Why it shows up¶
Processes see the kernel's page cache rather than the disk directly. A write() completes as soon as data is in memory, and the pages become "dirty". A kernel writeback thread later flushes the dirty pages to disk. Older kernels ran this as pdflush/bdflush (later flush-<major>:<minor>). Current kernels run writeback in kworker threads named like kworker/u16:3+flush-8:0.
It is not a garbage collector. High activity from it simply means the system is pushing a lot of dirty data to disk, and it usually spends its time in I/O wait. That is normal after big writes, package installs, or backups.
When it is worth investigating¶
- Sustained heavy writeback with high
wain top or highawaitin iostat. - Long stalls in applications. The dirty-page thresholds are
vm.dirty_background_ratioandvm.dirty_ratio(or the_bytesvariants). When dirty pages hitdirty_ratio, writers are throttled synchronously.
grep -E 'Dirty|Writeback' /proc/meminfo
sysctl vm.dirty_background_ratio vm.dirty_ratio vm.dirty_expire_centisecs
Lowering the thresholds makes writeback smoother on systems with slow disks and lots of RAM. See also sync.