Commit Graph

464 Commits

Author SHA1 Message Date
LuoChen aaf4ccd8c9 util, types: parse unix_socket_permission strictly
Default "0o770" failed the base-8 parse and silently became 0700.
Invalid, unquoted or above-0777 values now fail config load.

Fixes #3529
2026-10-09 11:42:53 +02:00
Jonas Schwartz 519b4621f3 policy/v2: add Grant.HasVia and tighten the changelog entry 2026-10-08 12:43:45 +02:00
Jonas Schwartz f8018f177a policy/v2: skip via resolution when the policy has no via grants
ViaRoutesForPeer runs for every peer of every map response. Before it
looks at Via, it converts every ACL to grants and resolves each grant's
sources and destinations against the whole node set. Only via grants
can add to the result and ACLs never carry via, so without a via grant
all of that work was discarded. On large tailnets it dominated map
generation. Return early instead.

BenchmarkViaRoutesForPeer, mean per peer (Apple M3 Pro):

	policy     nodes  before    after
	global     1000   21.8us    9ns, 0 allocs
	self       1000   45.0us    9ns, 0 allocs
	via        1000   8.1us     unchanged
	via-mixed  1000   69.0us    unchanged

Fixes #3512
2026-10-08 12:43:45 +02:00
Dan Cunningham 8798c9af83 hscontrol: never garbage collect an ephemeral node with a live session
A session arming the GC after a reconnect cancelled it left a stale timer.

Fixes #3535
Signed-off-by: Dan Cunningham <dan@digitaldan.com>
2026-10-08 12:14:58 +02:00
Kristoffer Dalby b7aa328e0c CHANGELOG: note SSH rule removal fix
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 2cd82ceb0c CHANGELOG: note the own approved routes fix
Updates #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby 31582dd2c2 CHANGELOG: link derp-admit to pull request 2026-10-07 22:55:03 +02:00
Kristoffer Dalby e7bb90bac1 CHANGELOG: name both DERP verify paths
Embedded DERP verifies in-process, not through /verify.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby 7ffdba7175 hscontrol: admit DERP clients via NodeKey index
/verify scanned every node per DERP connect; use GetNodeByNodeKey.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby 0e20065f6d CHANGELOG: link logtail to pull request 2026-10-07 18:11:07 +02:00
Kristoffer Dalby da6c8f9dd3 CHANGELOG: say audit-log clients stay down after the logtail fix 2026-10-07 18:11:07 +02:00
Kristoffer Dalby 52a7f8c89c mapper: send the logtail instruction on every full map
Full maps moved to buildFromChange and lost WithDebugConfig, so no
frame told clients to disable log upload. Enabled logtail sends nil.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby 56e08f10e7 CHANGELOG: link ping-full to pull request 2026-10-07 15:25:25 +02:00
Kristoffer Dalby d4948da301 mapper: keep pings when a full update collapses pending changes
A full renders state at drain time but cannot carry a one-shot
PingRequest; queue each ping as a ping-only frame after the full.
2026-10-07 15:25:25 +02:00
Kristoffer Dalby e93f5d6ee0 CHANGELOG: link pak-revalidate to pull request 2026-10-07 14:03:54 +02:00
Kristoffer Dalby c4ce3f7d14 state: revalidate pre-auth key reuse when registration applies 2026-10-07 14:03:54 +02:00
Kristoffer Dalby 00d64db9ef CHANGELOG: link ssh-verdict-once to pull request 2026-10-07 12:50:32 +02:00
Kristoffer Dalby b35cb278c8 CHANGELOG: reword SSH check replay fix 2026-10-07 12:50:32 +02:00
Kristoffer Dalby 133f8142c6 noise: re-decide SSH check follow-up after verdict consumed
Closed verdict channel yields zero AuthVerdict, which Accept() treats as
success; a replayed follow-up was accepted even after Reject.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby 2dcd5c876e CHANGELOG: note unknown users in groups for 0.29.5
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby a9cc142ebe CHANGELOG: link register-floor to pull request 2026-10-07 11:10:23 +02:00
Kristoffer Dalby 060f2aa59b CHANGELOG: shorten register floor entry to one clause 2026-10-07 11:10:23 +02:00
Kristoffer Dalby ed8d546675 noise: check capability floor before handleRegister
Below-floor register got 400 only after logout, key use or auth-cache
write had run.
2026-10-07 11:10:23 +02:00
Kristoffer Dalby eeaac680be mapper: drop DNSConfig from policy responses
It forced every client into a full netmap rebuild; the resolver race it
guarded against was a client bug (tailscale/tailscale#19749).
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 1bd62737b9 mapper: send removed peers as their own delta
Removals derived from a policy change, full update or reconnect rode a
response whose DNSConfig, SSHPolicy, Node or Peers force a full rebuild.

Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 46a287d1f1 CHANGELOG: note fewer peer map builds per write 2026-09-30 17:21:02 +02:00
Kristoffer Dalby 200c2c01e8 nix: add a NixOS test kit for Tailscale clients
nixosModules.testkit makes a node a control server every client joins without
trust setup; testkit-peer joins it with hs-join.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby d48883ca9b nix: write split DNS where headscale reads it
module.nix emitted dns.split; headscale reads dns.nameservers.split, so the
typed option was silently ignored. Old path now asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby f0ff407c05 nix: stop module.nix writing the deprecated ephemeral key
Its default made headscale warn on every start. The camelCase rename now
targets node.ephemeral.inactivity_timeout, and the old path asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 62f89ca25d cli: accept a user name in preauthkeys create --user
Resolved through lookupUser like the users commands, so scripts skip the
users list round trip. Digit-only values stay IDs.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 906016beb4 dns: pick the extra_records_path format by file extension
HuJSON and YAML records work too; an unknown extension fails instead of being
parsed as JSON.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby dd8ce695cf derp: pick the derp.paths format by file extension
Adds JSON and HuJSON maps. JSON read as YAML decoded to an empty map; unknown
extensions and empty maps now fail at startup.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 90732bdaaf derp: drop regions set to null in derp.paths
19d5d9de cloned regions while merging and skipped nil ones, so the documented
null-removal recipe silently kept the region.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 393dd3e2d9 db: store all credentials in one SHA-256-hashed table
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
2026-09-26 00:33:12 +02:00
Kristoffer Dalby e90500e3a9 db: drop migrations predating 0.29
Only 0.29.x -> 0.30 upgrades are supported; checkMinimumMigration refuses
older databases instead of silently skipping the removed steps.
2026-09-26 00:33:12 +02:00
Michael Lopez 04d1e3c83f db: name the nodes that block a user deletion
The error only said the user still has nodes, which the CLI prompt did
not mention at all. Wrap ErrUserStillHasNodes with the ID and hostname
of every blocking node so the operator knows what to remove. Run the
DestroyUser test table on Postgres as well as SQLite, since the two
schemas define different foreign-key actions; the Postgres variant
skips without a local server.
2026-09-25 23:56:02 +02:00
Michael Lopez 3746ad20db cli: distinguish no match from ambiguous match when resolving users
resolveSingleUser reported every non-single result as "multiple users
match query", including zero matches. An explicit --identifier 0 was
sent to the API, which treats id=0 as no filter, so it listed every
user and failed as ambiguous. Return a not-found error for zero matches,
list the matching users when several match, and reject a non-positive
identifier before calling the API.
2026-09-25 20:00:15 +02:00
Kristoffer Dalby eebeab3c1e docs: document joining nodes with an OAuth client
Prefix swap, baseURL, every attribute; examples for tailscale up,
container, tsnet, GitHub Action.
2026-09-25 17:09:19 +02:00
Kristoffer Dalby f227d68781 CHANGELOG: align the 0.29.4 section with the release branch
#3472 and #3487 merged without a changelog entry, and the #3409 and
peer map entries landed under 0.30.0 although they ship in 0.29.4.
Sets the release date.
2026-09-23 21:22:20 +02:00
Kristoffer Dalby 435cf74d9e changelog: document config validation and listener error rework
Updates #3227
2026-09-23 15:18:34 +02:00
Kristoffer Dalby e48bc46cc6 mapper: take peer visibility from the peer map only
Fixes #3408
2026-09-23 14:48:35 +02:00
Kristoffer Dalby 5401edb6a8 policy: ignore '#' metadata fields across the whole policy
The filter lived in ACL.UnmarshalJSON, so grants, ssh and nodeAttrs still
hit RejectUnknownMembers. Strip the members in the HuJSON AST instead, at
the single decode entrypoint. Grant "app" payloads are left untouched.

Fixes #3479
2026-09-23 09:30:22 +02:00
Andrei Korviakov c90ba0f0d6 changelog: note the acmeLogger renewal fix 2026-09-15 14:37:20 +02:00
Andrei Korviakov 7472e98f6c hscontrol: keep the ACME error body readable in acmeLogger
acmeLogger drained and closed the body of every ACME error response before
handing the response back to golang.org/x/crypto/acme. The client parses that
body to classify errors, so badNonce was no longer recognised: isBadNonce
returned false, clearNonces was never called and Client.post treated the 400 as
non-retriable.

One badNonce reply therefore stops certificate renewal for good. autocert
retries every 30-60 minutes, each attempt reuses a nonce stored from the
previous failed response, that nonce has already expired, and the loop repeats
until the process is restarted or the certificate expires.

Restore the body with a fresh reader after logging it.
2026-09-15 14:37:20 +02:00
Kristoffer Dalby f91702d7ec CHANGELOG: note the peer map reuse
Updates #3417
2026-09-10 13:06:13 +02:00
Kristoffer Dalby f9f31c5e08 CHANGELOG: note narrower map request handling
Updates #3417
2026-09-10 13:06:13 +02:00
Kristoffer Dalby 67d018258b CHANGELOG: merge the duplicate 0.29.4 sections
Two 0.29.4 headings had appeared. Move the node deletion, OIDC reload and
OIDC callback hardening entries into it, since all three ship in 0.29.4.
2026-09-10 09:37:09 +02:00
Kristoffer Dalby 9c9686eacd CHANGELOG: note OIDC confirmation reload fix
Updates #3365
2026-09-09 19:01:43 +02:00
Kristoffer Dalby 475d3ae82c CHANGELOG: note the self-as-peer map fix 2026-09-09 18:18:53 +02:00
Kristoffer Dalby 754327dd6b CHANGELOG: node deletion now ends the client's session
Updates #3410
2026-09-09 18:18:17 +02:00