diff --git a/hscontrol/policy/v2/issue_3233_test.go b/hscontrol/policy/v2/issue_3233_test.go index 6ddfe90d7..9a7924a5e 100644 --- a/hscontrol/policy/v2/issue_3233_test.go +++ b/hscontrol/policy/v2/issue_3233_test.go @@ -161,6 +161,11 @@ func TestViaInternetExitSteeringSurvivesUnrelatedRules(t *testing.T) { extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`, wantExcluded: true, }, + { + name: "acl-autogroup-internet", + extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["autogroup:internet:*"]}],`, + wantExcluded: false, + }, { name: "acl-wildcard", extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`, diff --git a/hscontrol/policy/v2/policy.go b/hscontrol/policy/v2/policy.go index 7a6cf30df..8aa228dc4 100644 --- a/hscontrol/policy/v2/policy.go +++ b/hscontrol/policy/v2/policy.go @@ -1437,10 +1437,14 @@ func (pm *PolicyManager) ViaRoutesForPeer(viewer, peer types.NodeView) types.Via } // grantReachesInternet reports whether a grant's destinations include -// the internet. The wildcard resolves to tailnet ranges only, but in a -// destination it also covers the internet. +// the internet. Neither the wildcard nor autogroup:internet resolves +// to 0.0.0.0/0, so check the aliases themselves. func grantReachesInternet(grant Grant) bool { return slices.ContainsFunc(grant.Destinations, func(d Alias) bool { + if ag, ok := d.(*AutoGroup); ok { + return ag.Is(AutoGroupInternet) + } + _, ok := d.(Asterix) return ok