The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Summarize memoryfree --human --wideView examples
Read kernel memory countersgrep -E \ '^(MemAvailable|SwapTotal|SwapFree|Dirty|Writeback|Slab|SReclaimable):' \ /proc/meminfoView examples
List swap areasswapon --show --output=NAME,TYPE,SIZE,USED,PRIOView examples
Read kernel swap tablecat /proc/swapsView examples
Sample reclaim and swappingvmstat 1 10View examples
Read memory PSIcat /proc/pressure/memoryView examples
Sample swap activitysar -W 1 10View examples
Rank processes by RSSps -eo pid,user,comm,rss,vsz --sort=-rss | head -20View examples
Inspect one process memorysudo cat /proc/1234/smaps_rollupView examples
Find OOM eventsjournalctl -k -g 'oom|Out of memory|Killed process' \ --since today --no-pagerView examples
Read swappinesssysctl vm.swappinessView examples
Read overcommit policysysctl vm.overcommit_memory vm.overcommit_ratioView examples
Enable prepared swapsudo swapon --priority 10 /swapfileView examples
Disable one swap areasudo swapoff /swapfileView examples
List zram deviceszramctl --output \ NAME,ALGORITHM,DISKSIZE,DATA,COMPR,TOTAL,STREAMS,MOUNTPOINTView examples
Read zram memory statscat /sys/block/zram0/mm_statView examples
Configure a zram devicesudo zramctl /dev/zram0 --algorithm zstd --size 4GView examples
Reset an unused zram devicesudo zramctl --reset /dev/zram0View examples
Read zswap statecat /sys/module/zswap/parameters/enabledView examples
Read cgroup memory eventscat \ /sys/fs/cgroup/system.slice/example.service/memory.eventsView examples

Swap is part of Linux virtual-memory policy, not proof that RAM is exhausted. zram stores compressed pages in RAM, while zswap is a compressed cache in front of a real swap device; enabling overlapping mechanisms without capacity analysis can waste CPU and memory. Diagnose pressure with workload, PSI, reclaim, and OOM evidence, and never disable active swap unless available memory and a rollback plan can absorb every resident page.

Step by step

Detailed examples

01

Start with available memory, not the free column

Linux uses idle RAM for reclaimable caches. MemAvailable estimates memory usable without swapping, while free alone can look alarming on a healthy host. Capture dirty/writeback, slab, page tables, huge pages, and cgroup limits before concluding that the machine needs more swap.

Capture a memory baseline
free --human --wide
grep -E '^(MemAvailable|SwapTotal|SwapFree|Dirty|Writeback|Slab|SReclaimable|PageTables|AnonHugePages):' /proc/meminfo
numastat 2>/dev/null
uptime
Back to quick reference ↑
02

Map every swap layer and its owner

Swap may be a partition, file, encrypted device, zram device, or distribution-managed systemd generator. Priority controls allocation preference. Compare live state with fstab and generator configuration before editing, and verify whether hibernation depends on a specific resume device and offset.

Inventory live and persistent swap
swapon --show --output=NAME,TYPE,SIZE,USED,PRIO
cat /proc/swaps
findmnt --fstab --types swap
systemctl list-units --type=swap --all
Back to quick reference ↑
03

Differentiate capacity, reclaim, and stall pressure

Nonzero swap use can be harmless cold-page placement. Sustained si/so, direct reclaim, elevated PSI some/full, I/O latency, and OOM events are stronger signals. The first vmstat row is an average since boot; use later samples. Correlate with a workload event rather than tuning from one snapshot.

Sample a bounded pressure window
vmstat 1 10
cat /proc/pressure/memory
cat /proc/pressure/io
sar -W 1 10
Back to quick reference ↑
04

Attribute memory to processes and cgroups carefully

RSS double-counts shared pages across processes; VSZ is address space, not resident consumption. PSS from smaps is more proportional but collecting it across many processes can be expensive. Containers and services can hit cgroup memory.max while the host has memory available.

Inspect host and one cgroup
ps -eo pid,user,comm,rss,vsz --sort=-rss | head -20
systemd-cgtop --depth=2 --iterations=1
cat /sys/fs/cgroup/system.slice/example.service/memory.current
cat /sys/fs/cgroup/system.slice/example.service/memory.events
Back to quick reference ↑
05

Tune virtual-memory policy only from measured behavior

swappiness changes the balance between reclaiming anonymous and file-backed memory; it does not set a swap percentage. overcommit controls allocation promises and can break applications that reserve large address spaces. Kernel semantics evolve, so test the deployed version under realistic load and persist only after rollback validation.

Read relevant policy
sysctl vm.swappiness
sysctl vm.overcommit_memory vm.overcommit_ratio
sysctl vm.dirty_background_ratio vm.dirty_ratio
uname -r
Back to quick reference ↑
06

Enable and disable swap without exhausting memory

A new swap file needs correct filesystem support, non-sparse allocation, mode 0600, mkswap initialization, and encrypted backing if confidentiality matters. swapoff must relocate all live pages and can stall or invoke OOM. Estimate headroom, quiesce load, and disable one area at a time with console access.

Review lifecycle gates
swapon --show
free --bytes
# Creation and activation are destructive/privileged and are intentionally not run here.
# sudo mkswap /swapfile
# sudo swapon --priority 10 /swapfile
# sudo swapoff /swapfile
Back to quick reference ↑
07

Size zram for compressed data and metadata, not advertised capacity

zram disksize is the uncompressed logical capacity; physical RAM usage is dynamic and includes allocator overhead. Incompressible pages can approach or exceed expected ratios. Choose an available algorithm, impose mem_limit where justified, give zram higher swap priority, and swapoff before reset or data is lost.

Inspect zram efficiency
zramctl --output NAME,ALGORITHM,DISKSIZE,DATA,COMPR,TOTAL,MOUNTPOINT
cat /sys/block/zram0/mm_stat
cat /sys/block/zram0/comp_algorithm
cat /sys/block/zram0/mem_limit
Back to quick reference ↑
08

Do not confuse zswap with zram swap

zswap is a compressed cache for pages headed to a real swap backend and evicts to that backend; zram is itself a compressed block device. Combining them can double-compress paths without benefit. Check boot parameters, runtime availability, pool size, compressor, and backing swap before enabling either design.

Audit zswap configuration
cat /sys/module/zswap/parameters/enabled
cat /sys/module/zswap/parameters/compressor
cat /sys/module/zswap/parameters/zpool
cat /sys/module/zswap/parameters/max_pool_percent
cat /proc/cmdline
Back to quick reference ↑
09

Treat OOM kills as evidence, not a random kernel failure

The global OOM killer and cgroup OOM can select different victims. Preserve the allocation context, chosen task, constraint, cgroup events, and preceding PSI. oom_score_adj affects victim selection and can make critical daemons safer only by shifting risk elsewhere; never globally disable OOM response without a bounded alternative.

Collect OOM evidence
journalctl -k -g 'oom|Out of memory|Killed process' --since today --no-pager
cat /sys/fs/cgroup/system.slice/example.service/memory.events
cat /proc/pressure/memory
systemctl show example.service -p MemoryCurrent -p MemoryMax -p OOMPolicy
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. Linux Kernel Projectzram: Compressed RAM-Based Block Deviceskernel.org
  2. Linux Kernel Projectzswapkernel.org
  3. Linux Kernel ProjectPSI: Pressure Stall Informationkernel.org
  4. Linux Kernel ProjectOut of Memory Handlingkernel.org
  5. Linux Kernel ProjectControl Group v2 Memory Controllerkernel.org
  6. util-linux Projectswapon(8) Manual Pageman7.org

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback