Kristoffer Dalby
97c4bf264e
noise: repeat concurrent SSH verdict waiters test
...
Nothing signals that both waiters parked before FinishAuth, so one
pass mostly checks them one after the other.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
c9992efaca
noise: cover SSH verdict replay ledger and removed check
...
A replay must neither record auth for auto-approval nor, once the
pair is no longer under a check, be answered from the consumed
verdict.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
133f8142c6
noise: re-decide SSH check follow-up after verdict consumed
...
Closed verdict channel yields zero AuthVerdict, which Accept() treats as
success; a replayed follow-up was accepted even after Reject.
2026-10-07 12:50:32 +02:00
Kristoffer Dalby
2dcd5c876e
CHANGELOG: note unknown users in groups for 0.29.5
...
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
925639b3aa
policy/v2: test unregistered users at every policy site
...
Each site must match the policy without them, and track their
registration and deletion.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
cb299184f7
servertest: check grant-v13 group via routes against SaaS
...
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
85c754a1ac
policy/v2: resolve unregistered users to an empty set
...
Callers bailing on the error dropped a whole group for one missing
member: via routes, SSH check, app grants, nodeAttrs.
Fixes #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
545322aec7
policy/v2: fail rejected-compile tests on an ambiguous user
...
A missing user will stop failing the compile.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
4776898029
state: roll back only registration fields on failed re-registration
...
Restoring the whole pre-update snapshot also reverted sessions that
connected during the failed write, stranding a live node offline.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
f7c8b4d93f
state: serialise IP backfill with node persistence
...
A persist between the backfill's database write and its NodeStore reload
wrote the old addresses back, silently undoing the backfill.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
84cf38ce24
derp/server: resolve the live DERP map in /bootstrap-dns
...
The handler captured the startup map, so hostnames added by
derp.auto_update never resolved.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
57358b7430
state: backfill only IPs into NodeStore
...
PutNode of the DB row dropped session state, stranding connected nodes
offline, and nil-dereferenced nodes without Hostinfo.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
9c34c0c90d
state: stop tag approval sorting the reported RequestTags
...
nodeToRegister.Tags aliased Hostinfo.RequestTags, so sort/compact rewrote
the stored Hostinfo ([b a a] became [a b ""]).
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
a99c8a030c
policy/v2: stop ViaRoutesForPeer appending into pm.pol.Grants
...
Readers share pm.pol under RLock; appending ACL grants into its spare
capacity raced between concurrent callers.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
a9cc142ebe
CHANGELOG: link register-floor to pull request
2026-10-07 11:10:23 +02:00
Kristoffer Dalby
060f2aa59b
CHANGELOG: shorten register floor entry to one clause
2026-10-07 11:10:23 +02:00
Kristoffer Dalby
5622b519b5
noise: test a decode failure at the capability floor
...
Nothing covered a body that clears the floor yet fails to decode. Dropping
or reordering that branch would run handleRegister on a half-decoded
request with no test failing.
Inline the single-use request builder into serveRegister and finish the
OversizedBody comment.
2026-10-07 11:10:23 +02:00
Kristoffer Dalby
ed8d546675
noise: check capability floor before handleRegister
...
Below-floor register got 400 only after logout, key use or auth-cache
write had run.
2026-10-07 11:10:23 +02:00
Kristoffer Dalby
b4d5cdd6aa
mapper: keep reconnect removals tracked until delivered
...
AddNode reset lastSentPeers before the queued removal went out, so a
superseding full or a disconnect before the tick lost it for good.
2026-10-07 11:09:47 +02:00
Kristoffer Dalby
f1293a805a
servertest: require via compat netmaps to hold across ticks
...
Accepting the first matching tick let a netmap that matched once and
then drifted pass. Require several consecutive passing ticks; a netmap
that settles still passes, so no assertion loosens.
2026-10-07 11:08:58 +02:00
Kristoffer Dalby
fdb3646b67
servertest: name filters in the via HA convergence comment
...
The PacketFilter rule count lags route approval as well, so say so, as
the map compat driver already does.
2026-10-07 11:08:58 +02:00
Kristoffer Dalby
74121aa339
servertest: retry via compat netmap comparison until converged
...
Peer count arrives before routes; compare-once raced route delivery.
2026-10-07 11:08:58 +02:00
github-actions[bot]
3e00a42bd2
Update VOUCHED list
...
https://github.com/juanfont/headscale/issues/3536#issuecomment-6033904453
2026-10-07 10:33:33 +02:00
Sandro
5f03627408
Update link to node attributes
2026-10-06 05:30:26 +02:00
Kristoffer Dalby
eeaac680be
mapper: drop DNSConfig from policy responses
...
It forced every client into a full netmap rebuild; the resolver race it
guarded against was a client bug (tailscale/tailscale#19749 ).
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
357f34a778
state: send a node's DNS config with its own refresh
...
Drained at dispatch for nodeAttrs changes from any policy, user or node
update, and for hostname/OS changes feeding NextDNS device metadata.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
59030f380d
servertest: cover a node's DNS config following its NextDNS inputs
...
Profile via policy reload or tag change, device metadata via hostname;
a hostname change today waits for the next policy response to reach DNS.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
60d42808b8
state: keep node removal apart from policy refresh in DeleteNode
...
Peers get the deletion as an explicit PeersRemoved change, independent of
their sent-peers tracking.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
1bd62737b9
mapper: send removed peers as their own delta
...
Removals derived from a policy change, full update or reconnect rode a
response whose DNSConfig, SSHPolicy, Node or Peers force a full rebuild.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
baca8309f1
servertest: reproduce removed peers missing from IPN bus deltas
...
Delta-only IPN bus watchers (the Android app since 1.100) miss removals
riding a full-rebuild response: deleted, policy-hidden, or while offline.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
611dc388e6
integration: wait for r2 to drop r1's route before pulling its cable
...
Headscale can report the new primary before r2 has the netmap; cutting r2
then strands r1's route in its table 52 and docker cannot set its gateway.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
46a287d1f1
CHANGELOG: note fewer peer map builds per write
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
90d3e0dd73
policy/v2: check cached per-node results against a fresh compile
...
Random node writes; every FilterForNode, MatchersForNode and SSHPolicy
read must match a PolicyManager built from the same nodes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
4fd766a431
policy/v2: leave the policy manager unchanged when a recompile fails
...
updateLocked runs every fallible step before writing pm, so a failed
SetUsers or SetNodes no longer leaves half a new filter live.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
edf5cc994e
policy/v2: drop per-node filter caches when users change
...
autogroup:self sources resolve users by name outside the filter hash,
so SetUsers left stale self rules cached and reported no change.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9526d74d61
state: send PolicyChange from SetApprovedRoutes only when visibility moved
...
Otherwise NodeAdded. Any SubnetRoutes/ExitRoutes change still bumps
NodesGeneration, so in practice only unannounced approvals narrow.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
c26f6e5255
state: approve routes inside the map request write
...
One NodeStore write, one peer build, one row update per
auto-approved map request, instead of a second SetApprovedRoutes write.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
21f6e46fb8
state: refresh policy nodes inside the peer map build
...
One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
311d9323e0
policy/v2: count node-driven recompiles
...
Lets a caller detect that its node write moved the policy when the
SetNodes ran on another goroutine.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
05fc17bc85
state: decide whole-peer updates at each caller, not in persist
...
persistNodeAndRefreshPolicy no longer fabricates NodeAdded; RenameNode
and SetNodeTags add it since both are peer visible.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
86b4f7c430
state,policy: add peer map and NodeStore write benchmarks
...
Cover BuildPeerMap, SetNodes, NodeStore writes and
UpdateNodeFromMapRequest across node counts and policy shapes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
d813144f3b
state: fail when a Node field is not classified for peer map reuse
...
Every exported types.Node field is pinned to relation/election/payload
in nodeFieldImpact; a new field fails until classified, and each
relation/election field gets a mutation check against updateChanges.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
1613023be9
state: check NodeStore adjacency against a full peer map build
...
Rapid test drives random writes through a real NodeStore and policy
manager, checking adjacency before and after syncPolicy against a
BuildPeerMap from a fresh policy manager.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9ce160ed5b
policy/v2: keep the live policy when SetPolicy fails to compile
...
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
3417e4cb77
policy/v2: add via exit node captures with unrelated rules
...
SaaS keeps via exit steering unless a rule reaches the internet, and
sends exit nodes every rule, with or without via.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
adbf4ba0f0
servertest: compare via capture filters as rule sets
...
Headscale merges rules sharing sources; SaaS does not. Compare
(src, dst, ports) triples, keyed by every captured node's addresses.
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7f5fdbe5d2
policy/v2: send exit nodes every user's autogroup:self rules
...
Same as other rules: exit routes contain every self destination.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
61d1599393
policyutil: send approved exit nodes every rule
...
Tailscale SaaS treats exit routes like subnet routes when reducing
filters; 0.0.0.0/0 contains every dst, so exit nodes get all rules.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7efd22d0bb
policy/v2: let autogroup:internet rules lift via exit steering
...
A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
c700b32eec
policy/v2: stop narrow rules from undoing via exit steering
...
Every address overlaps 0.0.0.0/0, so any regular rule matching the
viewer dropped the exclusion; only a wildcard dst now does.
Fixes #3493
2026-09-30 17:20:46 +02:00