Kristoffer Dalby
eeaac680be
mapper: drop DNSConfig from policy responses
...
It forced every client into a full netmap rebuild; the resolver race it
guarded against was a client bug (tailscale/tailscale#19749 ).
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
357f34a778
state: send a node's DNS config with its own refresh
...
Drained at dispatch for nodeAttrs changes from any policy, user or node
update, and for hostname/OS changes feeding NextDNS device metadata.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
59030f380d
servertest: cover a node's DNS config following its NextDNS inputs
...
Profile via policy reload or tag change, device metadata via hostname;
a hostname change today waits for the next policy response to reach DNS.
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
60d42808b8
state: keep node removal apart from policy refresh in DeleteNode
...
Peers get the deletion as an explicit PeersRemoved change, independent of
their sent-peers tracking.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
1bd62737b9
mapper: send removed peers as their own delta
...
Removals derived from a policy change, full update or reconnect rode a
response whose DNSConfig, SSHPolicy, Node or Peers force a full rebuild.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
baca8309f1
servertest: reproduce removed peers missing from IPN bus deltas
...
Delta-only IPN bus watchers (the Android app since 1.100) miss removals
riding a full-rebuild response: deleted, policy-hidden, or while offline.
Updates tailscale/tailscale#15660
2026-09-30 19:03:13 +02:00
Kristoffer Dalby
611dc388e6
integration: wait for r2 to drop r1's route before pulling its cable
...
Headscale can report the new primary before r2 has the netmap; cutting r2
then strands r1's route in its table 52 and docker cannot set its gateway.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
46a287d1f1
CHANGELOG: note fewer peer map builds per write
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
90d3e0dd73
policy/v2: check cached per-node results against a fresh compile
...
Random node writes; every FilterForNode, MatchersForNode and SSHPolicy
read must match a PolicyManager built from the same nodes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
4fd766a431
policy/v2: leave the policy manager unchanged when a recompile fails
...
updateLocked runs every fallible step before writing pm, so a failed
SetUsers or SetNodes no longer leaves half a new filter live.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
edf5cc994e
policy/v2: drop per-node filter caches when users change
...
autogroup:self sources resolve users by name outside the filter hash,
so SetUsers left stale self rules cached and reported no change.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9526d74d61
state: send PolicyChange from SetApprovedRoutes only when visibility moved
...
Otherwise NodeAdded. Any SubnetRoutes/ExitRoutes change still bumps
NodesGeneration, so in practice only unannounced approvals narrow.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
c26f6e5255
state: approve routes inside the map request write
...
One NodeStore write, one peer build, one row update per
auto-approved map request, instead of a second SetApprovedRoutes write.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
21f6e46fb8
state: refresh policy nodes inside the peer map build
...
One peer build per tag/user/IP/route write; callers detect policy moves
via NodesGeneration. Per-node caches only store results for the node
pm holds, so a mapper reading mid-build cannot pin a stale filter.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
311d9323e0
policy/v2: count node-driven recompiles
...
Lets a caller detect that its node write moved the policy when the
SetNodes ran on another goroutine.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
05fc17bc85
state: decide whole-peer updates at each caller, not in persist
...
persistNodeAndRefreshPolicy no longer fabricates NodeAdded; RenameNode
and SetNodeTags add it since both are peer visible.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
86b4f7c430
state,policy: add peer map and NodeStore write benchmarks
...
Cover BuildPeerMap, SetNodes, NodeStore writes and
UpdateNodeFromMapRequest across node counts and policy shapes.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
d813144f3b
state: fail when a Node field is not classified for peer map reuse
...
Every exported types.Node field is pinned to relation/election/payload
in nodeFieldImpact; a new field fails until classified, and each
relation/election field gets a mutation check against updateChanges.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
1613023be9
state: check NodeStore adjacency against a full peer map build
...
Rapid test drives random writes through a real NodeStore and policy
manager, checking adjacency before and after syncPolicy against a
BuildPeerMap from a fresh policy manager.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
9ce160ed5b
policy/v2: keep the live policy when SetPolicy fails to compile
...
SetPolicy assigned the new policy before compiling it, so a compile that
failed partway left the rejected filter live while the stored policy stayed
old.
2026-09-30 17:21:02 +02:00
Kristoffer Dalby
3417e4cb77
policy/v2: add via exit node captures with unrelated rules
...
SaaS keeps via exit steering unless a rule reaches the internet, and
sends exit nodes every rule, with or without via.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
adbf4ba0f0
servertest: compare via capture filters as rule sets
...
Headscale merges rules sharing sources; SaaS does not. Compare
(src, dst, ports) triples, keyed by every captured node's addresses.
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7f5fdbe5d2
policy/v2: send exit nodes every user's autogroup:self rules
...
Same as other rules: exit routes contain every self destination.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
61d1599393
policyutil: send approved exit nodes every rule
...
Tailscale SaaS treats exit routes like subnet routes when reducing
filters; 0.0.0.0/0 contains every dst, so exit nodes get all rules.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
7efd22d0bb
policy/v2: let autogroup:internet rules lift via exit steering
...
A regular rule to the internet allows every exit node, but
autogroup:internet resolves to no prefix, so it never matched.
Updates #3493
2026-09-30 17:20:46 +02:00
Kristoffer Dalby
c700b32eec
policy/v2: stop narrow rules from undoing via exit steering
...
Every address overlaps 0.0.0.0/0, so any regular rule matching the
viewer dropped the exclusion; only a wildcard dst now does.
Fixes #3493
2026-09-30 17:20:46 +02:00
yuwk
3486ab2fc2
docs: fix "is may be" grammar in policy reference
...
Signed-off-by: yuwk <1729065730@qq.com >
2026-09-29 18:30:38 +02:00
yuwk
32939914d3
docs: fix "specfic" typo in policy reference
...
Signed-off-by: yuwk <1729065730@qq.com >
2026-09-29 18:30:38 +02:00
github-actions[bot]
6d2fa015c4
Update VOUCHED list
...
https://github.com/juanfont/headscale/issues/3510#issuecomment-5890061652
2026-09-29 18:25:29 +02:00
Kristoffer Dalby
00663fbbfe
nix: run the headscale VM test on the test kit
...
Drops nginx, the cert and dead ip_prefixes. Proves DERP relay and TLS noise
after a restart, and puts nix/module.nix under CI.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
200c2c01e8
nix: add a NixOS test kit for Tailscale clients
...
nixosModules.testkit makes a node a control server every client joins without
trust setup; testkit-peer joins it with hs-join.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
35a90e0018
derp: serve a self-signed TLS listener for tests
...
HEADSCALE_DEBUG_INSECURE_TLS_LISTEN_ADDR serves the router over throwaway TLS
and marks the embedded region InsecureForTests: TLS DERP for CA-less clients
(tailscale-rs, Android), plus the :443 noise fallback Go redials use.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
740f930523
nix: list flake systems explicitly
...
eachDefaultSystem includes x86_64-darwin, which nixpkgs dropped; nix flake
show failed evaluating it.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
d48883ca9b
nix: write split DNS where headscale reads it
...
module.nix emitted dns.split; headscale reads dns.nameservers.split, so the
typed option was silently ignored. Old path now asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
f0ff407c05
nix: stop module.nix writing the deprecated ephemeral key
...
Its default made headscale warn on every start. The camelCase rename now
targets node.ephemeral.inactivity_timeout, and the old path asserts.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
62f89ca25d
cli: accept a user name in preauthkeys create --user
...
Resolved through lookupUser like the users commands, so scripts skip the
users list round trip. Digit-only values stay IDs.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
715c5a4a1c
cli: split the user lookup out of resolveSingleUser
...
Lets commands with their own flags resolve a user the same way.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
fbb04c5611
testcapture: read captures through util.ReadFileByExt
...
Drops its private HuJSON decoder.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
906016beb4
dns: pick the extra_records_path format by file extension
...
HuJSON and YAML records work too; an unknown extension fails instead of being
parsed as JSON.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
dd8ce695cf
derp: pick the derp.paths format by file extension
...
Adds JSON and HuJSON maps. JSON read as YAML decoded to an empty map; unknown
extensions and empty maps now fail at startup.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
d20a412079
util: decode files by their extension
...
UnmarshalByExt picks JSON, HuJSON or YAML from the file name; content can't
tell them apart, since YAML parses JSON syntax.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
90732bdaaf
derp: drop regions set to null in derp.paths
...
19d5d9de cloned regions while merging and skipped nil ones, so the documented
null-removal recipe silently kept the region.
2026-09-28 21:42:19 +02:00
Kristoffer Dalby
99cbba7aff
.github: run the version bump daily
...
AGENTS.md says the tool "opens one pull request a day", but the workflow
only had workflow_dispatch, so since it merged it has run zero times.
2026-09-28 11:56:25 +02:00
github-actions[bot]
8af711b50e
all: regenerate generated files
2026-09-28 07:28:19 +02:00
github-actions[bot]
3603418d70
.github: bump 13 action pins
2026-09-28 07:28:19 +02:00
github-actions[bot]
f0591d9047
Dockerfile: bump rust 1.95-trixie to 1.98-trixie
2026-09-28 07:28:19 +02:00
github-actions[bot]
adde0b6a4c
Dockerfile: bump node 24-alpine to 26-alpine
2026-09-28 07:28:19 +02:00
github-actions[bot]
41dc3ae539
Dockerfile: bump alpine 3.23 to 3.24
2026-09-28 07:28:19 +02:00
github-actions[bot]
3512566963
Dockerfile: bump golang builders to 1.27.1 / 1.27.1
2026-09-28 07:28:19 +02:00
github-actions[bot]
30bc139820
go.mod: update dependencies
2026-09-28 07:28:19 +02:00