From 8a3b40184bcda95a43fa42ce89fd9f05690bcd34 Mon Sep 17 00:00:00 2001 From: Patrick Mulligan Date: Mon, 2 Mar 2026 13:04:29 -0500 Subject: [PATCH] fix: prevent ATM freeze on memory-constrained machines - Add --disable-software-rasterizer to kill SwiftShader GPU process - Restore MemoryMax=1G so systemd OOM-kills Electron before system locks - Add 1GB swap file so kernel can page out under pressure - Clean /tmp on boot to prevent stale build artifacts filling disk Douro (1.8GB RAM, 15GB disk) was freezing from memory exhaustion with no swap and no memory limit on the Electron process. Co-Authored-By: Claude Opus 4.6 --- deploy/nixos/live.nix | 14 +++++++++++++- 1 file changed, 13 insertions(+), 1 deletion(-) diff --git a/deploy/nixos/live.nix b/deploy/nixos/live.nix index 7b9ab99..630f32d 100644 --- a/deploy/nixos/live.nix +++ b/deploy/nixos/live.nix @@ -141,7 +141,9 @@ in Environment = "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib"; # Electron needs --no-sandbox in the live/testing environment # --enable-logging makes renderer console.log visible in journalctl - ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --enable-logging ${atm-app}"; + ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --disable-software-rasterizer --enable-logging ${atm-app}"; + # Prevent Electron from consuming all RAM on memory-constrained ATMs + MemoryMax = lib.mkForce "1G"; # Disable all security hardening that conflicts with Electron NoNewPrivileges = lib.mkForce false; ProtectSystem = lib.mkForce false; @@ -179,6 +181,16 @@ in }; }; + # Swap file — Douro/Tejo have only 2GB RAM; without swap the system + # hard-freezes under memory pressure instead of gracefully OOM-killing. + swapDevices = [{ + device = "/var/swapfile"; + size = 1024; # MB + }]; + + # Clean /tmp on boot to prevent stale Nix build artifacts from filling disk + boot.tmp.cleanOnBoot = true; + # Allow SSH with password for initial setup on the live system services.openssh.settings.PasswordAuthentication = lib.mkForce true;