Levels/Boot, HAL & hardware/Startup & shutdown

Level 10 · Chapter 2

Startup & shutdown

By the time you see a desktop, nearly every subsystem this course has covered has already been brought up, in a specific, staged order.

Every level in this course, from System architecture down through the kernel, describes something that's already running by the time you're using the machine. This chapter is the missing piece: the staged sequence that actually brings all of it into existence, from a powered-off machine to an interactive desktop — and back down again.

Not one jump, but a staged handoff

It's tempting to picture boot as a single transition: firmware runs, then Windows appears. The reality is a sequence of distinct stages, each handing off to the next only once its own responsibilities are complete:

  1. Firmware and boot manager prepare the machine and identify which OS to start, per Secure Boot & measured boot's trust-establishment role.
  2. Boot loader to kernel handoff (covered next) prepares the kernel image, boot-critical drivers, and core memory structures, then transfers control into the kernel.
  3. Kernel and Executive initialization brings up the core managers covered throughout the Executive level — memory management, the object model, and more — entirely before any ordinary user-mode process exists yet.
  4. Early system processes (covered in the next chapter) — the Session Manager, foundational session infrastructure, services — come online.
  5. Winlogon and the interactive shell finally bring up something resembling what most people think of as "Windows starting": a sign-in prompt, and eventually a desktop.

Why early failures can be so opaque

A direct, practically important consequence of this staged model: a failure very early in the sequence — a boot-critical driver that won't load, a boot-loader configuration problem — can prevent every later stage from ever beginning, often with minimal or cryptic diagnostic information, precisely because most of the infrastructure that would normally produce a helpful error message (logging services, the event log itself, even a usable UI) hasn't started yet at the point of failure. This is exactly why boot failures are diagnosed differently from ordinary application crashes — tools like Windows Recovery Environment exist specifically because the ordinary, fully-booted diagnostic toolset isn't available when the problem prevents booting in the first place.

The desktop is not "the beginning"

Perhaps the single most useful reframing this chapter offers: by the moment a desktop becomes visible, an enormous amount of critical work has already completed successfully — kernel initialization, driver loading, session infrastructure, service startup, authentication. The desktop is closer to the end of a long, carefully staged sequence than the beginning of one. Seeing a login prompt at all is already evidence that stages 1 through 4 above succeeded.

Shutdown: the same staging, in reverse, with its own hazards

Shutdown isn't simply "boot in reverse" as a mirror image, but it does follow the same principle of ordered, dependency-aware transitions: services need a chance to stop cleanly (flushing data, releasing resources) before the components they depend on go away underneath them, and the kernel needs to reach a clean, quiescent state before power is actually cut or the machine restarts. A service or driver that doesn't respond correctly to a shutdown request can visibly stall the entire process — the familiar "shutting down" screen lingering — because Windows is genuinely waiting for that specific component to finish, rather than proceeding regardless.

A common mistake

Treating "Windows starting" as synonymous with "the desktop appearing" causes real confusion when diagnosing startup problems — a black screen after what looks like a successful login, for instance, is very often a late-stage failure (shell startup specifically, covered in the next chapter), not evidence that "Windows itself" failed to start; the kernel, session infrastructure, and even authentication may all have completed successfully before this later, more visible symptom appeared.

Where this connects