Capture ts ip -4 before taking its first line in manage verify - #876
Merged
Merged
Conversation
Both Unix installers piped Tailscale CLI output into head -1 for the plaintext-reachability probe, the shape security-remote.md's Network posture forbids. They now capture first and cut the first line with a parameter expansion, and deploy-lint forbids the piped shape. Refs #873
Deploying mouseterm with
|
| Latest commit: |
1fee8b9
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://abe99fa9.mouseterm.pages.dev |
| Branch Preview URL: | https://fix-installer-ts-ip-capture.mouseterm.pages.dev |
This was referenced Oct 1, 2026
nedtwigg
approved these changes
Oct 1, 2026
nedtwigg
left a comment
Member
There was a problem hiding this comment.
Reviewed the capture-then-first-line change against the pipefail invariant and the generic forbidden-rule mutation coverage. Corrected the stale spec claim that deploy-lint has only one forbidden rule. Installer lint/self-tests, verification helpers, shell syntax, and fresh CI passed; bot self-review found no new issues.
nedtwigg
requested a deployment
to
hosted-preview
October 1, 2026 21:16 — with
GitHub Actions
Waiting
This branch is waiting to be deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
manage verifyon macOS and Linux picked the Tailscale IPv4 for its plaintext-reachability probe withts ip -4 2>/dev/null | head -1(install-macos.sh:902,install-linux.sh:1131).security-remote.md-> "Network posture" forbids that shape: ahead -1that exits first can SIGPIPE the CLI, so every search over Tailscale output must run over text captured first. The nightly audit flagged it in #873. With|| trueand a one-line output, no wrong verdict was reachable today, but nothing would have caught the next site.Both installers now capture the output and keep its first line with
${tsip%%$'\n'*}, the idiomserve_root_targetalready uses. A newforbiddenrule inscripts/deploy-lint.mjsfails on anytailscale/tscommand piped intoheadorgrep -q, with Windows skipped because it already matches over capturedInvoke-Tailscalestrings. The rule reports both old sites, passes on the fixed installers, anddeploy-lint-selftest.mjsconfirms it goes red on the appended violation.installer-verify-test.mjsandbash -npass on both files.This settles the last of the three FAILs in #873; #874 and #875 take the other two.
Refs #873 — automated triage