When you open an application, play a video, or save a document, your computer must coordinate many different activities. Programs need processor time, memory, files, and access to devices.
In the previous tutorial, we introduced the operating system as the software that manages these resources and provides common services to applications.
At the center of that system is the kernel.
But what exactly is a kernel? How is it different from the operating system? And why do applications need it?
Let’s look inside this essential layer of software.
1. What Is a Kernel?
The kernel is the central part of an operating system that manages fundamental resources and controls important interactions between software and hardware.
It is software: a collection of instructions executed by the CPU, or central processing unit. It is not a separate chip inside your computer.
The kernel helps decide which work gets processor time, manages access to memory, and provides controlled ways for programs to use resources such as files and devices.
Consider several applications running together: a browser, a music player, and a text editor. Each has its own work to do, but they share the same computer.
The kernel helps coordinate that sharing while keeping applications from freely interfering with one another.
2. The Kernel Is Not the Entire Operating System
The words “kernel” and “operating system” are closely related, but they do not mean exactly the same thing.
A complete operating system normally includes the kernel together with other software, such as system services, libraries, command-line tools, and sometimes a graphical desktop.
A system service is a program that performs background work, such as managing network connections. A library is reusable code that other programs can call.
The kernel provides the foundation on which much of this software depends.
Linux offers a useful example. Strictly speaking, Linux is a kernel. A Linux distribution, such as Ubuntu or Debian, combines that kernel with tools, libraries, and other software to form a usable operating system.
The desktop you see is therefore not the kernel. Neither is the terminal window where you type commands.
Those interfaces let you interact with software that ultimately relies on kernel services.
3. Why Applications Need a Kernel
Imagine if every application could freely change any memory location, reconfigure devices, or take over the processor.
A mistake in one program could damage another program’s data. Two applications might send conflicting commands to the same device. A malicious program could alter critical system information.
The kernel provides a central place to coordinate access and enforce rules.
Applications usually ask for operating-system services through defined interfaces rather than independently controlling hardware.
For example, a text editor can request that data be written to a file. It does not need to know the detailed commands used by every possible storage device.
This provides both protection and abstraction.
An abstraction is a simpler interface that hides lower-level details. A file is a familiar example: an application works with a named collection of data without managing its physical storage locations itself.
4. The Kernel Manages CPU Time
A running program is represented by a process. A process includes resources such as its memory and information the operating system uses to manage it.
Inside a process, a thread is a sequence of instructions that can be scheduled to run. A process may contain one thread or several.
The kernel’s scheduler is the component that chooses which runnable thread gets CPU time.
A CPU core is an execution unit within the processor. Multiple cores allow multiple threads to run at the same time, while scheduling lets many more threads share the available execution capacity.
Suppose your browser is waiting for data from the network. Instead of leaving the processor idle, the operating system can let another ready thread run.
When execution changes from one thread to another, the system saves the information needed to resume the old thread and restores the information needed by the next one. This is called a context switch.
Through scheduling, the kernel helps the computer remain responsive while many programs make progress.
5. The Kernel Manages and Protects Memory
Applications need memory to hold instructions and data.
RAM, or random-access memory, is the working memory that holds information currently being used by the computer.
The kernel tracks physical memory and manages the mappings that make memory available to processes.
Modern general-purpose operating systems use virtual memory. This gives each process its own view of memory addresses rather than exposing all physical RAM directly.
The processor’s memory-management hardware translates these virtual addresses into physical addresses using information maintained by the operating system.
This arrangement also supports protection. One process normally cannot access another process’s private memory without permission.
For example, a mistake in a text editor should not let it overwrite a browser’s private data or critical kernel information.
The kernel and processor hardware work together to enforce these boundaries. The kernel establishes the mappings and permissions; hardware checks them during memory accesses.
6. The Kernel Helps Programs Use Files and Devices
Applications commonly work with files, network connections, keyboards, displays, and storage devices.
A file system is the set of rules and data structures used to organize files and directories on storage.
A device driver is software that knows how to communicate with a particular device or class of devices.
In many operating systems, file-system code and many device drivers run as part of the kernel. Other designs place some of these components in separate processes.
Either way, applications can use common interfaces without implementing every hardware detail themselves.
A program may request data from a file. The system checks access permissions, locates the requested data, and arranges any necessary device operation.
The application receives the data through a standard interface, even though the underlying storage hardware may differ between computers.
7. User Mode and Kernel Mode
The kernel needs authority that ordinary applications should not have.
Modern processors support execution modes with different privileges. Two important concepts are user mode and kernel mode.
User mode is a restricted execution mode used by ordinary application code. Kernel mode is a privileged execution mode used for trusted operating-system code.
A privileged operation is an operation restricted to trusted code, such as changing certain processor settings or configuring memory protection.
An application cannot simply choose to give itself these privileges. The processor enforces the rules for entering privileged execution.
This distinction helps explain why an application crash often leaves the rest of the computer running, while a serious kernel failure can stop the whole system.
The kernel has much greater authority, so errors in it can have much wider consequences.
Kernel mode is a processor execution mode, not a separate processor. The same CPU can execute application code in user mode and then execute kernel code in kernel mode.
8. How Applications Request Kernel Services
If applications run with restricted privileges, how do they open files or request other protected services?
They use system calls.
A system call is a controlled mechanism through which a program requests a service from the kernel.
Examples include requesting that the system open a file, read data, create a process, or communicate over a network.
Applications often reach system calls through library functions. A familiar programming function may prepare the request and perform the necessary transition into the kernel.
However, not every function call is a system call. Adding two numbers or searching through data already in memory can happen entirely inside the application.
When a system call occurs, the processor transfers execution to a defined kernel entry point. The kernel checks the request, performs the permitted work, and eventually returns a result.
This is a controlled entrance, not unrestricted access to everything the kernel can do.
Also, entering the kernel does not necessarily mean switching to another process. The kernel may handle the request and return directly to the same application.
9. Example: A Program Reads a File
Let’s connect these ideas with a simple example.
A text editor wants to read part of a document from an already opened file.
First, it calls a function that requests file data. That request reaches the kernel through a system call.
The kernel checks whether the request is valid and whether the opened file permits reading.
It then determines whether the requested data is already available in memory. Operating systems often keep recently used file data in a cache, which is a temporary store that helps avoid slower repeated accesses.
If the data is available there, the kernel may satisfy the request without reading the storage device.
If it is not available, the system arranges a storage operation through the relevant driver. While the editor waits, the scheduler can allow another thread to run.
Once the data becomes available, the system makes it available to the editor, and the read operation returns.
The editor can then interpret the document and display its contents.
What looks like one simple application operation can therefore involve system calls, access checks, memory, file-system code, drivers, and scheduling.
10. How the Kernel Responds to Hardware
Applications are not the only source of work for the kernel. Hardware also needs attention.
An interrupt is a signal that causes the processor to temporarily redirect execution to a handler for an event.
For example, a device may use an interrupt to report that an operation has completed. A timer interrupt can help the operating system track time and make scheduling decisions.
The handler is code that responds to the event or arranges further processing.
Interrupts allow the system to react to events without requiring applications to continuously check every device themselves.
A system call and a hardware interrupt have different starting points: an application deliberately requests a service through a system call, while hardware can signal an event through an interrupt.
Both can cause kernel code to run.
11. The Kernel Does Not Execute Every Application Instruction
It is easy to imagine the kernel as a middleman through which every instruction must pass.
That is not how normal execution works.
Application instructions usually execute directly on the CPU in user mode. Arithmetic, comparisons, and permitted memory accesses do not require the kernel to individually approve each instruction.
The kernel establishes the execution environment, manages resources, and responds when its involvement is needed.
That involvement may happen through a system call, an interrupt, or an exception—a processor-reported condition arising during instruction execution, such as an invalid memory access.
This combination makes the system practical: applications execute efficiently, while the processor and kernel enforce important boundaries.
12. Conclusion
The kernel is the core software layer that makes controlled resource sharing possible.
It schedules threads, manages memory, enforces protection, and provides essential services that help programs use files and devices.
But it is not the desktop, not a separate chip, and not the entire operating system.
Applications normally execute their own instructions directly on the CPU. When they need protected services, they enter the kernel through controlled interfaces.
Understanding this relationship gives us a foundation for studying how operating systems actually work.
In the next tutorial, we will look more closely at user mode and kernel mode: how the processor separates ordinary application code from privileged operating-system code, and how execution moves safely between them.
