fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(desktop): surface Tailscale Serve setup failures with admin link - #4552

Closed
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast
Closed

fix(desktop): surface Tailscale Serve setup failures with admin link#4552
GenKerensky wants to merge 4 commits into
pingdotgg:mainfrom
GenKerensky:fix/tailscale-serve-enable-error-toast

Conversation

@GenKerensky

@GenKerenskyGenKerensky commented Jul 26, 2026

Copy link
Copy Markdown

Summary

  • Preflight tailscale serve when enabling Tailscale HTTPS in the desktop app, so setup failures fail the Enable action instead of silently restarting with an unchecked toggle.
  • Extract safe CLI diagnostics (including the login.tailscale.com/f/serve configure URL) without leaking raw stderr secrets.
  • Show an error toast with the CLI-style message and an Open setup action that opens the admin URL.

Problem

Enable persisted tailscaleServeEnabled: true and relaunched the app, but the child server swallowed tailscale serve failures as warnings. The UI toggle is driven by HTTPS probe success, so it stayed off with no user-visible error. Locally this was:

Serve is not enabled on your tailnet.
To enable, visit:
https://login.tailscale.com/f/serve?node=...

Test plan

  • vp run --filter @t3tools/tailscale test
  • DesktopServerExposure unit tests (including Serve-not-enabled preflight failure)
  • typecheck for tailscale, desktop, server, web
  • Manual: with Serve disabled on the tailnet, open Settings → Connections → Tailscale HTTPS → Enable → confirm toast shows the error text and Open setup opens the Tailscale admin URL
  • Manual: after enabling Serve in the admin console, Enable succeeds, app relaunches, toggle becomes checked when HTTPS is reachable

Note

Surface Tailscale Serve setup failures with admin link and structured errors

  • When setTailscaleServeEnabled fails, a new DesktopTailscaleServeConfigureError is thrown with a user-readable reason and optional configureUrl extracted from sanitized CLI output (never raw stderr).
  • The failure toast in ConnectionsSettings.tsx now includes an action button to open the Tailscale Admin Serve URL in the browser when one is present in the error.
  • New utilities in tailscale.ts (extractTailscaleServeDiagnostics, formatTailscaleServeUserMessage, extractTailscaleServeConfigureUrl) parse and sanitize CLI errors into structured diagnostics and human-readable messages.
  • Behavioral Change: setTailscaleServeEnabled now performs a preflight ensureTailscaleServe check before persisting settings, and always returns requiresRelaunch=true on successful enable even when settings are unchanged.
📊 Macroscope summarized 4a0919b. 4 files reviewed, 0 issues evaluated, 0 issues filtered, 0 comments posted

🗂️ Filtered Issues

No issues evaluated.

@coderabbitai

coderabbitaiBot commented Jul 26, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on this repository. Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository UI

Review profile: CHILL

Plan: Pro Plus

Run ID: 1a257345-0db8-431f-be14-35b9b825b7d1

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actionsgithub-actionsBot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Jul 26, 2026
Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
Preflight `tailscale serve` when enabling HTTPS from the desktop app so
failures (e.g. Serve disabled on the tailnet) show an error toast with the
same configure URL the CLI prints, instead of silently restarting with an
unchecked toggle.
@GenKerensky
GenKerenskyforce-pushed the fix/tailscale-serve-enable-error-toast branch from b892ae3 to e470b80CompareJuly 26, 2026 04:00

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts

@macroscopeappmacroscopeappBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The Effect Service Conventions check found one issue in the new DesktopTailscaleServeConfigureError. Details inline.

Posted via Macroscope — Effect Service Conventions

Comment threadapps/desktop/src/backend/DesktopServerExposure.ts
After a successful Serve preflight, disable Serve when writing desktop
settings fails so HTTPS exposure is not left active while UI/settings
still report disabled.
Align DesktopTailscaleServeConfigureError with Effect service conventions:
preserve the underlying TailscaleCommandError as optional cause, store only
safe structural detail/configureUrl fields, and derive message from those
attributes instead of a free-form reason string.
preflightedServePort = servePort;
}

const result = yield* desktopSettings

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟠 Highbackend/DesktopServerExposure.ts:594

When enabling Tailscale Serve, the rollback uses Effect.tapError, which only fires on typed errors. If desktopSettings.setTailscaleServe is interrupted or throws a defect after ensureTailscaleServe has already opened the HTTPS mapping, the rollback to disableTailscaleServe never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using Effect.ensuring or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/backend/DesktopServerExposure.ts around line 594:
When enabling Tailscale Serve, the rollback uses `Effect.tapError`, which only fires on typed errors. If `desktopSettings.setTailscaleServe` is interrupted or throws a defect after `ensureTailscaleServe` has already opened the HTTPS mapping, the rollback to `disableTailscaleServe` never runs — leaving Serve active while the UI and settings still show it as disabled. Consider using `Effect.ensuring` or an acquire-release pattern so the cleanup executes on all non-success exits, not just typed persistence errors.

Electron's process.execPath inside an AppImage points at the temporary
mount, which is unmounted on exit. Use the APPIMAGE env path so restart
actually brings the app back up.
if (appImagePath) {
return {
execPath: appImagePath,
args: [],

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Mediumapp/resolveDesktopRelaunchOptions.ts:23

The AppImage branch returns args: [], dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve argv.slice(1) in both branches, since switching execPath to $APPIMAGE doesn't require discarding args.

🤖 Copy this AI Prompt to have your agent fix this:
In file @apps/desktop/src/app/resolveDesktopRelaunchOptions.ts around line 23:
The AppImage branch returns `args: []`, dropping all command-line arguments. When the app is launched with a meaningful argument (e.g. a file path or runtime switch) and then relaunches, the relaunched instance starts with no arguments and skips the requested startup behavior. The fix is to preserve `argv.slice(1)` in both branches, since switching `execPath` to `$APPIMAGE` doesn't require discarding args.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L100-499 changed lines (additions + deletions).vouch:unvouchedPR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@GenKerensky