Master the fundamental concepts of build a mini kernel through this focused micro-challenge.
You have read the whole brief, and the concepts above stay free on every task. Writing and running the code needs a plan.
Three hints are available for this task, revealed one at a time inside the code workspace so you can struggle productively before seeing them.
Every task includes starter code, theory, and hidden tests so you can implement and verify locally in the browser.
How it worksProtected mode enables paging, segmentation with descriptors, and ring separation. Switch requires loading a GDT, setting CR0.PE, far jumping to 32-bit code segment, and initializing segments.
Steps:
lgdtFor example, after the far jump, CS points at a descriptor with D/B flags for 32-bit operations while DS/ES/SS use flat data selectors.
Every OS you've ever booted on real x86 hardware , from DOS-era systems to modern Linux , passes through this exact real-mode-to-protected-mode transition, and forgetting the far jump after setting CR0.PE is a rite-of-passage bug that leaves the CPU executing stale real-mode instructions until it triple-faults. This is also the turning point where early teaching kernels like xv6's x86 predecessors first became genuinely 32-bit.
Before you call the implementation done, walk failure modes on purpose. Test empty structures, single-element edge cases, maximum concurrency, and errno paths that must not crash the program. OS code usually fails in production when happy-path tests pass but invariants break under contention or memory pressure.
Keep structures small and name fields after kernel counterparts when possible. That lets you read man pages and kernel source side by side while you work. Print observable events during development; remove noisy logs once tests pass reliably.
You will implement the mode transition assembly and verify 32-bit code runs. This exercise requires explaining why a near jump immediately after setting PE is illegal on x86.
Simulate the real-mode to protected-mode switch as a CPU sees it. In real mode, loading a segment register just sets base = selector × 16, and with the A20 line disabled, addresses wrap at 1 MiB. After lgdt and setting CR0.PE, the CPU is in protected mode, but every segment register still holds its cached real-mode descriptor until it's reloaded. The far jump reloads CS, and moves into DS/ES/SS reload the others. Each of these loads now goes through the GDT, with protection checks that raise faults.
| Command | Effect |
|---|---|
| `desc N code | data BASE LIMIT [notpresent]` |
lgdt | load the GDT; its size is the highest defined index + 1 (entry 0 is the null descriptor) |
| `a20 on | off` |
setpe | set CR0.PE (CR0 starts as 0x00000010) |
ljmp SEL:OFF | far jump: reload CS |
mov SEG, SEL | reload ds, es or ss (hex selector) |
access SEG:OFF | compute the linear address of a memory access |
state | show mode, CR0 and the four selectors |
Real mode: base = SEL × 16, limit = 0xFFFF, never faults.
Protected mode (checked in this order, for selector SEL with index SEL >> 3):
#GP (LDT selector, no LDT loaded);#GP (null selector); for DS/ES the load succeeds, but any later access through it is #GP (null segment);#GP (selector beyond GDT limit);#GP (not a code segment) / #GP (not a data segment);#NP (segment not present), or #SS (segment not present) for SS;A faulting load leaves the register unchanged. mov cs, … always prints mov cs: #UD (cannot load cs with mov).
access: an offset above the cached limit → #GP (offset beyond limit L). Otherwise linear = base + offset, masked to 20 bits in real mode with A20 off (report (wrapped, A20 off) when the mask changed it).
cLoading…
Faults replace the success text: ljmp 0x18:0x0: #GP (not a code segment), mov ss, 0x0: #GP (null selector). Numbers print in lower-case hex without leading zeros, except where widths are shown.
Input:
cLoading…
Output:
cLoading…
access uses only the cache, which is why the CPU keeps running right after setpe.load_segment function shared by ljmp and mov.Hidden tests cover every fault (LDT selector, null CS/SS, index beyond the GDT, wrong segment type, not-present data and stack segments), a limit violation, a non-zero segment base, and accessing through a stale real-mode cache after setpe.