Repository navigation
fix(desktop): exclude unrelated VPN addresses from Tailscale pairing - #15753
arthurkatcher wants to merge 1 commit into
Conversation
ApprovabilityVerdict: Approved at Macroscope's review found this PR approvable — This is a focused desktop bug fix that filters unrelated VPN addresses from existing Tailscale pairing discovery while preserving the existing cache, exposure gate, and MagicDNS behavior. The production change is localized and supported by targeted regression tests, with no new defaults, contracts, workflows, or infrastructure. You can add or adjust custom eligibility rules. Learn more. |
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (4)
Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 9 remain after this review. 📝 WalkthroughWalkthroughThe endpoint provider now reads full Tailscale status to derive the MagicDNS name and filter advertised IPv4 addresses. Desktop endpoint resolution passes its cached status to the provider. ChangesTailscale endpoint ownership
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested reviewers: Merge Risk: ⚪ Minimal · up to No actionable issue remains in the supplied review evidence; the change is mergeable after normal checks. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change narrows pairing address selection without adding a listener, changing access settings, or expanding privileges. No introduced security concern was established. Remaining uncertainty concerns concurrent refresh and interruption recovery of the shared status cache. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
6e87ff8 to
9b22501
Compare
Dismissing prior approval to re-evaluate 9b22501
Problem
With Proton VPN and Tailscale on the same host, desktop discovery labels Proton's
100.85.0.1interface as “Tailscale IP” and can put it in the pairing link. Phone pairing times out even though the real Tailscale address works. The provider currently treats membership in100.64.0.0/10as proof of Tailscale ownership.Closes #15750.
Change
Use the parsed Tailscale status already read by the desktop service to identify assigned IPv4 addresses. Retain the full status in the existing 60-second cache and share it between IP and MagicDNS discovery.
Keep native interface discovery working when the CLI is unavailable or its cached response predates a connection: recognize standard Tailscale adapter names and interfaces with Tailscale's IPv6 prefix. Advertise only qualifying IPv4 addresses that exist on local interfaces. This excludes the unrelated Proton interface while preserving renamed IPv4-only adapters when status identifies them.
The service and provider changes address the same endpoint-identification failure. Tests cover the Proton collision, absent assignments, unavailable/malformed/stale status, macOS and Windows adapter fixtures, renamed adapters, absent local addresses, and reuse of one cached status read.
Scope and approval
This is submitted under the guide's exception for a small, focused fix of an obvious bug: an unrelated VPN address is incorrectly labeled as Tailscale and generates an unusable pairing URL. It changes two desktop backend files with two associated test files. It adds no configuration, contracts, or new workflow. The linked issue establishes reproduction; no maintainer approval is claimed.
Related work: merged #9882 fixes LAN/Tailscale separation; closed #11920 proposed broader discovery changes. Frontend refresh and persistent endpoint preference changes have independent scope and are left for separate work.
Verification
Current base: main at
4ae976dbae39b3e80243b864a8b61da00f642dc4; head9b225017839cc5108e40f14ec22df5691412ebed. The rebase preserves upstream Effect import paths, test-helper names, and exposure-change serialization. Linux host: Ubuntu 24.04.4 LTS.vp test run apps/desktop/src/backend/tailscaleEndpointProvider.test.ts apps/desktop/src/backend/DesktopServerExposure.test.ts packages/tailscale/src/tailscale.test.ts: 36 passed on the rebased head (including the new upstream exposure-serialization test).4ee6bfd50ef4a089440d5c3662db2298da9cc50e, restoring only the two production files makes the two core Proton/cached-identity regressions fail with the extra100.85.0.1URL. Restoring this patch makes both pass.vp lintandvp fmt --checkon the four changed files: passed.vp run --filter @t3tools/desktop typecheck: passed, with one advisory in untouchedDesktopClerk.test.ts.git diff --check: passed.os.networkInterfaces()andtailscale status --json, using Node 24.13.1:The original pairing failure and successful manual address replacement were observed with an iPhone. The patched provider was verified against the live host inputs; a patched packaged Electron app was not run. macOS/Windows behavior is fixture-tested, not verified on live hosts.
Compatibility limit: a custom-named adapter with no Tailscale IPv6 address and no usable CLI status cannot be identified and is omitted. A successful status read supports that adapter. CLI timeout, cache duration, exposure gating, and HTTPS probing are preserved.
Model: GPT-6-Astra. Harness: Codex in T3 Code.