fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

fix(dev): share dev servers on the loopback Vite actually binds - #9324

Merged
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target
Sep 3, 2026
Merged

fix(dev): share dev servers on the loopback Vite actually binds#9324
juliusmarminge merged 1 commit into
mainfrom
fix/dev-share-loopback-target

Conversation

@juliusmarminge

@juliusmarmingejuliusmarminge commented Sep 3, 2026

Copy link
Copy Markdown
Member

Problem

vp run dev --share registers a tailscale serve rule that proxies https://<node>.ts.net:<webPort> to http://127.0.0.1:<webPort>. But Vite is configured with server.host: "localhost", and on Node 17+ localhost resolves to ::1 first (verbatim DNS order), so Vite binds only [::1]:<webPort>. Nothing listens on the IPv4 loopback, and the tailnet URL returns a 502 from Tailscale.

Reproduced on macOS with Node 24: lsof -iTCP:6561 -sTCP:LISTEN showed only [::1]:6561; curl http://127.0.0.1:6561/ was refused while curl http://[::1]:6561/ returned 200.

A secondary symptom you may notice while sharing: the dev runner logs "Port 6561 is in use on a wildcard address, but localhost:6561 is available". That wildcard holder is Tailscale's own serve listener on the tailnet IP, so the warning is misleading but harmless. Not addressed here.

Fix

scripts/lib/dev-share.ts now passes localHost: "localhost" to ensureTailscaleServe, so the Tailscale proxy resolves the same name Vite bound. A literal [::1] target is not an option: Tailscale rejects that form with a 500.

The @t3tools/tailscale default of 127.0.0.1 is unchanged. The server's own --tailscale-serve path passes 127.0.0.1 explicitly and binds it explicitly, and t3 pair --tailscale resolves its target from the recorded dev URL, so neither is affected.

Verification

  • Manual repro before the change: 502 on the tailnet URL; re-running tailscale serve --bg --https=6561 http://localhost:6561 by hand fixed it immediately, which is exactly what this change makes the runner do.
  • vp test run scripts/lib/dev-share.test.ts: 8 passed, including a new test asserting the serve call targets http://localhost:<port>.
  • npx tsgo -p scripts/tsconfig.json --noEmit: clean.
  • vp lint --report-unused-disable-directives scripts/lib/dev-share.ts scripts/lib/dev-share.test.ts: clean.

Claude Fable 5 via Claude Code.

🤖 Generated with Claude Code


Note

Low Risk
Narrow change to dev-share Tailscale proxy targeting; server --tailscale-serve and other explicit 127.0.0.1 paths are unchanged.

Overview
vp run dev --share was registering Tailscale to forward to http://127.0.0.1:<port> while Vite listens on localhost, which on Node 17+ often resolves to IPv6 (::1) only—so the tailnet URL returned 502.

shareDevServer now passes localHost: "localhost" into ensureTailscaleServe so the proxy target matches how Vite binds. Tests record spawned tailscale argv and assert the serve invocation uses http://localhost:<webPort> instead of 127.0.0.1.

Reviewed by Cursor Bugbot for commit 9a68fea. Bugbot is set up for automated code reviews on this repo. Configure here.

Note

Fix shareDevServer to proxy through localhost instead of 127.0.0.1

Updates the Tailscale serve command in dev-share.ts to pass localhost as the local host while keeping the requested web port. The returned tailnet HTTPS URL and all status/cleanup logic remain unchanged.

  • Extends the spawner test helper in dev-share.test.ts to record spawned command arguments, and adds a test asserting the serve command targets localhost on the requested port.

Macroscope summarized 9a68fea.

`vp run dev --share` registered a `tailscale serve` rule targeting
`http://127.0.0.1:<webPort>`, but Vite binds `localhost`, which Node 17+
resolves to `::1` first, so only the IPv6 loopback is listening and the
tailnet URL returned a 502.
Pass `localHost: "localhost"` from the dev-share path so the tailscale
proxy resolves the same name Vite bound. The server's own
`--tailscale-serve` path is untouched: it binds 127.0.0.1 explicitly.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@github-actionsgithub-actionsBot added vouch:trusted PR author is trusted by repo permissions or the VOUCHED list. size:S 10-29 changed lines (additions + deletions). labels Sep 3, 2026
@github-actions

Copy link
Copy Markdown
Contributor

Thread transfer impact

✅ Thread transfer remains within every enforced ceiling.

ProviderMetricMain baselineThis PRImpactPR ceiling
CodexTotal thread wire13.3 KiB13.4 KiB+156 B (+1.1%)15.1 KiB
CodexThread snapshot wire6.9 KiB6.9 KiB+4 B (+0.1%)7.3 KiB
CodexLive turn WebSocket wire6.4 KiB6.5 KiB+152 B (+2.3%)7.8 KiB
CodexLive turn WebSocket decoded55.6 KiB57.0 KiB+1.4 KiB (+2.6%)66.4 KiB
CodexLive turn messages10100 (0.0%)21
ClaudeTotal thread wire13.3 KiB13.3 KiB−16 B (−0.1%)15.1 KiB
ClaudeThread snapshot wire6.9 KiB6.9 KiB−3 B (−0.0%)7.3 KiB
ClaudeLive turn WebSocket wire6.4 KiB6.4 KiB−13 B (−0.2%)7.8 KiB
ClaudeLive turn WebSocket decoded56.4 KiB56.4 KiB0 B (0.0%)66.4 KiB
ClaudeLive turn messages10100 (0.0%)21

Baseline: b9b1b8f · PR result: 9a68fea · Source CI: success

Scenario and decoded snapshot size

10 historical turns, 5 command tools per turn, 878.9 KiB retained MCP result per historical turn, and a 1.05 MiB retained result in the measured turn.

  • Codex decoded thread snapshot: 109.4 KiB
  • Claude decoded thread snapshot: 110.1 KiB

Updated in place by a trusted workflow. PR artifacts are strictly validated and never executed.

@macroscopeapp

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 9a68fea

Macroscope's review found this PR approvable — This is a narrowly scoped, dev-only fix that makes the existing opt-in sharing command target the hostname Vite already binds, with unchanged ports, cleanup, and URL behavior. The added test directly verifies the generated Tailscale command, and no production or product defaults are changed.

You can add or adjust custom eligibility rules. Learn more.

@juliusmarminge
juliusmarminge merged commit 66419a1 into mainSep 3, 2026
22 checks passed
@juliusmarminge
juliusmarminge deleted the fix/dev-share-loopback-target branch September 3, 2026 03:08
github-actionsBot added a commit to omarcresp/t3code-flake that referenced this pull request Sep 3, 2026
## What's Changed
* chore(ci): only run check-run agents on vouched contributors by @juliusmarminge in pingdotgg/t3code#9298
* fix(web): stop remounting markdown on every activity delta by @juliusmarminge in pingdotgg/t3code#9306
* fix(pull-requests): keep cached PR chrome on reopen by @maria-rcks in pingdotgg/t3code#9294
* feat(environments): draw each environment as the machine it runs on by @juliusmarminge in pingdotgg/t3code#9299
* feat(web): apply and remove labels from the pull request tab by @juliusmarminge in pingdotgg/t3code#9313
* fix(sidebar): collapse settled and snoozed shelves by default by @maria-rcks in pingdotgg/t3code#9314
* refactor(media): unify file and media previews across clients by @juliusmarminge in pingdotgg/t3code#9253
* fix(chat): keep live tool labels in present tense by @maria-rcks in pingdotgg/t3code#9316
* chore: audit lint directives and move plugin allowlists into config by @juliusmarminge in pingdotgg/t3code#9300
* chore(ci): narrow the Effect conventions check-run agent by @juliusmarminge in pingdotgg/t3code#9321
* refactor(mobile): style plain views with Uniwind classes instead of the theme bridge by @juliusmarminge in pingdotgg/t3code#9322
* fix(dev): share dev servers on the loopback Vite actually binds by @juliusmarminge in pingdotgg/t3code#9324
* fix(web): line up the titlebar wordmark label and version pill by @tristanmanchester in pingdotgg/t3code#9255
* fix(web): make the diff layout toggle a persisted setting by @juliusmarminge in pingdotgg/t3code#9326
* chore: dedupe lightningcss and tailwind node bindings by @juliusmarminge in pingdotgg/t3code#9331
* chore: upgrade vite-plus to 0.3.0 by @juliusmarminge in pingdotgg/t3code#9327
* feat(web): add a file tree to the diff panel and pull request code tab by @juliusmarminge in pingdotgg/t3code#9330
* feat(web): add PageUp/PageDown chat navigation by @Yash-Singh1 in pingdotgg/t3code#9315
* fix(web): collapse PR header actions to icons when narrow by @maria-rcks in pingdotgg/t3code#9334
* fix(web): resolve Vite sourcemap and supports warnings by @juliusmarminge in pingdotgg/t3code#9343
* feat(web): choose whether links open in the default browser or in T3 Code by @juliusmarminge in pingdotgg/t3code#9339
* fix(web): add press feedback to buttons by @maria-rcks in pingdotgg/t3code#9349
* feat(web): add customizable project icons by @saphid in pingdotgg/t3code#9137
* fix(mobile): stop indented code overflowing Android chat bubbles by @Adamulek123 in pingdotgg/t3code#9347
* fix(web): let the pull request list use wide screens by @juliusmarminge in pingdotgg/t3code#9351
* feat: display native app and browser icons in work logs by @Yash-Singh1 in pingdotgg/t3code#9093
## New Contributors
* @tristanmanchester made their first contribution in pingdotgg/t3code#9255
**Full Changelog**: pingdotgg/t3code@v0.0.39-nightly.20260903.1262...v0.0.39-nightly.20260903.1265
Upstream release: https://github.com/pingdotgg/t3code/releases/tag/v0.0.39-nightly.20260903.1265
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:S10-29 changed lines (additions + deletions).vouch:trustedPR author is trusted by repo permissions or the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@juliusmarminge