From 3b4300d0337929ecfd32b2474843c00e8447df3e Mon Sep 17 00:00:00 2001 From: June Strawberry Date: Mon, 2 Feb 2026 18:17:21 -0500 Subject: [PATCH] set ManagedOOMPreference=avoid to default systemd unit Signed-off-by: June Strawberry --- arch/tuwunel.service | 2 ++ debian/tuwunel.service | 2 ++ rpm/tuwunel.service | 2 ++ 3 files changed, 6 insertions(+) diff --git a/arch/tuwunel.service b/arch/tuwunel.service index 334256fc..42f36ad3 100644 --- a/arch/tuwunel.service +++ b/arch/tuwunel.service @@ -25,6 +25,8 @@ TTYRows=40 AmbientCapabilities= CapabilityBoundingSet= +ManagedOOMPreference=avoid + DevicePolicy=closed LockPersonality=yes MemoryDenyWriteExecute=yes diff --git a/debian/tuwunel.service b/debian/tuwunel.service index bb2a3e63..bfd0c80e 100644 --- a/debian/tuwunel.service +++ b/debian/tuwunel.service @@ -18,6 +18,8 @@ ReadWritePaths=/var/lib/tuwunel /etc/tuwunel AmbientCapabilities= CapabilityBoundingSet= +ManagedOOMPreference=avoid + DevicePolicy=closed LockPersonality=yes MemoryDenyWriteExecute=yes diff --git a/rpm/tuwunel.service b/rpm/tuwunel.service index b37d202e..606ee39d 100644 --- a/rpm/tuwunel.service +++ b/rpm/tuwunel.service @@ -18,6 +18,8 @@ ReadWritePaths=/var/lib/tuwunel /etc/tuwunel AmbientCapabilities= CapabilityBoundingSet= +ManagedOOMPreference=avoid + DevicePolicy=closed LockPersonality=yes MemoryDenyWriteExecute=yes