You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/net
Andrea Gottardo d9aeb30281
net/interfaces: handle iOS network transitions (#10680)
Updates #8022
Updates #6075

On iOS, we currently rely on delegated interface information to figure out the default route interface.  The NetworkExtension framework in iOS seems to set the delegate interface only once, upon the *creation* of the VPN tunnel. If a network transition (e.g. from Wi-Fi to Cellular) happens while the tunnel is connected, it will be ignored and we will still try to set Wi-Fi as the default route because the delegated interface is not getting updated as connectivity transitions.

Here we work around this on the Swift side with a NWPathMonitor instance that observes the interface name of the first currently satisfied network path. Our Swift code will call into `UpdateLastKnownDefaultRouteInterface`, so we can rely on that when it is set.

If for any reason the Swift machinery didn't work and we don't get any updates, here we also have some fallback logic: we try finding a hardcoded Wi-Fi interface called en0. If en0 is down, we fall back to cellular (pdp_ip0) as a last resort. This doesn't handle all edge cases like USB-Ethernet adapters or multiple Ethernet interfaces, but it is good enough to ensure connectivity isn't broken.

I tested this on iPhones and iPads running iOS 17.1 and it appears to work. Switching between different cellular plans on a dual SIM configuration also works (the interface name remains pdp_ip0).

Signed-off-by: Andrea Gottardo <andrea@tailscale.com>
2 years ago
..
art all: cleanup unused code, part 2 (#10670) 2 years ago
connstats net/connstats: exclude traffic with internal Tailscale service (#7904) 3 years ago
dns all: cleanup unused code, part 2 (#10670) 2 years ago
dnscache all: cleanup unused code, part 2 (#10670) 2 years ago
dnsfallback net/dnsfallback: add singleflight to recursive resolver 2 years ago
flowtrack all: update copyright and license headers 3 years ago
interfaces net/interfaces: handle iOS network transitions (#10680) 2 years ago
memnet net/memnet: export the network name (#9111) 2 years ago
netaddr all: update copyright and license headers 3 years ago
netcheck net/netcheck: use DERP frames as a signal for home region liveness 2 years ago
neterror net/neterror, wgengine/magicsock: use UDP GSO and GRO on Linux (#7791) 3 years ago
netkernelconf client/tailscale,ipn/{ipnlocal,localapi}: check UDP GRO config (#10071) 2 years ago
netknob all: update copyright and license headers 3 years ago
netmon all: cleanup unused code, part 2 (#10670) 2 years ago
netns net/{interfaces,netmon}: remove "interesting", EqualFiltered API 2 years ago
netstat net/{netns,netstat}: use new x/sys/cpu.IsBigEndian 3 years ago
netutil all: cleanup unused code, part 2 (#10670) 2 years ago
packet all: cleanup unused code, part 1 (#10661) 2 years ago
ping net/ping: fix ICMP echo code field to 0 2 years ago
portmapper net/portmapper: check returned epoch from PMP and PCP protocols 2 years ago
proxymux all: cleanup unused code, part 1 (#10661) 2 years ago
routetable all: cleanup unused code, part 2 (#10670) 2 years ago
socks5 net/socks5: add password auth support 3 years ago
sockstats net/dns: retry forwarder requests over TCP 2 years ago
speedtest all: update copyright and license headers 3 years ago
stun wgengine/magicsock, types/nettype, etc: finish ReadFromUDPAddrPort netip migration 3 years ago
tcpinfo net/tcpinfo: add package to allow fetching TCP information 2 years ago
tlsdial cmd/tailscale/cli: make netcheck run even if machine lacks TLS certs 2 years ago
tsaddr all: cleanup unused code, part 1 (#10661) 2 years ago
tsdial all: cleanup unused code, part 1 (#10661) 2 years ago
tshttpproxy net/tshttpproxy: don't proxy through ourselves 3 years ago
tstun all: cleanup unused code, part 2 (#10670) 2 years ago
wsconn net/wsconn: accept a remote addr string and plumb it through 2 years ago