Re: Path forward for Virtualized Swap?

From: Nhat Pham

Date: Fri Sep 25 2026 - 12:59:51 EST


On Fri, Sep 25, 2026 at 6:15 AM Kairui Song <ryncsn@xxxxxxxxx> wrote:
>
> On Tue, Sep 22, 2026 at 09:44:37PM +0100, Chris Li wrote:
> > It seems you are talking about a different topic: the vswap charging issue.
> > There is a golden rule that we should follow: don't break existing
> > users. At least with the same persistence, this rule should apply
> > universally.
> > In the swap tiers discussion, the UAPI was such a big deal that we
> > couldn't implement new UAPI. On the other hand here we argue for
> > liberally changing user-space visible behavior.
> >
> > BTW, I already shared that changing swap counter charging will break
> > our and others' existing deployments.
>
> Hi all

Hi Kairui,

Thank you for your thoughtful response! Lots of food for thought for me :)


>
> As I read the threads and try to clean up the requirement, just
> realized that I forgot and ignored something previously. I think I can
> share a few things here.
>
> I also see that Rik mentioning that:
>
> > It adds up anonymous, file, accounted slab, and
> > (after compression) zswap memory use for a cgroup,
> > and can be limited with all the usual cgroup
> > limits.
>
> That's very true, and that's also the one reason we can't
> migrate some workload to zswap easily (at least yet) :D
> See below.
>
> The discussion on this can be saw two years before (I know
> things are different for V2, so see below):
> https://lore.kernel.org/linux-mm/CAMgjq7AYA91f4g-bknUZOMg6hApTD-X5LqjcTBN2u-Lu8pjs+w@xxxxxxxxxxxxxx/
>
> An minor update for that, memsw in V1 serves pretty well (we also
> modded that part and would try push to upstream if doable), and as
> memsw is missing in V2, we can still workaround that using
> memory.current and memory.swap.current. BUt missing the offloaded
> part in memory.swap seems a problem.
>
> First a little bit off topic, I'll be really happy if we can make
> both compressed memory and swap as separate counters (I even once
> tried to implement a zpool accounting to account compressed memory
> in some unified way, but, well, zpool got killed before I post
> that :P), or at least a way to do that, e.g. something like nokmem.
> Due to our real usage:
>
> With compressed memory staying in a separate counter (which
> we manged to do that with ZRAM) the memory.current + memory.swap
> (or, memsw for cgv1) could be the exactly planned or sold size of a
> container, the scheduler (e.g. from k8s level) is fully aware of
> the packing rate of a host based on this reading. and can make
> scheduling decisions based on that. And can control it by
> adjusting the limit two combined.
>
> But with compression as a fixed part in memory.current, first the
> compression rate is totally uncontrollable, both the user and us
> will be fully *unaware* of how much memory they can *actually* use,
> that makes the planning really awkward. memory.max stops being the
> bound of what we planned or sold, anything compressed lets the raw
> footprint go past it by however much the compression ratio happens
> to give, so what we oversold is bounded by the workload's data and
> not by anything we configure. We can substract the zswap reading
> though with adaption, however it's hard to change the performance,
> OOM behavior or reclaim behavior:
>
> As you may considering compression is trading CPU time with memory,
> then two things here: the user could use more memory than we expected
> by burning the CPU. And, some users has a leaking application, the
> application could goes super slow or experiencing high CPU usage due
> to memory being compressed. They really just want to get OOM killed
> in time when ever the application leaks beyound a threshold (and
> yes that is a real and actually practical model for many applications).
> And, we can't simply disable memory compression for them.
>
> In many cases we just want a best effort compression to make space
> for low priority tasks, and do not want ordinary containers to use
> compression at the cost of lose of performance. While still has
> a fixed limit as usual. So simply disable memory compression is also
> not the plan, we do need compression to make place for other
> applications, we just don't want their real raw usage to exceed
> memory.max, and we can dynamically adjust memory.swap.max to
> control the oversold part, compression or physical.
>
> And this is not about residency, so memory.min/low don't help here:
> it's about overselling, and about not leaving a container thrashing in
> compress/decompress loops instead of being killed.
>
> And if the memory compression is really fully transparent (not
> doable by software), yeah, that's great as there is nothing to do
> with reclaim. But, for now, we have to go through page fault / folio
> allocation / map it again. So For example, if we already have
> memory.max == memory.current or under high pressure, then now
> doing any read from the compressed part would need to some
> require further eviction first to make place for the decompressed
> new data, this is not like any kind of "real" memory, something
> feels not right here.
>
> Another thing is that I think we has been assuming that physical
> swap is slower than compressed memory, which is not always true either.
> They all need to be read through page fault, the page fault could
> be the real blocker here rather than IO or de-compression.
>
> I also want to separate two things that I think got bundled together
> here: not requiring a physical slot behind a compressed entry, and not
> charging the raw size to the swap counter. The first one is great, yeah,
> and it's exactly the part we want, it's what makes compression usable
> without provisioning disk. The second one is a policy change, maybe it's
> not needed for the first stage, charging a cgroup for the
> memories it has offloaded doesn't require any slot to exist behind them.
> If someone wants to run memory compression with no disk at all,
> memory.swap.max defaults to max, so that still works fine, right?
>
> And I'm not saying "keep everything as it is forever": it is that the
> raw offloaded size (the entries, whatever the backing ends up being)
> should stays accounted and enforceable, and that anything which wants
> to describe physical storage gets its own counter.
>
> And I'm not asking the compression layer to have an opinion on how
> much compression or ratio is too much, just think we need a sane limit
> for container schedulers to sets on top of it.
>
> And "it's opt-in so nobody breaks" doesn't really hold for us: we do
> want generic compression solution, that's the whole point, so we would
> be turning the knob on and losing the counter at the same time. If we
> want one generic solution for memory compression, this is not opt-in.
>
> And if we check again, currently, with upstream kernel,
> using ZRAM, we have:
>
> memory.max: control the raw usage of application.
> memory.swap.current/max: controls the offloaded size/limit of a application.
> With (memory.max + memory.swap.max) <= planned usage (and this is memsw).
>
> We can keep the compressed part in memory.current of course, as already
> did in upstream with ZSWAP, and things can be further adapted, we
> still have:
>
> memory.max: control the real usage of application.
> memory.swap.current/max: controls the offloaded size/limit of a application.
> With (memory.max - <compress memory> + memory.swap.max) <= planned usage.
>
> Things are not too crazy, but if we lose the compressed raw size in
> memory.swap, things seem to be out of control: the raw footprint can go
> past memory.max by whatever the compression ratio happens to give, and
> nothing bounds it in raw terms, memory.zswap.max is in compressed bytes
> and zero-filled entries are not covered by anything. I can't see a very
> clean offloading model for us here. And we note, use use both kind
> of deployments, pure compression and hybrid writeback.


Thanks for explaining your perspective!

>
> Just for reference. Maybe a seperate counter, tiering, is a better idea
> than changing the swap counter?

I think memory.swap.* is never meant to be used as the "offloaded
footprint". It is incidentally correct, because of architectural
limitations: zswap/swap cache/zero page usage leads to real
consumption of real resources (physical swapfile).

But I understand your concerns regarding the missing observability of
the "logical" footprint (i.e the "offloaded size"), and how that would
hamper legitimate use cases.

How about a vswap counter that tracks the vswap usage? That would
provide the "logical" view. Userspace can then monitor and act based
on it.

I think that should cover both of the situations that you (and
Johannes in [1]) pointed out:

(1): With memory.current and this vswap counter, you can kill any
workloads that violate the level of overcommitting that you set out.

(2): For us, we can use memory.swap.* counter to provide isolation to
the physical swap space, which is a real, static resource that can be
hogged.

There will unfortunately be changes in userspace programs/scripts that
is required. It's unavoidable. We're adding a new behavior. It's the
whole point of this line of work. But I think as long as we provide a)
a way for userspace to index on (the param which tells you if vswap is
enabled or not) and b) enough userspace machinery to achieve most
common use cases, it should be good.

Let me know what you think. I look forward to hearing from you :)

[1]: https://lore.kernel.org/all/araWKyJ5MENBwXCL@xxxxxxxxxxx/