4683 Commits

Author SHA1 Message Date
Martin -nexus- Mlynář a8d6f5be81 state: send a relogin as a whole node unless only its keys changed
A PeerChange patch cannot clear a peer's Expired flag or carry the
Hostinfo the relogin stored.

Fixes #3531
2026-10-09 11:44:37 +02:00
Kristoffer Dalby 49b848a83d state: compare peer-visible Hostinfo through views
Field by field: no allocation, no reflection.

Updates #3531
2026-10-09 11:44:37 +02:00
Kristoffer Dalby 9c764e5a99 state: return the replaced node from NodeStore updates
UpdateNodeDiff hands back the pre-update clone the writer already makes.

Updates #3531
2026-10-09 11:44:37 +02:00
LuoChen aaf4ccd8c9 util, types: parse unix_socket_permission strictly
Default "0o770" failed the base-8 parse and silently became 0700.
Invalid, unquoted or above-0777 values now fail config load.

Fixes #3529
2026-10-09 11:42:53 +02:00
Kristoffer Dalby c9852c43da ci: distribute the compiled integration test binary 2026-10-09 11:41:09 +02:00
Kristoffer Dalby bcc71f9b57 integration: reuse images and remove redundant scenario setup 2026-10-09 11:41:09 +02:00
Kristoffer Dalby 47653f06fb integration: avoid toolchain work and login waits in CI 2026-10-09 11:41:09 +02:00
Jonas Schwartz 519b4621f3 policy/v2: add Grant.HasVia and tighten the changelog entry 2026-10-08 12:43:45 +02:00
Jonas Schwartz 9d5ce0752f policy/v2: resolve via-route grants lazily
With a via grant in the policy, ViaRoutesForPeer still resolved every
grant's sources and destinations up front. Non-via grants are only read
once a via grant has matched the peer, which is rare (the peer must
advertise a covered route), and destinations only for grants whose
sources match the viewer. Resolve each grant on first use instead.

BenchmarkViaRoutesForPeer, mean per peer (Apple M3 Pro):

	policy     nodes  before    after
	via-mixed  100    9.5us     2.1us
	via-mixed  1000   69.0us    11.6us
	via        1000   8.1us     8.6us
2026-10-08 12:43:45 +02:00
Jonas Schwartz f8018f177a policy/v2: skip via resolution when the policy has no via grants
ViaRoutesForPeer runs for every peer of every map response. Before it
looks at Via, it converts every ACL to grants and resolves each grant's
sources and destinations against the whole node set. Only via grants
can add to the result and ACLs never carry via, so without a via grant
all of that work was discarded. On large tailnets it dominated map
generation. Return early instead.

BenchmarkViaRoutesForPeer, mean per peer (Apple M3 Pro):

	policy     nodes  before    after
	global     1000   21.8us    9ns, 0 allocs
	self       1000   45.0us    9ns, 0 allocs
	via        1000   8.1us     unchanged
	via-mixed  1000   69.0us    unchanged

Fixes #3512
2026-10-08 12:43:45 +02:00
Dan Cunningham 8798c9af83 hscontrol: never garbage collect an ephemeral node with a live session
A session arming the GC after a reconnect cancelled it left a stale timer.

Fixes #3535
Signed-off-by: Dan Cunningham <dan@digitaldan.com>
2026-10-08 12:14:58 +02:00
Kristoffer Dalby 4fd4da75f2 hscontrol: fix formatting after combining SSH policy changes
Updates #3517
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 8c66b76353 integration: block reused HA ping callback connections
Updates #3517
2026-10-08 10:29:23 +02:00
Kristoffer Dalby b8146aa7cd tests: preserve SSH regressions after combining policy fixes
Updates #3517
2026-10-08 10:29:23 +02:00
Kristoffer Dalby b7aa328e0c CHANGELOG: note SSH rule removal fix
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 785ba22c65 mapper: send SSHPolicy only when it changes for the connection
Any non-nil SSHPolicy forces a full client netmap rebuild; the empty
policy now sent to every node made each policy change one.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 41c137bb3b noise: drop unused ErrNoAuthSession
Kept separate so the check-rule fix cherry-picks to 0.29.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 9de8e9103f ci: regenerate integration test list
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 16c0e6b75a integration: test SSH is denied once its rules are removed
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 957a332d5d policy/v2: match the login user in SSHCheckParams
The client picks the check rule by login user; the server took the
first rule for the node pair, so a root login could get a 12h
localpart period instead of "always", or be approved after its rule
was removed while another user's rule remained. Hold URLs now carry
the concrete user: tailssh never expanded the encoded $LOCAL_USER.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby dceb584c89 noise: reject SSH checks the policy no longer requires
A stale check rule still held and accepted after login. Deny with a 200
Reject (tailssh retries errors); re-check after the verdict.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 03e723c611 policy/v2: find SSH check params for localpart self-access
compileSSHPolicy sends these check rules; SSHCheckParams missed them,
so they never auto-approved within checkPeriod.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby d7b333d2aa mapper: send an empty SSH policy when compiling it fails
Fail closed; nil kept the client's previous rules.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 2a0823ca41 policy/v2: send an empty SSH policy when no rule applies
Nil SSHPolicy means "unchanged" to clients; removed rules stayed live.
Match SaaS: "rules":[].

Fixes #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 82df3e088a servertest: test client drops SSH rules on policy removal
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby e98e9289d6 policy/v2: test SSH rule removal yields empty SSHPolicy
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 961535351f policy/v2: check SSHPolicy nil vs empty against captures
Nil keeps client's old rules; empty clears them. Old normalization hid it.

Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 48046dc9c5 mapper: allow unchanged self in the full-update ping test
Updates #3518
2026-10-07 23:36:16 +02:00
Kristoffer Dalby 2cd82ceb0c CHANGELOG: note the own approved routes fix
Updates #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby ea6b0bf0b7 mapper: reconcile self on policy recomputes
Self renders from the same state as peers, so leaving it out of policy
responses hid an exit node's approved routes until it reconnected.

Fixes #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby ba413fca3d state: return a node's primary routes in stable order
They came from map iteration, so an unchanged router rendered its self
node differently on every call.

Updates #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby 31582dd2c2 CHANGELOG: link derp-admit to pull request 2026-10-07 22:55:03 +02:00
Kristoffer Dalby e7bb90bac1 CHANGELOG: name both DERP verify paths
Embedded DERP verifies in-process, not through /verify.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby 541ef40c87 state: report unindexed node key instead of panicking
A missing key yields the zero NodeView; its ID() panicked inside a reader
goroutine and took down the test binary instead of failing with a diagnostic.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby 85bda7c2c9 types: drop unused Nodes.ContainsNodeKey 2026-10-07 22:55:03 +02:00
Kristoffer Dalby 7ffdba7175 hscontrol: admit DERP clients via NodeKey index
/verify scanned every node per DERP connect; use GetNodeByNodeKey.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby bc7fe6b8eb state: test NodeKey index agrees with node list
Covers put, rotation and payload writes on the reuse path, and delete.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby b35dd2238e integration: reuse the prebuilt image for mock OIDC
Updates #3522
2026-10-07 18:11:07 +02:00
Kristoffer Dalby 0e20065f6d CHANGELOG: link logtail to pull request 2026-10-07 18:11:07 +02:00
Kristoffer Dalby 29e18d80b4 docs: note the audit-log shutdown lasts until tailscale up
Clients that opt out of logging themselves hit it whatever logtail.enabled says.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby da6c8f9dd3 CHANGELOG: say audit-log clients stay down after the logtail fix 2026-10-07 18:11:07 +02:00
Kristoffer Dalby 0c9186d4a3 hscontrol: send the logtail instruction on the expired-self frame
It opens a deleted node's stream in place of the initial map.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby 52a7f8c89c mapper: send the logtail instruction on every full map
Full maps moved to buildFromChange and lost WithDebugConfig, so no
frame told clients to disable log upload. Enabled logtail sends nil.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby 56e08f10e7 CHANGELOG: link ping-full to pull request 2026-10-07 15:25:25 +02:00
Kristoffer Dalby 85587e2e29 change: drop untargeted pings when collapsing to a full
The ping ID in the URL is the only authentication on the answer, so
rescuing an untargeted ping for every node would let any node answer
for another. Rescue a ping only for the node it targets.
2026-10-07 15:25:25 +02:00
Kristoffer Dalby d4948da301 mapper: keep pings when a full update collapses pending changes
A full renders state at drain time but cannot carry a one-shot
PingRequest; queue each ping as a ping-only frame after the full.
2026-10-07 15:25:25 +02:00
Kristoffer Dalby e93f5d6ee0 CHANGELOG: link pak-revalidate to pull request 2026-10-07 14:03:54 +02:00
Kristoffer Dalby c4ce3f7d14 state: revalidate pre-auth key reuse when registration applies 2026-10-07 14:03:54 +02:00
Kristoffer Dalby 00d64db9ef CHANGELOG: link ssh-verdict-once to pull request 2026-10-07 12:50:32 +02:00
Kristoffer Dalby b35cb278c8 CHANGELOG: reword SSH check replay fix 2026-10-07 12:50:32 +02:00