From 502d06bddaff42de8ec33e9af707aa0db61ec58f Mon Sep 17 00:00:00 2001 From: unkin-agent Date: Mon, 5 Oct 2026 13:46:50 +1100 Subject: [PATCH] Cap boot unit restarts so it fails open --- packaging/tomswall.service | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/packaging/tomswall.service b/packaging/tomswall.service index 61f1931..7d714da 100644 --- a/packaging/tomswall.service +++ b/packaging/tomswall.service @@ -6,6 +6,8 @@ Wants=network-pre.target Before=network-pre.target shutdown.target After=local-fs.target systemd-sysctl.service Conflicts=shutdown.target tomswall-agent.service +StartLimitIntervalSec=60 +StartLimitBurst=5 [Service] Type=oneshot @@ -14,7 +16,7 @@ Environment=TOMSWALL_CONFIG=/etc/tomswall/tomswall.yaml EnvironmentFile=-/etc/tomswall/tomswall.env ExecStart=/usr/sbin/tomswall apply -c ${TOMSWALL_CONFIG} ExecReload=/usr/sbin/tomswall apply -c ${TOMSWALL_CONFIG} -# Fails open: once restarts are exhausted, boot continues without the ruleset. +# Fails open: after StartLimitBurst failures within StartLimitIntervalSec, boot continues without the ruleset. Restart=on-failure RestartSec=5 # No ExecStop: stopping the unit leaves the ruleset in place (flush would open the firewall).