ipn/ipnlocal: route extra WireGuard AllowedIPs through the route manager
The conn25 extension's ExtraWireGuardAllowedIPs hook (Transit IPs) was only appended to wgcfg.Config.Peers in authReconfig. Now that outbound peer selection comes from the route manager's outbound table via the engine's PeerByIPPacketFunc (which, when installed, replaces wireguard-go's AllowedIPs trie lookup entirely) and lazily created peers get their allowed IPs from the route manager via the engine's peer config func, those extras never reached either path: outbound packets to Transit IPs matched no peer, and lazily created peers didn't accept inbound Transit IP sources. Teach the route manager a per-peer set of extra allowed IPs, staged by Mutation.SetExtraAllowedIPs. They appear in the outbound table and in PeerAllowedIPs (so both outbound routing and per-peer allowed source prefixes see them) but are excluded from the OS route set, preserving the hook's contract that the extras reach WireGuard but not the OS routing table. authReconfig now feeds the hook's results into the route manager and incrementally syncs any changed peers to the WireGuard device; the append to cfg.Peers remains only so Reconfig's full per-peer device sync doesn't strip the extras from active peers, and goes away with Config.Peers. Updates #12542 Change-Id: I06c8fa30929fbf8fe171a2d34c47c6fcc3abfa16 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
This commit is contained in:
committed by
Brad Fitzpatrick
parent
aff605d163
commit
6a635c4e55
@@ -938,6 +938,28 @@ func (nb *nodeBackend) updateRouteManagerPrefs(p routePrefs) (changedAllowedIPs
|
||||
return res.AllowedIPs
|
||||
}
|
||||
|
||||
// updateRouteManagerExtras pushes each peer's extra WireGuard-only
|
||||
// allowed IPs into the route manager, obtained by calling fn (the
|
||||
// [ipnext.Hooks.ExtraWireGuardAllowedIPs] hook) with each peer's
|
||||
// public key.
|
||||
//
|
||||
// It returns the peers whose allowed source prefixes changed as a
|
||||
// result, as described by [routemanager.Result.AllowedIPs].
|
||||
func (nb *nodeBackend) updateRouteManagerExtras(fn func(key.NodePublic) views.Slice[netip.Prefix]) (changedAllowedIPs map[key.NodePublic][]netip.Prefix) {
|
||||
nb.mu.Lock()
|
||||
defer nb.mu.Unlock()
|
||||
var extras map[tailcfg.NodeID][]netip.Prefix
|
||||
for id, p := range nb.peers {
|
||||
if pfxs := fn(p.Key()); pfxs.Len() > 0 {
|
||||
mak.Set(&extras, id, pfxs.AsSlice())
|
||||
}
|
||||
}
|
||||
rt := nb.routeMgr.Begin()
|
||||
rt.SetExtraAllowedIPs(extras)
|
||||
res := rt.Commit()
|
||||
return res.AllowedIPs
|
||||
}
|
||||
|
||||
// osRoutes returns the sorted set of prefixes that the route manager
|
||||
// wants programmed into the OS routing table.
|
||||
func (nb *nodeBackend) osRoutes() []netip.Prefix {
|
||||
|
||||
Reference in New Issue
Block a user