Skip to content

network applet: merge the WireGuard and VPN sections, label each row's kind - #13913

Open
IvanTheGeek wants to merge 2 commits into
linuxmint:masterfrom
IvanTheGeek:feature/network-applet-improvements
Open

IvanTheGeek wants to merge 2 commits into
linuxmint:masterfrom
IvanTheGeek:feature/network-applet-improvements

Conversation

@IvanTheGeek

@IvanTheGeek IvanTheGeek commented Jul 30, 2026 •

Copy link
Copy Markdown
Contributor

What changes

  • WireGuard connections move into "VPN Connections"; NMDeviceWIREGUARD and its icon override go.
  • Each row shows its kind (WireGuard, OpenVPN, PPTP...) in the row's status column.

User-visible changes

  • One uncapped list holds both kinds, most recent first; the WIREGUARD heading goes.
  • VPN-plugin rows become switches: the menu stays open on click, the dot and bold style go, the switch flips before NM confirms.
  • The title switch covers both kinds: off disconnects every tunnel, on starts the most recently used one, possibly WireGuard.
  • WireGuard follows the Show "wired with a padlock" or "wireless with a padlock" icons when a VPN is connected #12142 icon path: Wi-Fi bars with a padlock when Wi-Fi is the main connection, "Connected to the VPN" / "Connecting to the VPN..." tooltips, plain bars while disconnecting.
  • With tunnels in mixed states, the first one NM lists sets the icon, as two VPN plugins already do.
  • WireGuard rows follow renames.
  • Three WIREGUARD strings become unused; none are added ("WireGuard" reuses the existing msgid).

Testing without special hardware
A WireGuard profile with no peer activates locally:

nmcli connection add type wireguard con-name wg-test ifname wg-test autoconnect no ipv4.method manual ipv4.addresses 192.0.2.10/32 ipv4.never-default yes ipv6.method disabled wireguard.private-key "$(wg genkey)"

An OpenVPN profile (network-manager-openvpn) pointing at 192.0.2.1 stays connecting until NM's VPN timeout (about 60 s).

Overlaps #13767 (both edit NMDeviceVPN._createSection); whichever lands second needs a rebase. Thanks @wocisjr: #13986 proposed the shared icon path.

Tested on: Cinnamon 6.6.9 (Mint 22.3), with this applet.js as a user-dir override, not a master build: three WireGuard tunnels up at once, OpenVPN rows, row toggles, deleting and renaming profiles, and the OpenVPN password dialog (it takes focus; Cancel turns the row off).

AI assistance: written with help from Claude Opus 5.5 (Anthropic); I reviewed it and tested it on my own machine.

@github-actions

Copy link
Copy Markdown

Best-practices scanner

This is a regex-based check for API usage that can pose security, performance or
maintainability issues, or that may already be provided by Cinnamon. Most findings
are advisory and do not automatically disqualify a pull request.

This check is not perfect and will not replace a normal review.


Found 3 potential issue(s):

⚠️ WARNING

⚠️ lang_bind

files/usr/share/cinnamon/applets/network@cinnamon.org/applet.js:935

this._speedChangedId = this.device.connect('notify::speed', Lang.bind(this, function() {

Lang.bind() is deprecated. Use arrow functions (() => {}) or Function.prototype.bind() instead.

files/usr/share/cinnamon/applets/network@cinnamon.org/applet.js:1275

obj.item.connect('toggled', Lang.bind(this, function(item, state) {

Lang.bind() is deprecated. Use arrow functions (() => {}) or Function.prototype.bind() instead.

files/usr/share/cinnamon/applets/network@cinnamon.org/applet.js:2235

this._watchedApId = ap.connect('notify::strength', Lang.bind(this, function() {

Lang.bind() is deprecated. Use arrow functions (() => {}) or Function.prototype.bind() instead.


Automated pattern check.

@IvanTheGeek
IvanTheGeek force-pushed the feature/network-applet-improvements branch from 887ad36 to 1d59a9f Compare July 30, 2026 19:17
@IvanTheGeek

Copy link
Copy Markdown
Contributor Author

The best-practices scanner findings above are addressed — all of the flagged Lang.bind() uses were in code this PR adds, and they are now arrow functions (which capture this the same way). No new Lang.bind() is introduced; the count in this file actually goes down versus master.

The scanner comment is stale rather than wrong: the workflow re-run is sitting in action_required, since runs from a first-time contributor need maintainer approval. It should clear once someone approves the run.

@mtwebster

Copy link
Copy Markdown
Member

Hi, I merged 13911 -

I'd be fine with merging the sections and adding labels.

I think the additional options here are overkill - the percentage strength is enough.

Wherever you take this, though, I'd prefer smaller PRs - something like this (even though you admitted you didn't expect this to be merged as-is) - is difficult to review, especially since some of it can depend on things the reviewer has no access to for testing. Small bits are easier to look at objectively.

@IvanTheGeek

Copy link
Copy Markdown
Contributor Author

Thanks for merging #13911.

Plan: I'll cut this PR down to merging the sections plus a label on each row showing its type (WireGuard, OpenVPN, …), rebuilt on current master. The settings, the band/width/security text and the panel-icon changes go. Two small fixes follow as separate PRs: WPA3/OWE classification (#13912 item 5) and a second splice() bug in the Wi-Fi code.

Sometimes a visual is helpful. Below is what I am running currently with all options turned on. The alignment is still an issue I can not get Claude to get quite right. This is what I will keep running on my box, but finding these issues seemed good to upstream as it was rather broken for my usages before.

image

(Drafted with help from Claude Opus 5.5.)

IvanTheGeek and others added 2 commits October 3, 2026 14:07
WireGuard connections had a section of their own, "WIREGUARD
Connections", backed by a copy of the VPN code (NMDeviceWIREGUARD) and
a panel-icon override of its own. To the user both lists hold the same
kind of thing, a tunnel on top of the real link, and the separate path
gets the panel wrong. The override keyed off the WireGuard title
switch, so the tooltip said "Connected to WIREGUARD" while a tunnel
was still connecting or already disconnecting. The override is also
older than the VPN icon from linuxmint#12142 (it came with linuxmint#11905), so with
Wi-Fi as the main connection a WireGuard tunnel replaced the signal
bars with the plain VPN icon, where a VPN-plugin connection shows the
Wi-Fi bars with a padlock.

List WireGuard connections under "VPN Connections" instead.
NMDeviceVPN accepts both types and WireGuard maps to the VPN category,
so WireGuard runs through the VPN code: the multiple-connection
handling from linuxmint#12930, the removal of deleted profiles that linuxmint#13847
copied for WireGuard, and the panel icon from linuxmint#12142. That icon shows
the Wi-Fi bars with a padlock when Wi-Fi is the main connection, the
VPN icon otherwise, and the acquiring icon while a tunnel connects.
NMDeviceWIREGUARD, the WIREGUARD category and the override go away.

Every row is now a switch that turns its own connection on or off, as
WireGuard rows have been since linuxmint#13911. VPN-plugin rows used to be
click-to-toggle items with a dot. Nameless connections still read
"Connected (private)", and WireGuard rows now follow a rename, as VPN
rows already did. The section's title switch keeps its code, so it now
covers both kinds: off disconnects every tunnel, WireGuard included,
and on starts the most recently used connection, which may now be a
WireGuard one.

This drops the three WIREGUARD strings and adds none.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
With WireGuard and VPN-plugin connections in one list, the name is all
a row has to go on, and connection names often do not say what kind
of tunnel they are. Show the kind next to the name, in the switch
row's status label: "WireGuard" for WireGuard connections, and for VPN
plugins a name looked up from the plugin's service type (OpenVPN,
PPTP, L2TP, OpenConnect, ...). A plugin that is not in the table shows
the last part of its service type, such as "iodine".

"WireGuard" reuses the translated string the applet already has for
the WireGuard device description. The plugin names are product and
protocol names and are left untranslated, so the change adds no
strings.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@IvanTheGeek
IvanTheGeek force-pushed the feature/network-applet-improvements branch from 1d59a9f to 86e91cd Compare October 3, 2026 18:07
@IvanTheGeek IvanTheGeek changed the title network applet: unified tunnel section, per-tunnel switches, band/encryption info, and settings (proposal — take any part or none) network applet: merge the WireGuard and VPN sections, label each row's kind Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants