Syscalls Under the Hood
A syscall is the only door between user code and the kernel. This video follows one from the libc wrapper to the kernel handler and back: the instruction that triggers it, how arguments cross the boundary, and why the return path has to handle signals and interrupts before your program ever sees its result.
Topics covered:
- Why user mode exists and what the CPU's privilege ring actually gates
syscallon x86-64 vs.svcon ARM: the single instruction that switches modes- How arguments are passed in registers and the syscall number convention
- The kernel's dispatch table and error handling via negative return values
stracedemystified: tracing syscalls without slowing them down- vsyscall/vDSO: syscalls that never leave user mode
- Why syscalls are slow, and how batching and
io_uringsidestep the cost
Related articles
What Really Happens During a System Call
Trap, ring transition, and the syscall table — the cost of asking the kernel for help and why it's never free.
The OOM Killer and Memory Pressure: Who Dies and Why
When reclaim fails, the kernel executes: how oom_score picks the victim, why overcommit makes malloc lie, and why killing innocent processes is a feature, not a bug.
cgroups and Container Isolation: Why Docker Is Not a VM
Namespaces change what a container sees; cgroups control what it gets — CPU shares, memory limits, the freezer — and the shared-kernel security reality behind Docker.
More in Operating Systems
Virtual Memory in One Diagram
Page tables, TLB, demand paging, and copy-on-write — how your 16GB laptop 'has' 128GB of addressable memory.
WatchContainer Isolation in Linux
What Docker and Kubernetes containers actually are — namespaces, cgroups, and the syscalls that make isolated processes without a VM.
DetailsSignals and Interrupts
Hardware interrupts and Unix signals — the two asynchronous mechanisms that interrupt your program, and what the kernel does between the wire and your handler.
DetailsLocks and Synchronization Primitives
Mutexes, spinlocks, semaphores, and condition variables — how they map to hardware atomics and futexes, and when each one is the right tool.
DetailsMemory-Mapped Files
How mmap() maps a file into your address space — demand paging from disk, the page cache, and why mapped I/O beats read() and write().
DetailsFile Systems Explained
How a file system stores your data — inodes, directory entries, extents, and journaling — and what actually happens on read and write.
DetailsThread Pools Explained
How thread pools work under the hood — worker threads, work queues, and why reusing threads beats spawning them for every request.
DetailsVirtual Memory Explained
Address translation, page tables, and the TLB — the full path from a virtual address to the physical RAM cell, including why the translation is cached.
DetailsProcess Scheduling, Visualized
How the Linux scheduler picks the next runnable process — time slices, priorities, CFS virtual runtime, and why your busy server still feels responsive.
DetailsDepth, delivered weekly
One technical dispatch a week — articles and episode notes before they go public.
One technical dispatch per week. No noise.