---
tags:
- linux
- l1
- flashcard-deck
- linux-memory
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Linux Memory Management](../../../../library/portal/topics.md) | **Domain:** Linux
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
linux-memory/05c2ddd9dc5f	linux-memory	easy	caching, linux, swap	What is the difference between MemFree and MemAvailable in /proc/meminfo?	MemFree - The amount of unused physical RAM in your system\nMemAvailable - The amount of available memory for new workloads (without pushing system to use swap) based on MemFree, Active(file), Inactive(file), and SReclaimable.\n\nRemember: `free -h`: available = free + reclaimable cache. That's what matters.\n\nGotcha: High "used" is normal — Linux caches aggressively. Check "available."	projects/knowledge/interview/linux/315-what-is-the-difference-between-memfree-and-memavai.txt
linux-memory/06a849eefe6e	linux-memory	medium	linux, memory, processes	How to check how much free memory a system has? How to check memory consumption by each process?	You can use the commands `top` and `free`\n\nRemember: `free -h`: available = free + reclaimable cache. That's what matters.\n\nGotcha: High "used" is normal — Linux caches aggressively. Check "available."	projects/knowledge/interview/linux/222-how-to-check-how-much-free-memory-a-system-has-how.txt
linux-memory/07398ab471e3	linux-memory	medium	linux, memory, oom-killer, kernel	What does the OOM killer consider when selecting a process?	Memory usage, reclaimable memory, `oom_score_adj`, root status, and system impact.\n\nInspect via `/proc/<pid>/oom_score`.\n\nRemember: OOM = kernel kills processes when memory exhausted. `dmesg | grep oom` for victims.	projects/knowledge/interview/linux/538-oom-killer-criteria.txt
linux-memory/0a93ce7558d4	linux-memory	hard	caching, linux, swap, system	What causes high kswapd CPU usage?	kswapd is the kernel swap daemon that reclaims memory pages. High CPU means memory pressure:\n\n**Causes**:\n* Memory pressure - system needs to reclaim pages constantly\n* Excessive page reclamation - too much dirty memory\n* Memory leaks - constant allocation without release\n* Overcommit with active workloads\n* Poor swappiness tuning for workload type\n\n\n\nRemember: Swap = disk overflow. swappiness(0-100) controls aggressiveness. K8s disables.\n\nGotcha: Swap masks memory problems. Databases/K8s prefer `swapoff -a`.	projects/knowledge/interview/linux/461-what-causes-high-kswapd-cpu-usage.txt
linux-memory/0d258daab8fd	linux-memory	hard	linux, system	How mount a temporary ram partition?	```bash\n# -t - filesystem type\n# -o - mount options\nmount -t tmpfs tmpfs /mnt -o size=64M\n```\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/117-how-mount-a-temporary-ram-partition.txt
linux-memory/3def65adf104	linux-memory	hard	caching, linux, mmap, swap, system	What is vm.swappiness and how does it control memory management?	Controls the kernel's tendency to swap anonymous memory vs reclaim page cache.\n\n**Range**: 0-200 (0-100 traditionally, 200 with newer kernels)\n\n**What it does**:\n* Higher value: More willing to swap out inactive anonymous pages\n* Lower value: Prefers keeping anonymous memory in RAM, reclaims file cache instead\n\n**It's NOT a threshold** - common misconception.\n\nRemember: Swap = disk overflow. swappiness(0-100) controls aggressiveness. K8s disables.\n\nGotcha: Swap masks memory problems. Databases/K8s prefer `swapoff -a`.	projects/knowledge/interview/linux/460-explain-vm-swappiness.txt
linux-memory/5c6f632bae62	linux-memory	hard	linux, memory, debugging, troubleshooting, production	How do you find and mitigate subtle memory leaks in a long-running process without restarting it?	Use a combination of monitoring, analysis tools, and containment strategies.\n\nDetection and analysis:\n- `smem` - shows PSS (Proportional Set Size) per process\n- `pmap -x <pid>` - detailed memory map with RSS per mapping\n- `valgrind --tool=massif` - heap profiler (if you can attach)\n- Monitor `/proc/<pid>/status` - track VmRSS and VmHWM over time\n- `/proc/<pid>/smaps` - detailed breakdown of\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/517-memory-leak-debugging-production.txt
linux-memory/5d534e6d0996	linux-memory	hard	linux, memory, swap, performance, tuning	Explain a real scenario where lowering swappiness makes performance worse.	"Low swappiness causes page cache starvation and increased I/O amplification.\n\nScenario: Application server with hot working set of files\n- swappiness=1 means ""never swap, always drop page cache""\n- Hot files constantly re-read from disk instead of staying cached\n- Anonymous memory (rarely used) stays in RAM\n- Result: massive I/O amplification, slower performance\n\n"\n\nRemember: Swap = disk overflow. swappiness(0-100) controls aggressiveness. K8s disables.\n\nGotcha: Swap masks memory problems. Databases/K8s prefer `swapoff -a`.	projects/knowledge/interview/linux/502-low-swappiness-worse-performance.txt
linux-memory/6a2272f8d6ce	linux-memory	medium	caching, linux, system	Why does free not show all available memory as free?	Linux aggressively uses RAM for cache and buffers. Free memory is wasted memory.\n\n**Understanding the output**:\n```\n              total    used    free   shared  buff/cache   available\nMem:           16G     4G      1G      200M       11G         10G\n```\n\n\n\nRemember: `free -h`: available = free + reclaimable cache. That's what matters.\n\nGotcha: High "used" is normal — Linux caches aggressively. Check "available."	projects/knowledge/interview/linux/463-why-does-free-not-show-all-available-memory.txt
linux-memory/6e3ef998aa9f	linux-memory	medium	linux, debugging, gdb, strace	How to debug binaries?	Several tools for debugging binaries:\n\n1. gdb - GNU Debugger (breakpoints, stepping, variables)\n2. strace - System call tracer\n3. ltrace - Library call tracer\n4. objdump - Disassembler\n5. nm - Symbol listing\n6. ldd - Shared library dependencies\n7. valgrind - Memory debugging (leaks, invalid access)\n\nCompile with -g flag for debug symbols.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/333-how-to-debug-binaries.txt
linux-memory/7528ce4d5a7c	linux-memory	medium	linux, memory, oom, kernel	What is the Linux kernel OOM killer and when does it activate?	OOM (Out of Memory) Killer terminates processes when memory is exhausted.\n\nWhen triggered:\n- Physical RAM exhausted\n- Swap full or disabled\n- Memory allocation fails\n\nHow it selects victims:\n- oom_score for each process (0-1000)\n- Higher score = more likely to die\n\nRemember: OOM = kernel kills processes when memory exhausted. `dmesg | grep oom` for victims.	projects/knowledge/interview/linux/363-explain-kernel-oom.txt
linux-memory/8c1a205759f0	linux-memory	easy	linux, memory, kernel	What is the difference between paging and swapping?	Both involve moving data between RAM and disk, but at different granularities.\n\nPaging:\n- Moves individual pages (4KB typically)\n- Fine-grained memory management\n- Pages moved to swap as needed\n- Demand paging: load pages only when accessed\n- Modern systems primarily use paging\n\nSwapping (traditional):\n\nRemember: Swap = disk overflow. swappiness(0-100) controls aggressiveness. K8s disables.\n\nGotcha: Swap masks memory problems. Databases/K8s prefer `swapoff -a`.	projects/knowledge/interview/linux/420-what-is-the-difference-between-paging-and-swapping.txt
linux-memory/9b38d2a5ce7b	linux-memory	hard	linux, kernel, memory, oom-killer, troubleshooting	Explain how the Linux OOM killer selects which process to kill.	The OOM killer uses /proc/<pid>/oom_score and /proc/<pid>/oom_score_adj to determine victims.\n\nScore calculation factors:\n- Memory usage (primary factor) - RSS and swap consumption\n- Process priority and niceness\n- Heuristics: root processes get lower scores, child processes factor in\n- Process age (newer processes may score higher)\n\n\n\nRemember: OOM = kernel kills processes when memory exhausted. `dmesg | grep oom` for victims.	projects/knowledge/interview/linux/510-oom-killer-process-selection.txt
linux-memory/a38ab75cf452	linux-memory	easy	linux, memory, swap	What is a swap partition? What is it used for?	Swap is disk space used as virtual memory extension.\n\nPurpose:\n- Extends available memory beyond physical RAM\n- Holds inactive memory pages\n- Enables hibernation (swap must be >= RAM)\n- Prevents OOM when RAM is full\n\nTypes:\n- Swap partition: Dedicated disk partition\n\nRemember: Swap = disk overflow. swappiness(0-100) controls aggressiveness. K8s disables.\n\nGotcha: Swap masks memory problems. Databases/K8s prefer `swapoff -a`.	projects/knowledge/interview/linux/349-what-is-a-swap-partition-what-is-it-used-for.txt
linux-memory/aef3b5c0ef96	linux-memory	hard	linux, oom, system	How does the Linux OOM killer decide what to kill?	When memory is exhausted and can't be reclaimed, the OOM killer selects a victim:\n\n**oom_score calculation**:\n* Based on memory usage (RSS)\n* Adjusted by `oom_score_adj` (-1000 to 1000)\n* -1000 = never kill, 1000 = always prefer\n* Root processes get slight protection by default\n\n**Selection criteria**:\n* Highest score wins (gets killed)\n\nRemember: OOM = kernel kills processes when memory exhausted. `dmesg | grep oom` for victims.	projects/knowledge/interview/linux/459-how-does-the-oom-killer-decide-what-to-kill.txt
linux-memory/b16c0a522b5e	linux-memory	easy	linux, programming, memory	What is the return value of malloc?	malloc returns a pointer to allocated memory, or NULL on failure.\n\nReturns:\n- Success: Pointer to allocated memory (void*)\n- Failure: NULL pointer\n\nImportant notes:\n- Memory is uninitialized (garbage values)\n- Use calloc() for zero-initialized memory\n- Always check for NULL before use\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/406-what-is-the-return-value-of-malloc.txt
linux-memory/be692d4a62b7	linux-memory	easy	linux, filesystem, memory, tmpfs	What is tmpfs and when would you use a RAM-backed filesystem?	tmpfs is a RAM-based temporary filesystem.\n\nFeatures:\n- Stored in memory (and swap)\n- Very fast I/O\n- Contents lost on reboot\n- Size is flexible (grows/shrinks)\n\nCommon uses:\n- /tmp - Temporary files\n- /run - Runtime data\n- /dev/shm - Shared memory\n\nMount: mount -t tmpfs -o size=1G tmpfs /mnt/ramdisk\n\nBenefits:\n- Speed (no disk I/O)\n- Automatic cleanup on reboot\n- Reduces disk wear (SSDs)\n\nDifference from ramfs: tmpfs can use swap, has size limits.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/357-what-is-tmpfs.txt
linux-memory/cce62a7cd81f	linux-memory	hard	linux, memory, oom, kernel	Why does Linux sometimes prefer killing a large cache-heavy process over a memory hog?	"The OOM killer targets unreclaimable memory, not total memory usage.\n\nKey points:\n- Page cache is reclaimable - kernel can drop it under pressure\n- Anonymous memory (heap, stack) requires swap or process death\n- OOM scoring penalizes unreclaimable RSS, not total VSZ\n- A process with 10GB page cache but 100MB anon memory is ""safer"" than one with 2GB anon\n- ""Big process != bad process"" from O"\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/501-oom-kills-cache-heavy-process.txt
linux-memory/cd756b23af96	linux-memory	easy	linux, memory, oom, kernel	Explain what is OOM killer	OOM Killer terminates processes when system runs out of memory.\n\nWhen triggered:\n- Physical memory exhausted\n- Swap full or disabled\n- Cannot allocate requested memory\n\nHow it selects:\n- Calculates oom_score (0-1000) for each process\n- Higher score = more likely to die\n\nRemember: OOM = kernel kills processes when memory exhausted. `dmesg | grep oom` for victims.	projects/knowledge/interview/linux/421-explain-what-is-oom-killer.txt
linux-memory/e07e5cfd0ab9	linux-memory	easy	linux, system, virtual-memory	How to check memory stats and CPU stats?	You'd use `top/htop` for both. Using `free` and `vmstat` command we can display the physical and virtual memory statistics respectively. With the help of `sar` command we see the CPU utilization & other stats (but `sar` isn't even installed in most systems).\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/011-how-to-check-memory-stats-and-cpu-stats.txt
linux-memory/fb2eed67a674	linux-memory	medium	linux, memory, monitoring, performance, virtual-memory	Explain RSS vs VSZ vs PSS.	They describe different views of process memory usage and how shared pages are counted.\n- VSZ: total virtual address space, including mapped files, shared libs, and reserved but unused pages.\n- RSS: physical pages currently resident for the process, but shared pages are fully counted for each process.\n\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/linux/536-rss-vsz-pss-explained.txt
linux-memory/zad1e2f3a4b5	linux-memory	hard	linux,proc,meminfo,cpuinfo	How would you check total available memory and CPU count on a Linux system without installing any tools?	cat /proc/meminfo for memory (look at MemTotal, MemFree, MemAvailable) and cat /proc/cpuinfo or grep -c processor /proc/cpuinfo for CPU count. These files are always available.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	zines/bite.size.linux.cleaned.notes
linux-memory/89998e94f7ca	linux-memory	medium	miscellaneous, control-flow, memory, metrics	How do you identify and resolve performance bottlenecks in a data center?	Identifying and resolving performance bottlenecks in a data center involves a systematic approach: **Monitoring:* • Utilize monitoring tools to collect performance metrics, including CPU utilization, memory usage, disk I/O, and network traffic. **Analysis:* • Analyze collected data to identify patterns and anomalies. Look for spikes or consistent high utilization in specific resources. **Profiling:* • Use profiling tools to identify performance bottlenecks in software applications or specific server processes.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	
linux-memory/fc376b78cce8	linux-memory	medium	miscellaneous, control-flow, memory, networking	How would you diagnose a sudden increase in server resource utilization?	• Identify the Resource: • Determine which resource is experiencing a sudden increase (CPU, memory, disk, or network). • Check Resource Monitoring: • Use monitoring tools (such as Task Manager or Performance Monitor) to review real-time resource utilization. • Review Recent Changes: • Investigate recent changes in software, configurations, or updates that may be contributing to increased utilization. • Check for Malware: • Scan for malware or unauthorized processes that could be consuming resources.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	
linux-memory/28489c778952	linux-memory	hard	cyber-security, linux, memory-management	Rsync triggered Linux OOM killer on a single 50 GB file. How does the OOM killer decide which process to kill first? How to control this?	The OOM killer selects processes to kill based on their `oom_score` (viewable at `/proc/<pid>/oom_score`). Higher scores mean higher kill priority. It targets processes that free the most memory with the least system impact.\n\nTo control it:\n- Check a process score: `cat /proc/<pid>/oom_score`\n- Protect a process: `echo -17 > /proc/<pid>/oom_adj` (or set `oom_score_adj` to -1000)\n- Use cgroups to set `oom.priority` — 0 makes processes immune, higher values make them preferred targets\n- System-wide: `/proc/sys/vm/overcommit_memory` controls whether the kernel overcommits memory (default 0 = heuristic overcommit)	projects/knowledge/interview/cyber-security/008-rsync-triggered-linux-oom-killer-on-a-single-50-gb.txt
linux-memory/46b306322e13	linux-memory	hard	cyber-security, linux, profiling	An application encounters some performance issues. You should to find the code we have to optimize. How to profile app in Linux environment?	Key profiling tools on Linux:\n\n1. **top** (batch mode): `top -b -p $(pidof app)` — shows CPU, memory, threads over time\n2. **ps**: `ps --format pid,pcpu,cputime,etime,size,vsz,cmd -p $(pidof app)`\n3. **perf**: Record with `perf record -g -p $(pidof app) sleep 10`, analyze with `perf report --stdio` — shows per-function CPU breakdown and call chains\n4. **valgrind/callgrind**: `valgrind --tool=callgrind ./binary` then visualize with `kcachegrind`\n5. **pstack/lsstack**: Quick stack snapshots of a running process\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.	projects/knowledge/interview/cyber-security/001-an-application-encounters-some-performance-issues-.txt
linux-memory/15e9e8ef8335	linux-memory	medium	linux, arrays, control-flow, memory	What happens when you execute ls -l?	"* Shell reads the input using getline() which reads the input file stream and stores into a buffer as a string\n* The buffer is broken down into tokens and stored in an array this way: {""ls"", ""-l"", ""NULL""}\n* Shell checks if an expansion is required (in case of ls *.c)\n\n* Once the program in memory, its execution starts. First by calling readdir()\n\nNotes:\n\n* getline() originates in GNU C library and used to read lines from input stream and stores those lines in the buffer"	projects/knowledge/interview/linux/306-what-happens-when-you-execute-ls-l.txt
linux-memory/d1705df99a79	linux-memory	easy	linux, commands	What does the man command provide?	The manual page for a specific command.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.\n\nRemember: `man` sections: 1=commands, 2=syscalls, 3=library, 5=file formats, 8=admin. `man 5 passwd` shows the file format, not the command.\n\nExample: `man -k keyword` searches all man pages. `man 2 open` shows the open() system call documentation.	projects/knowledge/interview/linux/582-man-command.txt
linux-memory/ea2d84fc8b22	linux-memory	easy	linux, system	Explain the file content commands along with the description.	- `head`: to check the starting of a file.\n- `tail`: to check the ending of the file. It is the reverse of head command.\n- `cat`: used to view, create, concatenate the files.\n- `more`: used to display the text in the terminal window in pager form.\n- `less`: used to view the text in the backward direction and also provides single line movement.\n\nRemember: Linux memory: RAM→Cache→Swap. `free -h` overview. "available" is key metric.\n\nGotcha: "unused RAM is wasted RAM" — Linux caches aggressively. This is healthy behavior.\n\nRemember: `head -n 20` = first 20 lines. `tail -f` = follow live. `less` = paginate (search with /). `cat` = dump all.\n\nGotcha: `cat` on a huge file floods the terminal. Use `less` or `head` for large files.	projects/knowledge/interview/linux/018-explain-the-file-content-commands-along-with-the-d.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [Linux Memory Management](../../../../library/topics/linux-memory-management/index.md) (Topic Pack, L1) — Linux Memory Management
- [Runbook: OOM Killer Activated](../../../../library/runbooks/linux/oom-killer.md) (Runbook, L1) — Linux Memory Management

<!-- wiki:related:end -->
