Linux System Calls (syscalls)
Learn how to perform common operating system operations like file I/O, process management, and memory allocation using Linux system calls.
Linux System Calls (syscalls) is a free Assembly Language & x86 Low-Level Systems Programming lesson on CoddyKit — lesson 2 of 4. You can read the complete lesson below for free — then practise it hands-on in the browser with a built-in code editor and a 24/7 AI tutor. It is part of the Assembly Language & x86 Low-Level Systems Programming learning path, one of 4 lessons in the course, and your progress syncs across the web and the CoddyKit app.
What are System Calls?
Welcome! In this lesson, we'll dive into Linux System Calls (syscalls). These are the fundamental way user-space programs request services from the operating system's kernel.
Think of them as a special set of functions that your program can call to do powerful things, like interacting with files, managing processes, or allocating memory.
User vs. Kernel Mode
Modern operating systems operate in different privilege levels. Typically, there's user mode (where your applications run) and kernel mode (where the OS core runs).
- User Mode: Limited access to hardware and critical memory.
- Kernel Mode: Full access, handles system resources securely.
System calls are the controlled gateway for user-mode programs to temporarily switch to kernel mode and ask the OS to perform privileged operations on their behalf.
Invoking Syscalls in x86-64
On x86-64 Linux, system calls are primarily invoked using the syscall instruction. Before calling syscall, you load specific registers with values:
- RAX: Holds the system call number.
- RDI, RSI, RDX, R10, R8, R9: Hold the system call arguments (up to 6).
- The return value is placed back in RAX.
Finding Syscall Numbers
How do you know which number corresponds to which system call? You can look them up!
- Use the
man syscallscommand in your terminal. - Consult header files like
/usr/include/asm/unistd_64.h.
For example, sys_write is system call number 1, and sys_exit is number 60.
Basic File I/O: sys_write
One of the most common syscalls is sys_write, used to write data to a file descriptor. Its parameters are:
- RDI: File descriptor (e.g., 1 for stdout).
- RSI: Pointer to the buffer containing data.
- RDX: Number of bytes to write.
Standard file descriptors are 0 (stdin), 1 (stdout), and 2 (stderr).
Hello, Syscall! Example
Let's write a simple program that prints "Hello, Syscall!" to the console using sys_write and then exits using sys_exit.
Try running this example:
section .data
msg db "Hello, Syscall!", 0xa ; Our string + newline
len equ $ - msg ; Length of our string
section .text
global _start
_start:
; sys_write(fd=1, buf=msg, count=len)
mov rax, 1 ; syscall number for sys_write
mov rdi, 1 ; fd=1 (stdout)
mov rsi, msg ; buffer (our string)
mov rdx, len ; count (length of string)
syscall ; Invoke kernel
; sys_exit(status=0)
mov rax, 60 ; syscall number for sys_exit
mov rdi, 0 ; exit status 0
syscall ; Invoke kernelBasic File I/O: sys_read
The counterpart to sys_write is sys_read, which reads data from a file descriptor into a buffer. Its parameters are:
- RDI: File descriptor (e.g., 0 for stdin).
- RSI: Pointer to the buffer to store data.
- RDX: Maximum number of bytes to read.
sys_read returns the number of bytes actually read, or an error code.
Echoing Input Example
Here's a program that reads up to 256 bytes from standard input (stdin) and then writes whatever it read back to standard output (stdout).
Try running this example:
section .bss
buffer resb 256 ; A buffer to store input
section .text
global _start
_start:
; sys_read(fd=0, buf=buffer, count=256)
mov rax, 0 ; syscall number for sys_read
mov rdi, 0 ; fd=0 (stdin)
mov rsi, buffer ; buffer to store input
mov rdx, 256 ; max bytes to read
syscall ; Invoke kernel
mov rbp, rax ; Store bytes read in rbp
; sys_write(fd=1, buf=buffer, count=rbp)
mov rax, 1 ; syscall number for sys_write
mov rdi, 1 ; fd=1 (stdout)
mov rsi, buffer ; buffer (our read input)
mov rdx, rbp ; count (actual bytes read)
syscall ; Invoke kernel
; sys_exit(status=0)
mov rax, 60 ; syscall number for sys_exit
mov rdi, 0 ; exit status 0
syscall ; Invoke kernelSyscall Arguments Check
Let's quickly check your understanding of how arguments are passed for x86-64 Linux system calls.
Recap: Linux System Calls
You've learned the basics of Linux system calls!
- Syscalls are how user programs request kernel services.
- The
syscallinstruction (x86-64) initiates the call. - RAX holds the syscall number, and RDI-R9 hold arguments.
- We explored
sys_write(to stdout),sys_read(from stdin), andsys_exit.
Mastering syscalls is key to understanding low-level Linux programming and operating system interaction.
Frequently asked questions
Is the “Linux System Calls (syscalls)” lesson free?
Yes — the full text of “Linux System Calls (syscalls)” is free to read here on the web, and the Assembly Language & x86 Low-Level Systems Programming course includes 4 lessons in total. To practise it interactively (a built-in code editor and a 24/7 AI tutor) and unlock the rest of the Assembly Language & x86 Low-Level Systems Programming course, upgrade to CoddyKit PRO.
What will I learn in “Linux System Calls (syscalls)”?
Learn how to perform common operating system operations like file I/O, process management, and memory allocation using Linux system calls. You practise Assembly Language & x86 Low-Level Systems Programming with hands-on code you run directly in the browser, and a 24/7 AI tutor answers your questions as you work through the lesson.
Do I need any experience to start Assembly Language & x86 Low-Level Systems Programming?
No prior experience is required. Assembly Language & x86 Low-Level Systems Programming on CoddyKit is structured for beginners through advanced learners; this is — lesson 2 of 4, so you can start here or from the beginning and move at your own pace.
How long does the “Linux System Calls (syscalls)” lesson take?
Most CoddyKit lessons take about 5–10 minutes. Each one is bite-sized and interactive, so you make steady progress and pick up exactly where you left off across the web and the app.
Can I write and run code in this Assembly Language & x86 Low-Level Systems Programming lesson?
Yes. Every Assembly Language & x86 Low-Level Systems Programming lesson includes a built-in code editor, so you write and run real code right in your browser and get instant AI feedback — no local setup required.
All lessons in this course
- Virtual Memory Concepts
- Linux System Calls (syscalls)
- Windows API Interaction
- Dynamic Memory: Heap Allocation in Assembly