Linux 系统调用(syscalls)
学习如何使用 Linux 系统调用执行常见的操作系统操作,例如文件输入输出、进程管理和内存分配。
Linux 系统调用(syscalls) 是 CoddyKit 上的免费 Assembly Language & x86 Low-Level Systems Programming 课时。 这是第 2 节课,共 4 节。 你可以在下方免费阅读本课时的完整内容 — 然后在浏览器中使用内置代码编辑器和全天候 AI 导师进行实践。 这是 Assembly Language & x86 Low-Level Systems Programming 学习路径的一部分,你的进度在网页和 CoddyKit 应用中同步。 Assembly Language & x86 Low-Level Systems Programming 课程共包含 4 节课。
本课时的部分内容尚未翻译,以英文显示。
What are System Calls?
Welcome! In this lesson, we'll dive into Linux System Calls (syscalls). These are the fundamental way user-space programs request services from the operating system's kernel.
Think of them as a special set of functions that your program can call to do powerful things, like interacting with files, managing processes, or allocating memory.
User vs. Kernel Mode
Modern operating systems operate in different privilege levels. Typically, there's user mode (where your applications run) and kernel mode (where the OS core runs).
- User Mode: Limited access to hardware and critical memory.
- Kernel Mode: Full access, handles system resources securely.
System calls are the controlled gateway for user-mode programs to temporarily switch to kernel mode and ask the OS to perform privileged operations on their behalf.
Invoking Syscalls in x86-64
On x86-64 Linux, system calls are primarily invoked using the syscall instruction. Before calling syscall, you load specific registers with values:
- RAX: Holds the system call number.
- RDI, RSI, RDX, R10, R8, R9: Hold the system call arguments (up to 6).
- The return value is placed back in RAX.
Finding Syscall Numbers
How do you know which number corresponds to which system call? You can look them up!
- Use the
man syscallscommand in your terminal. - Consult header files like
/usr/include/asm/unistd_64.h.
For example, sys_write is system call number 1, and sys_exit is number 60.
Basic File I/O: sys_write
One of the most common syscalls is sys_write, used to write data to a file descriptor. Its parameters are:
- RDI: File descriptor (e.g., 1 for stdout).
- RSI: Pointer to the buffer containing data.
- RDX: Number of bytes to write.
Standard file descriptors are 0 (stdin), 1 (stdout), and 2 (stderr).
Hello, Syscall! Example
Let's write a simple program that prints "Hello, Syscall!" to the console using sys_write and then exits using sys_exit.
Try running this example:
section .data
msg db "Hello, Syscall!", 0xa ; Our string + newline
len equ $ - msg ; Length of our string
section .text
global _start
_start:
; sys_write(fd=1, buf=msg, count=len)
mov rax, 1 ; syscall number for sys_write
mov rdi, 1 ; fd=1 (stdout)
mov rsi, msg ; buffer (our string)
mov rdx, len ; count (length of string)
syscall ; Invoke kernel
; sys_exit(status=0)
mov rax, 60 ; syscall number for sys_exit
mov rdi, 0 ; exit status 0
syscall ; Invoke kernelBasic File I/O: sys_read
The counterpart to sys_write is sys_read, which reads data from a file descriptor into a buffer. Its parameters are:
- RDI: File descriptor (e.g., 0 for stdin).
- RSI: Pointer to the buffer to store data.
- RDX: Maximum number of bytes to read.
sys_read returns the number of bytes actually read, or an error code.
Echoing Input Example
Here's a program that reads up to 256 bytes from standard input (stdin) and then writes whatever it read back to standard output (stdout).
Try running this example:
section .bss
buffer resb 256 ; A buffer to store input
section .text
global _start
_start:
; sys_read(fd=0, buf=buffer, count=256)
mov rax, 0 ; syscall number for sys_read
mov rdi, 0 ; fd=0 (stdin)
mov rsi, buffer ; buffer to store input
mov rdx, 256 ; max bytes to read
syscall ; Invoke kernel
mov rbp, rax ; Store bytes read in rbp
; sys_write(fd=1, buf=buffer, count=rbp)
mov rax, 1 ; syscall number for sys_write
mov rdi, 1 ; fd=1 (stdout)
mov rsi, buffer ; buffer (our read input)
mov rdx, rbp ; count (actual bytes read)
syscall ; Invoke kernel
; sys_exit(status=0)
mov rax, 60 ; syscall number for sys_exit
mov rdi, 0 ; exit status 0
syscall ; Invoke kernelSyscall Arguments Check
Let's quickly check your understanding of how arguments are passed for x86-64 Linux system calls.
Recap: Linux System Calls
You've learned the basics of Linux system calls!
- Syscalls are how user programs request kernel services.
- The
syscallinstruction (x86-64) initiates the call. - RAX holds the syscall number, and RDI-R9 hold arguments.
- We explored
sys_write(to stdout),sys_read(from stdin), andsys_exit.
Mastering syscalls is key to understanding low-level Linux programming and operating system interaction.
常见问题解答
「Linux 系统调用(syscalls)」课时是免费的吗?
是的 — 「Linux 系统调用(syscalls)」的完整文本可在网页上免费阅读。要进行交互式练习(内置代码编辑器和全天候 AI 导师)并解锁 Assembly Language & x86 Low-Level Systems Programming 课程的其余内容,请升级到 CoddyKit PRO。 Assembly Language & x86 Low-Level Systems Programming 课程共包含 4 节课。
「Linux 系统调用(syscalls)」这节课中我会学到什么?
学习如何使用 Linux 系统调用执行常见的操作系统操作,例如文件输入输出、进程管理和内存分配。 你通过在浏览器中直接运行的动手代码来练习 Assembly Language & x86 Low-Level Systems Programming,全天候 AI 导师会在你学习这节课的过程中回答你的问题。
学习 Assembly Language & x86 Low-Level Systems Programming 需要有经验吗?
无需任何先前经验。CoddyKit 上的 Assembly Language & x86 Low-Level Systems Programming 课程适合初学者到高级学习者,你可以从这里开始或从头开始,按照自己的节奏学习。 这是第 2 节课,共 4 节。
「Linux 系统调用(syscalls)」课时需要多长时间?
大多数 CoddyKit 课程大约需要 5–10 分钟。每节课都很精短且互动,所以你能稳步进步,并在网页和应用中从离开的地方继续。
我能在这节 Assembly Language & x86 Low-Level Systems Programming 课中编写并运行代码吗?
能。每节 Assembly Language & x86 Low-Level Systems Programming 课都包含内置代码编辑器,你可以在浏览器中直接编写并运行真实代码,并获得即时 AI 反馈 — 无需本地设置。
此课程中的所有课时
- 虚拟内存概念
- Linux 系统调用(syscalls)
- Windows API 交互
- 动态内存:汇编中的堆分配