mirror of
https://github.com/juanfont/headscale.git
synced 2026-10-05 22:30:07 +09:00
policy/v2: let autogroup:internet rules lift via exit steering
A regular rule to the internet allows every exit node, but autogroup:internet resolves to no prefix, so it never matched. Updates #3493
This commit is contained in:
@@ -161,6 +161,11 @@ func TestViaInternetExitSteeringSurvivesUnrelatedRules(t *testing.T) {
|
|||||||
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`,
|
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`,
|
||||||
wantExcluded: true,
|
wantExcluded: true,
|
||||||
},
|
},
|
||||||
|
{
|
||||||
|
name: "acl-autogroup-internet",
|
||||||
|
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["autogroup:internet:*"]}],`,
|
||||||
|
wantExcluded: false,
|
||||||
|
},
|
||||||
{
|
{
|
||||||
name: "acl-wildcard",
|
name: "acl-wildcard",
|
||||||
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`,
|
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`,
|
||||||
|
|||||||
@@ -1437,10 +1437,14 @@ func (pm *PolicyManager) ViaRoutesForPeer(viewer, peer types.NodeView) types.Via
|
|||||||
}
|
}
|
||||||
|
|
||||||
// grantReachesInternet reports whether a grant's destinations include
|
// grantReachesInternet reports whether a grant's destinations include
|
||||||
// the internet. The wildcard resolves to tailnet ranges only, but in a
|
// the internet. Neither the wildcard nor autogroup:internet resolves
|
||||||
// destination it also covers the internet.
|
// to 0.0.0.0/0, so check the aliases themselves.
|
||||||
func grantReachesInternet(grant Grant) bool {
|
func grantReachesInternet(grant Grant) bool {
|
||||||
return slices.ContainsFunc(grant.Destinations, func(d Alias) bool {
|
return slices.ContainsFunc(grant.Destinations, func(d Alias) bool {
|
||||||
|
if ag, ok := d.(*AutoGroup); ok {
|
||||||
|
return ag.Is(AutoGroupInternet)
|
||||||
|
}
|
||||||
|
|
||||||
_, ok := d.(Asterix)
|
_, ok := d.(Asterix)
|
||||||
|
|
||||||
return ok
|
return ok
|
||||||
|
|||||||
Reference in New Issue
Block a user