set ManagedOOMPreference=avoid to default systemd unit
Signed-off-by: June Strawberry <june@vern.cc>
This commit is contained in:
@@ -25,6 +25,8 @@ TTYRows=40
|
|||||||
AmbientCapabilities=
|
AmbientCapabilities=
|
||||||
CapabilityBoundingSet=
|
CapabilityBoundingSet=
|
||||||
|
|
||||||
|
ManagedOOMPreference=avoid
|
||||||
|
|
||||||
DevicePolicy=closed
|
DevicePolicy=closed
|
||||||
LockPersonality=yes
|
LockPersonality=yes
|
||||||
MemoryDenyWriteExecute=yes
|
MemoryDenyWriteExecute=yes
|
||||||
|
|||||||
2
debian/tuwunel.service
vendored
2
debian/tuwunel.service
vendored
@@ -18,6 +18,8 @@ ReadWritePaths=/var/lib/tuwunel /etc/tuwunel
|
|||||||
AmbientCapabilities=
|
AmbientCapabilities=
|
||||||
CapabilityBoundingSet=
|
CapabilityBoundingSet=
|
||||||
|
|
||||||
|
ManagedOOMPreference=avoid
|
||||||
|
|
||||||
DevicePolicy=closed
|
DevicePolicy=closed
|
||||||
LockPersonality=yes
|
LockPersonality=yes
|
||||||
MemoryDenyWriteExecute=yes
|
MemoryDenyWriteExecute=yes
|
||||||
|
|||||||
@@ -18,6 +18,8 @@ ReadWritePaths=/var/lib/tuwunel /etc/tuwunel
|
|||||||
AmbientCapabilities=
|
AmbientCapabilities=
|
||||||
CapabilityBoundingSet=
|
CapabilityBoundingSet=
|
||||||
|
|
||||||
|
ManagedOOMPreference=avoid
|
||||||
|
|
||||||
DevicePolicy=closed
|
DevicePolicy=closed
|
||||||
LockPersonality=yes
|
LockPersonality=yes
|
||||||
MemoryDenyWriteExecute=yes
|
MemoryDenyWriteExecute=yes
|
||||||
|
|||||||
Reference in New Issue
Block a user