it's detecting an inactive vpn interface (not sure if it's the mullvad client when disconnected, or tailscale) and going red immediately. it should only show the vpn interface on macOS if the vpn is connected.
it's detecting an inactive vpn interface (not sure if it's the mullvad client when disconnected, or tailscale) and going red immediately. it should only show the vpn interface on macOS if the vpn is connected.
Recorded. Sorry this sat unanswered since yesterday.
The fix: on macOS, show the VPN only when a VPN is actually connected. An interface left behind by a disconnected client (Mullvad or Tailscale, whichever it is) no longer turns the display red.
rtnetmon is paused under your 2026-09-22 priority ruling. This is queued as its first unit when the pause lifts. If you want it fixed before then, say so here; it is one small unit.
Model: opus-5-5
Recorded. Sorry this sat unanswered since yesterday.
The fix: on macOS, show the VPN only when a VPN is actually connected. An interface left behind by a disconnected client (Mullvad or Tailscale, whichever it is) no longer turns the display red.
rtnetmon is paused under your 2026-09-22 priority ruling. This is queued as its first unit when the pause lifts. If you want it fixed before then, say so here; it is one small unit.
Model: opus-5-5
clawbot
self-assigned this 2026-09-23 13:57:45 +02:00
Cause: on macOS a tunnel interface (utunN) counts as the VPN when it carries a default route, or when it is up with a routable IPv4 address (findVPN in internal/netdetect/netdetect.go). The second rule is the bug. Tailscale's tunnel is up with a 100.x address whenever Tailscale is on, without carrying internet traffic, and a client that has disconnected can leave its tunnel behind. Either one becomes the VPN pane, the probes bound to it fail, and the display goes red.
Fix: a tunnel is the VPN only while internet traffic goes through it, as read from netstat -rn -f inet: it carries the default route, or both halves 0/1 and 128.0/1, which WireGuard-style clients install instead of replacing the default route. The rule "up with a routable address" is removed. Nothing else about macOS selection changes.
Done when:
Tests in internal/netdetect drive selection from recorded netstat -rn -f inet output and interface lists for: no tunnel; Tailscale on without an exit node (tunnel up with a 100.x address, no default route), giving the physical pane only; a tunnel left by a disconnected client (routable address, no default route), giving the physical pane only; a VPN on a default row, giving two panes; a VPN on 0/1 plus 128.0/1, giving two panes; idle Tailscale next to a connected VPN, where the connected one is the VPN pane.
The existing test that takes a tunnel with only a routable address as the VPN now expects no VPN.
The README's macOS paragraph says the VPN pane appears only while a VPN carries the default route.
Not run on a real Mac; the PR says so in one line. The first run on your Mac is the test.
Model: opus-5-5
Plan.
Cause: on macOS a tunnel interface (`utunN`) counts as the VPN when it carries a default route, or when it is up with a routable IPv4 address (`findVPN` in `internal/netdetect/netdetect.go`). The second rule is the bug. Tailscale's tunnel is up with a `100.x` address whenever Tailscale is on, without carrying internet traffic, and a client that has disconnected can leave its tunnel behind. Either one becomes the VPN pane, the probes bound to it fail, and the display goes red.
Fix: a tunnel is the VPN only while internet traffic goes through it, as read from `netstat -rn -f inet`: it carries the `default` route, or both halves `0/1` and `128.0/1`, which WireGuard-style clients install instead of replacing the default route. The rule "up with a routable address" is removed. Nothing else about macOS selection changes.
Done when:
- Tests in `internal/netdetect` drive selection from recorded `netstat -rn -f inet` output and interface lists for: no tunnel; Tailscale on without an exit node (tunnel up with a `100.x` address, no default route), giving the physical pane only; a tunnel left by a disconnected client (routable address, no default route), giving the physical pane only; a VPN on a `default` row, giving two panes; a VPN on `0/1` plus `128.0/1`, giving two panes; idle Tailscale next to a connected VPN, where the connected one is the VPN pane.
- The existing test that takes a tunnel with only a routable address as the VPN now expects no VPN.
- The README's macOS paragraph says the VPN pane appears only while a VPN carries the default route.
- Not run on a real Mac; the PR says so in one line. The first run on your Mac is the test.
Model: opus-5-5
Labelled critical: on a Mac with Tailscale running or a disconnected VPN client, rtnetmon takes the idle tunnel for the VPN and shows it red from the first second, so it cannot be used as a network monitor there.
Model: opus-5-5
Labelled critical: on a Mac with Tailscale running or a disconnected VPN client, rtnetmon takes the idle tunnel for the VPN and shows it red from the first second, so it cannot be used as a network monitor there.
Model: opus-5-5
Built in #15: on macOS the VPN pane now appears only while a tunnel carries the default route; a tunnel that is merely up (idle Tailscale, or one a disconnected client left behind) is ignored. Not run on a real Mac yet; the first run on yours is the test.
Model: opus-5-5
Built in https://git.eeqj.de/sneak/rtnetmon/pulls/15: on macOS the VPN pane now appears only while a tunnel carries the default route; a tunnel that is merely up (idle Tailscale, or one a disconnected client left behind) is ignored. Not run on a real Mac yet; the first run on yours is the test.
Model: opus-5-5
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
it's detecting an inactive vpn interface (not sure if it's the mullvad client when disconnected, or tailscale) and going red immediately. it should only show the vpn interface on macOS if the vpn is connected.
Recorded. Sorry this sat unanswered since yesterday.
The fix: on macOS, show the VPN only when a VPN is actually connected. An interface left behind by a disconnected client (Mullvad or Tailscale, whichever it is) no longer turns the display red.
rtnetmon is paused under your 2026-09-22 priority ruling. This is queued as its first unit when the pause lifts. If you want it fixed before then, say so here; it is one small unit.
Model: opus-5-5
Plan.
Cause: on macOS a tunnel interface (
utunN) counts as the VPN when it carries a default route, or when it is up with a routable IPv4 address (findVPNininternal/netdetect/netdetect.go). The second rule is the bug. Tailscale's tunnel is up with a100.xaddress whenever Tailscale is on, without carrying internet traffic, and a client that has disconnected can leave its tunnel behind. Either one becomes the VPN pane, the probes bound to it fail, and the display goes red.Fix: a tunnel is the VPN only while internet traffic goes through it, as read from
netstat -rn -f inet: it carries thedefaultroute, or both halves0/1and128.0/1, which WireGuard-style clients install instead of replacing the default route. The rule "up with a routable address" is removed. Nothing else about macOS selection changes.Done when:
internal/netdetectdrive selection from recordednetstat -rn -f inetoutput and interface lists for: no tunnel; Tailscale on without an exit node (tunnel up with a100.xaddress, no default route), giving the physical pane only; a tunnel left by a disconnected client (routable address, no default route), giving the physical pane only; a VPN on adefaultrow, giving two panes; a VPN on0/1plus128.0/1, giving two panes; idle Tailscale next to a connected VPN, where the connected one is the VPN pane.Model: opus-5-5
Labelled critical: on a Mac with Tailscale running or a disconnected VPN client, rtnetmon takes the idle tunnel for the VPN and shows it red from the first second, so it cannot be used as a network monitor there.
Model: opus-5-5
Built in #15: on macOS the VPN pane now appears only while a tunnel carries the default route; a tunnel that is merely up (idle Tailscale, or one a disconnected client left behind) is ignored. Not run on a real Mac yet; the first run on yours is the test.
Model: opus-5-5