mirror of
https://github.com/juanfont/headscale.git
synced 2026-10-05 22:30:07 +09:00
policy/v2: let autogroup:internet rules lift via exit steering
A regular rule to the internet allows every exit node, but autogroup:internet resolves to no prefix, so it never matched. Updates #3493
This commit is contained in:
@@ -161,6 +161,11 @@ func TestViaInternetExitSteeringSurvivesUnrelatedRules(t *testing.T) {
|
||||
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`,
|
||||
wantExcluded: true,
|
||||
},
|
||||
{
|
||||
name: "acl-autogroup-internet",
|
||||
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["autogroup:internet:*"]}],`,
|
||||
wantExcluded: false,
|
||||
},
|
||||
{
|
||||
name: "acl-wildcard",
|
||||
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`,
|
||||
|
||||
@@ -1437,10 +1437,14 @@ func (pm *PolicyManager) ViaRoutesForPeer(viewer, peer types.NodeView) types.Via
|
||||
}
|
||||
|
||||
// grantReachesInternet reports whether a grant's destinations include
|
||||
// the internet. The wildcard resolves to tailnet ranges only, but in a
|
||||
// destination it also covers the internet.
|
||||
// the internet. Neither the wildcard nor autogroup:internet resolves
|
||||
// to 0.0.0.0/0, so check the aliases themselves.
|
||||
func grantReachesInternet(grant Grant) bool {
|
||||
return slices.ContainsFunc(grant.Destinations, func(d Alias) bool {
|
||||
if ag, ok := d.(*AutoGroup); ok {
|
||||
return ag.Is(AutoGroupInternet)
|
||||
}
|
||||
|
||||
_, ok := d.(Asterix)
|
||||
|
||||
return ok
|
||||
|
||||
Reference in New Issue
Block a user