Kristoffer Dalby
133f8142c6
noise: re-decide SSH check follow-up after verdict consumed
...
Closed verdict channel yields zero AuthVerdict, which Accept() treats as
success; a replayed follow-up was accepted even after Reject.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
925639b3aa
policy/v2: test unregistered users at every policy site
...
Each site must match the policy without them, and track their
registration and deletion.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
cb299184f7
servertest: check grant-v13 group via routes against SaaS
...
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
85c754a1ac
policy/v2: resolve unregistered users to an empty set
...
Callers bailing on the error dropped a whole group for one missing
member: via routes, SSH check, app grants, nodeAttrs.
Fixes #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
545322aec7
policy/v2: fail rejected-compile tests on an ambiguous user
...
A missing user will stop failing the compile.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
4776898029
state: roll back only registration fields on failed re-registration
...
Restoring the whole pre-update snapshot also reverted sessions that
connected during the failed write, stranding a live node offline.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
f7c8b4d93f
state: serialise IP backfill with node persistence
...
A persist between the backfill's database write and its NodeStore reload
wrote the old addresses back, silently undoing the backfill.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
84cf38ce24
derp/server: resolve the live DERP map in /bootstrap-dns
...
The handler captured the startup map, so hostnames added by
derp.auto_update never resolved.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
57358b7430
state: backfill only IPs into NodeStore
...
PutNode of the DB row dropped session state, stranding connected nodes
offline, and nil-dereferenced nodes without Hostinfo.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
9c34c0c90d
state: stop tag approval sorting the reported RequestTags
...
nodeToRegister.Tags aliased Hostinfo.RequestTags, so sort/compact rewrote
the stored Hostinfo ([b a a] became [a b ""]).
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
a99c8a030c
policy/v2: stop ViaRoutesForPeer appending into pm.pol.Grants
...
Readers share pm.pol under RLock; appending ACL grants into its spare
capacity raced between concurrent callers.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
5622b519b5
noise: test a decode failure at the capability floor
...
Nothing covered a body that clears the floor yet fails to decode. Dropping
or reordering that branch would run handleRegister on a half-decoded
request with no test failing.
Inline the single-use request builder into serveRegister and finish the
OversizedBody comment.
2026-10-07 11:10:23 +02:00
Kristoffer Dalby
ed8d546675
noise: check capability floor before handleRegister
...
Below-floor register got 400 only after logout, key use or auth-cache
write had run.
2026-10-07 11:10:23 +02:00
Kristoffer Dalby
b4d5cdd6aa
mapper: keep reconnect removals tracked until delivered
...
AddNode reset lastSentPeers before the queued removal went out, so a
superseding full or a disconnect before the tick lost it for good.
2026-10-07 11:09:47 +02:00
Kristoffer Dalby
f1293a805a
servertest: require via compat netmaps to hold across ticks
...
Accepting the first matching tick let a netmap that matched once and
then drifted pass. Require several consecutive passing ticks; a netmap
that settles still passes, so no assertion loosens.
2026-10-07 11:08:58 +02:00
Kristoffer Dalby
fdb3646b67
servertest: name filters in the via HA convergence comment
...
The PacketFilter rule count lags route approval as well, so say so, as
the map compat driver already does.
2026-10-07 11:08:58 +02:00
Kristoffer Dalby
74121aa339
servertest: retry via compat netmap comparison until converged
...
Peer count arrives before routes; compare-once raced route delivery.
2026-10-07 11:08:58 +02:00
Kristoffer Dalby
eeaac680be
mapper: drop DNSConfig from policy responses
...
It forced every client into a full netmap rebuild; the resolver race it
guarded against was a client bug (tailscale/tailscale#19749 ).
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
357f34a778
state: send a node's DNS config with its own refresh
...
Drained at dispatch for nodeAttrs changes from any policy, user or node
update, and for hostname/OS changes feeding NextDNS device metadata.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
59030f380d
servertest: cover a node's DNS config following its NextDNS inputs
...
Profile via policy reload or tag change, device metadata via hostname;
a hostname change today waits for the next policy response to reach DNS.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
60d42808b8
state: keep node removal apart from policy refresh in DeleteNode
...
Peers get the deletion as an explicit PeersRemoved change, independent of
their sent-peers tracking.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
1bd62737b9
mapper: send removed peers as their own delta
...
Removals derived from a policy change, full update or reconnect rode a
response whose DNSConfig, SSHPolicy, Node or Peers force a full rebuild.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
baca8309f1
servertest: reproduce removed peers missing from IPN bus deltas
...
Delta-only IPN bus watchers (the Android app since 1.100) miss removals
riding a full-rebuild response: deleted, policy-hidden, or while offline.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
90d3e0dd73
policy/v2: check cached per-node results against a fresh compile
...
Random node writes; every FilterForNode, MatchersForNode and SSHPolicy
read must match a PolicyManager built from the same nodes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
4fd766a431
policy/v2: leave the policy manager unchanged when a recompile fails
...
updateLocked runs every fallible step before writing pm, so a failed
SetUsers or SetNodes no longer leaves half a new filter live.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
edf5cc994e
policy/v2: drop per-node filter caches when users change
...
autogroup:self sources resolve users by name outside the filter hash,
so SetUsers left stale self rules cached and reported no change.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9526d74d61
state: send PolicyChange from SetApprovedRoutes only when visibility moved
...
Otherwise NodeAdded. Any SubnetRoutes/ExitRoutes change still bumps
NodesGeneration, so in practice only unannounced approvals narrow.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
c26f6e5255
state: approve routes inside the map request write
...
One NodeStore write, one peer build, one row update per
auto-approved map request, instead of a second SetApprovedRoutes write.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
21f6e46fb8
state: refresh policy nodes inside the peer map build
...
One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
311d9323e0
policy/v2: count node-driven recompiles
...
Lets a caller detect that its node write moved the policy when the
SetNodes ran on another goroutine.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
05fc17bc85
state: decide whole-peer updates at each caller, not in persist
...
persistNodeAndRefreshPolicy no longer fabricates NodeAdded; RenameNode
and SetNodeTags add it since both are peer visible.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
86b4f7c430
state,policy: add peer map and NodeStore write benchmarks
...
Cover BuildPeerMap, SetNodes, NodeStore writes and
UpdateNodeFromMapRequest across node counts and policy shapes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
d813144f3b
state: fail when a Node field is not classified for peer map reuse
...
Every exported types.Node field is pinned to relation/election/payload
in nodeFieldImpact; a new field fails until classified, and each
relation/election field gets a mutation check against updateChanges.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
1613023be9
state: check NodeStore adjacency against a full peer map build
...
Rapid test drives random writes through a real NodeStore and policy
manager, checking adjacency before and after syncPolicy against a
BuildPeerMap from a fresh policy manager.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9ce160ed5b
policy/v2: keep the live policy when SetPolicy fails to compile
...
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
3417e4cb77
policy/v2: add via exit node captures with unrelated rules
...
SaaS keeps via exit steering unless a rule reaches the internet, and
sends exit nodes every rule, with or without via.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
adbf4ba0f0
servertest: compare via capture filters as rule sets
...
Headscale merges rules sharing sources; SaaS does not. Compare
(src, dst, ports) triples, keyed by every captured node's addresses.
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7f5fdbe5d2
policy/v2: send exit nodes every user's autogroup:self rules
...
Same as other rules: exit routes contain every self destination.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
61d1599393
policyutil: send approved exit nodes every rule
...
Tailscale SaaS treats exit routes like subnet routes when reducing
filters; 0.0.0.0/0 contains every dst, so exit nodes get all rules.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7efd22d0bb
policy/v2: let autogroup:internet rules lift via exit steering
...
A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
c700b32eec
policy/v2: stop narrow rules from undoing via exit steering
...
Every address overlaps 0.0.0.0/0, so any regular rule matching the
viewer dropped the exclusion; only a wildcard dst now does.
Fixes #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
35a90e0018
derp: serve a self-signed TLS listener for tests
...
HEADSCALE_DEBUG_INSECURE_TLS_LISTEN_ADDR serves the router over throwaway TLS
and marks the embedded region InsecureForTests: TLS DERP for CA-less clients
(tailscale-rs, Android), plus the :443 noise fallback Go redials use.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
fbb04c5611
testcapture: read captures through util.ReadFileByExt
...
Drops its private HuJSON decoder.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
906016beb4
dns: pick the extra_records_path format by file extension
...
HuJSON and YAML records work too; an unknown extension fails instead of being
parsed as JSON.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
dd8ce695cf
derp: pick the derp.paths format by file extension
...
Adds JSON and HuJSON maps. JSON read as YAML decoded to an empty map; unknown
extensions and empty maps now fail at startup.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
d20a412079
util: decode files by their extension
...
UnmarshalByExt picks JSON, HuJSON or YAML from the file name; content can't
tell them apart, since YAML parses JSON syntax.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
90732bdaaf
derp: drop regions set to null in derp.paths
...
19d5d9de cloned regions while merging and skipped nil ones, so the documented
null-removal recipe silently kept the region.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
393dd3e2d9
db: store all credentials in one SHA-256-hashed table
...
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
2026-09-26 00:33:12 +02:00
Kristoffer Dalby
e90500e3a9
db: drop migrations predating 0.29
...
Only 0.29.x -> 0.30 upgrades are supported; checkMinimumMigration refuses
older databases instead of silently skipping the removed steps.
2026-09-26 00:33:12 +02:00
Michael Lopez
04d1e3c83f
db: name the nodes that block a user deletion
...
The error only said the user still has nodes, which the CLI prompt did
not mention at all. Wrap ErrUserStillHasNodes with the ID and hostname
of every blocking node so the operator knows what to remove. Run the
DestroyUser test table on Postgres as well as SQLite, since the two
schemas define different foreign-key actions; the Postgres variant
skips without a local server.
2026-09-25 23:56:02 +02:00