ipn/ipnlocal, wgengine/wgcfg/nmcfg: stop building peer lists on delta path

Processing a peer add/remove delta still materialized the full netmap
(an O(n) slicesx.MapValues plus sort over all peers, at 10k+
peers in a large tailnet) twice per delta: once in UpdateNetmapDelta
purely to hand the self node to Engine.SetSelfNode, and once in
authReconfigLocked.

Neither needs peers anymore. SetSelfNode gets the self node from the
existing nodeBackend.Self accessor. authReconfigLocked only reads
self-node fields (SelfNode, NodeKey, GetAddresses, HasCap) now that
WireGuard peers ride the incremental route manager and per-peer config
source, so it can use the peers-free NetMap accessor.

That also makes nmcfg.WGCfg vestigial: since wgcfg.Config lost its
Peers field, its peer walk existed only to emit the [v1] skip logs
(expired peers, unselected exit nodes, unaccepted subnet routes),
duplicating filtering the route manager already does. Delete the
package and construct the two-field wgcfg.Config inline. The skip
logs go away; if they're missed, the route manager can log them
incrementally at upsert time instead of rescanning every peer on
every reconfig.

With this, the runtime.DidRange analysis (see the ts_rangehook test)
shows a delta netmap update performing no O(n) range loops except
updateRouteManagerExtras, and the delta phase of that test drops from
1.09s to 0.14s for 400 deltas at n=10000 (from 4.79s at the
start of this effort, before the incremental route manager work).

Updates #12542

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: Ia0e03ef9db0c988790b2c29de1f0505305e93f58
This commit is contained in:
Brad Fitzpatrick
2026-07-15 11:21:36 -04:00
committed by Brad Fitzpatrick
parent 3515b009c2
commit 4660a961eb
10 changed files with 36 additions and 161 deletions
+17 -21
View File
@@ -81,7 +81,6 @@ import (
"tailscale.com/wgengine/filter"
"tailscale.com/wgengine/filter/filtertype"
"tailscale.com/wgengine/wgcfg"
"tailscale.com/wgengine/wgcfg/nmcfg"
"tailscale.com/wgengine/wglog"
)
@@ -246,6 +245,17 @@ func newMagicStackWithKey(t testing.TB, logf logger.Logf, ln nettype.PacketListe
}
}
// wgCfgOf builds a test node's wgcfg.Config from its netmap the same
// way ipnlocal.authReconfigLocked does in production: just the private
// key and self addresses. Peers ride the per-peer config source
// instead; see [magicStack.Reconfig].
func wgCfgOf(pk key.NodePrivate, nm *netmap.NetworkMap) *wgcfg.Config {
return &wgcfg.Config{
PrivateKey: pk,
Addresses: nm.GetAddresses().AsSlice(),
}
}
// Reconfig applies cfg and peers to the stack's WireGuard device and
// tun-layer data plane. In production these flow from LocalBackend
// (via [tailscale.com/wgengine.Engine.Reconfig] and the live per-peer
@@ -259,8 +269,8 @@ func (s *magicStack) Reconfig(cfg *wgcfg.Config, peers []tailcfg.NodeView) error
rm := routemanager.New(nil)
mut := rm.Begin()
// Mirror the netmap.AllowSubnetRoutes flag the tests pass to
// nmcfg.WGCfg.
// Tests want subnet routes accepted, matching what production
// gets from Prefs.RouteAll.
mut.SetPrefs(routemanager.Prefs{RouteAll: true})
// idByKey stands in for nodeBackend's public-key-to-node-ID
// index, which LocalBackend uses to serve the engine's per-peer
@@ -412,12 +422,7 @@ func meshStacks(logf logger.Logf, mutateNetmap func(idx int, nm *netmap.NetworkM
for i, m := range ms {
nm := buildNetmapLocked(i)
m.conn.SetNetworkMap(nm.SelfNode, nm.Peers)
wg, err := nmcfg.WGCfg(ms[i].privateKey, nm, logf, 0, "")
if err != nil {
// We're too far from the *testing.T to be graceful,
// blow up. Shouldn't happen anyway.
panic(fmt.Sprintf("failed to construct wgcfg from netmap: %v", err))
}
wg := wgCfgOf(ms[i].privateKey, nm)
if err := m.Reconfig(wg, nm.Peers); err != nil {
if ctx.Err() != nil || errors.Is(err, errConnClosed) {
// shutdown race, don't care.
@@ -2568,10 +2573,7 @@ func TestIsWireGuardOnlyPeer(t *testing.T) {
}
m.conn.SetNetworkMap(nm.SelfNode, nm.Peers)
cfg, err := nmcfg.WGCfg(m.privateKey, nm, t.Logf, netmap.AllowSubnetRoutes, "")
if err != nil {
t.Fatal(err)
}
cfg := wgCfgOf(m.privateKey, nm)
m.Reconfig(cfg, nm.Peers)
pbuf := tuntest.Ping(wgaip.Addr(), tsaip.Addr())
@@ -2629,10 +2631,7 @@ func TestIsWireGuardOnlyPeerWithMasquerade(t *testing.T) {
}
m.conn.SetNetworkMap(nm.SelfNode, nm.Peers)
cfg, err := nmcfg.WGCfg(m.privateKey, nm, t.Logf, netmap.AllowSubnetRoutes, "")
if err != nil {
t.Fatal(err)
}
cfg := wgCfgOf(m.privateKey, nm)
m.Reconfig(cfg, nm.Peers)
pbuf := tuntest.Ping(wgaip.Addr(), tsaip.Addr())
@@ -2669,10 +2668,7 @@ func applyNetworkMap(t *testing.T, m *magicStack, nm *netmap.NetworkMap) {
m.conn.noV6.Store(true)
// Turn the network map into a wireguard config (for the tailscale internal wireguard device).
cfg, err := nmcfg.WGCfg(m.privateKey, nm, t.Logf, netmap.AllowSubnetRoutes, "")
if err != nil {
t.Fatal(err)
}
cfg := wgCfgOf(m.privateKey, nm)
// Apply the wireguard config to the tailscale internal wireguard device.
if err := m.Reconfig(cfg, nm.Peers); err != nil {
t.Fatal(err)
-117
View File
@@ -1,117 +0,0 @@
// Copyright (c) Tailscale Inc & contributors
// SPDX-License-Identifier: BSD-3-Clause
// Package nmcfg converts a controlclient.NetMap into a wgcfg config.
package nmcfg
import (
"bufio"
"cmp"
"fmt"
"net/netip"
"strings"
"tailscale.com/net/tsaddr"
"tailscale.com/tailcfg"
"tailscale.com/types/key"
"tailscale.com/types/logger"
"tailscale.com/types/netmap"
"tailscale.com/wgengine/wgcfg"
)
func nodeDebugName(n tailcfg.NodeView) string {
name, _, _ := strings.Cut(cmp.Or(n.Name(), n.Hostinfo().Hostname()), ".")
return name
}
// cidrIsSubnet reports whether cidr is a non-default-route subnet
// exported by node that is not one of its own self addresses.
func cidrIsSubnet(node tailcfg.NodeView, cidr netip.Prefix) bool {
if cidr.Bits() == 0 {
return false
}
if !cidr.IsSingleIP() {
return true
}
if tsaddr.IsTailscaleIP(cidr.Addr()) {
return false
}
for _, selfCIDR := range node.Addresses().All() {
if cidr == selfCIDR {
return false
}
}
return true
}
// WGCfg returns the NetworkMaps's WireGuard configuration.
//
// The config does not include peers; wireguard-go gets those from the
// live per-peer config source installed via
// [tailscale.com/wgengine.Engine.SetPeerConfigFunc], fed by the route
// manager. WGCfg still walks the peers to log which ones are not
// routable and why, mirroring the route manager's filtering.
func WGCfg(pk key.NodePrivate, nm *netmap.NetworkMap, logf logger.Logf, flags netmap.WGConfigFlags, exitNode tailcfg.StableNodeID) (*wgcfg.Config, error) {
cfg := &wgcfg.Config{
PrivateKey: pk,
Addresses: nm.GetAddresses().AsSlice(),
}
var skippedExitNode, skippedSubnetRouter, skippedExpired []tailcfg.NodeView
for _, peer := range nm.Peers {
if peer.DiscoKey().IsZero() && peer.HomeDERP() == 0 && !peer.IsWireGuardOnly() {
// Peer predates both DERP and active discovery, we cannot
// communicate with it.
logf("[v1] wgcfg: skipped peer %s, doesn't offer DERP or disco", peer.Key().ShortString())
continue
}
// Skip expired peers; we'll end up failing to connect to them
// anyway, since control intentionally breaks node keys for
// expired peers so that we can't discover endpoints via DERP.
if peer.Expired() {
skippedExpired = append(skippedExpired, peer)
continue
}
didExitNodeLog := false
for _, allowedIP := range peer.AllowedIPs().All() {
if allowedIP.Bits() == 0 && peer.StableID() != exitNode {
if didExitNodeLog {
// Don't log about both the IPv4 /0 and IPv6 /0.
continue
}
didExitNodeLog = true
skippedExitNode = append(skippedExitNode, peer)
} else if cidrIsSubnet(peer, allowedIP) {
if (flags & netmap.AllowSubnetRoutes) == 0 {
skippedSubnetRouter = append(skippedSubnetRouter, peer)
}
}
}
}
logList := func(title string, nodes []tailcfg.NodeView) {
if len(nodes) == 0 {
return
}
logf("[v1] wgcfg: %s from %d nodes: %s", title, len(nodes), logger.ArgWriter(func(bw *bufio.Writer) {
const max = 5
for i, n := range nodes {
if i == max {
fmt.Fprintf(bw, "... +%d", len(nodes)-max)
return
}
if i > 0 {
bw.WriteString(", ")
}
fmt.Fprintf(bw, "%s (%s)", nodeDebugName(n), n.StableID())
}
}))
}
logList("skipped unselected exit nodes", skippedExitNode)
logList("did not accept subnet routes", skippedSubnetRouter)
logList("skipped expired peers", skippedExpired)
return cfg, nil
}