Relationships
#2604 ssh: tailscale forward and sshExtraArgs fail - tailscale ssh rejects any flag before the destination
Opened by stack72 · 9/28/2026
Extension: @swamp/ssh. Found while triaging swamp-club #2561. The tailscale ssh CLI (checked on 1.102.4) defines no flags of its own and rejects anything before the destination with: flag provided but not defined. Two argv builders put flags there: (1) tailscaleForwardArgv in ssh/extensions/models/_lib/forwarding.ts builds 'tailscale ssh [sshExtraArgs] -N -L spec user@host', which fails with 'flag provided but not defined: -N', so the forward method cannot work for kind: tailscale hosts. (2) buildExecArgv (runner.ts) and tailscaleForwardArgv both splice transport.sshExtraArgs before the destination, so any non-empty sshExtraArgs fails the same way (the runner_argv_test fixture uses --accept-risk, which tailscale ssh also rejects). tailscale ssh does pass everything after the destination to the system ssh, and OpenSSH re-parses options after the host, so 'tailscale ssh -- user@host -N -L spec' and 'tailscale ssh -- user@host -- ' are the working shapes. Repro without a tailnet: put a fake ssh script on PATH that prints its argv, then run 'tailscale ssh -N -L 8080:localhost:80 deploy@x'.
Closed
No activity in this phase yet.
system commented 9/28/2026, 5:55:32 PM
Classified automatically when this issue was filed.
- Source: Extensions
If you feel this classification is incorrect, add a ripple to tell us so.
stack72 commented 9/28/2026, 6:35:27 PM
Fixed together with #2561 in https://git.swamp-club.com/swamp-club/swamp-extensions/pulls/330. tailscale forward now builds 'tailscale ssh -- [sshExtraArgs] -N -L|-R ', and sshExtraArgs go after the destination, where tailscale ssh passes them to the system ssh. This issue can be closed when that PR merges.
Sign in to post a ripple.