The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Summarize memory | free --human --wide | View examples |
| Read kernel memory counters | grep -E \
'^(MemAvailable|SwapTotal|SwapFree|Dirty|Writeback|Slab|SReclaimable):' \
/proc/meminfo | View examples |
| List swap areas | swapon --show --output=NAME,TYPE,SIZE,USED,PRIO | View examples |
| Read kernel swap table | cat /proc/swaps | View examples |
| Sample reclaim and swapping | vmstat 1 10 | View examples |
| Read memory PSI | cat /proc/pressure/memory | View examples |
| Sample swap activity | sar -W 1 10 | View examples |
| Rank processes by RSS | ps -eo pid,user,comm,rss,vsz --sort=-rss | head -20 | View examples |
| Inspect one process memory | sudo cat /proc/1234/smaps_rollup | View examples |
| Find OOM events | journalctl -k -g 'oom|Out of memory|Killed process' \
--since today --no-pager | View examples |
| Read swappiness | sysctl vm.swappiness | View examples |
| Read overcommit policy | sysctl vm.overcommit_memory vm.overcommit_ratio | View examples |
| Enable prepared swap | sudo swapon --priority 10 /swapfile | View examples |
| Disable one swap area | sudo swapoff /swapfile | View examples |
| List zram devices | zramctl --output \
NAME,ALGORITHM,DISKSIZE,DATA,COMPR,TOTAL,STREAMS,MOUNTPOINT | View examples |
| Read zram memory stats | cat /sys/block/zram0/mm_stat | View examples |
| Configure a zram device | sudo zramctl /dev/zram0 --algorithm zstd --size 4G | View examples |
| Reset an unused zram device | sudo zramctl --reset /dev/zram0 | View examples |
| Read zswap state | cat /sys/module/zswap/parameters/enabled | View examples |
| Read cgroup memory events | cat \
/sys/fs/cgroup/system.slice/example.service/memory.events | View examples |
Swap is part of Linux virtual-memory policy, not proof that RAM is exhausted. zram stores compressed pages in RAM, while zswap is a compressed cache in front of a real swap device; enabling overlapping mechanisms without capacity analysis can waste CPU and memory. Diagnose pressure with workload, PSI, reclaim, and OOM evidence, and never disable active swap unless available memory and a rollback plan can absorb every resident page.
Step by step
Detailed examples
Start with available memory, not the free column
Linux uses idle RAM for reclaimable caches. MemAvailable estimates memory usable without swapping, while free alone can look alarming on a healthy host. Capture dirty/writeback, slab, page tables, huge pages, and cgroup limits before concluding that the machine needs more swap.
free --human --wide
grep -E '^(MemAvailable|SwapTotal|SwapFree|Dirty|Writeback|Slab|SReclaimable|PageTables|AnonHugePages):' /proc/meminfo
numastat 2>/dev/null
uptime Map every swap layer and its owner
Swap may be a partition, file, encrypted device, zram device, or distribution-managed systemd generator. Priority controls allocation preference. Compare live state with fstab and generator configuration before editing, and verify whether hibernation depends on a specific resume device and offset.
swapon --show --output=NAME,TYPE,SIZE,USED,PRIO
cat /proc/swaps
findmnt --fstab --types swap
systemctl list-units --type=swap --all Differentiate capacity, reclaim, and stall pressure
Nonzero swap use can be harmless cold-page placement. Sustained si/so, direct reclaim, elevated PSI some/full, I/O latency, and OOM events are stronger signals. The first vmstat row is an average since boot; use later samples. Correlate with a workload event rather than tuning from one snapshot.
vmstat 1 10
cat /proc/pressure/memory
cat /proc/pressure/io
sar -W 1 10 Attribute memory to processes and cgroups carefully
RSS double-counts shared pages across processes; VSZ is address space, not resident consumption. PSS from smaps is more proportional but collecting it across many processes can be expensive. Containers and services can hit cgroup memory.max while the host has memory available.
ps -eo pid,user,comm,rss,vsz --sort=-rss | head -20
systemd-cgtop --depth=2 --iterations=1
cat /sys/fs/cgroup/system.slice/example.service/memory.current
cat /sys/fs/cgroup/system.slice/example.service/memory.events Tune virtual-memory policy only from measured behavior
swappiness changes the balance between reclaiming anonymous and file-backed memory; it does not set a swap percentage. overcommit controls allocation promises and can break applications that reserve large address spaces. Kernel semantics evolve, so test the deployed version under realistic load and persist only after rollback validation.
sysctl vm.swappiness
sysctl vm.overcommit_memory vm.overcommit_ratio
sysctl vm.dirty_background_ratio vm.dirty_ratio
uname -r Enable and disable swap without exhausting memory
A new swap file needs correct filesystem support, non-sparse allocation, mode 0600, mkswap initialization, and encrypted backing if confidentiality matters. swapoff must relocate all live pages and can stall or invoke OOM. Estimate headroom, quiesce load, and disable one area at a time with console access.
swapon --show
free --bytes
# Creation and activation are destructive/privileged and are intentionally not run here.
# sudo mkswap /swapfile
# sudo swapon --priority 10 /swapfile
# sudo swapoff /swapfile Size zram for compressed data and metadata, not advertised capacity
zram disksize is the uncompressed logical capacity; physical RAM usage is dynamic and includes allocator overhead. Incompressible pages can approach or exceed expected ratios. Choose an available algorithm, impose mem_limit where justified, give zram higher swap priority, and swapoff before reset or data is lost.
zramctl --output NAME,ALGORITHM,DISKSIZE,DATA,COMPR,TOTAL,MOUNTPOINT
cat /sys/block/zram0/mm_stat
cat /sys/block/zram0/comp_algorithm
cat /sys/block/zram0/mem_limit Do not confuse zswap with zram swap
zswap is a compressed cache for pages headed to a real swap backend and evicts to that backend; zram is itself a compressed block device. Combining them can double-compress paths without benefit. Check boot parameters, runtime availability, pool size, compressor, and backing swap before enabling either design.
cat /sys/module/zswap/parameters/enabled
cat /sys/module/zswap/parameters/compressor
cat /sys/module/zswap/parameters/zpool
cat /sys/module/zswap/parameters/max_pool_percent
cat /proc/cmdline Treat OOM kills as evidence, not a random kernel failure
The global OOM killer and cgroup OOM can select different victims. Preserve the allocation context, chosen task, constraint, cgroup events, and preceding PSI. oom_score_adj affects victim selection and can make critical daemons safer only by shifting risk elsewhere; never globally disable OOM response without a bounded alternative.
journalctl -k -g 'oom|Out of memory|Killed process' --since today --no-pager
cat /sys/fs/cgroup/system.slice/example.service/memory.events
cat /proc/pressure/memory
systemctl show example.service -p MemoryCurrent -p MemoryMax -p OOMPolicy Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
- Linux Kernel Projectzram: Compressed RAM-Based Block Deviceskernel.org
- Linux Kernel Projectzswapkernel.org
- Linux Kernel ProjectPSI: Pressure Stall Informationkernel.org
- Linux Kernel ProjectOut of Memory Handlingkernel.org
- Linux Kernel ProjectControl Group v2 Memory Controllerkernel.org
- util-linux Projectswapon(8) Manual Pageman7.org
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



