Denton Gentry and Denton Gentry
29a35d4a5d
cmd/sniproxy: switch to peterbourgon/ff for flags
...
Add support for TS_APPC_* variables to supply arguments by
switching to https://github.com/peterbourgon/ff for CLI
flag parsing. For example:
TS_APPC_FORWARDS=tcp/22/github.com ./sniproxy
Updates https://github.com/tailscale/tailscale/issues/1748
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-30 06:05:40 -07:00
Denton Gentry and Denton Gentry
535db01b3f
scripts/installer: add Kaisen, Garuda, Fedora-Asahi.
...
Fixes https://github.com/tailscale/tailscale/issues/8648
Fixes https://github.com/tailscale/tailscale/issues/8737
Fixes https://github.com/tailscale/tailscale/issues/9087
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-25 08:40:14 -07:00
Denton Gentry and Denton Gentry
24d41e4ae7
cmd/sniproxy: add port forwarding and prometheus metrics
...
1. Add TCP port forwarding.
For example: ./sniproxy -forwards=tcp/22/github.com
will forward SSH to github.
% ssh -i ~/.ssh/id_ecdsa.pem -T git@github.com
Hi GitHubUser! You've successfully authenticated, but GitHub does not
provide shell access.
% ssh -i ~/.ssh/id_ecdsa.pem -T git@100.65 .x.y
Hi GitHubUser! You've successfully authenticated, but GitHub does not
provide shell access.
2. Additionally export clientmetrics as prometheus metrics for local
scraping over the tailnet: http://sniproxy-hostname:8080/debug/varz
Updates https://github.com/tailscale/tailscale/issues/1748
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-24 15:52:17 -07:00
Denton Gentry and Denton Gentry
1b8a538953
scripts/installer.sh: add CloudLinux and Alibaba Linux
...
Fixes https://github.com/tailscale/tailscale/issues/9010
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-23 15:29:17 -07:00
Denton Gentry and Denton Gentry
f486041fd1
tsnet: add support for clientmetrics.
...
Updates https://github.com/tailscale/tailscale/issues/1748
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-21 06:26:40 -07:00
Denton Gentry and Denton Gentry
e8d140654a
cmd/derper: count bootstrap dns unique lookups.
...
Updates https://github.com/tailscale/corp/issues/13979
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-17 08:02:56 -07:00
Denton Gentry and Denton Gentry
7e15c78a5a
syncs: add map.Clear() method
...
Updates https://github.com/tailscale/corp/issues/13979
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-17 08:02:56 -07:00
Denton Gentry and Denton Gentry
4940a718a1
scripts/installer.sh: set Deepin to a debian version
...
Deepin Linux 20.x reports its version as "apricot"
Set it to bullseye, the Debian version it corresponds to.
Also fix the installer CI: OpenSUSE Leap appears to have removed
curl from the base image recently, we have to install it now.
Fixes https://github.com/tailscale/tailscale/issues/8850
Updates https://github.com/tailscale/tailscale/issues/7862
Updates https://github.com/tailscale/corp/issues/8952
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-12 07:51:11 -07:00
Denton Gentry and Denton Gentry
ec9213a627
cmd/sniproxy: add client metrics
...
Count number of sessions, number of DNS queries answered
successfully and in error, and number of http->https redirects.
Updates #1748
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-08-01 12:14:01 -07:00
Denton Gentry and Denton Gentry
4f95b6966b
cmd/tailscale: remove TS_EXPERIMENT_OAUTH_AUTHKEY guardrail
...
We've had support for OAuth client keys in `--authkey=...`
for several releases, and we're using it in
https://github.com/tailscale/github-action
Remove the TS_EXPERIMENT_* guardrail, it is fully supported now.
Fixes https://github.com/tailscale/tailscale/issues/8403
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-07-13 07:20:38 -07:00
Denton Gentry and Denton Gentry
5b110685fb
wgengine/netstack: increase maxInFlightConnectionAttempts
...
Address reports of subnet router instability when running in
`--tun=userspace-networking` mode.
Fixes https://github.com/tailscale/corp/issues/12184
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-06-12 12:00:38 -07:00
Denton Gentry and Denton Gentry
64f16f7f38
net/dnscache: use PreferGo on Windows.
...
Updates https://github.com/tailscale/tailscale/issues/5161
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-06-05 15:58:49 -07:00
Denton Gentry and Denton Gentry
6554a0cbec
build_dist.sh: use $go consistently.
...
The invocation at the end unconditionally used
./tool/go, but the structuring on lines 14-17
sets up to use a different toolchain if the
platform requires it.
Fixes https://github.com/tailscale/tailscale/issues/8156
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-06-05 10:21:03 -07:00
Denton Gentry and Denton Gentry
4321d1d6e9
scripts/installer.sh: add sle-micro-rancher.
...
Fixes https://github.com/tailscale/tailscale/issues/5633
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-06-04 17:05:51 -07:00
Denton Gentry and Denton Gentry
67882ad35d
scripts/installer.sh: add BlendOS support.
...
Fixes https://github.com/tailscale/tailscale/issues/8100
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-06-04 08:31:58 -07:00
Denton Gentry and Denton Gentry
399a80785e
wgengine/netstack: use ping6 on BSD platforms
...
Various BSD-derived operating systems including macOS and FreeBSD
require that ping6 be used for IPv6 destinations. The "ping" command
does not understand an IPv6 destination.
FreeBSD 13.x and later do handle IPv6 in the regular ping command,
but also retain a ping6 command. We use ping6 on all versions of
FreeBSD.
Fixes https://github.com/tailscale/tailscale/issues/8225
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-05-28 09:50:21 -07:00
Denton Gentry and Denton Gentry
a82f275619
cmd/sniproxy: Set App name in tsnet hostinfo
...
Updates #1748
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-04-28 21:50:30 -07:00
Denton Gentry and Denton Gentry
1145b9751d
VERSION.txt: this is v1.41.0
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-04-26 15:58:30 -07:00
Denton Gentry and Denton Gentry
c791e64881
scripts/installer: add Deepin, RisiOS.
...
Fixes https://github.com/tailscale/tailscale/issues/7862
Fixes https://github.com/tailscale/tailscale/issues/7899
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-04-20 18:51:50 -07:00
Denton Gentry and Denton Gentry
ed10a1769b
scripts/installer.sh: check Photon OS version with pkg server.
...
Photon OS support crossed streams with using pkgserve to check
for supported versions 6f9aed1656 .
Make Photon OS also rely on pkgserve.
Updates https://github.com/tailscale/tailscale/issues/7651
Updates https://github.com/tailscale/corp/issues/8952
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-25 18:08:20 -07:00
Denton Gentry and Denton Gentry
d5abdd915e
scripts/installer: add VMWare PhotonOS.
...
Fixes https://github.com/tailscale/tailscale/issues/7651
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-25 04:53:40 -07:00
Denton Gentry and Denton Gentry
cc3806056f
scripts/installer.sh: Add Ubuntu Lunar Lobster 23.04.
...
pkgs.tailscale.com added support in January, need to
add it to the installer script.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-21 15:17:38 -07:00
Denton Gentry and Denton Gentry
ebc630c6c0
net/interfaces: also allow link-local for AzureAppServices.
...
In May 2021, Azure App Services used 172.16.x.x addresses:
```
10: eth0@if11: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP
link/ether 02:42:ac:10:01:03 brd ff:ff:ff:ff:ff:ff
inet 172.16.1.3/24 brd 172.16.1.255 scope global eth0
valid_lft forever preferred_lft forever
```
Now it uses link-local:
```
2: eth0@if6: <BROADCAST,MULTICAST,UP,LOWER_UP,M-DOWN> mtu 1500 qdisc noqueue state UP
link/ether 8a:30:1f:50:1d:23 brd ff:ff:ff:ff:ff:ff
inet 169.254.129.3/24 brd 169.254.129.255 scope global eth0
valid_lft forever preferred_lft forever
```
This is reasonable for them to choose to do, it just broke the handling in net/interfaces.
This PR proposes to:
1. Always allow link-local in LocalAddresses() if we have no better
address available.
2. Continue to make isUsableV4() conditional on an environment we know
requires it.
I don't love the idea of having to discover these environments one by
one, but I don't understand the consequences of making isUsableV4()
return true unconditionally. It makes isUsableV4() essentially always
return true and perform no function.
Fixes https://github.com/tailscale/tailscale/issues/7603
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-20 13:40:38 -07:00
Denton Gentry and Denton Gentry
6d3490f399
VERSION.txt: this is 1.39
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-14 13:50:57 -07:00
Denton Gentry and Denton Gentry
047b324933
scripts/installer: add PureOS and Amazon Linux Next
...
Fixes https://github.com/tailscale/tailscale/issues/7410
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-10 15:22:27 -08:00
Denton Gentry and Denton Gentry
b46c5ae82a
cmd/sniproxy: draw the rest of the DNS owl.
...
Add a DNS server which always responds as its own IP addresses.
Additionally add a tsnet TailscaleIPs() function to return the
IP addresses, both IPv4 and IPv6.
Updates https://github.com/tailscale/tailscale/issues/1748
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-06 19:29:01 -08:00
Denton Gentry and Denton Gentry
51288221ce
cmd/tailscale: use request Schema+Host for QNAP authLogin.cgi
...
QNAP allows users to set the port number for the management WebUI,
which includes authLogin.cgi. If they do, then connecting to
localhost:8080 fails.
https://github.com/tailscale/tailscale-qpkg/issues/74#issuecomment-1407486911
Fixes https://github.com/tailscale/tailscale/issues/7108
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-03-01 18:00:06 -08:00
Denton Gentry and Denton Gentry
bf7573c9ee
cmd/nginx-auth: build for arm64
...
Fixes https://github.com/tailscale/tailscale/issues/6978
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-25 17:16:31 -08:00
Denton Gentry and Denton Gentry
9ab992e7a1
syncs: re-enable TestWatchMultipleValues
...
We've updated to a different set of CI machines since this test
was disabled.
Fixes https://github.com/tailscale/tailscale/issues/1513
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-25 17:03:16 -08:00
Denton Gentry
6dabb34c7f
scripts/installer.sh: add GalliumOS and Sangoma Linux
...
Fixes https://github.com/tailscale/tailscale/issues/6541
Fixes https://github.com/tailscale/tailscale/issues/6555
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-18 23:13:05 +00:00
Denton Gentry
1ba0b7fd79
scripts/installer.sh: add postmarketos support.
...
Fixes https://github.com/tailscale/tailscale/issues/7300
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-18 16:06:47 +00:00
Denton Gentry
fdc2018d67
wgengine/magicsock: remove superfluous "discokey" from log
...
The stringification of the discokey type now prepends "discokey:"
Fixes https://github.com/tailscale/tailscale/issues/3074
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-12 21:05:05 +00:00
Denton Gentry
01d58c9b61
scripts/installer.sh: add Mendel OS and OpenMandriva.
...
Fixes https://github.com/tailscale/tailscale/issues/6926
Fixes https://github.com/tailscale/tailscale/issues/7076
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-11 17:57:49 +00:00
Denton Gentry and Denton Gentry
5bca44d572
cmd/sync-containers: update latest and stable tags
...
Fixes https://github.com/tailscale/tailscale/issues/7251
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-10 20:47:18 -08:00
Denton Gentry and Denton Gentry
4daba23cd4
cmd/get-authkey: add an OAuth API client to produce an authkey
...
Updates https://github.com/tailscale/tailscale/issues/3243
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-02-03 22:52:54 -08:00
Denton Gentry and Denton Gentry
7439bc7ba6
cmd/sync-containers: add github.Keychain
...
Running sync-containers in a GitHub workflow will be
simpler if we check github.Keychain, which uses the
GITHUB_TOKEN if present.
Updates https://github.com/tailscale/corp/issues/8461
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-01-25 19:55:15 -08:00
Denton Gentry and Denton Gentry
9af7e8a0ff
VERSION.txt: this is 1.37
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-01-24 15:32:02 -08:00
Denton Gentry and Denton Gentry
22ebb25e83
cmd/tailscale: disable HTTPS verification for QNAP auth.
...
QNAP's "Force HTTPS" mode redirects even localhost HTTP to
HTTPS, but uses a self-signed certificate which fails
verification. We accommodate this by disabling checking
of the cert.
Fixes https://github.com/tailscale/tailscale/issues/6903
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-01-10 21:49:28 -08:00
Denton Gentry and Denton Gentry
467ace7d0c
cmd/tailscale: use localhost for QNAP authLogin.cgi
...
When the user clicks on the Tailscale app in the QNAP App Center,
we do a GET from /cgi-bin/authLogin.cgi to look up their SID.
If the user clicked "secure login" on the QNAP login page to use
HTTPS, then our access to authLogin.cgi will also use HTTPS
but the certiciate is self-signed. Our GET fails with:
Get "https://10.1.10.41/cgi-bin/authLogin.cgi?sid=abcd0123 ":
x509: cannot validate certificate for 10.1.10.41 because it
doesn't contain any IP SANs
or similar errors.
Instead, access QNAP authentication via http://localhost:8080/
as documented in
https://download.qnap.com/dev/API_QNAP_QTS_Authentication.pdf
Fixes https://github.com/tailscale/tailscale-qpkg/issues/62
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2023-01-03 06:09:10 -08:00
Denton Gentry and Denton Gentry
2a1f1c79ca
scripts/installer.sh: add SUSE Enterprise Server.
...
Fixes https://github.com/tailscale/tailscale/issues/6840
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-12-24 08:12:01 -08:00
Denton Gentry and Denton Gentry
da53b1347b
cmd/gitops-pusher: support alternate api-server URLs
...
Fixes https://github.com/tailscale/coral/issues/90
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-12-14 05:07:12 -08:00
Denton Gentry and Denton Gentry
c933b8882c
VERSION.txt: this is v1.35.0
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-12-05 09:51:51 -08:00
Denton Gentry and Denton Gentry
7c4d017636
paths: set QNAP socket to /tmp.
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-12-02 22:07:42 -08:00
Denton Gentry and Denton Gentry
a200a23f97
Revert "cmd/tailscale: access QNAP via localhost"
...
When running `tailscale web` as a standalone process,
it was necessary to send auth requests to QTS using
localhost to avoid hitting the proxy recursively.
However running `tailscale web` as a process means it is
consuming RAM all the time even when it isn't actively
doing anything.
After switching back to the `tailscale web` CGI mode, we
don't need to specifically use localhost for QNAP auth.
This reverts commit e0cadc5496 .
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-11-29 16:17:34 -08:00
Denton Gentry and Denton Gentry
b8fe89d15f
net/portmapper: add test for Huawei router
...
Updates https://github.com/tailscale/tailscale/issues/6320
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-11-25 07:42:31 -08:00
Denton Gentry and Denton Gentry
e0cadc5496
cmd/tailscale: access QNAP via localhost
...
QNAP 5.x works much better if we let Apache proxy
tailscale web, which means the URLs can no longer
be relative since apache sends us an internal
URL. Access QNAP authentication via
http://localhost:8080/ as documented in
https://download.qnap.com/dev/API_QNAP_QTS_Authentication.pdf
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-11-14 21:43:52 -08:00
Denton Gentry and Denton Gentry
446057d613
scripts/installer.sh: add Nobara Linux.
...
Fixes https://github.com/tailscale/tailscale/issues/5763
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-11-10 14:25:26 -08:00
Denton Gentry and Denton Gentry
3d8eda5b72
scripts/install.sh: add RHEL7.
...
Fixes https://github.com/tailscale/tailscale/issues/5729
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-31 05:35:32 -07:00
Denton Gentry and Denton Gentry
5677ed1e85
scripts/installer.sh: add Debian Sid (rolling release)
...
There is no VERSION_ID.
root@sid:~# cat /etc/os-release
PRETTY_NAME="Debian GNU/Linux bookworm/sid"
NAME="Debian GNU/Linux"
VERSION_CODENAME=bookworm
ID=debian
HOME_URL="https://www.debian.org/ "
SUPPORT_URL="https://www.debian.org/support "
BUG_REPORT_URL="https://bugs.debian.org/ "
Fixes https://github.com/tailscale/tailscale/issues/5522
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-31 05:35:32 -07:00
Denton Gentry and Denton Gentry
798dba14eb
scripts/install.sh: add openSUSE Leap 15.4
...
Fixes https://github.com/tailscale/tailscale/issues/6095
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-31 05:35:32 -07:00
Denton Gentry and Denton Gentry
dafc822654
cmd/nginx-auth: increment version.
...
We need a new release to handle TCD changes
after MagicDNS GA
Updates https://github.com/tailscale/tailscale/issues/6048
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-25 08:38:54 -07:00
Denton Gentry and Denton Gentry
9beb07b4ff
scripts/install.sh: add Ubuntu Kinetic Kudu
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-24 07:17:00 -07:00
b55761246b
prober: add utilities to generate alerts and warnings.
...
sendAlert will trigger the Incident Response system.
sendWarning will post to Slack.
Co-authored-by: M. J. Fromberger <fromberger@tailscale.com >
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-16 23:34:04 -07:00
Denton Gentry and Denton Gentry
19dfdeb1bb
cmd/tailscale: correct --cpu-profile help text
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-16 09:07:24 -07:00
Denton Gentry and Denton Gentry
1b9ed9f365
VERSION.txt: this is 1.33.
...
We did not get this VERSION.txt file checked in at the correct time,
the prior 10 commits in `main` between the v1.32.0 tag point and
this commit were not part of release 1.32. We did no unstable builds
during this time, so the error should have no impact.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-12 09:53:06 -07:00
Denton Gentry and Denton Gentry
51d488673a
scripts/installer.sh: add OSMC
...
Fixes https://github.com/tailscale/tailscale/issues/4960
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-10-11 04:24:41 -07:00
Denton Gentry and Denton Gentry
42f1d92ae0
net/netns: implement UseSocketMark for Android.
...
Build fails on Android:
`../../../../go/pkg/mod/tailscale.com@v1.1.1-0.20220916223019-65c24b6334e9/wgengine/magicsock/magicsock_linux.go:133:12: undefined: netns.UseSocketMark`
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-09-17 23:19:24 -07:00
Denton Gentry and Denton Gentry
53e08bd7ea
VERSION.txt: this is 1.31
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-31 06:48:24 -07:00
Denton Gentry and Denton Gentry
0ae0439668
docs/k8s: add IPv6 forwarding in proxy.yaml
...
Fixes https://github.com/tailscale/tailscale/issues/4999
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-30 06:03:15 -07:00
Denton Gentry and Denton Gentry
6dcc6313a6
CI: add go mod tidy workflow
...
Fixes https://github.com/tailscale/tailscale/issues/4567
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-30 06:02:34 -07:00
Denton Gentry and Denton Gentry
78dbb59a00
CI: make all workflows get Go version from go.mod
...
The next time we update the toolchain, all of the CI
Actions will automatically use it when go.mod is updated.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-30 06:02:14 -07:00
Denton Gentry and Denton Gentry
3c8d257b3e
cmd/tailscale: set /dev/net perms in configure-host
...
Several customers have had issues due to the permissions
on /dev/net. Set permissions to 0755.
Fixes https://github.com/tailscale/tailscale/issues/5048
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-19 06:55:34 -07:00
Denton Gentry and Denton Gentry
1c0286e98a
scripts/installer.sh: add -y for unattended install
...
Fixes https://github.com/tailscale/tailscale/issues/5377
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-15 10:28:55 -07:00
Denton Gentry and Denton Gentry
5d731ca13f
installer.sh: add manjaro-arm & EndeavourOS.
...
Fixes https://github.com/tailscale/tailscale/issues/5192
Fixes https://github.com/tailscale/tailscale/issues/5284
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-08-10 20:10:48 -07:00
Denton Gentry and Denton Gentry
7fd03ad4b4
logpolicy: put QNAP logs buffer in /tmp
...
Ongoing log writing keeps the spinning disks from hibernating.
Extends earlier implementation for Synology to also handle QNAP.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-25 09:45:04 -07:00
Denton Gentry and Denton Gentry
f85bb60eba
ipn/ipnlocal: prevent attempting to run SSH on QNAP for now
...
tailscaled runs as a non-root user, SSH is not immediately working.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-25 09:45:04 -07:00
Denton Gentry and Denton Gentry
4dd799ec43
hostinfo: determine QNAP QTS version
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-22 19:43:47 -07:00
Denton Gentry and Denton Gentry
d17849461c
ipn/{ipnserver,ipnlocal}: support incoming Taildrop on QNAP
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-22 19:43:47 -07:00
Denton Gentry and Denton Gentry
3c892d106c
VERSION.txt: this is v1.29.0
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-18 10:23:52 -07:00
Denton Gentry and Denton Gentry
9fcda1f0a0
cmd/tailscale/cli/web: add QNAP NAS_SID authentication
...
QTS 5.0 doesn't always pass a qtoken, in some circumstances
it sends a NAS_SID cookie for us to verify instead.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-17 12:21:03 -07:00
Denton Gentry and Denton Gentry
755396d6fe
tsweb: add Float expvar support in varz
...
We make assertions about stringification of 0.5. IEEE floating point and
all reasonable proprietary floating point can exactly represent 0.5.
We don't make assertions about other floating point values, too brittle
in tests.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-11 21:16:46 -07:00
Denton Gentry and Denton Gentry
e6572a0f08
install.sh: Add archarm and Raspbian Stretch
...
Fixes https://github.com/tailscale/tailscale/issues/4959
Fixes https://github.com/tailscale/tailscale/issues/4897
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-07-06 05:41:06 -07:00
Denton Gentry and Denton Gentry
d7f452c0a1
net/portmapper: send discovery packet for IGD specifically.
...
There appear to be devices out there which send only their
first descriptor in response to a discovery packet for
`ssdp:all`, for example the Sagemcom FAST3890V3 only sends
urn:schemas-wifialliance-org:device:WFADevice:1
Send both ssdp:all and a discovery frame for
InternetGatewayDevice specifically.
Updates https://github.com/tailscale/tailscale/issues/3557
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-28 03:55:17 -07:00
Denton Gentry and Denton Gentry
09eaba91ad
net/portmap: add a test for Sagemcom FAST3890V3.
...
Updates https://github.com/tailscale/tailscale/issues/3557
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-28 03:55:17 -07:00
Denton Gentry and Denton Gentry
b5553c6ad2
net/portmap: run go fmt
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-28 03:55:17 -07:00
Denton Gentry and Denton Gentry
de4c635e54
net/portmapper: make pcpCodeNotAuthorized log more descriptive
...
If PCP is present but disabled, turning it on might help
get direct connections.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-28 03:55:17 -07:00
Denton Gentry and Denton Gentry
1392a93445
socks5: add a simple test
...
Start up a backend service, put a SOCKS5 server in front
of it, and verify that we can get data from the backend via
SOCKS5.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-09 10:41:06 -07:00
Denton Gentry and Denton Gentry
7fffddce8e
net/portmapper: enable for iOS
...
In the 1.27 unstable releases we set the min-version to iOS15,
which means we have 50 MBytes of RAM in the Network Extension.
https://tailscale.com/blog/go-linker/
Include the UPnP/NAT-PMP/PCP portmapper support now that there
is memory for it.
Fixes https://github.com/tailscale/tailscale/issues/2495
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-09 10:40:25 -07:00
Denton Gentry and Denton Gentry
cfb5bd0559
VERSION.txt: this is v1.27.0
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-06 16:11:18 -07:00
Denton Gentry and Denton Gentry
c6ac82e3a6
hostinfo,distro: Identify Western Digital MyCloud devices.
...
root@WDMyCloud HD_a2 # ./tailscale debug hostinfo
{
"IPNVersion": "1.25.0-dev20220605-t7fea52e02",
"OS": "linux",
"OSVersion": "5.22.113",
"Desktop": false,
"DeviceModel": "WD My Cloud Gen2: Marvell Armada 375",
"Hostname": "WDMyCloud",
"GoArch": "arm"
}
Updates https://github.com/tailscale/tailscale/issues/4622
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-05 08:22:42 -07:00
Denton Gentry and Denton Gentry
0687195bee
logpolicy: put Synology logs buffer in /tmp
...
Ongoing log writing keeps the spinning disks from hibernating.
Fixes https://github.com/tailscale/tailscale/issues/3551
Tested on DSM6 and DSM7.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-06-04 22:06:14 -07:00
Denton Gentry and Denton Gentry
0f95eaa8bb
scripts/installer: fix elementaryOS
...
c2b907c965 moved UBUNTU_VERSION out
of the ubuntu case and into linuxmint, but linuxmint wasn't the
only Ubuntu-based system which needed it. Restore UBUNTU_VERSION
handling in the ubuntu case.
Break elementaryOS out into its own handling so we can get the
version number handling correct for keyring support.
Tested on an elementaryOS 6.1 VM.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-05-27 06:21:15 -07:00
Denton Gentry and Denton Gentry
36af49ae7f
install.sh: add RHEL9.
...
Fixes https://github.com/tailscale/tailscale/issues/4718
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-05-20 09:49:39 -07:00
Denton Gentry and Denton Gentry
53f6c3f9f2
api.md: document preauthorized and tags fields
...
Updates https://github.com/tailscale/tailscale/issues/2120
Updates https://github.com/tailscale/tailscale/issues/4571
Updates https://github.com/tailscale/tailscale/issues/1369
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-05-17 09:25:13 -07:00
Denton Gentry and Denton Gentry
afb3f62b01
scripts/installer.sh: add Xen Enterprise
...
Tested on a VM running Xen Enterprise 8.2.1.
https://xcp-ng.org/
Fixes https://github.com/tailscale/tailscale/issues/4655
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-05-16 08:37:39 -07:00
Denton Gentry and Denton Gentry
d819bb3bb0
VERSION.txt: This is 1.25.0
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-04-22 13:26:24 -07:00
Denton Gentry and Denton Gentry
13f75b9667
scripts/install: add Alma Linux.
...
Tested using an Alma Linux 8.5 VM.
Updates https://github.com/tailscale/tailscale/issues/2915
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-04-20 17:43:49 -07:00
Denton Gentry and Denton Gentry
c2b907c965
scripts/installer: support LinuxMint Debian.
...
The primary distribution for LinuxMint is based on Ubuntu,
but there is an alternate Debian-based distribution called
LMDE. Both variations identify themselves as "linuxmint"
We added UBUNTU_VERSION to the Ubuntu handling for linuxmint,
the only distribution so far found to do this. Instead, split
linuxmint out into its own case and use either UBUNTU_VERSION
or DEBIAN_VERSION, whichever is present.
Tested on an LMDE 5 (elsie) VM.
Updates https://github.com/tailscale/tailscale/issues/2915
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-04-20 17:43:49 -07:00
Denton Gentry and Denton Gentry
61868f281e
scripts/installer: call emerge with --ask=n
...
Fixes https://github.com/tailscale/tailscale/issues/4354
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-04-20 17:43:49 -07:00
Denton Gentry and Denton Gentry
db7da6622a
scripts/installer: add ParrotOS support
...
Support ParrotSec https://parrotsec.org/
Tested using a Parrot 5.0 VM.
Updates https://github.com/tailscale/tailscale/issues/2915
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-04-20 17:43:49 -07:00
Denton Gentry and Dave Anderson
d8953bf2ba
cmd/derpprobe: don't alert for smaller failures.
...
There is a Cosmic Background level of DERP Unreachability,
with individual nodes or regions becoming unreachable briefly
and returning a short time later. This is due to hosting provider
outages or just the Internet sloshing about.
Returning a 500 error pages a human. Being awoken at 3am for
a transient error is annoying.
For relatively small levels of badness don't page a human,
just post to Slack. If the outage impacts a significant fraction
of the DERP fleet, then page a human.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-03-16 18:22:22 -07:00
Denton Gentry and Denton Gentry
8175504584
VERSION.txt: This is 1.23.
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-02-23 15:51:28 -08:00
Denton Gentry and Denton Gentry
dbea8217ac
net/dns: add NetworkManager regression test
...
Use the exact /etc/resolv.conf file from a user report.
Updates https://github.com/tailscale/tailscale/issues/3531
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-02-10 15:01:49 -08:00
Denton Gentry and Denton Gentry
16652ae52c
installer.sh: accommodate linuxmint versioning.
...
Recent linuxmint releases now use VERSION_CODENAME for
a linuxmint release (like "uma") and set UBUNTU_CODENAME to
the Ubuntu release they branched from.
Tested in a linuxmint 20.2 VM.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-02-07 07:06:00 -08:00
Denton Gentry and Denton Gentry
27da7fd5cb
VERSION.txt: This is 1.21.
...
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2022-01-12 17:38:49 -08:00
Denton Gentry and Denton Gentry
e133bb570b
install.sh: add linuxmint, kali, several more.
...
After apt install, Kali Linux had not enabled nor started
the tailscaled systemd service. Add a quirks mode to enable
and start it after apt install for debian platforms.
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2021-12-13 11:38:29 -08:00
Denton Gentry and Denton Gentry
878a20df29
net/dns: add GetBaseConfig to CallbackRouter.
...
Allow users of CallbackRouter to supply a GetBaseConfig
implementation. This is expected to be used on Android,
which currently lacks both a) platform support for
Split-DNS and b) a way to retrieve the current DNS
servers.
iOS/macOS also use the CallbackRouter but have platform
support for SplitDNS, so don't need getBaseConfig.
Updates https://github.com/tailscale/tailscale/issues/2116
Updates https://github.com/tailscale/tailscale/issues/988
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2021-12-08 16:49:11 -08:00
Denton Gentry and Denton Gentry
ffb16cdffb
cmd/tailscale: add --json for up
...
Print JSON to stdout containing everything needed for
authentication.
{
"AuthURL": "https://login.tailscale.com/a/0123456789 ",
"QR": "data:image/png;base64,iV...QmCC",
"BackendState": "NeedsLogin"
}
{
"BackendState": "Running"
}
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2021-12-06 21:17:15 -08:00
Denton Gentry and Denton Gentry
e121c2f724
logpolicy: export NewLogtailTransport for Android
...
Android doesn't use logpolicy and currently has enough
unique stuff about its logging that makes it difficult to
do so. For example, its logsDir comes from Gio.
Export NewLogtailTransport to let Android use it.
Updates https://github.com/tailscale/tailscale/issues/3046
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2021-11-26 07:45:13 -08:00
Denton Gentry and Denton Gentry
f56a7559ce
scripts/installer.sh: add more Linux variants.
...
Updates https://github.com/tailscale/tailscale/issues/2915
Signed-off-by: Denton Gentry <dgentry@tailscale.com >
2021-11-23 15:12:29 -08:00