OS//OS process

An OS process is a running program as the operating system sees it: an instance with its own virtual address space, open files, a numeric identifier and at least one thread, kept apart from every other process by the kernel. It is the unit the OS schedules, isolates, limits and kills, so it is also the unit an engineer reasons about when a server, a PLC gateway or an AI agent runs code.


An OS process is a running program as the operating system sees it: an instance with its own virtual address space, open files, a numeric identifier and at least one thread, kept apart from every other process by the kernel. It is the unit the OS schedules, isolates, limits and kills, so it is also the unit an engineer reasons about when a server, a PLC gateway or an AI agent runs code.

A program on disk is a recipe; the process is the cook at work, with a workbench nobody else may touch. Two copies of the same program are two processes with separate memory, and a crash in one leaves the other running.

A process starts other processes. A child process inherits the parent's environment (its environment variables, its working directory, its limits) and reports back an exit code, zero for success. Python's subprocess.run(...) and Node's child_process are the everyday doors: an agent that runs a shell command or a test suite is spawning a child process and reading its output.

Everything a process does outside its own memory goes through the kernel by a syscall: reading a file, opening a socket, starting a child. That boundary is where the OS can count, refuse and isolate.

Isolation is the point and the cost. Separate address spaces mean a bug cannot corrupt a neighbour, but talking between processes needs pipes, sockets or shared memory, and starting one costs milliseconds where starting a thread costs microseconds. Many waits inside one process are the job of asynchronous programming instead.

A process inside a container is still an ordinary process on the host kernel, only with a narrowed view and capped resources (Docker). A command an agent spawns there inherits the container's limits, which is why sandboxing an agent means sandboxing its processes.

The process is the boundary the OS defends.

Memory, permissions, resource limits and failure all stop at it, so deciding what runs in its own process is deciding what may fail alone.

A process is often confused with a thread: threads share one process's memory and fail together, processes do not. The machinery underneath lives in OS kernel and concurrency.