Rapid test drives random writes through a real NodeStore and policy
manager, checking adjacency before and after syncPolicy against a
BuildPeerMap from a fresh policy manager.
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
HEADSCALE_DEBUG_INSECURE_TLS_LISTEN_ADDR serves the router over throwaway TLS
and marks the embedded region InsecureForTests: TLS DERP for CA-less clients
(tailscale-rs, Android), plus the :443 noise fallback Go redials use.
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
The error only said the user still has nodes, which the CLI prompt did
not mention at all. Wrap ErrUserStillHasNodes with the ID and hostname
of every blocking node so the operator knows what to remove. Run the
DestroyUser test table on Postgres as well as SQLite, since the two
schemas define different foreign-key actions; the Postgres variant
skips without a local server.
resolveSingleUser reported every non-single result as "multiple users
match query", including zero matches. An explicit --identifier 0 was
sent to the API, which treats id=0 as no filter, so it listed every
user and failed as ambiguous. Return a not-found error for zero matches,
list the matching users when several match, and reject a non-positive
identifier before calling the API.
Stand up a nix-built headscale over self-signed TLS with embedded DERP and a
regular node joined via pre-auth, then drive the official tailscale/github-action
against it: connect over OAuth (tskey-client-) and an auth key with ping as the
success gate, and exercise its hostname, version, tailscaled-args, statedir and
args inputs.
The upstream tailscale client only runs its OAuth client-credentials exchange
for secrets prefixed tskey-client-, so accept it as an alias for hskey-client-.
The prefix is only a label sliced off before lookup, so the same stored client
authenticates under either; lets the official client and GitHub Action mint auth
keys against headscale.
Auto-close PRs from authors not listed in .github/VOUCHED.td. Issues
stay open to everyone; the close message points contributors at
CONTRIBUTING.md. Maintainers manage the list with !vouch, !denounce
and !unvouch comments, and a weekly job resyncs CODEOWNERS.
The workflows use GITHUB_TOKEN with explicit least-privilege
permissions.
Diffing go.mod catches a downgrade wherever selection produced it;
reading what go get printed only catches what go get did itself. The
lockstep partners are exempt, since repin lowers them on purpose.
`go get -u` takes the highest semver the proxy offers: a fork's stray tag
sorting above its real branch, or a module that has moved and kept
tagging under the old path. Resolving first refuses both, and names the
compare link for every version that does move.