jsIPN.localAPI serves localapi.Handler in-process through an httptest.ResponseRecorder, so nothing ever dialled the safesocket listener that run() opened. The other in-tree callers of safesocket.ConnectContext do not apply either: driveimpl's FileSystemForRemote is replaced by jsFileSystemForRemote in this build, and logpolicy's fallback is behind version.IsWindowsGUI. Remove the listener, and with it ipnserver, whose only remaining use was serving that listener. ipnserver.New builds a struct and SetLocalBackend stores a pointer, so dropping both leaves LocalBackend untouched. Two behaviours go with it: srv.Run's deferred lb.Shutdown, which made shutdown call lb.Shutdown twice, and its localapi.Shutdown bus subscription, which nothing in this build emits. safesocket's generated per-listener name existed so several IPNs could share one runtime. Each runtime has its own Go heap and its own memconn registry, so the fixed name never conflicted between runtimes, and there is now at most one IPN in each. Restoring the fixed name returns safesocket_js.go to its upstream contents. Co-Authored-By: claude-opus-5 <noreply@anthropic.com>
tsconnect
The tsconnect command builds and serves the static site that is generated for the Tailscale Connect JS/WASM client.
Development
To start the development server:
./tool/go run ./cmd/tsconnect dev
The site is served at http://localhost:9090/. JavaScript, CSS and Go wasm package changes can be picked up with a browser reload. Server-side Go changes require the server to be stopped and restarted. In development mode the state the Tailscale client state is stored in sessionStorage and will thus survive page reloads (but not the tab being closed).
Deployment
To build the static assets necessary for serving, run:
./tool/go run ./cmd/tsconnect build
To serve them, run:
./tool/go run ./cmd/tsconnect serve
By default the build output is placed in the dist/ directory and embedded in the binary, but this can be controlled by the -distdir flag. The -addr flag controls the interface and port that the serve listens on.
Library / NPM Package
The client is also available as an NPM package. To build it, run:
./tool/go run ./cmd/tsconnect build-pkg
That places the output in the pkg/ directory, which may then be uploaded to a package registry (or installed from the file path directly).
To do two-sided development (on both the NPM package and code that uses it), run:
./tool/go run ./cmd/tsconnect dev-pkg
This serves the module at http://localhost:9090/pkg/pkg.js and the generated wasm file at http://localhost:9090/pkg/main.wasm. The two files can be used as drop-in replacements for normal imports of the NPM module.