fix: prevent ATM freeze on memory-constrained machines

- Add --disable-software-rasterizer to kill SwiftShader GPU process
- Restore MemoryMax=1G so systemd OOM-kills Electron before system locks
- Add 1GB swap file so kernel can page out under pressure
- Clean /tmp on boot to prevent stale build artifacts filling disk

Douro (1.8GB RAM, 15GB disk) was freezing from memory exhaustion with
no swap and no memory limit on the Electron process.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
This commit is contained in:
Patrick Mulligan 2026-03-02 13:04:29 -05:00
commit 8a3b40184b

View file

@ -141,7 +141,9 @@ in
Environment = "LD_LIBRARY_PATH=${pkgs.stdenv.cc.cc.lib}/lib";
# Electron needs --no-sandbox in the live/testing environment
# --enable-logging makes renderer console.log visible in journalctl
ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --enable-logging ${atm-app}";
ExecStart = lib.mkForce "${pkgs-unstable.electron}/bin/electron --no-sandbox --disable-gpu-sandbox --disable-gpu --disable-software-rasterizer --enable-logging ${atm-app}";
# Prevent Electron from consuming all RAM on memory-constrained ATMs
MemoryMax = lib.mkForce "1G";
# Disable all security hardening that conflicts with Electron
NoNewPrivileges = lib.mkForce false;
ProtectSystem = lib.mkForce false;
@ -179,6 +181,16 @@ in
};
};
# Swap file — Douro/Tejo have only 2GB RAM; without swap the system
# hard-freezes under memory pressure instead of gracefully OOM-killing.
swapDevices = [{
device = "/var/swapfile";
size = 1024; # MB
}];
# Clean /tmp on boot to prevent stale Nix build artifacts from filling disk
boot.tmp.cleanOnBoot = true;
# Allow SSH with password for initial setup on the live system
services.openssh.settings.PasswordAuthentication = lib.mkForce true;