Module Overview
Kernel modules are dynamically loadable pieces of code that extend the Linux kernel's functionality without requiring a full kernel rebuild. They act as plugins, allowing the kernel to support hardware devices, file systems, network protocols, and other features on demand. Unlike user-space programs, which run in a protected environment, kernel modules execute in kernel space, granting direct access to hardware and low-level system resources. This capability enables fine-grained control over system behavior but also demands rigorous adherence to safety and stability constraints.
What are Kernel Modules?¶
A kernel module is a compiled object file (typically .ko on Linux) that contains code and data structures compatible with the kernel's internal APIs. Modules can be loaded into the kernel at runtime using tools like insmod or modprobe, and removed with rmmod. They are often used to add support for hardware drivers, cryptographic algorithms, or filesystems without bloating the kernel binary.
For example:
Role in Linux¶
Kernel modules enable the Linux kernel to remain lean and adaptable. By separating core functionality from optional features, they allow:
- Hardware support: Drivers for USB devices, network cards, and GPUs.
- Feature extensibility: Adding support for new filesystems (e.g., fuse, nfs) or cryptographic algorithms.
- Resource efficiency: Avoiding unnecessary kernel code in memory unless needed.
Modules also facilitate hot-plugging of devices, enabling the kernel to adapt to dynamically changing hardware configurations.
Differences from User-Space Programs¶
| Feature | Kernel Module | User-Space Program |
|---|---|---|
| Execution Context | Runs in kernel space (privileged) | Runs in user space (protected) |
| Memory Access | Direct access to physical memory | Limited to virtual memory mappings |
| Error Handling | Crashes the kernel on bugs | Crashes the process, not the system |
| Compilation | Linked against kernel headers | Linked against user-space libraries |
| Debugging | Requires kprobe or ftrace tools |
Uses standard debuggers (e.g., gdb) |
Kernel modules must adhere to strict coding standards to prevent security vulnerabilities or kernel panics. They are typically written in C and compiled with the kernel's build system.
Compilation and Loading Basics¶
Modules are compiled using the Linux kernel's build tools. A typical workflow involves:
1. Writing module code (e.g., hello.c):
#include <linux/module.h>
#include <linux/kernel.h>
MODULE_LICENSE("GPL");
MODULE_AUTHOR("Your Name");
int init_module(void) {
printk(KERN_INFO "Hello, world!\n");
return 0;
}
void cleanup_module(void) {
printk(KERN_INFO "Goodbye, world!\n");
}
-
Compiling with
make(using aMakefile): -
Building and loading:
Key takeaways¶
- Kernel modules extend the kernel's capabilities dynamically without rebooting.
- They operate in kernel space, offering direct hardware access but requiring strict safety measures.
- Modules differ fundamentally from user-space programs in execution context, error handling, and resource access.
- Compilation and loading rely on the kernel's build system and tools like
insmod/rmmod. - Proper module design is critical to system stability and security.