[BUG/RFC] mm/madvise: MADV_WILLNEED skips swapped file-backed COW pages

From: Mike Kaplinskiy

Date: Mon Aug 31 2026 - 16:12:58 EST


Hi,

I'm seeing a strange behavior when using MADV_WILLNEED to schedule
swap page-in. It seems MADV_WILLNEED does not schedule swap reads for
swapped-out COW pages in an ordinary file-backed MAP_PRIVATE mapping.

I reproduced this on Linux 7.0.14 on aarch64, but I think this code
hasn't changed in a while. mm/madvise.c:madvise_willneed walks swap
PTEs only when vma->vm_file is NULL, and sends other file-backed
mappings to vfs_fadvise(POSIX_FADV_WILLNEED). This skips the case of
MAP_PRIVATE mappings with changes, which frequently happens for
libraries/binaries with relocations and/or writable globals.

The code is at the top of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/mm/madvise.c#n282
.

Minimal reproducer attached. Would there be interest in changing this
path to prefetch private copies in addition to the readahead?

Thanks,
Mike
#define _GNU_SOURCE
#include <assert.h>
#include <fcntl.h>
#include <stdio.h>
#include <stdlib.h>
#include <string.h>
#include <sys/mman.h>
#include <unistd.h>

#define SIZE (64UL << 20)

static size_t swap_kib(void *mapping)
{
FILE *f = fopen("/proc/self/smaps", "r");
char line[256], perms[5];
unsigned long start, end, value = 0;
int ours = 0;

assert(f);
while (fgets(line, sizeof(line), f)) {
if (sscanf(line, "%lx-%lx %4s", &start, &end, perms) == 3)
ours = start == (unsigned long)mapping;
else if (ours && sscanf(line, "Swap: %lu kB", &value) == 1)
break;
}
fclose(f);
return value;
}

static unsigned long pswpin(void)
{
FILE *f = fopen("/proc/vmstat", "r");
char name[32];
unsigned long value = 0;

assert(f);
while (fscanf(f, "%31s %lu", name, &value) == 2)
if (!strcmp(name, "pswpin"))
break;
fclose(f);
return value;
}

int main(void)
{
char path[] = "/tmp/madvise-cow-XXXXXX";
int fd = mkstemp(path);
char *p;
unsigned long before;
volatile unsigned long sum = 0;

assert(fd >= 0 && !ftruncate(fd, SIZE));
p = mmap(NULL, SIZE, PROT_READ | PROT_WRITE, MAP_PRIVATE, fd, 0);
assert(p != MAP_FAILED);
unlink(path);

for (size_t i = 0; i < SIZE; i += getpagesize())
p[i] = i / getpagesize() + 1; /* create private COW pages */
assert(!madvise(p, SIZE, MADV_PAGEOUT));
usleep(500000);
printf("after PAGEOUT: Swap=%zu kB\n", swap_kib(p));

before = pswpin();
assert(!madvise(p, SIZE, MADV_WILLNEED));
sleep(2); /* WILLNEED is asynchronous */
printf("after WILLNEED: Swap=%zu kB, pswpin=+%lu\n",
swap_kib(p), pswpin() - before);

before = pswpin();
for (size_t i = 0; i < SIZE; i += getpagesize())
sum += p[i];
printf("after touch: pswpin=+%lu (sum=%lu)\n",
pswpin() - before, sum);
}