Send and receive files with Taildrop (#6375)

* Send files to a tailnet machine with Taildrop

The panel gets a send button next to the copy one on every machine that
Tailscale grades as a Taildrop target, and `s` does the same from the
keyboard. Picking runs through the XDG portal chooser, so it looks like
the file dialog every other app opens.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TJQJfHXXApUk6En8EZisHg

* Save incoming Taildrop files and say so

Linux keeps Taildrop files in the daemon's inbox until someone asks for
them, so nothing arrived until you ran `tailscale file get` by hand. A
user service now stages each delivery next to the downloads directory,
hands it over under a free name, and announces it — with a preview when
it's an image, and a click to open it.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TJQJfHXXApUk6En8EZisHg

* Float every portal dialog, not just the titled ones

The portal only ever shows dialogs, and the title regex missed any
chooser an app names something else — ours included.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01TJQJfHXXApUk6En8EZisHg

* Re-run the Taildrop enable now that the unit ships

The unit was never installed to /usr/lib/systemd/user/, so the enable had
nothing to act on and machines that already ran the migration carry a marker
for a no-op. Rename it so they get a working pass, and report what systemctl
says instead of a bare failure line.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Wait for the file chooser on the connection that asked for it

The portal answers a request with a Response signal directed at the connection
that made it, and dbus-daemon delivers directed signals only to that
connection. gdbus monitor registers with AddMatch rather than BecomeMonitor, so
it never saw the reply: every pick left omarchy-file-select blocked on a read
that could not arrive, taking omarchy-tailscale-send down with it before it
reached either its notification or the transfer.

Make the call and wait for the signal on one connection, and give up after ten
minutes so an unanswered dialog cannot strand the caller.

Drop the "Sending to" notification while here, so a send reports once.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Mark Taildrop notifications with the panel's send glyph

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Stop a hung tailscale poll from freezing the panel

Each poll is skipped while its own process is still running, so one that never
exits leaves the panel showing whatever it last read, for good: the peer list
keeps a woken machine missing, and opening the panel cannot help because open
runs the same refresh that hits the same guard.

Reap anything still running fifteen seconds after a refresh, well inside the
thirty second interval, so the next tick starts clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Place a moved widget where an added one lands

'move omarchy.media left' named a section, not a slot, but the section went
through as an explicit target, which resolves a missing index by appending. The
widget landed on the far end of the row instead of after the section anchor
where 'add' puts it.

Its test has never run: the assertion covering this went in four hours after an
unrelated layout change had already stopped the file, and the runner stops the
whole suite at the first failure.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Keep the config test from failing on things it is not about

The center layout assertion pinned the whole row, so parking the indicators
left of the clock broke a test named for update sitting next to weather. Assert
that adjacency instead.

The package-defaults check reads PKGBUILDs from the omarchy-pkgs repo and blew
up with a traceback wherever that is not a sibling checkout. Skip it when the
checkout is absent, honour OMARCHY_PKGS_ROOT when it is somewhere else, and
keep failing when it is present and wrong.

Between them these stopped the suite eighty files early.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Make the file chooser a Python command rather than a bash host for one

The portal work was a heredoc wedged inside a bash script that existed only to
parse two flags. Drop the host: argparse covers the flags, and the file says at
the top why it is the one command here not written in bash.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* Tell a chooser that never opened apart from one that was dismissed

Three fixes from review:

The poll watchdog rearmed on every refresh, so a refresh interval shorter than
its timeout — the setting goes down to five seconds — pushed the deadline ahead
of a hung process forever. Arm it on the launch that needs watching and leave
it alone.

omarchy-file-select exited 1 both for nothing picked and for a chooser that
could not run, and omarchy-tailscale-send read it through a process
substitution, which drops the status anyway. A session bus that was not there
looked exactly like someone changing their mind. Separate the two exits and
read them with a command substitution.

Delivery picked a free name and then renamed, which overwrites anything that
takes the name in between. Link to the name instead: link(2) refuses one that
is taken, so the check and the claim are the same step.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
David Heinemeier Hansson
2026-07-26 19:07:11 -07:00
committed by GitHub
co-authored by Claude Opus 5
parent 6465513534
commit e57f3b286c
17 changed files with 540 additions and 15 deletions
+29
View File
@@ -73,10 +73,35 @@ function loginPlan(needsLogin, authUrl) {
return { authUrl: "", command: ["tailscale", "up"] }
}
// Taildrop is a tailnet feature the admin can turn off, so the button for it
// only makes sense when this profile actually carries the capability.
function hasFileSharing(self) {
var capability = "https://tailscale.com/cap/file-sharing"
var capMap = (self && self.CapMap) || null
if (capMap && capMap[capability] !== undefined) return true
var capabilities = (self && self.Capabilities) || []
for (var i = 0; i < capabilities.length; i++) {
if (String(capabilities[i]) === capability) return true
}
return false
}
// Tailscale grades every peer itself — offline, wrong owner, an OS without
// Taildrop, no peer API — so take its word when the status carries one, and
// fall back to same-owner for daemons too old to say.
function isTaildropTarget(peer, selfUserId) {
var target = peer && peer.TaildropTarget
if (typeof target === "number" && target !== 0) return target === 1
var owner = String((peer && peer.UserID) || "")
return owner !== "" && owner === String(selfUserId || "")
}
function peerFromStatus(id, peer) {
return {
id: id,
HostName: displayHostName(peer.HostName, peer.DNSName),
UserID: String(peer.UserID || ""),
TaildropTarget: typeof peer.TaildropTarget === "number" ? peer.TaildropTarget : 0,
DNSName: cleanDnsName(peer.DNSName),
DisplayName: displayHostName(peer.HostName, peer.DNSName),
TailscaleIPs: filterIPv4(peer.TailscaleIPs || []),
@@ -235,6 +260,8 @@ function parseStatus(raw) {
selfName: displayHostName(self.HostName, self.DNSName),
selfDnsName: cleanDnsName(self.DNSName),
selfIp: selfIps.length > 0 ? selfIps[0] : "",
selfUserId: String(self.UserID || ""),
fileSharing: hasFileSharing(self),
peers: peers,
exitNodes: exitNodes
}
@@ -285,6 +312,8 @@ if (typeof module !== "undefined") {
osIcon: osIcon,
accountLabel: accountLabel,
loginPlan: loginPlan,
hasFileSharing: hasFileSharing,
isTaildropTarget: isTaildropTarget,
isMullvadPeer: isMullvadPeer,
peerFromStatus: peerFromStatus,
parseExitNodeList: parseExitNodeList,
+19
View File
@@ -295,6 +295,13 @@ Panel {
scrollCursorIntoView()
}
// The file picker takes over from here, so get the panel out of the way.
function sendPeerFile(peer) {
if (!tailscale.canSendFiles(peer)) return
tailscale.sendFile(peer)
close()
}
function openSelectedPeerCopyMenu() {
if (!peerColumn || peerIndex < 0 || peerIndex >= peerColumn.children.length) return
var item = peerColumn.children[peerIndex]
@@ -416,6 +423,7 @@ Panel {
else if (t === "c" || t === "C") tailscale.copyPeerIp(root.selectedPeer())
else if (t === "n" || t === "N") tailscale.copyPeerName(root.selectedPeer())
else if (t === "d" || t === "D") tailscale.copyPeerDnsName(root.selectedPeer())
else if (t === "s" || t === "S") root.sendPeerFile(root.selectedPeer())
}
Flickable {
@@ -973,6 +981,17 @@ Panel {
}
}
PanelActionButton {
id: sendButton
visible: tailscale.canSendFiles(peerRow.peer)
iconText: "󰒊"
tooltipText: "Send files"
foreground: root.foreground
fontFamily: root.fontFamily
Layout.alignment: Qt.AlignVCenter
onClicked: root.sendPeerFile(peerRow.peer)
}
PanelActionButton {
id: copyButton
iconText: "󰆏"
+11
View File
@@ -10,6 +10,7 @@ Native Omarchy bar widget for Tailscale.
- Switch between available Tailscale connections when multiple are available
- Browse machines from `tailscale status --json`
- Copy a machine's Tailscale IP, host name, or DNS name
- Send files to a machine with Taildrop, when the tailnet allows file sharing
## Keyboard shortcuts
@@ -20,6 +21,7 @@ Inside the panel:
- `c`: copy selected peer IP
- `n`: copy selected peer name
- `d`: copy selected peer DNS name
- `s`: send files to selected peer
- `t`: toggle Tailscale
- `r`: refresh status
- `esc`: close
@@ -28,6 +30,15 @@ Inside the panel:
- `tailscale` CLI on `PATH`
- `wl-copy` for clipboard copy actions
- Taildrop enabled for the tailnet, to send files
## Receiving files
Incoming Taildrop files are saved to `~/Downloads` by the
`omarchy-tailscale-receive` service, which announces each one with a
notification (an image preview when the file is an image, and a click to open
it). The Tailscale service install enables it; `omarchy tailscale receive`
runs the same loop by hand.
## Icon
+52 -4
View File
@@ -24,6 +24,8 @@ Item {
property string selfName: ""
property string selfDnsName: ""
property string selfIp: ""
property string selfUserId: ""
property bool fileSharing: false
property string authUrl: ""
property var peers: []
property var exitNodes: []
@@ -123,6 +125,26 @@ Item {
copyToClipboard(cleanDnsName(peer.DNSName), displayHostName(peer.HostName, peer.DNSName) + " DNS name")
}
function peerAddress(peer) {
if (!peer) return ""
if (peer.DNSName) return cleanDnsName(peer.DNSName)
if (peer.HostName) return String(peer.HostName)
var ips = filterIPv4(peer.TailscaleIPs || [])
return ips.length > 0 ? ips[0] : ""
}
function canSendFiles(peer) {
if (!fileSharing || !running || !peer) return false
return Model.isTaildropTarget(peer, selfUserId)
}
function sendFile(peer) {
if (!canSendFiles(peer)) return
var target = peerAddress(peer)
if (target === "") return
Quickshell.execDetached(["omarchy-tailscale-send", target])
}
function refresh(forceAccounts) {
if (installed) {
refreshStatusAndAccounts(forceAccounts === true)
@@ -137,18 +159,21 @@ Item {
function refreshStatusAndAccounts(forceAccounts) {
if (!installed) return
var launched = false
if (!statusProcess.running) {
_statusOutput = ""
_statusError = ""
refreshing = true
statusProcess.command = ["tailscale", "status", "--json"]
statusProcess.running = true
launched = true
}
if (!mullvadExitNodesProcess.running) {
_mullvadExitNodesOutput = ""
_mullvadExitNodesError = ""
mullvadExitNodesProcess.command = ["tailscale", "exit-node", "list"]
mullvadExitNodesProcess.running = true
launched = true
}
var now = Date.now()
var shouldRefreshAccounts = forceAccounts === true || accounts.length === 0 || now - _lastAccountsRefreshMs > 60000
@@ -158,7 +183,13 @@ Item {
_lastAccountsRefreshMs = now
accountsProcess.command = ["tailscale", "switch", "--list", "--json"]
accountsProcess.running = true
launched = true
}
// Arm on the launch that needs watching and leave it alone after that.
// Restarting it every refresh pushes the deadline out ahead of a hung
// process forever once the refresh interval is shorter than the timeout,
// and refreshIntervalSec goes down to five seconds.
if (launched && !pollWatchdog.running) pollWatchdog.start()
}
function elideStatus(text) {
@@ -175,6 +206,8 @@ Item {
selfName = ""
selfDnsName = ""
selfIp = ""
selfUserId = ""
fileSharing = false
authUrl = ""
peers = []
exitNodes = []
@@ -212,6 +245,8 @@ Item {
selfName = parsed.selfName
selfDnsName = parsed.selfDnsName
selfIp = parsed.selfIp
selfUserId = parsed.selfUserId
fileSharing = parsed.fileSharing
peers = parsed.running ? parsed.peers : []
tailnetExitNodes = parsed.running ? parsed.exitNodes : []
exitNodes = parsed.running ? tailnetExitNodes.concat(mullvadRegions) : []
@@ -295,10 +330,7 @@ Item {
var mullvadIps = filterIPv4(peer.TailscaleIPs || [])
if (mullvadIps.length > 0) return mullvadIps[0]
}
if (peer.DNSName) return cleanDnsName(peer.DNSName)
if (peer.HostName) return String(peer.HostName)
var ips = filterIPv4(peer.TailscaleIPs || [])
return ips.length > 0 ? ips[0] : ""
return peerAddress(peer)
}
function setExitNode(peer) {
@@ -386,6 +418,22 @@ Item {
onTriggered: root.refresh()
}
Timer {
// Every poll is skipped while its own process is still running, so one that
// never exits — tailscale can hang on a network that is coming and going —
// silently stops the panel refreshing at all, and it stays stopped. Reap
// anything still running well inside the refresh interval so the next tick
// starts clean.
id: pollWatchdog
interval: 15000
repeat: false
onTriggered: {
if (statusProcess.running) statusProcess.running = false
if (mullvadExitNodesProcess.running) mullvadExitNodesProcess.running = false
if (accountsProcess.running) accountsProcess.running = false
}
}
Timer {
id: actionStatusTimer
interval: 2200