From 7efd22d0bb36d5b155a598571aec5e184ee6a3cb Mon Sep 17 00:00:00 2001 From: Kristoffer Dalby Date: Fri, 25 Sep 2026 12:39:19 +0000 Subject: [PATCH] policy/v2: let autogroup:internet rules lift via exit steering A regular rule to the internet allows every exit node, but autogroup:internet resolves to no prefix, so it never matched. Updates #3493 --- hscontrol/policy/v2/issue_3233_test.go | 5 +++++ hscontrol/policy/v2/policy.go | 8 ++++++-- 2 files changed, 11 insertions(+), 2 deletions(-) diff --git a/hscontrol/policy/v2/issue_3233_test.go b/hscontrol/policy/v2/issue_3233_test.go index 6ddfe90d7..9a7924a5e 100644 --- a/hscontrol/policy/v2/issue_3233_test.go +++ b/hscontrol/policy/v2/issue_3233_test.go @@ -161,6 +161,11 @@ func TestViaInternetExitSteeringSurvivesUnrelatedRules(t *testing.T) { extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`, wantExcluded: true, }, + { + name: "acl-autogroup-internet", + extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["autogroup:internet:*"]}],`, + wantExcluded: false, + }, { name: "acl-wildcard", extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`, diff --git a/hscontrol/policy/v2/policy.go b/hscontrol/policy/v2/policy.go index 7a6cf30df..8aa228dc4 100644 --- a/hscontrol/policy/v2/policy.go +++ b/hscontrol/policy/v2/policy.go @@ -1437,10 +1437,14 @@ func (pm *PolicyManager) ViaRoutesForPeer(viewer, peer types.NodeView) types.Via } // grantReachesInternet reports whether a grant's destinations include -// the internet. The wildcard resolves to tailnet ranges only, but in a -// destination it also covers the internet. +// the internet. Neither the wildcard nor autogroup:internet resolves +// to 0.0.0.0/0, so check the aliases themselves. func grantReachesInternet(grant Grant) bool { return slices.ContainsFunc(grant.Destinations, func(d Alias) bool { + if ag, ok := d.(*AutoGroup); ok { + return ag.Is(AutoGroupInternet) + } + _, ok := d.(Asterix) return ok