Caught by running the actual test suite on Linux (go test ./...) after
pulling v2.2.0 -- local_route_test.go is a shared cross-platform suite
exercising the same "already exists" / "not found" tolerance for both
platforms' addHostRoute/delHostRoute, but local_route_windows.go had the
tolerance checks and local_route_unix.go didn't:
- addHostRoute (unix): had no "already exists" check at all. `ip route
replace` is idempotent in real usage so this rarely bites in practice,
but the implementation should match its own test coverage rather than
relying on that.
- delHostRoute (unix): checked "no such process"/"cannot find" but not
"route not found", the fixture text the shared test uses (and a real
message some `ip route del` failures produce).
Both now mirror local_route_windows.go's tolerance logic. go test ./...
passes on Linux again.
Completes the mDNS local-discovery feature on Windows (was Linux-only since
v2.1.2). Three parts:
1. Windows hosts override (hosts_override_windows.go): %SystemRoot%...\\hosts,
CRLF-aware read/write, ipconfig /flushdns after each change. The agent runs
as a SYSTEM service so elevation is a non-issue. hosts_override.go split
into shared rewrite logic + platform files; the hosts tests now run the real
Windows write path on CI instead of skipping.
2. Local route pinning (local_route*.go): the hosts override only fixes name
resolution -- the packet path is the routing table's job. If the WG mesh
tunnel is up with AllowedIPs covering the LAN (or full-tunnel 0.0.0.0/0) it
swallows the direct connection. Discovery now pins a /32 host route via the
owning local interface (route.exe metric 1 on Windows, ip route replace on
Linux) and drops it on revert. Closes a gap in the shipped Linux path too.
3. Prompt reconnect: apply/revert signals the WS loop so it reconnects
immediately instead of waiting out the 5s backoff.
Route/hosts code is injectable + unit tested; go test passes natively on
Windows (this machine), and linux/amd64 + windows/arm64 cross-builds are clean.