Program vs process: what is the difference?

Difficulty: Beginner

Question

What is the difference between a program and a process? What does a process consist of in memory?

Answer

This looks like a trivial warm-up, but a lot of candidates fumble it by saying they are "the same thing". They are not, and the cleanest way to remember it is a recipe versus cooking. A recipe is a static set of instructions sitting in a book. Cooking is the activity: someone is actually following the recipe, using ingredients, occupying the stove, and at any moment you can point at where they are in the steps. The program is the recipe; the process is the cooking.

Formally, a program is a passive entity: an executable file stored on disk (an ELF binary on Linux, an .exe on Windows) containing machine code, initialized data and metadata. It has no state and consumes no CPU. A process is an active entity: a program in execution, with a program counter pointing to the next instruction, CPU register values, a stack, allocated memory, open files and a state such as running or waiting. The same program can produce many processes. If you open three terminals and run the same binary, you have one program but three separate processes, each with its own process ID, memory and registers.

Now the memory layout, which is a common follow-up. When the OS loads a program to make a process, the virtual address space is divided into segments. The text segment holds the machine code and is read-only and shareable between processes running the same program. The data segment holds initialized global and static variables, and the BSS segment holds uninitialized globals, zeroed at startup. The heap is used for dynamic allocation (malloc, new) and grows upward towards higher addresses. The stack holds function call frames, local variables, return addresses and arguments, and grows downward. In between there is unused virtual space, and memory-mapped regions such as shared libraries.

Two things to say to stand out. First, stack and heap grow towards each other, and a stack overflow happens when deep recursion or a huge local array eats the space, while a heap leak is memory that was allocated and never freed. Second, alongside memory, the OS keeps a data structure describing the process, the Process Control Block, which stores everything the kernel needs to pause and later resume it.

You can also draw an important distinction between a process being created and being loaded: a call like fork() duplicates an existing process, while exec() replaces the current process image with a new program. So a program becomes a process only when the kernel loads it and gives it those resources.

Finally, remember that a process is also the unit of resource ownership and protection. Two processes cannot directly read each other's memory; that requires explicit inter-process communication. This isolation is what lets your browser tab crash without taking down your music player, and it is the reason threads, which share memory, are treated as a lighter but less isolated alternative.

Code examples

Where variables live in a process

#include <stdio.h>
#include <stdlib.h>

int initialized = 42;      /* data segment */
int uninitialized;         /* BSS segment  */

int main(void) {
    int local = 7;                          /* stack */
    int *dyn = malloc(sizeof(int));         /* heap  */
    printf("code  : %p\n", (void*)main);
    printf("data  : %p\n", (void*)&initialized);
    printf("bss   : %p\n", (void*)&uninitialized);
    printf("heap  : %p\n", (void*)dyn);
    printf("stack : %p\n", (void*)&local);
    free(dyn);
    return 0;
}

Addresses differ per run due to ASLR, but the ordering shows code low, then data/bss, heap above, and stack at the top of the address space.

Key points

Concepts covered

process, program, process image, address space