policy/v2: let autogroup:internet rules lift via exit steering

A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.

Updates #3493
This commit is contained in:
Kristoffer Dalby
2026-09-25 12:39:19 +00:00
parent c700b32eec
commit 7efd22d0bb
2 changed files with 11 additions and 2 deletions
+5
View File
@@ -161,6 +161,11 @@ func TestViaInternetExitSteeringSurvivesUnrelatedRules(t *testing.T) {
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`, extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["tag:exit-b:*"]}],`,
wantExcluded: true, wantExcluded: true,
}, },
{
name: "acl-autogroup-internet",
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["autogroup:internet:*"]}],`,
wantExcluded: false,
},
{ {
name: "acl-wildcard", name: "acl-wildcard",
extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`, extra: `"acls": [{"action": "accept", "src": ["autogroup:member"], "dst": ["*:*"]}],`,
+6 -2
View File
@@ -1437,10 +1437,14 @@ func (pm *PolicyManager) ViaRoutesForPeer(viewer, peer types.NodeView) types.Via
} }
// grantReachesInternet reports whether a grant's destinations include // grantReachesInternet reports whether a grant's destinations include
// the internet. The wildcard resolves to tailnet ranges only, but in a // the internet. Neither the wildcard nor autogroup:internet resolves
// destination it also covers the internet. // to 0.0.0.0/0, so check the aliases themselves.
func grantReachesInternet(grant Grant) bool { func grantReachesInternet(grant Grant) bool {
return slices.ContainsFunc(grant.Destinations, func(d Alias) bool { return slices.ContainsFunc(grant.Destinations, func(d Alias) bool {
if ag, ok := d.(*AutoGroup); ok {
return ag.Is(AutoGroupInternet)
}
_, ok := d.(Asterix) _, ok := d.(Asterix)
return ok return ok