Linux Operations

Linux OOM Killer Debugging Guide

Investigate Linux out-of-memory kills with kernel evidence, cgroup limits, working-set growth, swap behavior and application allocation signals. Last updated September 28, 2026.

Investigate Linux out-of-memory kills with kernel evidence, cgroup limits, working-set growth, swap behavior and application allocation signals. This reference is written for developers who need practical validation behavior, reviewable rules and safe examples rather than copied snippets with no explanation.

Recommended workflow

StepWhy it matters
Prove the killUse kernel messages and exit status to distinguish OOM from application termination.
Identify the boundaryCheck host memory, container cgroup limits and systemd MemoryMax separately.
Measure the working setCompare resident memory, cache, anonymous pages and growth over time.
Connect to application behaviorCorrelate deploys, load, queues and allocation profiles with the pressure window.

Starter snippet

journalctl -k -b | grep -Ei 'out of memory|killed process|oom'

Review checks

Common mistakes

Validation should help users correct input while protecting systems from bad data. Keep syntax checks, product policy, security review and deliverability checks separate.

Related Formalint references

Continue with Docker Container Logs Guide, Java Memory Debugging Guide, Prometheus Alert Rule Debugging.