held by one thread while the others sleep on it. module 9
semaphore
A counter of permits that blocks a thread when no permits are left. module 9
binary semaphore
A semaphore with exactly one permit. module 9
counting semaphore
A semaphore that lets a preset number of threads in. module 9
condition variable
A way to sleep until a condition holds and be woken up when it does. module 9
spinlock
A lock on which a thread does not sleep but spins in a loop and checks again. module 9
atomic operation
An operation that other threads see either fully done or not started. module 9
compare-and-swap
Atomically replace a value provided it has not changed since it was last read. module 9
memory barrier
A point across which the processor and the compiler may not reorder memory accesses. module 9
memory model
The rules for the order in which threads see each other's writes to memory. module 9
deadlock
Several threads hold resources and wait for each other, now forever. module 9
priority inversion
An important task waits for a minor one because the minor one holds the lock it needs. module 9
lock-free
An algorithm in which stopping one thread does not stop the rest. module 9
bounded-buffer problem
The classic problem of a producer and a consumer sharing a queue of finite size. module 9
dining philosophers problem
The classic deadlock problem where each worker needs two resources at once. module 9
readers-writers problem
The classic access problem where reading can be done together but writing only alone. module 9

IV. Memory

logical address
The address the program sees. module 10
physical address
The address the memory chip itself sees. module 10
address space
All the addresses available to a process, together with what lies behind them. module 10
address translation
Converting a logical address into a physical one on every memory access. module 10
base register
The start of a process's memory region under contiguous allocation. module 10
limit register
The size of a process's region; an access beyond the limit raises an exception. module 10
contiguous allocation
A scheme in which a process occupies one solid piece of memory. module 10
internal fragmentation
Space lost inside an allocated block. module 10
external fragmentation
There is enough free memory, but it is scattered in small pieces. module 10
compaction
Moving occupied blocks to gather the free space into one place. module 10
paging
Splitting memory into equal-sized pages that can go into any free frames. module 11
page
A fixed-size block of virtual memory, usually 4 KiB. module 11
frame
A block of physical memory the same size as a page. module 11
page table
The mapping of pages to frames, separate for each process. module 11
multi-level page table
A table split into levels so it does not need an entry for every address in the space. module 11
inverted page table
One entry per frame instead of one entry per page in every process. module 11
hashed page table
Looking up the frame by a hash of the page number. module 11
TLB
A small cache of ready-made address translations inside the processor. module 11
TLB miss
The cache has no ready translation, so the page table has to be walked. module 11
huge page
A 2 MiB or 1 GiB page, meaning fewer table entries and fewer TLB misses. module 11
segmentation
Dividing memory into parts by content: code, data, stack. module 11
segment table
A description of the start and length of each segment of a process. module 11
virtual memory
Each process sees its own address space, larger than the physical memory available. module 12
page fault
The process accessed a page that is not in memory right now; the kernel brings it in. module 12
demand paging
A page is brought into memory only when it is actually accessed. module 12
page replacement
Choosing which page to evict when there are no free frames left. module 12
valid-invalid bit
A mark in the page table saying whether the page is in memory right now. module 12
copy-on-write
A shared page is copied only when someone writes to it. module 12
working set
The pages a process is using during the current period of its work. module 12
thrashing
The system spends almost all its time moving pages instead of doing useful work. module 12
swapping
Evicting pages to disk to free up physical memory. module 12
swap file
The place on disk where evicted pages go. module 12
page cache
Memory where the kernel keeps data already read from disk, in case it is needed again. module 12
memory allocator
Code that hands out pieces of memory to a program and keeps track of free space. module 12
OOM killer
The kernel picks a process and kills it when memory has run out for good. module 12

V. Storage and I/O

I/O
Exchanging data between a program and the world outside the processor. module 13
block device
A device accessed in equal-sized blocks and in any order. module 13
character device
A device read as a stream of bytes in sequence, with no random access. module 13
device driver
Kernel code that knows how to talk to a particular piece of hardware. module 13
polling
Checking a device's status periodically instead of waiting for an interrupt from it. module 13
buffering
Accumulating data in memory so the device is bothered less often. module 13
blocking I/O
The call does not return until the data is ready. module 13
non-blocking I/O
The call returns immediately, even if there is no data yet. module 13
I/O multiplexing
A single wait on many descriptors at once instead of a thread for each. module 13
sector
The smallest unit a disk can address. module 14
LBA
Sequential numbering of disk blocks with no reference to the disk's geometry. module 14
disk scheduling
The order in which pending requests are sent to the device. module 14
FTL
SSD firmware that hides block erasure behind the familiar disk interface. module 14
wear leveling
Spreading writes across cells so they wear out evenly. module 14
striping
Spreading data across several disks for speed. module 14
mirroring
The same contents on two disks at once. module 14
parity
Redundant data used to rebuild the contents of a lost disk. module 14
logical volume
A partition built from the space of several physical disks and independent of their boundaries. module 14
snapshot
The state of a volume frozen at a given moment, which stays available despite later changes. module 14
file system
A way to lay out files and directories across the blocks of a device and find them again later. module 15
VFS
A kernel layer that gives all file systems a common interface. module 15
inode
A record with a file's metadata and the list of its blocks; the file name is not in it. module 15
file descriptor
A number by which a process refers to a file it has opened. module 15
hard link
One more name for the same inode. module 15
symbolic link
A file that contains the path to another file. module 15
mounting
Attaching a file system to a directory in the shared tree. module 15
mount point
The directory in which the contents of an attached file system become visible. module 15
journaling
Writing down intentions in advance so that consistency can be restored after a crash. module 15
extent
A contiguous range of blocks described by a single record instead of a list. module 15
permissions
Who may read a file, write to it and execute it. module 15
ACL
Permissions for specific users on top of the usual owner, group and others. module 15

VI. Isolation and Security

authentication
Confirming that you are who you say you are. module 16
authorization
Checking whether you are allowed to do what you are asking for. module 16
DAC
The permissions on a file are set by its owner. module 16
MAC
The permissions are set by a system policy, and the file owner cannot bypass it. module 16
capability
A single one of root's privileges, granted to a process without all the others. module 16
privilege escalation
Gaining more privileges than you are entitled to. module 16
ASLR
Placing memory regions at random locations each time a program starts. module 16
stack canary
A check value placed before the return address; if it gets corrupted, it gives away an overflow. module 16
sandbox
A restricted environment in which a program is allowed exactly what it needs. module 16
threat model
A list of whom and what you are actually protecting against. module 16
virtualization
Running an entire operating system as a program on top of another one. module 17
hypervisor
A layer that creates virtual machines and divides the real hardware among them. module 17
guest OS
An operating system running inside a virtual machine. module 17
host
The machine on which virtual machines or containers run. module 17
paravirtualization
The guest system knows it is virtual and calls the hypervisor directly. module 17
namespace
A mechanism that shows a process only part of the system's resources instead of all of them. module 17
cgroup
A mechanism for limiting and accounting resources for a group of processes. module 17
container
A process in its own namespaces and under cgroup limits; it shares the kernel with the host. module 17
container image
A set of file system layers from which a container is started. module 17
tracing
Observing events inside a running system without stopping it. module 18
confidential computing
Protecting data while it is being processed, including from the owner of the hardware. module 18
hard real-time
A missed deadline means the system has failed. module 18
soft real-time
A missed deadline degrades quality but does not break the system. module 18