Kristoffer Dalby
925639b3aa
policy/v2: test unregistered users at every policy site
...
Each site must match the policy without them, and track their
registration and deletion.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
85c754a1ac
policy/v2: resolve unregistered users to an empty set
...
Callers bailing on the error dropped a whole group for one missing
member: via routes, SSH check, app grants, nodeAttrs.
Fixes #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
545322aec7
policy/v2: fail rejected-compile tests on an ambiguous user
...
A missing user will stop failing the compile.
Updates #3513
2026-10-07 11:10:51 +02:00
Kristoffer Dalby
a99c8a030c
policy/v2: stop ViaRoutesForPeer appending into pm.pol.Grants
...
Readers share pm.pol under RLock; appending ACL grants into its spare
capacity raced between concurrent callers.
2026-10-07 11:10:38 +02:00
Kristoffer Dalby
357f34a778
state: send a node's DNS config with its own refresh
...
Drained at dispatch for nodeAttrs changes from any policy, user or node
update, and for hostname/OS changes feeding NextDNS device metadata.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
90d3e0dd73
policy/v2: check cached per-node results against a fresh compile
...
Random node writes; every FilterForNode, MatchersForNode and SSHPolicy
read must match a PolicyManager built from the same nodes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
4fd766a431
policy/v2: leave the policy manager unchanged when a recompile fails
...
updateLocked runs every fallible step before writing pm, so a failed
SetUsers or SetNodes no longer leaves half a new filter live.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
edf5cc994e
policy/v2: drop per-node filter caches when users change
...
autogroup:self sources resolve users by name outside the filter hash,
so SetUsers left stale self rules cached and reported no change.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
21f6e46fb8
state: refresh policy nodes inside the peer map build
...
One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
311d9323e0
policy/v2: count node-driven recompiles
...
Lets a caller detect that its node write moved the policy when the
SetNodes ran on another goroutine.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
86b4f7c430
state,policy: add peer map and NodeStore write benchmarks
...
Cover BuildPeerMap, SetNodes, NodeStore writes and
UpdateNodeFromMapRequest across node counts and policy shapes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9ce160ed5b
policy/v2: keep the live policy when SetPolicy fails to compile
...
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
3417e4cb77
policy/v2: add via exit node captures with unrelated rules
...
SaaS keeps via exit steering unless a rule reaches the internet, and
sends exit nodes every rule, with or without via.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7f5fdbe5d2
policy/v2: send exit nodes every user's autogroup:self rules
...
Same as other rules: exit routes contain every self destination.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
61d1599393
policyutil: send approved exit nodes every rule
...
Tailscale SaaS treats exit routes like subnet routes when reducing
filters; 0.0.0.0/0 contains every dst, so exit nodes get all rules.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7efd22d0bb
policy/v2: let autogroup:internet rules lift via exit steering
...
A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
c700b32eec
policy/v2: stop narrow rules from undoing via exit steering
...
Every address overlaps 0.0.0.0/0, so any regular rule matching the
viewer dropped the exclusion; only a wildcard dst now does.
Fixes #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
393dd3e2d9
db: store all credentials in one SHA-256-hashed table
...
API keys, pre-auth keys and OAuth clients/tokens share one table and verify
path. Secrets carry 256 bits of crypto/rand entropy, so a SHA-256 digest
needs no stretching; bcrypt/argon2id rows rehash on use until 0.32.
2026-09-26 00:33:12 +02:00
Kristoffer Dalby
c604874dba
policy/v2: suggest approved exit nodes by default
...
Matches SaaS; Apple clients hide the exit-node list without a suggestion.
Fixes #3415
2026-09-23 14:48:45 +02:00
Kristoffer Dalby
06fa3075da
hscontrol: replace tailscale line refs with doc links
...
Line numbers drift on every upstream bump.
2026-09-23 14:48:45 +02:00
Kristoffer Dalby
0e8a3bba54
policy/v2: compare peer CapMap against SaaS route captures
...
SaaS stamps suggest-exit-node on approved exit peers without nodeAttrs.
Updates #3415
2026-09-23 14:48:45 +02:00
Kristoffer Dalby
e48bc46cc6
mapper: take peer visibility from the peer map only
...
Fixes #3408
2026-09-23 14:48:35 +02:00
Kristoffer Dalby
5861005ef6
policy/v2: add via exit node capture
...
Updates #3408
2026-09-23 14:48:35 +02:00
Kristoffer Dalby
5401edb6a8
policy: ignore '#' metadata fields across the whole policy
...
The filter lived in ACL.UnmarshalJSON, so grants, ssh and nodeAttrs still
hit RejectUnknownMembers. Strip the members in the HuJSON AST instead, at
the single decode entrypoint. Grant "app" payloads are left untouched.
Fixes #3479
2026-09-23 09:30:22 +02:00
Kristoffer Dalby
95ba787417
policy,state: key the peer map by node ID
...
Adjacency becomes immutable, so a snapshot can resolve peers through its
own fresh views instead of storing them.
Updates #3417
2026-09-10 13:06:13 +02:00
Kristoffer Dalby
be322e8ea7
policy,types: skip recompile when the user list is unchanged
...
SetUsers now also reports whether user-derived peer adjacency moved.
Updates #3417
2026-09-10 13:06:13 +02:00
Kristoffer Dalby
63123196cc
all: inline deprecated tailcfg capability aliases
...
go 1.27 vet reports the //go:fix inline directives tailscale added to
the tailcfg cap aliases; applied with `go fix -inline ./...`.
2026-08-25 21:59:00 +02:00
Kristoffer Dalby
1994f50fe8
policy/v2: drop elided struct types in test users
...
Promoted field keys let the literals skip the embedded gorm.Model.
2026-08-25 21:59:00 +02:00
Kristoffer Dalby
93e29ec38d
all: use strings.CutLast
...
Replaces LastIndex plus slice arithmetic when splitting on the last
separator.
2026-08-25 21:59:00 +02:00
Kristoffer Dalby
77caa94400
policy/v2: use value receiver for SSHCheckPeriod.Validate
...
recvcheck ignores UnmarshalJSON, so the pointer receiver here was the
odd one out against value-receiver MarshalJSON. Validate only reads.
2026-08-25 21:59:00 +02:00
Kristoffer Dalby
2c76d5c5b7
all: apply golangci-lint autofixes
...
Go 1.27 allows setting promoted fields of embedded structs directly in
composite literals, so gorm.Model wrappers go away. Plus strings.Cut,
errors.AsType, reflect.TypeAssert and one gofumpt nit.
2026-08-25 21:59:00 +02:00
Kristoffer Dalby
6275e3a356
policy,state: authorize reauth tags against the authenticating user
...
Re-authenticating a tagged node with --advertise-tags checked the tag-owned
node, not the authenticating user, so every tag was rejected.
Fixes #3374
2026-07-28 11:55:17 +02:00
alaningtrump
048308511c
chore: fix function comment to match actual function name
...
Signed-off-by: alaningtrump <alaningtrump@outlook.com >
2026-07-03 07:27:08 +02:00
Kristoffer Dalby
d528686f14
mapper,policy: add reconnect-storm and lock-concurrency regression tests
...
TestInitialMapNotStarvedByReconnectStorm reproduces the #3346 stall;
TestPolicyManagerConcurrentReads guards the RLock cache access under -race.
Updates #3346
2026-07-01 14:41:03 +02:00
Kristoffer Dalby
6f317c7576
policy: take RLock for reads so map generation runs concurrently
...
One exclusive mutex serialized every policy read, so a mass reconnect on
autogroup:self/via/relay policies stalled clients into "unexpected EOF"
retries. Per-node caches become xsync.Maps for lazy population under RLock.
Fixes #3346
2026-07-01 14:41:03 +02:00
Kristoffer Dalby
ee95cf58d9
hscontrol: add the OAuth client and access-token model
...
Add the OAuth client type, its database storage, the scope grant package,
policy tag-ownership exposure, and the state operations backing the v2
OAuth client-credentials flow.
2026-06-26 09:18:06 +02:00
Kristoffer Dalby
66937040f2
policy: allow the tailscale.com/cap/secrets capability
...
It's setec's official cap; allowlist it so it can be granted via policy.
2026-06-24 18:41:33 +02:00
Kristoffer Dalby
4fa6af0102
policy/v2: write the SSH check period as time arithmetic
...
Express the maximum SSH check period as 7 * 24 * time.Hour instead of a
bare nanosecond constant, matching how the rest of the code spells out
magic durations.
2026-06-21 04:17:03 +02:00
Kristoffer Dalby
4f4e95fc80
all: adopt strings, errors, and os helpers
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
27468f944b
all: adopt maps and cmp helpers
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
ac725f27e4
all: adopt slices helpers
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
fdc7e26c8a
util: consolidate parsing and encoding helpers
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
03e2d24c79
policy/v2, policy/matcher: consolidate alias and IP-set helpers
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
e6ef1dda4d
policy: consolidate cache-invalidation and evaluation helpers
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
ed6596f9d7
policy, mapper, capver, hscontrol: remove dead code
2026-06-17 16:12:19 +02:00
Kristoffer Dalby
40ed210521
policy: read pm.pol under the mutex
...
NodeCanHaveTag, TagExists, ViaRoutesForPeer checked pm.pol before
taking pm.mu, racing SetPolicy's write (caught by -race in
TestRaceConcurrentServerMutations). DebugString read pol, filter, and
the derived maps with no lock at all.
2026-06-11 16:28:25 +02:00
Kristoffer Dalby
020560fc5f
policy: remove unused top-level BuildPeerMap
...
Zero non-test callers; production uses policy/v2 PolicyManager.BuildPeerMap.
A stray second copy of the peer-visibility predicate invites drift.
2026-06-09 15:21:18 +02:00
Kristoffer Dalby
56cd3eb24d
policy: guard SSHCheckParams autogroup:self against nil User
...
The autogroup:self SSH-check branch dereferenced node.User().ID() guarded only by !IsTagged(); a non-tagged node with an unhydrated User (UserID set, association nil) crashed the server via the Noise SSH-check path. Gate on User().Valid() like filter.go, same shape as 171fd7a3 .
2026-06-09 15:21:18 +02:00
Kristoffer Dalby
2c9164b1c4
policy: precompute node routes in the peer-map build
...
CanAccess recomputed each node's routes per pair, making the scan O(n^2)-heavy.
2026-06-08 10:04:49 +02:00
Kristoffer Dalby
bceac495f9
policy: add NodeNeedsPeerRecompute predicate
...
Reports whether a node's online/offline transition forces peers to recompute their netmap. True for subnet routers, relay targets (tailscale.com/cap/relay), and via targets; false otherwise.
The relay-target IP set and via-target tag set are precompiled from the grants in updateLocked, alongside the existing filter, so the per-node check is a cheap set lookup. Keyed on the node itself, so an ordinary node in a tailnet that uses relay or via for other nodes is still classified as not needing a recompute.
Updates #3293
2026-06-03 14:51:57 +02:00