Read /proc/zoneinfo Without Mistaking Counters for Capacity
You will finish with a safe way to inspect the Linux kernel's memory-zone report, identify the zones on a host, and compare current free pages with the zone watermarks. The report is diagnostic data: reading it changes no memory settings, services or processes.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about fifteen minutes. You need a shell and a Linux system with /proc mounted. The examples were checked against Linux man-pages 6.7, installed here as package version 6.7-2. The kernel that produces the report is independent of the man-pages package, so the exact zones, fields and values depend on the running kernel and hardware.
1. Confirm that the file is available
Read the file as an ordinary user. No elevated privilege is required:
$ test -r /proc/zoneinfo && echo 'readable'
readable
$ head -n 12 /proc/zoneinfo
Node 0, zone DMA
per-node stats
nr_inactive_anon ...
The final counter values are host-specific and can change while you are looking at them. The first lines establish the shape of the report: a node and zone header, followed by statistics. If the test fails, check whether procfs is mounted before trying sudo:
$ findmnt /proc
TARGET SOURCE FSTYPE OPTIONS
/proc proc proc ...
Your findmnt output may have different columns and mount options. If it prints nothing, ask the administrator to investigate the host's procfs setup. Do not mount filesystems or change boot configuration as part of this read-only check.
2. List the memory zones
First reduce the large report to its zone headers:
$ awk '/^Node [0-9]+, zone/ {print}' /proc/zoneinfo
Node 0, zone DMA
Node 0, zone DMA32
Node 0, zone Normal
Node 0, zone Movable
The output varies. A machine may have several NUMA nodes, and not every zone shown above will exist. Treat the pair of node number and zone name as the identity of a section. Do not compare a value from one zone with a value from another without keeping those identities attached.
Checkpoint: save a timestamped copy only if you need to compare later. This writes a file in the current directory, so choose a directory where you are happy to create it:
$ stamp=$(date +%Y%m%d-%H%M%S)
$ sed -n '1,240p' /proc/zoneinfo > "zoneinfo-$stamp.txt"
$ wc -l "zoneinfo-$stamp.txt"
<line-count> zoneinfo-<timestamp>.txt
The line count and timestamp are host-specific. Remove the snapshot with rm -- "zoneinfo-$stamp.txt" when you no longer need it. That is the only state-changing command in this guide, and it affects only the copy you created.
3. Read free pages and watermarks together
Within each zone, the pages section includes free, min, low, high, spanned, present and managed. Print those lines with their section headers:
$ awk '
/^Node [0-9]+, zone/ { zone=$0 }
/^ pages free/ || /^ (min|low|high|spanned|present|managed) / {
print zone " | " $0
}' /proc/zoneinfo
Node 0, zone DMA | pages free 2816
Node 0, zone DMA | min 7
Node 0, zone DMA | low 10
Node 0, zone DMA | high 13
This filter is deliberately small. It is useful for a quick comparison, but it does not calculate available system memory and it does not describe every allocator reserve. The values are page counts, not bytes. To convert one count, obtain the system page size and multiply; do not assume that a page is always 4096 bytes:
$ getconf PAGESIZE
4096
$ awk '/^ pages free/ {print $0}' /proc/zoneinfo | head -n 1
pages free 2816
For a rough byte calculation, multiply a selected numeric value by the output of getconf PAGESIZE. Keep the result labelled as a zone-level page count converted to bytes. It is not a promise that an application can allocate that amount.
4. Understand what a comparison can and cannot prove
A zone with free below low is a useful signal that reclaim or allocation pressure may be worth investigating. It is not, by itself, proof of an outage. The kernel can reclaim different kinds of pages, other zones can have headroom, and the report is a snapshot taken while counters are changing.
spanned describes the range covered by a zone, while present and managed help show how much of that range is present and under normal management. Do not turn a single field into a total-memory figure. Firmware reservations, holes, NUMA placement, movable memory and kernel configuration all affect the practical result.
The per-node counters near the start of each section include names such as nr_active_anon, nr_inactive_file, nr_dirty and nr_writeback. Use their names to form a focused hypothesis, then compare repeated captures or corroborate with tools such as free, vmstat and application metrics. Avoid declaring a leak from one large counter: many are cumulative or represent a category at the instant of the read.
5. Capture two readings before escalating
For a changing condition, collect two short readings rather than repeatedly scrolling through the whole file:
$ for pass in 1 2; do
date --iso-8601=seconds
awk '/^Node [0-9]+, zone/ { zone=$0 }
/^ pages free/ { print zone " | " $0 }
/^ (min|low|high) / { print zone " | " $0 }' /proc/zoneinfo
[ "$pass" -eq 1 ] && sleep 5
done
<timestamp>
Node 0, zone DMA | pages free 2816
Node 0, zone DMA | min 7
Node 0, zone DMA | low 10
Node 0, zone DMA | high 13
<timestamp>
Node 0, zone DMA | pages free 2790
Node 0, zone DMA | min 7
Node 0, zone DMA | low 10
Node 0, zone DMA | high 13
The timestamps and counter values will be different on your host. Use the command's output to spot direction and zone-specific pressure. If the condition is service-affecting, preserve the captures and continue with the system's normal incident process. Reading /proc/zoneinfo does not repair low memory and does not require restarting a service.
6. Avoid the common traps
- Do not treat
/proc/zoneinfoas a configuration file. It is a kernel-generated report, and writing to it is not the normal interface for changing memory policy. - Do not use
sudoby habit. Start with an unprivileged read. If access is denied, check the mount and the host's policy rather than copying the report into a privileged command. - Do not compare readings taken on different kernels or hardware as if the zone layout were identical. Record the host, kernel and timestamp with any diagnostic capture.
- Do not confuse free pages in one zone with free RAM for the whole machine. A workload may be constrained by placement or reclaim behaviour even when another zone has spare pages.
Done means
- You confirmed that
/proc/zoneinfois readable without elevated privileges. - You listed the node and zone sections present on the host.
- You examined
free,min,lowandhightogether. - You kept page counts distinct from bytes and from total available memory.
- You used repeated, timestamped readings before making a pressure claim.
- You changed no kernel setting, mount, service or process state.