1
00:00:00,005 --> 00:00:05,005
- [Instructor] System calls are a essential interface

2
00:00:05,005 --> 00:00:09,002
between user space and the kernel.

3
00:00:09,002 --> 00:00:12,001
The kernel provides services to user space

4
00:00:12,001 --> 00:00:14,007
by providing a set of functions.

5
00:00:14,007 --> 00:00:18,004
Those functions are called system calls.

6
00:00:18,004 --> 00:00:19,002
(page turning)

7
00:00:19,002 --> 00:00:22,008
So, these are functions implemented by the kernel

8
00:00:22,008 --> 00:00:26,001
and meant to be called from user space,

9
00:00:26,001 --> 00:00:30,000
although the mechanism (sniffs) isn't the same

10
00:00:30,000 --> 00:00:32,007
as a function call.

11
00:00:32,007 --> 00:00:36,004
In a program, it looks like you're just calling a function.

12
00:00:36,004 --> 00:00:40,005
The Linux kernel has somewhere around 300 system calls,

13
00:00:40,005 --> 00:00:43,002
not a huge number,

14
00:00:43,002 --> 00:00:46,001
and you can see some information

15
00:00:46,001 --> 00:00:48,000
about what they're called

16
00:00:48,000 --> 00:00:52,004
in the kernel source code of course.

17
00:00:52,004 --> 00:00:55,000
And there's an include file

18
00:00:55,000 --> 00:00:58,008
for basic system call information.

19
00:00:58,008 --> 00:01:02,006
Your man pages have system call information,

20
00:01:02,006 --> 00:01:06,006
and the documentation for system calls is in section two.

21
00:01:06,006 --> 00:01:10,007
So, if you say man two read,

22
00:01:10,007 --> 00:01:13,007
it would tell you about the read system call.

23
00:01:13,007 --> 00:01:17,006
But in actuality, an application like written

24
00:01:17,006 --> 00:01:22,005
in C or C++, other kind of compile languages

25
00:01:22,005 --> 00:01:26,008
will call a system call through a library.

26
00:01:26,008 --> 00:01:30,000
So, if a C program calls read,

27
00:01:30,000 --> 00:01:33,002
it's not directly calling the read function in the kernel,

28
00:01:33,002 --> 00:01:36,006
it's calling a read function in the library.

29
00:01:36,006 --> 00:01:40,006
Then the library is doing some special trap

30
00:01:40,006 --> 00:01:44,004
or other special operation

31
00:01:44,004 --> 00:01:48,005
to invoke the corresponding function in the kernel, right?

32
00:01:48,005 --> 00:01:50,009
And that mechanism,

33
00:01:50,009 --> 00:01:53,005
the library uses is architecture dependent.

34
00:01:53,005 --> 00:01:57,001
So, it's a special instruction, typically.

35
00:01:57,001 --> 00:02:00,003
And to make system calls efficient.

36
00:02:00,003 --> 00:02:01,009
Oftentimes parameters

37
00:02:01,009 --> 00:02:05,005
of system calls are put into registers.

38
00:02:05,005 --> 00:02:10,006
That's pointers and integers and stuff like that.

39
00:02:10,006 --> 00:02:12,007
When the kernel gets invoked,

40
00:02:12,007 --> 00:02:15,001
then it looks in the appropriate register

41
00:02:15,001 --> 00:02:18,005
to find out which system call is being called.

42
00:02:18,005 --> 00:02:21,000
Each system call has a unique number,

43
00:02:21,000 --> 00:02:25,000
and then the kernel calls its function

44
00:02:25,000 --> 00:02:28,009
that supports that system call.

45
00:02:28,009 --> 00:02:30,009
When a system call is done,

46
00:02:30,009 --> 00:02:34,002
it returns back to the library

47
00:02:34,002 --> 00:02:36,003
and it has a return value

48
00:02:36,003 --> 00:02:39,003
and the library uses that return value

49
00:02:39,003 --> 00:02:44,009
to set a global variable in your process called errno.

50
00:02:44,009 --> 00:02:50,007
And if what it got back from the kernel was an error,

51
00:02:50,007 --> 00:02:53,002
which is represented by a negative value coming back

52
00:02:53,002 --> 00:02:56,003
from the kernel to the library,

53
00:02:56,003 --> 00:02:59,008
then the library returns minus one.

54
00:02:59,008 --> 00:03:04,001
So, if the library gets a minus value from the kernel,

55
00:03:04,001 --> 00:03:06,002
then it sets errno to absolute value of that.

56
00:03:06,002 --> 00:03:08,007
That represents an error and returns minus one.

57
00:03:08,007 --> 00:03:11,000
So, if you get minus one in an application

58
00:03:11,000 --> 00:03:13,008
from a system call function like read,

59
00:03:13,008 --> 00:03:15,007
that means there was an error

60
00:03:15,007 --> 00:03:19,006
and look at errno node to find out what error it was.

61
00:03:19,006 --> 00:03:21,006
When there's not an error,

62
00:03:21,006 --> 00:03:25,008
the library ordinarily doesn't change errno.

63
00:03:25,008 --> 00:03:30,003
Related to all this is a very handy utility called strace.

64
00:03:30,003 --> 00:03:33,007
I use strace almost every day.

65
00:03:33,007 --> 00:03:38,000
Strace will show the system calls a process is making

66
00:03:38,000 --> 00:03:40,000
while the process is running,

67
00:03:40,000 --> 00:03:43,000
so you can get a real good idea of what it's doing.

68
00:03:43,000 --> 00:03:46,007
And if say a program is failing mysteriously,

69
00:03:46,007 --> 00:03:49,000
if you can run it again with strace,

70
00:03:49,000 --> 00:03:52,000
you can maybe get a good clue as to why it failed.

71
00:03:52,000 --> 00:03:54,002
Maybe it's trying to open up a file,

72
00:03:54,002 --> 00:03:55,008
file's not there,

73
00:03:55,008 --> 00:03:57,002
and the program's just exiting

74
00:03:57,002 --> 00:03:59,008
without any kind of error message.

75
00:03:59,008 --> 00:04:01,007
Strace could help with that.

76
00:04:01,007 --> 00:04:05,001
If a process is already running, you can attach to it

77
00:04:05,001 --> 00:04:07,005
and look at what it's doing with strace.

78
00:04:07,005 --> 00:04:09,009
You just use the minus P option strace

79
00:04:09,009 --> 00:04:12,004
and give the process ID of the process,

80
00:04:12,004 --> 00:04:15,003
and then it'll start showing you the system calls

81
00:04:15,003 --> 00:04:17,005
the process is making.

82
00:04:17,005 --> 00:04:19,008
If you think a process is hung,

83
00:04:19,008 --> 00:04:20,009
sometimes this is helpful

84
00:04:20,009 --> 00:04:24,005
to see if it's actually doing anything or not.

85
00:04:24,005 --> 00:04:27,008
System calls are cool and then we'll have a challenge

86
00:04:27,008 --> 00:04:30,000
and you can look at some of this stuff.

