Commit Graph

460 Commits

Author SHA1 Message Date
Kristoffer Dalby b7aa328e0c CHANGELOG: note SSH rule removal fix
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby 2cd82ceb0c CHANGELOG: note the own approved routes fix
Updates #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby 31582dd2c2 CHANGELOG: link derp-admit to pull request 2026-10-07 22:55:03 +02:00
Kristoffer Dalby e7bb90bac1 CHANGELOG: name both DERP verify paths
Embedded DERP verifies in-process, not through /verify.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby 7ffdba7175 hscontrol: admit DERP clients via NodeKey index
/verify scanned every node per DERP connect; use GetNodeByNodeKey.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby 0e20065f6d CHANGELOG: link logtail to pull request 2026-10-07 18:11:07 +02:00
Kristoffer Dalby da6c8f9dd3 CHANGELOG: say audit-log clients stay down after the logtail fix 2026-10-07 18:11:07 +02:00
Kristoffer Dalby 52a7f8c89c mapper: send the logtail instruction on every full map
Full maps moved to buildFromChange and lost WithDebugConfig, so no
frame told clients to disable log upload. Enabled logtail sends nil.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby 56e08f10e7 CHANGELOG: link ping-full to pull request 2026-10-07 15:25:25 +02:00
Kristoffer Dalby d4948da301 mapper: keep pings when a full update collapses pending changes
A full renders state at drain time but cannot carry a one-shot
PingRequest; queue each ping as a ping-only frame after the full.
2026-10-07 15:25:25 +02:00
Kristoffer Dalby e93f5d6ee0 CHANGELOG: link pak-revalidate to pull request 2026-10-07 14:03:54 +02:00
Kristoffer Dalby c4ce3f7d14 state: revalidate pre-auth key reuse when registration applies 2026-10-07 14:03:54 +02:00
Kristoffer Dalby 00d64db9ef CHANGELOG: link ssh-verdict-once to pull request 2026-10-07 12:50:32 +02:00
Kristoffer Dalby b35cb278c8 CHANGELOG: reword SSH check replay fix 2026-10-07 12:50:32 +02:00
Kristoffer Dalby 133f8142c6 noise: re-decide SSH check follow-up after verdict consumed
Closed verdict channel yields zero AuthVerdict, which Accept() treats as
success; a replayed follow-up was accepted even after Reject.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby 2dcd5c876e CHANGELOG: note unknown users in groups for 0.29.5
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby a9cc142ebe CHANGELOG: link register-floor to pull request 2026-10-07 11:10:23 +02:00
Kristoffer Dalby 060f2aa59b CHANGELOG: shorten register floor entry to one clause 2026-10-07 11:10:23 +02:00
Kristoffer Dalby ed8d546675 noise: check capability floor before handleRegister
Below-floor register got 400 only after logout, key use or auth-cache
write had run.
2026-10-07 11:10:23 +02:00
Kristoffer Dalby eeaac680be mapper: drop DNSConfig from policy responses
It forced every client into a full netmap rebuild; the resolver race it
guarded against was a client bug (tailscale/tailscale#19749).
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 1bd62737b9 mapper: send removed peers as their own delta
Removals derived from a policy change, full update or reconnect rode a
response whose DNSConfig, SSHPolicy, Node or Peers force a full rebuild.

Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 46a287d1f1 CHANGELOG: note fewer peer map builds per write 2026-09-30 17:21:02 +02:00
Kristoffer Dalby 200c2c01e8 nix: add a NixOS test kit for Tailscale clients
nixosModules.testkit makes a node a control server every client joins without
trust setup; testkit-peer joins it with hs-join.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby d48883ca9b nix: write split DNS where headscale reads it
module.nix emitted dns.split; headscale reads dns.nameservers.split, so the
typed option was silently ignored. Old path now asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby f0ff407c05 nix: stop module.nix writing the deprecated ephemeral key
Its default made headscale warn on every start. The camelCase rename now
targets node.ephemeral.inactivity_timeout, and the old path asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 62f89ca25d cli: accept a user name in preauthkeys create --user
Resolved through lookupUser like the users commands, so scripts skip the
users list round trip. Digit-only values stay IDs.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 906016beb4 dns: pick the extra_records_path format by file extension
HuJSON and YAML records work too; an unknown extension fails instead of being
parsed as JSON.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby dd8ce695cf derp: pick the derp.paths format by file extension
Adds JSON and HuJSON maps. JSON read as YAML decoded to an empty map; unknown
extensions and empty maps now fail at startup.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 90732bdaaf derp: drop regions set to null in derp.paths
19d5d9de cloned regions while merging and skipped nil ones, so the documented
null-removal recipe silently kept the region.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 393dd3e2d9 db: store all credentials in one SHA-256-hashed table
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
2026-09-26 00:33:12 +02:00
Kristoffer Dalby e90500e3a9 db: drop migrations predating 0.29
Only 0.29.x -> 0.30 upgrades are supported; checkMinimumMigration refuses
older databases instead of silently skipping the removed steps.
2026-09-26 00:33:12 +02:00
Michael Lopez 04d1e3c83f db: name the nodes that block a user deletion
The error only said the user still has nodes, which the CLI prompt did
not mention at all. Wrap ErrUserStillHasNodes with the ID and hostname
of every blocking node so the operator knows what to remove. Run the
DestroyUser test table on Postgres as well as SQLite, since the two
schemas define different foreign-key actions; the Postgres variant
skips without a local server.
2026-09-25 23:56:02 +02:00
Michael Lopez 3746ad20db cli: distinguish no match from ambiguous match when resolving users
resolveSingleUser reported every non-single result as "multiple users
match query", including zero matches. An explicit --identifier 0 was
sent to the API, which treats id=0 as no filter, so it listed every
user and failed as ambiguous. Return a not-found error for zero matches,
list the matching users when several match, and reject a non-positive
identifier before calling the API.
2026-09-25 20:00:15 +02:00
Kristoffer Dalby eebeab3c1e docs: document joining nodes with an OAuth client
Prefix swap, baseURL, every attribute; examples for tailscale up,
container, tsnet, GitHub Action.
2026-09-25 17:09:19 +02:00
Kristoffer Dalby f227d68781 CHANGELOG: align the 0.29.4 section with the release branch
#3472 and #3487 merged without a changelog entry, and the #3409 and
peer map entries landed under 0.30.0 although they ship in 0.29.4.
Sets the release date.
2026-09-23 21:22:20 +02:00
Kristoffer Dalby 435cf74d9e changelog: document config validation and listener error rework
Updates #3227
2026-09-23 15:18:34 +02:00
Kristoffer Dalby e48bc46cc6 mapper: take peer visibility from the peer map only
Fixes #3408
2026-09-23 14:48:35 +02:00
Kristoffer Dalby 5401edb6a8 policy: ignore '#' metadata fields across the whole policy
The filter lived in ACL.UnmarshalJSON, so grants, ssh and nodeAttrs still
hit RejectUnknownMembers. Strip the members in the HuJSON AST instead, at
the single decode entrypoint. Grant "app" payloads are left untouched.

Fixes #3479
2026-09-23 09:30:22 +02:00
Andrei Korviakov c90ba0f0d6 changelog: note the acmeLogger renewal fix 2026-09-15 14:37:20 +02:00
Andrei Korviakov 7472e98f6c hscontrol: keep the ACME error body readable in acmeLogger
acmeLogger drained and closed the body of every ACME error response before
handing the response back to golang.org/x/crypto/acme. The client parses that
body to classify errors, so badNonce was no longer recognised: isBadNonce
returned false, clearNonces was never called and Client.post treated the 400 as
non-retriable.

One badNonce reply therefore stops certificate renewal for good. autocert
retries every 30-60 minutes, each attempt reuses a nonce stored from the
previous failed response, that nonce has already expired, and the loop repeats
until the process is restarted or the certificate expires.

Restore the body with a fresh reader after logging it.
2026-09-15 14:37:20 +02:00
Kristoffer Dalby f91702d7ec CHANGELOG: note the peer map reuse
Updates #3417
2026-09-10 13:06:13 +02:00
Kristoffer Dalby f9f31c5e08 CHANGELOG: note narrower map request handling
Updates #3417
2026-09-10 13:06:13 +02:00
Kristoffer Dalby 67d018258b CHANGELOG: merge the duplicate 0.29.4 sections
Two 0.29.4 headings had appeared. Move the node deletion, OIDC reload and
OIDC callback hardening entries into it, since all three ship in 0.29.4.
2026-09-10 09:37:09 +02:00
Kristoffer Dalby 9c9686eacd CHANGELOG: note OIDC confirmation reload fix
Updates #3365
2026-09-09 19:01:43 +02:00
Kristoffer Dalby 475d3ae82c CHANGELOG: note the self-as-peer map fix 2026-09-09 18:18:53 +02:00
Kristoffer Dalby 754327dd6b CHANGELOG: node deletion now ends the client's session
Updates #3410
2026-09-09 18:18:17 +02:00
Saleh 95ba1f0566 types: lowercase DNS extra record names
DNS names are case-insensitive, but clients match extra records against
the lowercased query name, so records with mixed-case names (for example
"Printer.fritz.box" in an extra_records_path file) never resolved and
queries fell through to the global nameserver.

Normalize record names to lowercase where the records enter the tailcfg
DNS config, covering both dns.extra_records and extra_records_path.

Fixes #2782
2026-09-09 12:09:52 +02:00
Kristoffer Dalby 5f955cb4b4 CHANGELOG: add 0.29.4 section
Fixes backported to release-branch/0.29 had nowhere to go, so the users
rename entry opened a stray Fixes heading under 0.30.0. Add the 0.29.4
section and move the backported entries into it. Drop an empty link the
pre-commit and nix prettier disagree on.
2026-09-04 17:16:00 +02:00
Lukas Runge 0af4081444 docs: link the PR from the users rename changelog entry 2026-09-04 11:37:56 +02:00
Lukas Runge f790af27be docs: clarify the users rename changelog entry 2026-09-04 11:37:56 +02:00