The GlitchMod knowledge base

Information about IOS

IOP-OS (IOS) is the operating system of the Wii. It runs on the Starlet and is responsible for providing services to the Broadway that give access to the rest of the Wii hardware. The Kernel is the core of an Operating System. It acts as t…

5 min readUpdated Oct 9, 2026

IOP-OS (IOS) is the operating system of the Wii. It runs on the Starlet and is responsible for providing services to the Broadway that give access to the rest of the Wii hardware.

Kernel

The Kernel is the core of an Operating System. It acts as the layer between hardware and software and is responsible for not letting user code crash the system. The IOS uses a microkernel architecture, meaning very little is done in the kernel's code and things such as the Filesystem and USB drivers are done as separate processes from the kernel.

The Kernel is the first piece of code executed by IOS. The executable, aka binary, is in an ELF format and consists of the microkernel itself, the cryptography core, and the bare minimum of drivers required for loading the rest of IOS.

On IOS version predating 28, the kernel binary is monolithic and contains the entirety of IOS and it's modules. The IOS kernel upon loading maps out basic memory regions, and any user regions as other processes begin starting. The kernel also maps out Domains, areas of memory that belong to specific processes. Domain 1 belongs to the STM process, so any memory region that has its domain value set to 1 will only be able to be accessed by the STM process.

The kernel is also in charge of scheduling threads, and giving other processes CPU time. IOS's scheduler is similar to that of the DS, with the exception of using round-robin scheduling. The scheduler gives time to processes in equal time slots, such as 20 milliseconds. Meaning every thread that is active gets 20ms of CPU time to complete it's task and if it doesn't within it's allotted time, the thread gets suspended by the scheduler until every other thread gets 20ms of their own, then is resumed.

The kernel also handles memory allocation, message queues and handling, interupts, and parts of the IPC subsystem.

IPC

IPC is how the Hollywood facilitates communication between the Starlet and the Broadway. On the Hollywood, It consists of 2 general-purpose registers and 2 sets of flags with different access rights between the Starlet and Broadway. Each side of the IPC system can be configured to generate an IRQ (Interrupt Request) from the Hollywood upon flags being set.

The IPC system consists of 2 sets of flags. X1 and X2 can be freely read/set/zeroed by the Broadway, but only read/zeroed by the Starlet. Y1 and Y2 can be freely read/set/zeroed by the Starlet, but only read/zeroed by the Broadway. The Broadway and Starlet each have their own control registers inside the Hollywood used for controlling the IPC flags.

HW_IPC_PPCMSG is one of the general-purpose registers inside the Hollywood and consists of 32-bits. Conventionally, the Broadway writes to this register and the Starlet reads from it. However, there is no enforcement of this and either CPU can write to this register freely.

HW_IPC_PPCCTRL is exposed to the Starlet and Broadway by the Hollywood. It is used by the Broadway to control it's side of the IPC system. It's a 32-bit register but only 6 bits (0-5) are used.

Bit 0 - X1, can be freely read or written to.

Bit 1 - Y2, can be read, or cleared by writing a 1.

Bit 2 - Y1, can be read, or cleared by writing a 1.

Bit 3 - X2, can be freely read or written to.

Bit 4 - Generate IRQ #30 from Hollywood when Y1 is set.

Bit 5 - Generate IRQ #30 from Hollywood when Y2 is set.

HW_IPC_ARMMSG is the other general-purpose register inside the Hollywood and is equivalent to it's Broadway counterpart with the convention being reversed, with the Starlet writing to this register and the Broadway reading from it, however this is not enforced. Either CPU can freely read or write to this register.

HW_IPC_ARMCTRL is the other control-register inside the Hollywood and also consists of a 32-bit register with only 6 bits (0-5) being used. This register is unique being the only register in the IPC system accessible to only the Starlet and not the Broadway.

Bit 0 - Y1, can be freely read or written to.

Bit 1 - X2, can be read, or cleared by writing a 1.

Bit 2 - X1, can be read, or cleared by writing a 1.

Bit 3 - Y2, can be freely read or written to.

Bit 4 - Generate IRQ #31 from Hollywood when X1 is set.

Bit 5 - Generate IRQ #31 from Hollywood when X2 is set.

IOS uses IPC to facilitate calls to IOS from PPC code on the Broadway. It consists of 7 calls that can be used by PPC code.

1. open

2. close

3. read

4. write

5. seek

6. ioctl

7. ioctlv

These calls are typically used on files inside the /dev/ directory, which consists of device files used by IOS for interfacing with device drivers. From here, PPC code is able to interface with drivers inside IOS.

Modules

Modules refer to the additional processes and drivers that make up the rest of IOS. It consists of anything that runs outside of the kernel but still runs as part of IOS. Modules can vary between IOS versions, but typically consists of ES (E-Ticket System), FS (Filesystem), and drivers such as the ones for the Keyboard, WiFi controller, Network Interfaces and TCP/IP stack.

ES is the module responsible for the installation and removal of titles, but more importantly also bootstrapping the Broadway. ES acts as the security system of the Wii, having higher access rights than other processes inside IOS and for giving Broadway access to title contents.

Other modules are given PIDs and GIDs that can only be changed by the Kernel or ES. PID 15 is notable for being the IPC server's process, so any request from the Broadway appear to come from the IPC server.