Tessera network help

WSL2 and Tailscale MTU warning

Tessera detected a WSL2 network shape that can allow SSH to connect while silently dropping larger terminal replies. This is a host networking issue, not damage to your tmux session.

Why “attaching pane” can stall

1

Small replies pass

Authentication and short tmux control messages fit below the broken packet-size boundary.

2

A pane capture is larger

Tessera requests the visible pane and scrollback so the restored terminal can paint immediately.

3

The path drops it

The SSH connection stays open, but the larger encrypted response never reaches the device.

What the probe reads

The probe is read-only, runs over the SSH connection you already authorized, and does not use sudo or change the host.

WSL version signal/proc/sys/kernel/osrelease
Connection routeThe server address from SSH_CONNECTION, matched against addresses on tailscale0
Outer MTUThe MTU of WSL’s default-route interface
Inner MTU/sys/class/net/tailscale0/mtu

Verify the host

Run these commands inside the affected WSL distribution. They only display state.

uname -a
ip -br link
ip route show default

default_dev="$(ip route show default | awk 'NR == 1 { print $5 }')"
printf 'default interface: %s\n' "$default_dev"
cat "/sys/class/net/$default_dev/mtu"
cat /sys/class/net/tailscale0/mtu 2>/dev/null || true

tailscale version 2>/dev/null || true
tailscale status 2>/dev/null || true

For Tailscale running inside WSL2, the common healthy relationship is an outer/default interface of at least 1340 carrying the 1280-byte Tailscale interface.

Choose the remediation that matches your topology

Keep Tailscale inside WSL2

Update Tailscale and confirm its WSL workaround raises the outer/default interface to 1340. Test a temporary MTU adjustment before making startup configuration persistent.

Important safety notes

Do not lower tailscale0 blindly, reset the Windows network stack, shut down WSL, or disable either Tailscale installation from a remote session. Those actions can end the connection you need for recovery.

A configured MTU is not proof of the end-to-end path. If the warning persists after correction, compare ordinary OS traffic with Tailscale’s layered pings and perform a bounded packet-size test from another device.

Authoritative references

Tailscale: Install on Windows with WSL2
Tailscale: Troubleshoot TCP connection issues

Tessera reports this as a possible cause because other routing, VPN, firewall, and packet-loss problems can produce similar symptoms.