all: remove network lock references from private method names
Updates tailscale/corp#37904 Change-Id: I312d46d958209ca3d1152d1877fb91a57c91798d Signed-off-by: Alex Chan <alexc@tailscale.com>
This commit is contained in:
@@ -241,7 +241,7 @@ var (
|
|||||||
sysPolicyCmd,
|
sysPolicyCmd,
|
||||||
maybeWebCmd,
|
maybeWebCmd,
|
||||||
maybeDriveCmd,
|
maybeDriveCmd,
|
||||||
maybeNetlockCmd,
|
maybeTailnetLockCmd,
|
||||||
maybeFunnelCmd,
|
maybeFunnelCmd,
|
||||||
maybeServeCmd,
|
maybeServeCmd,
|
||||||
maybeCertCmd,
|
maybeCertCmd,
|
||||||
@@ -294,7 +294,7 @@ change in the future.
|
|||||||
nilOrCall(fileCmd),
|
nilOrCall(fileCmd),
|
||||||
bugReportCmd,
|
bugReportCmd,
|
||||||
nilOrCall(maybeCertCmd),
|
nilOrCall(maybeCertCmd),
|
||||||
nilOrCall(maybeNetlockCmd),
|
nilOrCall(maybeTailnetLockCmd),
|
||||||
licensesCmd,
|
licensesCmd,
|
||||||
exitNodeCmd(),
|
exitNodeCmd(),
|
||||||
nilOrCall(maybeUpdateCmd),
|
nilOrCall(maybeUpdateCmd),
|
||||||
|
|||||||
@@ -1614,7 +1614,7 @@ func TestParseNLArgs(t *testing.T) {
|
|||||||
|
|
||||||
for _, tc := range tcs {
|
for _, tc := range tcs {
|
||||||
t.Run(tc.name, func(t *testing.T) {
|
t.Run(tc.name, func(t *testing.T) {
|
||||||
keys, disablements, err := parseNLArgs(tc.input, tc.parseKeys, tc.parseDisablements)
|
keys, disablements, err := parseTLArgs(tc.input, tc.parseKeys, tc.parseDisablements)
|
||||||
if (tc.wantErr == nil && err != nil) ||
|
if (tc.wantErr == nil && err != nil) ||
|
||||||
(tc.wantErr != nil && err == nil) ||
|
(tc.wantErr != nil && err == nil) ||
|
||||||
(tc.wantErr != nil && err != nil && tc.wantErr.Error() != err.Error()) {
|
(tc.wantErr != nil && err != nil && tc.wantErr.Error() != err.Error()) {
|
||||||
|
|||||||
@@ -32,30 +32,30 @@ import (
|
|||||||
)
|
)
|
||||||
|
|
||||||
func init() {
|
func init() {
|
||||||
maybeNetlockCmd = func() *ffcli.Command { return netlockCmd }
|
maybeTailnetLockCmd = func() *ffcli.Command { return tailnetLockCmd }
|
||||||
}
|
}
|
||||||
|
|
||||||
var netlockCmd = &ffcli.Command{
|
var tailnetLockCmd = &ffcli.Command{
|
||||||
Name: "lock",
|
Name: "lock",
|
||||||
ShortUsage: "tailscale lock <subcommand> [arguments...]",
|
ShortUsage: "tailscale lock <subcommand> [arguments...]",
|
||||||
ShortHelp: "Manage tailnet lock",
|
ShortHelp: "Manage tailnet lock",
|
||||||
LongHelp: "Manage tailnet lock",
|
LongHelp: "Manage tailnet lock",
|
||||||
Subcommands: []*ffcli.Command{
|
Subcommands: []*ffcli.Command{
|
||||||
nlInitCmd,
|
tlInitCmd,
|
||||||
nlStatusCmd,
|
tlStatusCmd,
|
||||||
nlAddCmd,
|
tlAddCmd,
|
||||||
nlRemoveCmd,
|
tlRemoveCmd,
|
||||||
nlSignCmd,
|
tlSignCmd,
|
||||||
nlDisableCmd,
|
tlDisableCmd,
|
||||||
nlDisablementKDFCmd,
|
tlDisablementKDFCmd,
|
||||||
nlLogCmd,
|
tlLogCmd,
|
||||||
nlLocalDisableCmd,
|
tlLocalDisableCmd,
|
||||||
nlRevokeKeysCmd,
|
tlRevokeKeysCmd,
|
||||||
},
|
},
|
||||||
Exec: runNetworkLockNoSubcommand,
|
Exec: runTailnetLockNoSubcommand,
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockNoSubcommand(ctx context.Context, args []string) error {
|
func runTailnetLockNoSubcommand(ctx context.Context, args []string) error {
|
||||||
// Detect & handle the deprecated command 'lock tskey-wrap'.
|
// Detect & handle the deprecated command 'lock tskey-wrap'.
|
||||||
if len(args) >= 2 && args[0] == "tskey-wrap" {
|
if len(args) >= 2 && args[0] == "tskey-wrap" {
|
||||||
return runTskeyWrapCmd(ctx, args[1:])
|
return runTskeyWrapCmd(ctx, args[1:])
|
||||||
@@ -64,7 +64,7 @@ func runNetworkLockNoSubcommand(ctx context.Context, args []string) error {
|
|||||||
return fmt.Errorf("tailscale lock: unknown subcommand: %s", args[0])
|
return fmt.Errorf("tailscale lock: unknown subcommand: %s", args[0])
|
||||||
}
|
}
|
||||||
|
|
||||||
return runNetworkLockStatus(ctx, args)
|
return runTailnetLockStatus(ctx, args)
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlInitArgs struct {
|
var nlInitArgs struct {
|
||||||
@@ -73,7 +73,7 @@ var nlInitArgs struct {
|
|||||||
confirm bool
|
confirm bool
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlInitCmd = &ffcli.Command{
|
var tlInitCmd = &ffcli.Command{
|
||||||
Name: "init",
|
Name: "init",
|
||||||
ShortUsage: "tailscale lock init [--gen-disablement-for-support] --gen-disablements N <trusted-key>...",
|
ShortUsage: "tailscale lock init [--gen-disablement-for-support] --gen-disablements N <trusted-key>...",
|
||||||
ShortHelp: "Initialize tailnet lock",
|
ShortHelp: "Initialize tailnet lock",
|
||||||
@@ -98,7 +98,7 @@ will be generated and transmitted to Tailscale, which support can use to disable
|
|||||||
tailnet lock. We recommend setting this flag.
|
tailnet lock. We recommend setting this flag.
|
||||||
|
|
||||||
`),
|
`),
|
||||||
Exec: runNetworkLockInit,
|
Exec: runTailnetLockInit,
|
||||||
FlagSet: (func() *flag.FlagSet {
|
FlagSet: (func() *flag.FlagSet {
|
||||||
fs := newFlagSet("lock init")
|
fs := newFlagSet("lock init")
|
||||||
fs.IntVar(&nlInitArgs.numDisablements, "gen-disablements", 1, "number of disablement secrets to generate")
|
fs.IntVar(&nlInitArgs.numDisablements, "gen-disablements", 1, "number of disablement secrets to generate")
|
||||||
@@ -108,7 +108,7 @@ tailnet lock. We recommend setting this flag.
|
|||||||
})(),
|
})(),
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockInit(ctx context.Context, args []string) error {
|
func runTailnetLockInit(ctx context.Context, args []string) error {
|
||||||
st, err := localClient.NetworkLockStatus(ctx)
|
st, err := localClient.NetworkLockStatus(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fixTailscaledConnectError(err)
|
return fixTailscaledConnectError(err)
|
||||||
@@ -118,7 +118,7 @@ func runNetworkLockInit(ctx context.Context, args []string) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Parse initially-trusted keys & disablement values.
|
// Parse initially-trusted keys & disablement values.
|
||||||
keys, disablementValues, err := parseNLArgs(args, true, true)
|
keys, disablementValues, err := parseTLArgs(args, true, true)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -198,11 +198,11 @@ var nlStatusArgs struct {
|
|||||||
json jsonoutput.JSONSchemaVersion
|
json jsonoutput.JSONSchemaVersion
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlStatusCmd = &ffcli.Command{
|
var tlStatusCmd = &ffcli.Command{
|
||||||
Name: "status",
|
Name: "status",
|
||||||
ShortUsage: "tailscale lock status",
|
ShortUsage: "tailscale lock status",
|
||||||
ShortHelp: "Output the state of tailnet lock",
|
ShortHelp: "Output the state of tailnet lock",
|
||||||
Exec: runNetworkLockStatus,
|
Exec: runTailnetLockStatus,
|
||||||
FlagSet: (func() *flag.FlagSet {
|
FlagSet: (func() *flag.FlagSet {
|
||||||
fs := newFlagSet("lock status")
|
fs := newFlagSet("lock status")
|
||||||
fs.Var(&nlStatusArgs.json, "json", "output in JSON format")
|
fs.Var(&nlStatusArgs.json, "json", "output in JSON format")
|
||||||
@@ -210,7 +210,7 @@ var nlStatusCmd = &ffcli.Command{
|
|||||||
})(),
|
})(),
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockStatus(ctx context.Context, args []string) error {
|
func runTailnetLockStatus(ctx context.Context, args []string) error {
|
||||||
if len(args) > 0 {
|
if len(args) > 0 {
|
||||||
return fmt.Errorf("tailscale lock status: unexpected argument")
|
return fmt.Errorf("tailscale lock status: unexpected argument")
|
||||||
}
|
}
|
||||||
@@ -301,22 +301,22 @@ func runNetworkLockStatus(ctx context.Context, args []string) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlAddCmd = &ffcli.Command{
|
var tlAddCmd = &ffcli.Command{
|
||||||
Name: "add",
|
Name: "add",
|
||||||
ShortUsage: "tailscale lock add <public-key>...",
|
ShortUsage: "tailscale lock add <public-key>...",
|
||||||
ShortHelp: "Add one or more trusted signing keys to tailnet lock",
|
ShortHelp: "Add one or more trusted signing keys to tailnet lock",
|
||||||
Exec: runNetworkLockAdd,
|
Exec: runTailnetLockAdd,
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlRemoveArgs struct {
|
var nlRemoveArgs struct {
|
||||||
resign bool
|
resign bool
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlRemoveCmd = &ffcli.Command{
|
var tlRemoveCmd = &ffcli.Command{
|
||||||
Name: "remove",
|
Name: "remove",
|
||||||
ShortUsage: "tailscale lock remove [--re-sign=false] <public-key>...",
|
ShortUsage: "tailscale lock remove [--re-sign=false] <public-key>...",
|
||||||
ShortHelp: "Remove one or more trusted signing keys from tailnet lock",
|
ShortHelp: "Remove one or more trusted signing keys from tailnet lock",
|
||||||
Exec: runNetworkLockRemove,
|
Exec: runTailnetLockRemove,
|
||||||
FlagSet: (func() *flag.FlagSet {
|
FlagSet: (func() *flag.FlagSet {
|
||||||
fs := newFlagSet("lock remove")
|
fs := newFlagSet("lock remove")
|
||||||
fs.BoolVar(&nlRemoveArgs.resign, "re-sign", true, "resign signatures which would be invalidated by removal of trusted signing keys")
|
fs.BoolVar(&nlRemoveArgs.resign, "re-sign", true, "resign signatures which would be invalidated by removal of trusted signing keys")
|
||||||
@@ -324,8 +324,8 @@ var nlRemoveCmd = &ffcli.Command{
|
|||||||
})(),
|
})(),
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockRemove(ctx context.Context, args []string) error {
|
func runTailnetLockRemove(ctx context.Context, args []string) error {
|
||||||
removeKeys, _, err := parseNLArgs(args, true, false)
|
removeKeys, _, err := parseTLArgs(args, true, false)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -399,7 +399,7 @@ of the Tailscale network. Proceed with caution.
|
|||||||
return localClient.NetworkLockModify(ctx, nil, removeKeys)
|
return localClient.NetworkLockModify(ctx, nil, removeKeys)
|
||||||
}
|
}
|
||||||
|
|
||||||
// parseNLArgs parses a slice of strings into slices of tka.Key & disablement
|
// parseTLArgs parses a slice of strings into slices of tka.Key & disablement
|
||||||
// values/secrets.
|
// values/secrets.
|
||||||
// The keys encoded in args should be specified using their key.NLPublic.MarshalText
|
// The keys encoded in args should be specified using their key.NLPublic.MarshalText
|
||||||
// representation with an optional '?<votes>' suffix.
|
// representation with an optional '?<votes>' suffix.
|
||||||
@@ -408,7 +408,7 @@ of the Tailscale network. Proceed with caution.
|
|||||||
//
|
//
|
||||||
// If any element could not be parsed,
|
// If any element could not be parsed,
|
||||||
// a nil slice is returned along with an appropriate error.
|
// a nil slice is returned along with an appropriate error.
|
||||||
func parseNLArgs(args []string, parseKeys, parseDisablements bool) (keys []tka.Key, disablements [][]byte, err error) {
|
func parseTLArgs(args []string, parseKeys, parseDisablements bool) (keys []tka.Key, disablements [][]byte, err error) {
|
||||||
for i, a := range args {
|
for i, a := range args {
|
||||||
if parseDisablements && (strings.HasPrefix(a, "disablement:") || strings.HasPrefix(a, "disablement-secret:")) {
|
if parseDisablements && (strings.HasPrefix(a, "disablement:") || strings.HasPrefix(a, "disablement-secret:")) {
|
||||||
b, err := hex.DecodeString(a[strings.Index(a, ":")+1:])
|
b, err := hex.DecodeString(a[strings.Index(a, ":")+1:])
|
||||||
@@ -446,8 +446,8 @@ func parseNLArgs(args []string, parseKeys, parseDisablements bool) (keys []tka.K
|
|||||||
return keys, disablements, nil
|
return keys, disablements, nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockAdd(ctx context.Context, addArgs []string) error {
|
func runTailnetLockAdd(ctx context.Context, addArgs []string) error {
|
||||||
addKeys, _, err := parseNLArgs(addArgs, true, false)
|
addKeys, _, err := parseTLArgs(addArgs, true, false)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -469,7 +469,7 @@ func runNetworkLockAdd(ctx context.Context, addArgs []string) error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlSignCmd = &ffcli.Command{
|
var tlSignCmd = &ffcli.Command{
|
||||||
Name: "sign",
|
Name: "sign",
|
||||||
ShortUsage: "tailscale lock sign <node-key> [<rotation-key>]\ntailscale lock sign <auth-key>",
|
ShortUsage: "tailscale lock sign <node-key> [<rotation-key>]\ntailscale lock sign <auth-key>",
|
||||||
ShortHelp: "Sign a node or pre-approved auth key",
|
ShortHelp: "Sign a node or pre-approved auth key",
|
||||||
@@ -481,10 +481,10 @@ var nlSignCmd = &ffcli.Command{
|
|||||||
|
|
||||||
If any of the key arguments begin with "file:", the key is retrieved from
|
If any of the key arguments begin with "file:", the key is retrieved from
|
||||||
the file at the path specified in the argument suffix.`,
|
the file at the path specified in the argument suffix.`,
|
||||||
Exec: runNetworkLockSign,
|
Exec: runTailnetLockSign,
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockSign(ctx context.Context, args []string) error {
|
func runTailnetLockSign(ctx context.Context, args []string) error {
|
||||||
// If any of the arguments start with "file:", replace that argument
|
// If any of the arguments start with "file:", replace that argument
|
||||||
// with the contents of the file. We do this early, before the check
|
// with the contents of the file. We do this early, before the check
|
||||||
// to see if the first argument is an auth key.
|
// to see if the first argument is an auth key.
|
||||||
@@ -531,7 +531,7 @@ func runNetworkLockSign(ctx context.Context, args []string) error {
|
|||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlDisableCmd = &ffcli.Command{
|
var tlDisableCmd = &ffcli.Command{
|
||||||
Name: "disable",
|
Name: "disable",
|
||||||
ShortUsage: "tailscale lock disable <disablement-secret>",
|
ShortUsage: "tailscale lock disable <disablement-secret>",
|
||||||
ShortHelp: "Consume a disablement secret to shut down tailnet lock for the tailnet",
|
ShortHelp: "Consume a disablement secret to shut down tailnet lock for the tailnet",
|
||||||
@@ -546,11 +546,11 @@ Once this secret is used, it has been distributed
|
|||||||
to all nodes in the tailnet and should be considered public.
|
to all nodes in the tailnet and should be considered public.
|
||||||
|
|
||||||
`),
|
`),
|
||||||
Exec: runNetworkLockDisable,
|
Exec: runTailnetLockDisable,
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockDisable(ctx context.Context, args []string) error {
|
func runTailnetLockDisable(ctx context.Context, args []string) error {
|
||||||
_, secrets, err := parseNLArgs(args, false, true)
|
_, secrets, err := parseTLArgs(args, false, true)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -560,7 +560,7 @@ func runNetworkLockDisable(ctx context.Context, args []string) error {
|
|||||||
return localClient.NetworkLockDisable(ctx, secrets[0])
|
return localClient.NetworkLockDisable(ctx, secrets[0])
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlLocalDisableCmd = &ffcli.Command{
|
var tlLocalDisableCmd = &ffcli.Command{
|
||||||
Name: "local-disable",
|
Name: "local-disable",
|
||||||
ShortUsage: "tailscale lock local-disable",
|
ShortUsage: "tailscale lock local-disable",
|
||||||
ShortHelp: "Disable tailnet lock for this node only",
|
ShortHelp: "Disable tailnet lock for this node only",
|
||||||
@@ -575,22 +575,22 @@ that the current node will accept traffic from other nodes in the tailnet
|
|||||||
that are locked out.
|
that are locked out.
|
||||||
|
|
||||||
`),
|
`),
|
||||||
Exec: runNetworkLockLocalDisable,
|
Exec: runTailnetLockLocalDisable,
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockLocalDisable(ctx context.Context, args []string) error {
|
func runTailnetLockLocalDisable(ctx context.Context, args []string) error {
|
||||||
return localClient.NetworkLockForceLocalDisable(ctx)
|
return localClient.NetworkLockForceLocalDisable(ctx)
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlDisablementKDFCmd = &ffcli.Command{
|
var tlDisablementKDFCmd = &ffcli.Command{
|
||||||
Name: "disablement-kdf",
|
Name: "disablement-kdf",
|
||||||
ShortUsage: "tailscale lock disablement-kdf <hex-encoded-disablement-secret>",
|
ShortUsage: "tailscale lock disablement-kdf <hex-encoded-disablement-secret>",
|
||||||
ShortHelp: "Compute a disablement value from a disablement secret (advanced users only)",
|
ShortHelp: "Compute a disablement value from a disablement secret (advanced users only)",
|
||||||
LongHelp: "Compute a disablement value from a disablement secret (advanced users only)",
|
LongHelp: "Compute a disablement value from a disablement secret (advanced users only)",
|
||||||
Exec: runNetworkLockDisablementKDF,
|
Exec: runTailnetLockDisablementKDF,
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockDisablementKDF(ctx context.Context, args []string) error {
|
func runTailnetLockDisablementKDF(ctx context.Context, args []string) error {
|
||||||
if len(args) != 1 {
|
if len(args) != 1 {
|
||||||
return errors.New("usage: tailscale lock disablement-kdf <hex-encoded-disablement-secret>")
|
return errors.New("usage: tailscale lock disablement-kdf <hex-encoded-disablement-secret>")
|
||||||
}
|
}
|
||||||
@@ -607,12 +607,12 @@ var nlLogArgs struct {
|
|||||||
json jsonoutput.JSONSchemaVersion
|
json jsonoutput.JSONSchemaVersion
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlLogCmd = &ffcli.Command{
|
var tlLogCmd = &ffcli.Command{
|
||||||
Name: "log",
|
Name: "log",
|
||||||
ShortUsage: "tailscale lock log [--limit N]",
|
ShortUsage: "tailscale lock log [--limit N]",
|
||||||
ShortHelp: "List changes applied to tailnet lock",
|
ShortHelp: "List changes applied to tailnet lock",
|
||||||
LongHelp: "List changes applied to tailnet lock",
|
LongHelp: "List changes applied to tailnet lock",
|
||||||
Exec: runNetworkLockLog,
|
Exec: runTailnetLockLog,
|
||||||
FlagSet: (func() *flag.FlagSet {
|
FlagSet: (func() *flag.FlagSet {
|
||||||
fs := newFlagSet("lock log")
|
fs := newFlagSet("lock log")
|
||||||
fs.IntVar(&nlLogArgs.limit, "limit", 50, "max number of updates to list")
|
fs.IntVar(&nlLogArgs.limit, "limit", 50, "max number of updates to list")
|
||||||
@@ -693,7 +693,7 @@ func nlDescribeUpdate(update ipnstate.NetworkLockUpdate, color bool) (string, er
|
|||||||
return stanza.String(), nil
|
return stanza.String(), nil
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockLog(ctx context.Context, args []string) error {
|
func runTailnetLockLog(ctx context.Context, args []string) error {
|
||||||
st, err := localClient.NetworkLockStatus(ctx)
|
st, err := localClient.NetworkLockStatus(ctx)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fixTailscaledConnectError(err)
|
return fixTailscaledConnectError(err)
|
||||||
@@ -709,10 +709,10 @@ func runNetworkLockLog(ctx context.Context, args []string) error {
|
|||||||
|
|
||||||
out, useColor := colorableOutput()
|
out, useColor := colorableOutput()
|
||||||
|
|
||||||
return printNetworkLockLog(updates, out, nlLogArgs.json, useColor)
|
return printTailnetLockLog(updates, out, nlLogArgs.json, useColor)
|
||||||
}
|
}
|
||||||
|
|
||||||
func printNetworkLockLog(updates []ipnstate.NetworkLockUpdate, out io.Writer, jsonSchema jsonoutput.JSONSchemaVersion, useColor bool) error {
|
func printTailnetLockLog(updates []ipnstate.NetworkLockUpdate, out io.Writer, jsonSchema jsonoutput.JSONSchemaVersion, useColor bool) error {
|
||||||
if jsonSchema.IsSet {
|
if jsonSchema.IsSet {
|
||||||
if jsonSchema.Value == 1 {
|
if jsonSchema.Value == 1 {
|
||||||
return jsonoutput.PrintNetworkLockLogJSONV1(out, updates)
|
return jsonoutput.PrintNetworkLockLogJSONV1(out, updates)
|
||||||
@@ -784,13 +784,13 @@ func wrapAuthKey(ctx context.Context, keyStr string, status *ipnstate.Status) er
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlRevokeKeysArgs struct {
|
var tlRevokeKeysArgs struct {
|
||||||
cosign bool
|
cosign bool
|
||||||
finish bool
|
finish bool
|
||||||
forkFrom string
|
forkFrom string
|
||||||
}
|
}
|
||||||
|
|
||||||
var nlRevokeKeysCmd = &ffcli.Command{
|
var tlRevokeKeysCmd = &ffcli.Command{
|
||||||
Name: "revoke-keys",
|
Name: "revoke-keys",
|
||||||
ShortUsage: "tailscale lock revoke-keys <tailnet-lock-key>...\n revoke-keys [--cosign] [--finish] <recovery-blob>",
|
ShortUsage: "tailscale lock revoke-keys <tailnet-lock-key>...\n revoke-keys [--cosign] [--finish] <recovery-blob>",
|
||||||
ShortHelp: "Revoke compromised tailnet-lock keys",
|
ShortHelp: "Revoke compromised tailnet-lock keys",
|
||||||
@@ -806,20 +806,20 @@ Revocation is a multi-step process that requires several signing nodes to ` + "`
|
|||||||
most recent command output on the next signing node in sequence.
|
most recent command output on the next signing node in sequence.
|
||||||
3. Once the number of ` + "`--cosign`" + `s is greater than the number of keys being revoked,
|
3. Once the number of ` + "`--cosign`" + `s is greater than the number of keys being revoked,
|
||||||
run the command one final time with ` + "`--finish`" + ` instead of ` + "`--cosign`" + `.`,
|
run the command one final time with ` + "`--finish`" + ` instead of ` + "`--cosign`" + `.`,
|
||||||
Exec: runNetworkLockRevokeKeys,
|
Exec: runTailnetLockRevokeKeys,
|
||||||
FlagSet: (func() *flag.FlagSet {
|
FlagSet: (func() *flag.FlagSet {
|
||||||
fs := newFlagSet("lock revoke-keys")
|
fs := newFlagSet("lock revoke-keys")
|
||||||
fs.BoolVar(&nlRevokeKeysArgs.cosign, "cosign", false, "continue generating the recovery using the tailnet lock key on this device and the provided recovery blob")
|
fs.BoolVar(&tlRevokeKeysArgs.cosign, "cosign", false, "continue generating the recovery using the tailnet lock key on this device and the provided recovery blob")
|
||||||
fs.BoolVar(&nlRevokeKeysArgs.finish, "finish", false, "finish the recovery process by transmitting the revocation")
|
fs.BoolVar(&tlRevokeKeysArgs.finish, "finish", false, "finish the recovery process by transmitting the revocation")
|
||||||
fs.StringVar(&nlRevokeKeysArgs.forkFrom, "fork-from", "", "parent AUM hash to rewrite from (advanced users only)")
|
fs.StringVar(&tlRevokeKeysArgs.forkFrom, "fork-from", "", "parent AUM hash to rewrite from (advanced users only)")
|
||||||
return fs
|
return fs
|
||||||
})(),
|
})(),
|
||||||
}
|
}
|
||||||
|
|
||||||
func runNetworkLockRevokeKeys(ctx context.Context, args []string) error {
|
func runTailnetLockRevokeKeys(ctx context.Context, args []string) error {
|
||||||
// First step in the process
|
// First step in the process
|
||||||
if !nlRevokeKeysArgs.cosign && !nlRevokeKeysArgs.finish {
|
if !tlRevokeKeysArgs.cosign && !tlRevokeKeysArgs.finish {
|
||||||
revokeKeys, _, err := parseNLArgs(args, true, false)
|
revokeKeys, _, err := parseTLArgs(args, true, false)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return err
|
return err
|
||||||
}
|
}
|
||||||
@@ -837,16 +837,16 @@ func runNetworkLockRevokeKeys(ctx context.Context, args []string) error {
|
|||||||
}
|
}
|
||||||
|
|
||||||
var forkFrom tka.AUMHash
|
var forkFrom tka.AUMHash
|
||||||
if nlRevokeKeysArgs.forkFrom != "" {
|
if tlRevokeKeysArgs.forkFrom != "" {
|
||||||
if len(nlRevokeKeysArgs.forkFrom) == (len(forkFrom) * 2) {
|
if len(tlRevokeKeysArgs.forkFrom) == (len(forkFrom) * 2) {
|
||||||
// Hex-encoded: like the output of the lock log command.
|
// Hex-encoded: like the output of the lock log command.
|
||||||
b, err := hex.DecodeString(nlRevokeKeysArgs.forkFrom)
|
b, err := hex.DecodeString(tlRevokeKeysArgs.forkFrom)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("invalid fork-from hash: %v", err)
|
return fmt.Errorf("invalid fork-from hash: %v", err)
|
||||||
}
|
}
|
||||||
copy(forkFrom[:], b)
|
copy(forkFrom[:], b)
|
||||||
} else {
|
} else {
|
||||||
if err := forkFrom.UnmarshalText([]byte(nlRevokeKeysArgs.forkFrom)); err != nil {
|
if err := forkFrom.UnmarshalText([]byte(tlRevokeKeysArgs.forkFrom)); err != nil {
|
||||||
return fmt.Errorf("invalid fork-from hash: %v", err)
|
return fmt.Errorf("invalid fork-from hash: %v", err)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -873,7 +873,7 @@ func runNetworkLockRevokeKeys(ctx context.Context, args []string) error {
|
|||||||
return fmt.Errorf("decoding recovery AUM: %v", err)
|
return fmt.Errorf("decoding recovery AUM: %v", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
if nlRevokeKeysArgs.cosign {
|
if tlRevokeKeysArgs.cosign {
|
||||||
aumBytes, err := localClient.NetworkLockCosignRecoveryAUM(ctx, recoveryAUM)
|
aumBytes, err := localClient.NetworkLockCosignRecoveryAUM(ctx, recoveryAUM)
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return fmt.Errorf("co-signing recovery AUM failed: %w", err)
|
return fmt.Errorf("co-signing recovery AUM failed: %w", err)
|
||||||
@@ -889,7 +889,7 @@ Alternatively if you are done with co-signing, complete recovery by running the
|
|||||||
`, os.Args[0], aumBytes, os.Args[0], aumBytes)
|
`, os.Args[0], aumBytes, os.Args[0], aumBytes)
|
||||||
}
|
}
|
||||||
|
|
||||||
if nlRevokeKeysArgs.finish {
|
if tlRevokeKeysArgs.finish {
|
||||||
if err := localClient.NetworkLockSubmitRecoveryAUM(ctx, recoveryAUM); err != nil {
|
if err := localClient.NetworkLockSubmitRecoveryAUM(ctx, recoveryAUM); err != nil {
|
||||||
return fmt.Errorf("submitting recovery AUM failed: %w", err)
|
return fmt.Errorf("submitting recovery AUM failed: %w", err)
|
||||||
}
|
}
|
||||||
@@ -18,7 +18,7 @@ import (
|
|||||||
"tailscale.com/types/tkatype"
|
"tailscale.com/types/tkatype"
|
||||||
)
|
)
|
||||||
|
|
||||||
func TestNetworkLockLogOutput(t *testing.T) {
|
func TestTailnetLockLogOutput(t *testing.T) {
|
||||||
votes := uint(1)
|
votes := uint(1)
|
||||||
aum1 := tka.AUM{
|
aum1 := tka.AUM{
|
||||||
MessageKind: tka.AUMAddKey,
|
MessageKind: tka.AUMAddKey,
|
||||||
@@ -88,7 +88,7 @@ func TestNetworkLockLogOutput(t *testing.T) {
|
|||||||
json := jsonoutput.JSONSchemaVersion{}
|
json := jsonoutput.JSONSchemaVersion{}
|
||||||
useColor := false
|
useColor := false
|
||||||
|
|
||||||
printNetworkLockLog(updates, &outBuf, json, useColor)
|
printTailnetLockLog(updates, &outBuf, json, useColor)
|
||||||
|
|
||||||
t.Logf("%s", outBuf.String())
|
t.Logf("%s", outBuf.String())
|
||||||
|
|
||||||
@@ -195,7 +195,7 @@ KeyID: tlpub:0202
|
|||||||
}
|
}
|
||||||
useColor := false
|
useColor := false
|
||||||
|
|
||||||
printNetworkLockLog(updates, &outBuf, json, useColor)
|
printTailnetLockLog(updates, &outBuf, json, useColor)
|
||||||
|
|
||||||
want := jsonV1
|
want := jsonV1
|
||||||
|
|
||||||
@@ -205,7 +205,7 @@ KeyID: tlpub:0202
|
|||||||
})
|
})
|
||||||
}
|
}
|
||||||
|
|
||||||
func TestNetworkLockStatusOutput(t *testing.T) {
|
func TestTailnetLockStatusOutput(t *testing.T) {
|
||||||
aum := tka.AUM{
|
aum := tka.AUM{
|
||||||
MessageKind: tka.AUMNoOp,
|
MessageKind: tka.AUMNoOp,
|
||||||
}
|
}
|
||||||
@@ -46,14 +46,14 @@ import (
|
|||||||
|
|
||||||
var (
|
var (
|
||||||
errMissingNetmap = errors.New("missing netmap: verify that you are logged in")
|
errMissingNetmap = errors.New("missing netmap: verify that you are logged in")
|
||||||
errNetworkLockNotActive = errors.New("tailnet-lock is not active")
|
errTailnetLockNotActive = errors.New("tailnet-lock is not active")
|
||||||
)
|
)
|
||||||
|
|
||||||
// IsNetworkLockNotActive reports whether the given error indicates that
|
// IsNetworkLockNotActive reports whether the given error indicates that
|
||||||
// tailnet-lock is not active. Stop-gap for feature/tailnetlock to check this
|
// tailnet-lock is not active. Stop-gap for feature/tailnetlock to check this
|
||||||
// until all of this is code is moved to the feature.
|
// until all of this is code is moved to the feature.
|
||||||
func IsNetworkLockNotActive(err error) bool {
|
func IsNetworkLockNotActive(err error) bool {
|
||||||
return errors.Is(err, errNetworkLockNotActive)
|
return errors.Is(err, errTailnetLockNotActive)
|
||||||
}
|
}
|
||||||
|
|
||||||
type tkaState struct {
|
type tkaState struct {
|
||||||
@@ -107,10 +107,10 @@ func (b *LocalBackend) initTKALocked() error {
|
|||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// noNetworkLockStateDirWarnable is a Warnable to warn the user that Tailnet Lock data
|
// noTailnetLockStateDirWarnable is a Warnable to warn the user that Tailnet Lock data
|
||||||
// (in particular, the list of AUMs in the TKA state) is being stored in memory and will
|
// (in particular, the list of AUMs in the TKA state) is being stored in memory and will
|
||||||
// be lost when tailscaled restarts.
|
// be lost when tailscaled restarts.
|
||||||
var noNetworkLockStateDirWarnable = health.Register(&health.Warnable{
|
var noTailnetLockStateDirWarnable = health.Register(&health.Warnable{
|
||||||
Code: "no-tailnet-lock-state-dir",
|
Code: "no-tailnet-lock-state-dir",
|
||||||
Title: "No statedir for Tailnet Lock",
|
Title: "No statedir for Tailnet Lock",
|
||||||
Severity: health.SeverityMedium,
|
Severity: health.SeverityMedium,
|
||||||
@@ -495,7 +495,7 @@ func (b *LocalBackend) tkaBootstrapFromGenesisLocked(g tkatype.MarshaledAUM, per
|
|||||||
root := b.TailscaleVarRoot()
|
root := b.TailscaleVarRoot()
|
||||||
var storage tka.CompactableChonk
|
var storage tka.CompactableChonk
|
||||||
if root == "" {
|
if root == "" {
|
||||||
b.health.SetUnhealthy(noNetworkLockStateDirWarnable, nil)
|
b.health.SetUnhealthy(noTailnetLockStateDirWarnable, nil)
|
||||||
b.logf("tailnet-lock using in-memory storage; no state directory")
|
b.logf("tailnet-lock using in-memory storage; no state directory")
|
||||||
storage = tka.ChonkMem()
|
storage = tka.ChonkMem()
|
||||||
} else {
|
} else {
|
||||||
@@ -711,7 +711,7 @@ func (b *LocalBackend) NetworkLockVerifySignatureForTest(nks tkatype.MarshaledSi
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return errNetworkLockNotActive
|
return errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
return b.tka.authority.NodeKeyAuthorized(nodeKey, nks)
|
return b.tka.authority.NodeKeyAuthorized(nodeKey, nks)
|
||||||
}
|
}
|
||||||
@@ -733,7 +733,7 @@ func (b *LocalBackend) NetworkLockForceLocalDisable() error {
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return errNetworkLockNotActive
|
return errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
|
|
||||||
id1, id2 := b.tka.authority.StateIDs()
|
id1, id2 := b.tka.authority.StateIDs()
|
||||||
@@ -769,7 +769,7 @@ func (b *LocalBackend) NetworkLockSign(nodeKey key.NodePublic, rotationPublic []
|
|||||||
}
|
}
|
||||||
|
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return key.NodePublic{}, tka.NodeKeySignature{}, errNetworkLockNotActive
|
return key.NodePublic{}, tka.NodeKeySignature{}, errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
if !b.tka.authority.KeyTrusted(nlPriv.KeyID()) {
|
if !b.tka.authority.KeyTrusted(nlPriv.KeyID()) {
|
||||||
return key.NodePublic{}, tka.NodeKeySignature{}, errors.New(tsconst.TailnetLockNotTrustedMsg)
|
return key.NodePublic{}, tka.NodeKeySignature{}, errors.New(tsconst.TailnetLockNotTrustedMsg)
|
||||||
@@ -830,7 +830,7 @@ func (b *LocalBackend) NetworkLockModify(addKeys, removeKeys []tka.Key) (err err
|
|||||||
return errMissingNetmap
|
return errMissingNetmap
|
||||||
}
|
}
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return errNetworkLockNotActive
|
return errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
if !b.tka.authority.KeyTrusted(nlPriv.KeyID()) {
|
if !b.tka.authority.KeyTrusted(nlPriv.KeyID()) {
|
||||||
return errors.New("this node does not have a trusted tailnet lock key")
|
return errors.New("this node does not have a trusted tailnet lock key")
|
||||||
@@ -896,7 +896,7 @@ func (b *LocalBackend) NetworkLockDisable(secret []byte) error {
|
|||||||
ourNodeKey = p.Persist().PublicNodeKey()
|
ourNodeKey = p.Persist().PublicNodeKey()
|
||||||
}
|
}
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
err = errNetworkLockNotActive
|
err = errTailnetLockNotActive
|
||||||
} else {
|
} else {
|
||||||
head = b.tka.authority.Head()
|
head = b.tka.authority.Head()
|
||||||
if !b.tka.authority.ValidDisablement(secret) {
|
if !b.tka.authority.ValidDisablement(secret) {
|
||||||
@@ -921,7 +921,7 @@ func (b *LocalBackend) NetworkLockLog(maxEntries int) ([]ipnstate.NetworkLockUpd
|
|||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
|
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return nil, errNetworkLockNotActive
|
return nil, errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
|
|
||||||
var out []ipnstate.NetworkLockUpdate
|
var out []ipnstate.NetworkLockUpdate
|
||||||
@@ -964,7 +964,7 @@ func (b *LocalBackend) NetworkLockAffectedSigs(keyID tkatype.KeyID) ([]tkatype.M
|
|||||||
ourNodeKey = p.Persist().PublicNodeKey()
|
ourNodeKey = p.Persist().PublicNodeKey()
|
||||||
}
|
}
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
err = errNetworkLockNotActive
|
err = errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
b.mu.Unlock()
|
b.mu.Unlock()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
@@ -979,7 +979,7 @@ func (b *LocalBackend) NetworkLockAffectedSigs(keyID tkatype.KeyID) ([]tkatype.M
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return nil, errNetworkLockNotActive
|
return nil, errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
|
|
||||||
// Confirm for ourselves tha the signatures would actually be invalidated
|
// Confirm for ourselves tha the signatures would actually be invalidated
|
||||||
@@ -1019,7 +1019,7 @@ func (b *LocalBackend) NetworkLockGenerateRecoveryAUM(removeKeys []tkatype.KeyID
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return nil, errNetworkLockNotActive
|
return nil, errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
var nlPriv key.NLPrivate
|
var nlPriv key.NLPrivate
|
||||||
if p := b.pm.CurrentPrefs(); p.Valid() && p.Persist().Valid() {
|
if p := b.pm.CurrentPrefs(); p.Valid() && p.Persist().Valid() {
|
||||||
@@ -1052,7 +1052,7 @@ func (b *LocalBackend) NetworkLockCosignRecoveryAUM(aum *tka.AUM) (*tka.AUM, err
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return nil, errNetworkLockNotActive
|
return nil, errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
var nlPriv key.NLPrivate
|
var nlPriv key.NLPrivate
|
||||||
if p := b.pm.CurrentPrefs(); p.Valid() && p.Persist().Valid() {
|
if p := b.pm.CurrentPrefs(); p.Valid() && p.Persist().Valid() {
|
||||||
@@ -1081,7 +1081,7 @@ func (b *LocalBackend) NetworkLockSubmitRecoveryAUM(aum *tka.AUM) error {
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return errNetworkLockNotActive
|
return errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
var ourNodeKey key.NodePublic
|
var ourNodeKey key.NodePublic
|
||||||
if p := b.pm.CurrentPrefs(); p.Valid() && p.Persist().Valid() && !p.Persist().PrivateNodeKey().IsZero() {
|
if p := b.pm.CurrentPrefs(); p.Valid() && p.Persist().Valid() && !p.Persist().PrivateNodeKey().IsZero() {
|
||||||
@@ -1109,7 +1109,7 @@ func (b *LocalBackend) NetworkLockWrapPreauthKey(preauthKey string, tkaKey key.N
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return "", errNetworkLockNotActive
|
return "", errTailnetLockNotActive
|
||||||
}
|
}
|
||||||
|
|
||||||
pub, priv, err := ed25519.GenerateKey(nil) // nil == crypto/rand
|
pub, priv, err := ed25519.GenerateKey(nil) // nil == crypto/rand
|
||||||
@@ -1137,7 +1137,7 @@ func (b *LocalBackend) NetworkLockVerifySigningDeeplink(url string) tka.Deeplink
|
|||||||
b.mu.Lock()
|
b.mu.Lock()
|
||||||
defer b.mu.Unlock()
|
defer b.mu.Unlock()
|
||||||
if b.tka == nil {
|
if b.tka == nil {
|
||||||
return tka.DeeplinkValidationResult{IsValid: false, Error: errNetworkLockNotActive.Error()}
|
return tka.DeeplinkValidationResult{IsValid: false, Error: errTailnetLockNotActive.Error()}
|
||||||
}
|
}
|
||||||
|
|
||||||
return b.tka.authority.ValidateDeeplink(url)
|
return b.tka.authority.ValidateDeeplink(url)
|
||||||
Reference in New Issue
Block a user