You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/net
Andrea Gottardo d9aeb30281
net/interfaces: handle iOS network transitions (#10680)
Updates #8022
Updates #6075

On iOS, we currently rely on delegated interface information to figure out the default route interface.  The NetworkExtension framework in iOS seems to set the delegate interface only once, upon the *creation* of the VPN tunnel. If a network transition (e.g. from Wi-Fi to Cellular) happens while the tunnel is connected, it will be ignored and we will still try to set Wi-Fi as the default route because the delegated interface is not getting updated as connectivity transitions.

Here we work around this on the Swift side with a NWPathMonitor instance that observes the interface name of the first currently satisfied network path. Our Swift code will call into `UpdateLastKnownDefaultRouteInterface`, so we can rely on that when it is set.

If for any reason the Swift machinery didn't work and we don't get any updates, here we also have some fallback logic: we try finding a hardcoded Wi-Fi interface called en0. If en0 is down, we fall back to cellular (pdp_ip0) as a last resort. This doesn't handle all edge cases like USB-Ethernet adapters or multiple Ethernet interfaces, but it is good enough to ensure connectivity isn't broken.

I tested this on iPhones and iPads running iOS 17.1 and it appears to work. Switching between different cellular plans on a dual SIM configuration also works (the interface name remains pdp_ip0).

Signed-off-by: Andrea Gottardo <andrea@tailscale.com>
5 months ago
..
art all: cleanup unused code, part 2 (#10670) 5 months ago
connstats net/connstats: exclude traffic with internal Tailscale service (#7904) 1 year ago
dns all: cleanup unused code, part 2 (#10670) 5 months ago
dnscache all: cleanup unused code, part 2 (#10670) 5 months ago
dnsfallback net/dnsfallback: add singleflight to recursive resolver 7 months ago
flowtrack all: update copyright and license headers 1 year ago
interfaces net/interfaces: handle iOS network transitions (#10680) 5 months ago
memnet net/memnet: export the network name (#9111) 9 months ago
netaddr all: update copyright and license headers 1 year ago
netcheck net/netcheck: use DERP frames as a signal for home region liveness 6 months ago
neterror net/neterror, wgengine/magicsock: use UDP GSO and GRO on Linux (#7791) 1 year ago
netkernelconf client/tailscale,ipn/{ipnlocal,localapi}: check UDP GRO config (#10071) 7 months ago
netknob all: update copyright and license headers 1 year ago
netmon all: cleanup unused code, part 2 (#10670) 5 months ago
netns net/{interfaces,netmon}: remove "interesting", EqualFiltered API 9 months ago
netstat net/{netns,netstat}: use new x/sys/cpu.IsBigEndian 1 year ago
netutil all: cleanup unused code, part 2 (#10670) 5 months ago
packet all: cleanup unused code, part 1 (#10661) 5 months ago
ping net/ping: fix ICMP echo code field to 0 9 months ago
portmapper net/portmapper: check returned epoch from PMP and PCP protocols 5 months ago
proxymux all: cleanup unused code, part 1 (#10661) 5 months ago
routetable all: cleanup unused code, part 2 (#10670) 5 months ago
socks5 net/socks5: add password auth support 1 year ago
sockstats net/dns: retry forwarder requests over TCP 8 months ago
speedtest all: update copyright and license headers 1 year ago
stun wgengine/magicsock, types/nettype, etc: finish ReadFromUDPAddrPort netip migration 1 year ago
tcpinfo net/tcpinfo: add package to allow fetching TCP information 11 months ago
tlsdial cmd/tailscale/cli: make netcheck run even if machine lacks TLS certs 9 months ago
tsaddr all: cleanup unused code, part 1 (#10661) 5 months ago
tsdial all: cleanup unused code, part 1 (#10661) 5 months ago
tshttpproxy net/tshttpproxy: don't proxy through ourselves 1 year ago
tstun all: cleanup unused code, part 2 (#10670) 5 months ago
wsconn net/wsconn: accept a remote addr string and plumb it through 9 months ago