分页操作下虚拟地址与交换分区/后备存储地址的映射机制咨询
Great question—let’s break this down step by step, since virtual memory swapping is one of those core OS concepts that’s easy to gloss over but super important under the hood.
When a page is swapped out to a swap partition or backing storage (like a disk file), the mapping between virtual addresses and backing storage is dynamic, not static. It relies on a combination of per-process page table entries (PTEs) and global OS management structures to work.
1. What Happens When a Page is Swapped Out
You’re right that the PTE gets evicted from the TLB when a page is swapped out, but the PTE itself isn’t removed from the page table entirely. Instead:
- The PTE is marked as
invalid(thepresentbit is set to 0). - Reserved fields in the PTE are repurposed to store metadata about where the page lives in backing storage:
- For swap partitions: The PTE stores the swap area ID and the offset of the page within that swap area.
- For file-backed pages (like code from an executable): The PTE stores the file’s inode and the offset of the page within the file (since these pages can be reloaded directly from the original file instead of swap).
2. Mapping Mechanism: Dynamic, Not Static
Static mapping makes no sense here—OSes can’t predict which pages will be swapped out in advance, and the set of swapped pages changes constantly as processes run. Two common implementations are:
- Hash-based reverse mapping: The OS maintains a global hash table that uses a virtual page + process ID (or physical page, if cached) as the key, pointing to the backing storage location. This lets the kernel quickly look up if a page has been swapped out.
- PTE metadata storage: As mentioned earlier, the PTE itself carries the backing storage location. When a page fault occurs, the kernel reads this metadata directly from the PTE to trigger a page reload.
3. Where Mapping Information Lives
Beyond the PTEs, the OS maintains global structures to manage swap and backing storage:
- For swap partitions: A list of swap area structures that track total size, used pages, free page lists, and reference counts for each swapped page.
- For file-backed storage: The page cache (a kernel cache for disk files) links virtual pages to their corresponding file inodes and offsets, so the kernel can quickly find where to reload the page from.
4. Example C Structures (Linux Kernel Context)
Linux uses well-defined structures to manage this process. Here are simplified versions of the key ones:
a. Swapped Page Table Entry (PTE)
For x86 systems, the PTE repurposes bits to store swap metadata when a page is swapped out:
// Simplified x86 PTE for swapped-out pages typedef struct { unsigned int present : 1; // 0 = page is swapped out unsigned int write : 1; unsigned int user : 1; // ... other permission/state flags ... unsigned int swap_type : 5; // ID of the swap partition (max 32) unsigned int swap_offset: 20; // Offset of the page within the swap partition (in pages) } pte_t;
b. Swap Area Management
The kernel uses swap_info_struct to track each configured swap partition:
struct swap_info_struct { unsigned int flags; // Status (e.g., active/inactive) struct file *file; // File object representing the swap partition unsigned int pages; // Total number of pages in the swap area unsigned int inuse_pages; // Number of pages currently in use unsigned long *swap_map; // Reference count for each swapped page struct list_head list; // Links to other swap areas in a global list };
c. File-Backed Page Mapping
For pages loaded from disk files, the struct page (used to track physical pages in the kernel) links to the file’s metadata:
struct page { unsigned long flags; struct address_space *mapping; // Points to the file's address space pgoff_t index; // Offset of the page within the file // ... other physical page metadata ... };
5. Page Fault Handling Flow (Simplified)
When a process tries to access a swapped-out page:
- The CPU triggers a page fault, and the kernel takes over.
- The kernel checks the PTE for the virtual address and sees the
presentbit is 0. - It extracts the swap/file metadata from the PTE.
- The kernel reads the page from the swap partition or file into free physical memory.
- It updates the PTE: sets
presentto 1, writes the new physical page address, and clears the swap metadata. - The TLB is refreshed, and the process resumes execution.
内容的提问来源于stack exchange,提问作者techie11

