Commit Graph

4609 Commits

Author SHA1 Message Date
Kristoffer Dalby eeaac680be mapper: drop DNSConfig from policy responses
It forced every client into a full netmap rebuild; the resolver race it
guarded against was a client bug (tailscale/tailscale#19749).
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 357f34a778 state: send a node's DNS config with its own refresh
Drained at dispatch for nodeAttrs changes from any policy, user or node
update, and for hostname/OS changes feeding NextDNS device metadata.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 59030f380d servertest: cover a node's DNS config following its NextDNS inputs
Profile via policy reload or tag change, device metadata via hostname;
a hostname change today waits for the next policy response to reach DNS.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 60d42808b8 state: keep node removal apart from policy refresh in DeleteNode
Peers get the deletion as an explicit PeersRemoved change, independent of
their sent-peers tracking.

Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 1bd62737b9 mapper: send removed peers as their own delta
Removals derived from a policy change, full update or reconnect rode a
response whose DNSConfig, SSHPolicy, Node or Peers force a full rebuild.

Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby baca8309f1 servertest: reproduce removed peers missing from IPN bus deltas
Delta-only IPN bus watchers (the Android app since 1.100) miss removals
riding a full-rebuild response: deleted, policy-hidden, or while offline.

Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby 611dc388e6 integration: wait for r2 to drop r1's route before pulling its cable
Headscale can report the new primary before r2 has the netmap; cutting r2
then strands r1's route in its table 52 and docker cannot set its gateway.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 46a287d1f1 CHANGELOG: note fewer peer map builds per write 2026-09-30 17:21:02 +02:00
Kristoffer Dalby 90d3e0dd73 policy/v2: check cached per-node results against a fresh compile
Random node writes; every FilterForNode, MatchersForNode and SSHPolicy
read must match a PolicyManager built from the same nodes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 4fd766a431 policy/v2: leave the policy manager unchanged when a recompile fails
updateLocked runs every fallible step before writing pm, so a failed
SetUsers or SetNodes no longer leaves half a new filter live.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby edf5cc994e policy/v2: drop per-node filter caches when users change
autogroup:self sources resolve users by name outside the filter hash,
so SetUsers left stale self rules cached and reported no change.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 9526d74d61 state: send PolicyChange from SetApprovedRoutes only when visibility moved
Otherwise NodeAdded. Any SubnetRoutes/ExitRoutes change still bumps
NodesGeneration, so in practice only unannounced approvals narrow.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby c26f6e5255 state: approve routes inside the map request write
One NodeStore write, one peer build, one row update per
auto-approved map request, instead of a second SetApprovedRoutes write.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 21f6e46fb8 state: refresh policy nodes inside the peer map build
One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 311d9323e0 policy/v2: count node-driven recompiles
Lets a caller detect that its node write moved the policy when the
SetNodes ran on another goroutine.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 05fc17bc85 state: decide whole-peer updates at each caller, not in persist
persistNodeAndRefreshPolicy no longer fabricates NodeAdded; RenameNode
and SetNodeTags add it since both are peer visible.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 86b4f7c430 state,policy: add peer map and NodeStore write benchmarks
Cover BuildPeerMap, SetNodes, NodeStore writes and
UpdateNodeFromMapRequest across node counts and policy shapes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby d813144f3b state: fail when a Node field is not classified for peer map reuse
Every exported types.Node field is pinned to relation/election/payload
in nodeFieldImpact; a new field fails until classified, and each
relation/election field gets a mutation check against updateChanges.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 1613023be9 state: check NodeStore adjacency against a full peer map build
Rapid test drives random writes through a real NodeStore and policy
manager, checking adjacency before and after syncPolicy against a
BuildPeerMap from a fresh policy manager.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 9ce160ed5b policy/v2: keep the live policy when SetPolicy fails to compile
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby 3417e4cb77 policy/v2: add via exit node captures with unrelated rules
SaaS keeps via exit steering unless a rule reaches the internet, and
sends exit nodes every rule, with or without via.

Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby adbf4ba0f0 servertest: compare via capture filters as rule sets
Headscale merges rules sharing sources; SaaS does not. Compare
(src, dst, ports) triples, keyed by every captured node's addresses.
2026-09-30 17:20:46 +02:00
Kristoffer Dalby 7f5fdbe5d2 policy/v2: send exit nodes every user's autogroup:self rules
Same as other rules: exit routes contain every self destination.

Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby 61d1599393 policyutil: send approved exit nodes every rule
Tailscale SaaS treats exit routes like subnet routes when reducing
filters; 0.0.0.0/0 contains every dst, so exit nodes get all rules.

Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby 7efd22d0bb policy/v2: let autogroup:internet rules lift via exit steering
A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.

Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby c700b32eec policy/v2: stop narrow rules from undoing via exit steering
Every address overlaps 0.0.0.0/0, so any regular rule matching the
viewer dropped the exclusion; only a wildcard dst now does.

Fixes #3493
2026-09-30 17:20:46 +02:00
yuwk 3486ab2fc2 docs: fix "is may be" grammar in policy reference
Signed-off-by: yuwk <1729065730@qq.com>
2026-09-29 18:30:38 +02:00
yuwk 32939914d3 docs: fix "specfic" typo in policy reference
Signed-off-by: yuwk <1729065730@qq.com>
2026-09-29 18:30:38 +02:00
github-actions[bot] 6d2fa015c4 Update VOUCHED list
https://github.com/juanfont/headscale/issues/3510#issuecomment-5890061652
2026-09-29 18:25:29 +02:00
Kristoffer Dalby 00663fbbfe nix: run the headscale VM test on the test kit
Drops nginx, the cert and dead ip_prefixes. Proves DERP relay and TLS noise
after a restart, and puts nix/module.nix under CI.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 200c2c01e8 nix: add a NixOS test kit for Tailscale clients
nixosModules.testkit makes a node a control server every client joins without
trust setup; testkit-peer joins it with hs-join.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 35a90e0018 derp: serve a self-signed TLS listener for tests
HEADSCALE_DEBUG_INSECURE_TLS_LISTEN_ADDR serves the router over throwaway TLS
and marks the embedded region InsecureForTests: TLS DERP for CA-less clients
(tailscale-rs, Android), plus the :443 noise fallback Go redials use.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 740f930523 nix: list flake systems explicitly
eachDefaultSystem includes x86_64-darwin, which nixpkgs dropped; nix flake
show failed evaluating it.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby d48883ca9b nix: write split DNS where headscale reads it
module.nix emitted dns.split; headscale reads dns.nameservers.split, so the
typed option was silently ignored. Old path now asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby f0ff407c05 nix: stop module.nix writing the deprecated ephemeral key
Its default made headscale warn on every start. The camelCase rename now
targets node.ephemeral.inactivity_timeout, and the old path asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 62f89ca25d cli: accept a user name in preauthkeys create --user
Resolved through lookupUser like the users commands, so scripts skip the
users list round trip. Digit-only values stay IDs.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 715c5a4a1c cli: split the user lookup out of resolveSingleUser
Lets commands with their own flags resolve a user the same way.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby fbb04c5611 testcapture: read captures through util.ReadFileByExt
Drops its private HuJSON decoder.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 906016beb4 dns: pick the extra_records_path format by file extension
HuJSON and YAML records work too; an unknown extension fails instead of being
parsed as JSON.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby dd8ce695cf derp: pick the derp.paths format by file extension
Adds JSON and HuJSON maps. JSON read as YAML decoded to an empty map; unknown
extensions and empty maps now fail at startup.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby d20a412079 util: decode files by their extension
UnmarshalByExt picks JSON, HuJSON or YAML from the file name; content can't
tell them apart, since YAML parses JSON syntax.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 90732bdaaf derp: drop regions set to null in derp.paths
19d5d9de cloned regions while merging and skipped nil ones, so the documented
null-removal recipe silently kept the region.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby 99cbba7aff .github: run the version bump daily
AGENTS.md says the tool "opens one pull request a day", but the workflow
only had workflow_dispatch, so since it merged it has run zero times.
2026-09-28 11:56:25 +02:00
github-actions[bot] 8af711b50e all: regenerate generated files 2026-09-28 07:28:19 +02:00
github-actions[bot] 3603418d70 .github: bump 13 action pins 2026-09-28 07:28:19 +02:00
github-actions[bot] f0591d9047 Dockerfile: bump rust 1.95-trixie to 1.98-trixie 2026-09-28 07:28:19 +02:00
github-actions[bot] adde0b6a4c Dockerfile: bump node 24-alpine to 26-alpine 2026-09-28 07:28:19 +02:00
github-actions[bot] 41dc3ae539 Dockerfile: bump alpine 3.23 to 3.24 2026-09-28 07:28:19 +02:00
github-actions[bot] 3512566963 Dockerfile: bump golang builders to 1.27.1 / 1.27.1 2026-09-28 07:28:19 +02:00
github-actions[bot] 30bc139820 go.mod: update dependencies 2026-09-28 07:28:19 +02:00