Skip to content

Archive

Memory Management

23 articles
Artificial Intelligence 24 Sep 2026 5 min read

PagedAttention Decouples Logical KV Sequences from Physical Cache Blocks

Autoregressive serving keeps a growing key-value state for every active sequence. If that state must occupy one contiguous physical region sized for a request, allocation becomes coupled to uncertain sequence length: reserving too much wastes capacity, while extending or relocating a growing region complicates memory management. PagedAttention changes that allocation boundary. A sequence is represented as logical KV blocks, while its physical blocks may reside at unrelated locations in the cache pool.

Cybersecurity 19 Sep 2026 6 min read

userfaultfd Write Protection Moves Memory Writes Behind a User-Space Fault Boundary

A thread can hold a writable virtual memory mapping and still block when it attempts to modify a particular page. Linux userfaultfd write-protect mode lets user space register a memory range, apply write protection to pages in that range, and receive a page-fault event when a protected page is written. The VMA can remain logically writable while page-table state creates a narrower interception boundary. This mechanism is not a general authorization system. It is a memory-fault control interface. Its security relevance comes from the placement of the decision point: a write can be suspended before the protected page changes, allowing a separate handler to record state, coordinate migration, preserve a snapshot boundary, or reject progress by leaving the fault unresolved.

Linux 19 Sep 2026 5 min read

userfaultfd Moves Selected Page-Fault Resolution into User Space

A memory access normally enters the kernel page-fault path and completes without an application choosing the page contents at that instant. Linux userfaultfd changes that boundary for registered virtual address ranges: selected faults become events on a file descriptor, and a user-space manager can supply or activate the page before the faulting thread continues. The mechanism does not replace the process page tables with a user-space data structure. The kernel still owns page-table state and performs the final mapping operation. User space gains control over specific fault classes and the timing of their resolution.

Tech 19 Sep 2026 6 min read

TLB Shootdowns Extend Page-Table Changes Across CPUs

TLB Shootdowns Extend Page-Table Changes Across CPUs Changing a page-table entry in memory does not by itself retire every translation derived from that entry. A CPU that previously used the mapping can retain it in a translation lookaside buffer, or TLB. On a multiprocessor system, other CPUs may hold their own cached copies, so a mapping change can require coordination beyond the CPU that modified the page table. Linux exposes this distinction through its TLB-flush interfaces. After page-table state changes, architecture code must make the affected translations unusable on every relevant CPU before software relies on the new mapping or releases memory that the old mapping could reach.

Tech 19 Sep 2026 7 min read

TLB Shootdowns Coordinate Page-Table Changes Across CPUs

A page-table entry can change in memory while another CPU still holds the old address translation in its translation lookaside buffer (TLB). Updating the page table alone therefore does not necessarily make the new mapping effective on every processor that has executed the affected address space. Operating systems close that gap with TLB invalidation. When a mapping change can make a cached translation unsafe, processors that may retain the translation must invalidate it before the kernel treats the change as globally complete. On a multiprocessor system, coordinating those remote invalidations is commonly called a TLB shootdown.

Tech 19 Sep 2026 5 min read

PCIe ATS Moves Address Translation Caching Into the Device

PCIe ATS Moves Address Translation Caching Into the Device An IOMMU can translate DMA addresses on behalf of a device, but that arrangement puts translation machinery in the path of device memory traffic. PCIe Address Translation Services (ATS) adds another option: a capable device can request a translation and retain the result in its own translation cache. Later transactions can carry the translated address instead of requiring the same translation work at the IOMMU for every access.

Linux 19 Sep 2026 6 min read

PAGEMAP_SCAN Batches Page-Table State into Address Ranges

A large virtual address range may contain only a small number of page-state transitions. Reading one pagemap entry for every virtual page exposes that state at page granularity, but it also makes user space inspect a long sequence of entries. Linux PAGEMAP_SCAN moves the filtering into the kernel and reports matching spans as struct page_region records. The interface is an ioctl() on /proc/PID/pagemap. A request supplies an address interval, category predicates, a return mask, and an output vector. The kernel walks page tables and emits contiguous regions whose selected page properties match the request. This changes the shape of page-table inspection from a stream of per-page values into a filtered range query.

Tech 19 Sep 2026 6 min read

IOMMU IOTLB Invalidation Controls When DMA Remapping Takes Effect

IOMMU IOTLB Invalidation Controls When DMA Remapping Takes Effect Changing an IOMMU page-table entry does not necessarily change the translation used by the next DMA request. An IOMMU can cache address translations in an I/O translation lookaside buffer, commonly called an IOTLB. Software must invalidate affected cached state when a mapping is removed or replaced, then observe the invalidation semantics required by that IOMMU before treating the old translation as retired.

Linux 18 Sep 2026 5 min read

userfaultfd Turns Page Faults into Userspace Events

A thread can fault on a virtual address and remain blocked while another userspace thread or process decides what page state should make that access continue. userfaultfd provides this boundary by turning selected page faults into messages on a file descriptor and pairing those messages with ioctls that resolve the fault. The mechanism does not replace the kernel page-fault machinery. It inserts userspace control at registered ranges and fault classes, while the kernel still owns page tables, fault blocking, and the transition that makes the page usable again.

Linux 18 Sep 2026 4 min read

process_madvise Applies Memory Reclaim Advice Across Process Boundaries

process_madvise() can make one Linux process request memory-management action for virtual-address ranges owned by another process. The target is identified by a pidfd, while an iovec array names the target ranges. This separates memory-policy decisions from the process whose mappings receive the advice. The interface is useful for controllers that already have external knowledge about workload state. A runtime manager can mark inactive memory cold or request page reclamation without injecting code into the managed process. That capability is bounded by permission checks, supported advice values, and partial-progress semantics.

Linux 18 Sep 2026 5 min read

mseal Locks Memory Mapping Layout and Permissions

A process can establish a memory mapping with the intended address, size, and protection bits, then later alter that mapping with operations such as munmap(), mprotect(), or mremap(). Linux mseal() adds a one-way state transition: selected virtual memory areas can be sealed so a class of later mapping modifications is rejected by the kernel. The mechanism protects mapping structure rather than the bytes stored in the mapping. A writable sealed mapping remains writable through ordinary stores. Sealing instead constrains operations that could remove the mapping, relocate it, replace it, or change attributes covered by the sealing rules.

Software Engineering 18 Sep 2026 4 min read

Linux memfd Seals Turn Mutable Memory Files into Enforced State Transitions

A file created by memfd_create() can begin as mutable storage and later acquire kernel-enforced restrictions that apply to the underlying file rather than to one descriptor. With MFD_ALLOW_SEALING, a process can add seals through fcntl(F_ADD_SEALS) and make selected mutations unavailable to every holder of that file. This creates a state transition that ordinary descriptor permissions do not express. A producer can populate bytes, fix the file’s size, and then publish the descriptor with restrictions that remain attached even after the descriptor crosses a process boundary.

Software Engineering 18 Sep 2026 6 min read

Linux memfd Seals Convert Mutable Anonymous Files into Restricted Capabilities

A file descriptor returned by memfd_create() can begin as a writable, resizable anonymous file and later become an object whose permitted mutation operations have been permanently reduced. Linux implements that transition with file seals. The mechanism is attached to the underlying file rather than to one descriptor, so passing a duplicate descriptor across a process boundary does not create an independent sealing state. This property makes sealing more than a convenience around temporary storage. It changes the authority carried by every descriptor that refers to the same memfd object. The transition is monotonic: seals can be added, but they cannot be removed.

Cybersecurity 17 Sep 2026 5 min read

Userfaultfd Moves Page-Fault Resolution Into Userspace

Userfaultfd Moves Page-Fault Resolution Into Userspace A thread touches a registered virtual-memory page and stops before the access completes. Instead of resolving the fault entirely inside the kernel, Linux can report the event through a userfaultfd and let another userspace component decide when and with what content execution may continue. That design supports live migration, post-copy memory transfer, checkpointing, and related memory-management systems, but it also places a concurrency-sensitive decision point outside the faulting thread.

Software Engineering 17 Sep 2026 6 min read

Linux memfd Seals Turn Mutable File State Into a Restricted Contract

Linux memfd Seals Turn Mutable File State Into a Restricted Contract A file returned by memfd_create() begins as mutable file state backed by memory-oriented storage, but Linux can progressively remove mutation operations from that file. When creation uses MFD_ALLOW_SEALING, fcntl() with F_ADD_SEALS can prohibit shrinking, growth, writes, future writes, or further changes to the seal set. The resulting restrictions belong to the inode, not to one descriptor, so passing another descriptor for the same object does not restore operations that a seal removed.

Software Engineering 17 Sep 2026 7 min read

Linux memfd Seals Turn Mutable Bytes Into a Kernel-Enforced Contract

A memfd can begin as a writable anonymous file and later reject whole classes of mutation through kernel-enforced seals. The transition is attached to the inode, not to one descriptor, so a process cannot preserve an unrestricted duplicate descriptor and use it to bypass a seal added through another reference. This makes sealing materially different from handing another component a descriptor opened with narrower access. Descriptor access mode constrains one open file description. A seal changes which operations the kernel permits against the file itself, including operations attempted through other descriptors that refer to the same inode.

Python 04 Sep 2026 8 min read

Use Slotted Dataclasses When Object Shape Is Fixed in Python

Python dataclasses reduce boilerplate for record-like classes, but their instances are still ordinary Python objects by default. Declared fields normally live in an instance dictionary, and new attributes can be attached later. That flexibility is useful until the model is supposed to have a fixed shape. Coordinates, parsed records, configuration snapshots, protocol messages, and other compact value objects often have a known set of fields. When many such objects exist, keeping dynamic per-instance attribute storage may also be unnecessary.

Linux 04 Sep 2026 13 min read

Understand Memory-Mapped Files on Linux with mmap

Reading a file usually means calling read() and copying bytes into a buffer that your program manages. That model is explicit and works well for most file I/O. Linux offers another model with mmap(): map a file region into the process’s virtual address space, then access the file through ordinary memory loads and stores. That can simplify workloads such as random access into large files, shared file-backed state, indexes, and binary formats whose access pattern naturally looks like “read bytes at offset N.” It can also avoid an application-managed read buffer for those accesses.

Go 04 Sep 2026 9 min read

Understand Escape Analysis and Heap Allocations in Go

A Go program can create many values without you choosing whether each value lives on a goroutine stack or in heap memory. The compiler usually makes that decision for you. This becomes important when a hot path allocates more than expected. A small helper function may look harmless, yet a value it creates can outlive the function call and require heap storage. More heap allocation can mean more work for the garbage collector, but changing code blindly to avoid the heap can make a program harder to understand without producing a measurable benefit.

Python 03 Sep 2026 11 min read

Use Weak References for Non-Owning Object Relationships in Python

Most Python code should use ordinary references. If one object stores another object in an attribute, list, or dictionary, that reference normally means the stored object should remain available for as long as the owner needs it. Some relationships are different. A cache may want to reuse an object only while another part of the program already owns it. A registry may want to discover live objects without extending their lifetime. An observer table may want to remember listeners without becoming the reason those listeners can never be collected.

Go 03 Sep 2026 11 min read

Use sync.Pool for Temporary Object Reuse in Go

Repeatedly allocating short-lived helper objects can become expensive in a hot path. A formatter may create temporary buffers for every request, an encoder may allocate scratch space for every record, or a parser may repeatedly construct helper objects that are discarded immediately after use. Go’s sync.Pool can reuse some of those temporary objects across independent operations. That can reduce allocation work and garbage-collector pressure when the same kind of object is created frequently under load.

Python 02 Sep 2026 8 min read

Weak References in Python: Caches, Object Lifetimes, and Cleanup

A normal Python reference keeps an object alive. That is usually exactly what you want: if a dictionary contains an object, the object should remain available while the dictionary needs it. Some infrastructure has a different requirement. A cache, registry, or metadata table may want to refer to an object without becoming the reason that object stays alive forever. Python’s weakref module provides references and containers for that ownership model.

Python 02 Sep 2026 9 min read

Python memoryview: Zero-Copy Access to Binary Buffers

Binary-processing code often needs only a small region of a larger byte buffer. A normal bytes or bytearray slice is convenient, but it creates a new object containing copied data. When buffers are large or slicing happens repeatedly on a hot path, those copies can become unnecessary allocation and memory traffic. Python’s memoryview provides a different model. It exposes data from an object that supports the buffer protocol and lets Python code work with that data without first copying it into a new bytes object.