policy/v2: send an empty SSH policy when no rule applies

Nil SSHPolicy means "unchanged" to clients; removed rules stayed live.
Match SaaS: "rules":[].

Fixes #3508
This commit is contained in:
Kristoffer Dalby
2026-10-02 08:57:20 +00:00
committed by Kristoffer Dalby
parent 82df3e088a
commit 2a0823ca41
3 changed files with 7 additions and 5 deletions
+1 -1
View File
@@ -458,7 +458,7 @@ func TestSSHPolicyRules(t *testing.T) {
}
]
}`,
wantSSH: &tailcfg.SSHPolicy{Rules: nil},
wantSSH: &tailcfg.SSHPolicy{Rules: []*tailcfg.SSHRule{}},
},
{
name: "invalid-action",
+5 -3
View File
@@ -261,13 +261,15 @@ func (pol *Policy) compileSSHPolicy(
node types.NodeView,
nodes views.Slice[types.NodeView],
) (*tailcfg.SSHPolicy, error) {
if pol == nil || pol.SSHs == nil || len(pol.SSHs) == 0 {
return nil, nil //nolint:nilnil // intentional: no SSH policy when none configured
// Never nil: clients read a nil SSHPolicy as "keep the previous
// rules", so revoked access would stay. SaaS sends "rules":[].
if pol == nil || len(pol.SSHs) == 0 {
return &tailcfg.SSHPolicy{Rules: []*tailcfg.SSHRule{}}, nil
}
log.Trace().Caller().Msgf("compiling SSH policy for node %q", node.Hostname())
var rules []*tailcfg.SSHRule
rules := []*tailcfg.SSHRule{}
for index, rule := range pol.SSHs {
var autogroupSelfDests, otherDests []Alias
+1 -1
View File
@@ -618,7 +618,7 @@ func TestCompileSSHPolicy_UserMapping(t *testing.T) {
},
},
},
want: &tailcfg.SSHPolicy{},
want: &tailcfg.SSHPolicy{Rules: []*tailcfg.SSHRule{}},
},
}