Jonas Schwartz
519b4621f3
policy/v2: add Grant.HasVia and tighten the changelog entry
2026-10-08 12:43:45 +02:00
Jonas Schwartz
9d5ce0752f
policy/v2: resolve via-route grants lazily
...
With a via grant in the policy, ViaRoutesForPeer still resolved every
grant's sources and destinations up front. Non-via grants are only read
once a via grant has matched the peer, which is rare (the peer must
advertise a covered route), and destinations only for grants whose
sources match the viewer. Resolve each grant on first use instead.
BenchmarkViaRoutesForPeer, mean per peer (Apple M3 Pro):
policy nodes before after
via-mixed 100 9.5us 2.1us
via-mixed 1000 69.0us 11.6us
via 1000 8.1us 8.6us
2026-10-08 12:43:45 +02:00
Jonas Schwartz
f8018f177a
policy/v2: skip via resolution when the policy has no via grants
...
ViaRoutesForPeer runs for every peer of every map response. Before it
looks at Via, it converts every ACL to grants and resolves each grant's
sources and destinations against the whole node set. Only via grants
can add to the result and ACLs never carry via, so without a via grant
all of that work was discarded. On large tailnets it dominated map
generation. Return early instead.
BenchmarkViaRoutesForPeer, mean per peer (Apple M3 Pro):
policy nodes before after
global 1000 21.8us 9ns, 0 allocs
self 1000 45.0us 9ns, 0 allocs
via 1000 8.1us unchanged
via-mixed 1000 69.0us unchanged
Fixes #3512
2026-10-08 12:43:45 +02:00
Dan Cunningham
8798c9af83
hscontrol: never garbage collect an ephemeral node with a live session
...
A session arming the GC after a reconnect cancelled it left a stale timer.
Fixes #3535
Signed-off-by: Dan Cunningham <dan@digitaldan.com >
2026-10-08 12:14:58 +02:00
Kristoffer Dalby
4fd4da75f2
hscontrol: fix formatting after combining SSH policy changes
...
Updates #3517
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
8c66b76353
integration: block reused HA ping callback connections
...
Updates #3517
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
b8146aa7cd
tests: preserve SSH regressions after combining policy fixes
...
Updates #3517
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
b7aa328e0c
CHANGELOG: note SSH rule removal fix
...
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
785ba22c65
mapper: send SSHPolicy only when it changes for the connection
...
Any non-nil SSHPolicy forces a full client netmap rebuild; the empty
policy now sent to every node made each policy change one.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
41c137bb3b
noise: drop unused ErrNoAuthSession
...
Kept separate so the check-rule fix cherry-picks to 0.29.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
9de8e9103f
ci: regenerate integration test list
...
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
16c0e6b75a
integration: test SSH is denied once its rules are removed
...
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
957a332d5d
policy/v2: match the login user in SSHCheckParams
...
The client picks the check rule by login user; the server took the
first rule for the node pair, so a root login could get a 12h
localpart period instead of "always", or be approved after its rule
was removed while another user's rule remained. Hold URLs now carry
the concrete user: tailssh never expanded the encoded $LOCAL_USER.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
dceb584c89
noise: reject SSH checks the policy no longer requires
...
A stale check rule still held and accepted after login. Deny with a 200
Reject (tailssh retries errors); re-check after the verdict.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
03e723c611
policy/v2: find SSH check params for localpart self-access
...
compileSSHPolicy sends these check rules; SSHCheckParams missed them,
so they never auto-approved within checkPeriod.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
d7b333d2aa
mapper: send an empty SSH policy when compiling it fails
...
Fail closed; nil kept the client's previous rules.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
2a0823ca41
policy/v2: send an empty SSH policy when no rule applies
...
Nil SSHPolicy means "unchanged" to clients; removed rules stayed live.
Match SaaS: "rules":[].
Fixes #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
82df3e088a
servertest: test client drops SSH rules on policy removal
...
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
e98e9289d6
policy/v2: test SSH rule removal yields empty SSHPolicy
...
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
961535351f
policy/v2: check SSHPolicy nil vs empty against captures
...
Nil keeps client's old rules; empty clears them. Old normalization hid it.
Updates #3508
2026-10-08 10:29:23 +02:00
Kristoffer Dalby
48046dc9c5
mapper: allow unchanged self in the full-update ping test
...
Updates #3518
2026-10-07 23:36:16 +02:00
Kristoffer Dalby
2cd82ceb0c
CHANGELOG: note the own approved routes fix
...
Updates #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby
ea6b0bf0b7
mapper: reconcile self on policy recomputes
...
Self renders from the same state as peers, so leaving it out of policy
responses hid an exit node's approved routes until it reconnected.
Fixes #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby
ba413fca3d
state: return a node's primary routes in stable order
...
They came from map iteration, so an unchanged router rendered its self
node differently on every call.
Updates #3502
2026-10-07 23:36:16 +02:00
Kristoffer Dalby
31582dd2c2
CHANGELOG: link derp-admit to pull request
2026-10-07 22:55:03 +02:00
Kristoffer Dalby
e7bb90bac1
CHANGELOG: name both DERP verify paths
...
Embedded DERP verifies in-process, not through /verify.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby
541ef40c87
state: report unindexed node key instead of panicking
...
A missing key yields the zero NodeView; its ID() panicked inside a reader
goroutine and took down the test binary instead of failing with a diagnostic.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby
85bda7c2c9
types: drop unused Nodes.ContainsNodeKey
2026-10-07 22:55:03 +02:00
Kristoffer Dalby
7ffdba7175
hscontrol: admit DERP clients via NodeKey index
...
/verify scanned every node per DERP connect; use GetNodeByNodeKey.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby
bc7fe6b8eb
state: test NodeKey index agrees with node list
...
Covers put, rotation and payload writes on the reuse path, and delete.
2026-10-07 22:55:03 +02:00
Kristoffer Dalby
b35dd2238e
integration: reuse the prebuilt image for mock OIDC
...
Updates #3522
2026-10-07 18:11:07 +02:00
Kristoffer Dalby
0e20065f6d
CHANGELOG: link logtail to pull request
2026-10-07 18:11:07 +02:00
Kristoffer Dalby
29e18d80b4
docs: note the audit-log shutdown lasts until tailscale up
...
Clients that opt out of logging themselves hit it whatever logtail.enabled says.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby
da6c8f9dd3
CHANGELOG: say audit-log clients stay down after the logtail fix
2026-10-07 18:11:07 +02:00
Kristoffer Dalby
0c9186d4a3
hscontrol: send the logtail instruction on the expired-self frame
...
It opens a deleted node's stream in place of the initial map.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby
52a7f8c89c
mapper: send the logtail instruction on every full map
...
Full maps moved to buildFromChange and lost WithDebugConfig, so no
frame told clients to disable log upload. Enabled logtail sends nil.
2026-10-07 18:11:07 +02:00
Kristoffer Dalby
56e08f10e7
CHANGELOG: link ping-full to pull request
2026-10-07 15:25:25 +02:00
Kristoffer Dalby
85587e2e29
change: drop untargeted pings when collapsing to a full
...
The ping ID in the URL is the only authentication on the answer, so
rescuing an untargeted ping for every node would let any node answer
for another. Rescue a ping only for the node it targets.
2026-10-07 15:25:25 +02:00
Kristoffer Dalby
d4948da301
mapper: keep pings when a full update collapses pending changes
...
A full renders state at drain time but cannot carry a one-shot
PingRequest; queue each ping as a ping-only frame after the full.
2026-10-07 15:25:25 +02:00
Kristoffer Dalby
e93f5d6ee0
CHANGELOG: link pak-revalidate to pull request
2026-10-07 14:03:54 +02:00
Kristoffer Dalby
c4ce3f7d14
state: revalidate pre-auth key reuse when registration applies
2026-10-07 14:03:54 +02:00
Kristoffer Dalby
00d64db9ef
CHANGELOG: link ssh-verdict-once to pull request
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
b35cb278c8
CHANGELOG: reword SSH check replay fix
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
97c4bf264e
noise: repeat concurrent SSH verdict waiters test
...
Nothing signals that both waiters parked before FinishAuth, so one
pass mostly checks them one after the other.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
c9992efaca
noise: cover SSH verdict replay ledger and removed check
...
A replay must neither record auth for auto-approval nor, once the
pair is no longer under a check, be answered from the consumed
verdict.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
133f8142c6
noise: re-decide SSH check follow-up after verdict consumed
...
Closed verdict channel yields zero AuthVerdict, which Accept() treats as
success; a replayed follow-up was accepted even after Reject.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
2dcd5c876e
CHANGELOG: note unknown users in groups for 0.29.5
...
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
925639b3aa
policy/v2: test unregistered users at every policy site
...
Each site must match the policy without them, and track their
registration and deletion.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
cb299184f7
servertest: check grant-v13 group via routes against SaaS
...
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
85c754a1ac
policy/v2: resolve unregistered users to an empty set
...
Callers bailing on the error dropped a whole group for one missing
member: via routes, SSH check, app grants, nodeAttrs.
Fixes #3513
2026-10-07 11:10:51 +02:00