David Anderson
6e42430ad8
wgengine/monitor: don't log any single-IP routes added to the tailscale table.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-22 20:21:51 -08:00
David Anderson
df5adb2e23
wgengine/monitor: on linux, also monitor for IPv6 changes.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-22 19:38:07 -08:00
David Anderson and Dave Anderson
b83c273737
wgengine/filter: use IPSet for localNets instead of prefixes.
...
Part of #1177 , preparing for doing fancier set operations on
the allowed local nets.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-22 14:51:22 -08:00
David Anderson
e86b39b73f
ipn/ipnlocal: don't short-circuit default route filtering.
...
If no exit node is specified, the filter must still run to remove
offered default routes from all peers.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-05 20:33:18 -08:00
David Anderson and Dave Anderson
a046b48593
cmd/tailscale/cli: display currently active exit node in tailscale status.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-05 14:53:17 -08:00
David Anderson
ace57d7627
wgengine/magicsock: set a dummy private key in benchmark.
...
Magicsock started dropping all traffic internally when Tailscale is
shut down, to avoid spurious wireguard logspam. This made the benchmark
not receive anything. Setting a dummy private key is sufficient to get
magicsock to pass traffic for benchmarking purposes.
Fixes #1270 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-05 13:36:05 -08:00
David Anderson and Dave Anderson
b9c2231fdf
ipn: program exit node into the data plane according to user pref.
...
Part of #1153 , #1154 . Fixes #1224 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-05 13:07:11 -08:00
David Anderson
45fe06a89f
Revert "tailcfg: remove v6-overlay debug option."
...
This reverts commit da4ec54756 .
Since v6 got disabled for Windows nodes, I need the debug flag back
to figure out why it was broken.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-03 16:11:56 -08:00
David Anderson and Dave Anderson
267531e4f8
wgengine/router: probe better for v6 policy routing support.
...
Previously we disabled v6 support if the disable_policy knob was
missing in /proc, but some kernels support policy routing without
exposing the toggle. So instead, treat disable_policy absence as a
"maybe", and make the direct `ip -6 rule` probing a bit more
elaborate to compensate.
Fixes #1241 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-01 16:12:17 -08:00
David Anderson
de497358b8
cmd/tailscaled: add /run to the allowed paths for iptables.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-28 12:58:07 -08:00
David Anderson
7a16ac80b7
VERSION.txt: this is 1.5.0.
2021-01-27 18:45:22 -08:00
David Anderson and Dave Anderson
692a011b54
net/interfaces: remove IsTailscaleIP, make callers use tsaddr.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-26 15:10:51 -08:00
David Anderson
9f7cbf6cf1
wgengine/filter: add a Clone method.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-22 17:31:37 -08:00
David Anderson and Dave Anderson
49d00b6a28
tailcfg: add StableID to Node. #1178
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-21 13:33:19 -08:00
David Anderson
ab9cccb292
cmd/tailscale/cli: require v4 and v6 default routes to be advertised together.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-19 16:49:06 -08:00
David Anderson
78338ac029
types/logger: trim spaces from the rate-limited example message.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-19 16:48:44 -08:00
David Anderson
da4ec54756
tailcfg: remove v6-overlay debug option.
...
It's about to become a no-op in control.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-18 17:47:23 -08:00
David Anderson
9936cffc1a
wgengine: correctly track all node IPs in lazy config.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-18 13:32:16 -08:00
David Anderson
e23b4191c4
wgengine/magicsock: disable legacy networking everywhere except TwoDevicePing.
...
TwoDevicePing is explicitly testing the behavior of the legacy codepath, everything
else is happy to assume that code no longer exists.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-15 16:02:31 -08:00
David Anderson
0733c5d2e0
wgengine/magicsock: disable legacy behavior in a few more tests.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-15 15:57:41 -08:00
David Anderson
57d95dd005
wgengine/magicsock: default legacy networking to off for some tests.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-15 15:54:45 -08:00
David Anderson and Dave Anderson
a2463e8948
wgengine/magicsock: add an option to disable legacy peer handling.
...
Used in tests to ensure we're not relying on behavior we're going
to remove eventually.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-15 15:01:33 -08:00
David Anderson and Dave Anderson
d456bfdc6d
wgengine/magicsock: fix BenchmarkReceiveFrom.
...
Previously, this benchmark relied on behavior of the legacy
receive codepath, which I changed in 22507adf . With this
change, the benchmark instead relies on the new active discovery
path.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-15 15:01:33 -08:00
David Anderson
01e8b7fb7e
go.mod: bump wireguard-go version.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-15 10:53:49 -08:00
David Anderson and Dave Anderson
9abcb18061
wgengine/magicsock: import more of wireguard-go, update docstrings.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-14 12:56:48 -08:00
David Anderson and Dave Anderson
22507adf54
wgengine/magicsock: stop depending on UpdateDst in legacy codepaths.
...
This makes connectivity between ancient and new tailscale nodes slightly
worse in some cases, but only in cases where the ancient version would
likely have failed to get connectivity anyway.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-01-14 12:56:48 -08:00
David Anderson
86fe22a1b1
Update netaddr, and adjust wgengine/magicsock due to API change.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-30 17:36:03 -08:00
David Anderson and Brad Fitzpatrick
cb96b14bf4
net/packet: remove the custom IP4/IP6 types in favor of netaddr.IP.
...
Upstream netaddr has a change that makes it alloc-free, so it's safe to
use in hot codepaths. This gets rid of one of the many IP types in our
codebase.
Performance is currently worse across the board. This is likely due in
part to netaddr.IP being a larger value type (4b -> 24b for IPv4,
16b -> 24b for IPv6), and in other part due to missing low-hanging fruit
optimizations in netaddr. However, the regression is less bad than
it looks at first glance, because we'd micro-optimized packet.IP* in
the past few weeks. This change drops us back to roughly where we
were at the 1.2 release, but with the benefit of a significant
code and architectural simplification.
name old time/op new time/op delta
pkg:tailscale.com/net/packet goos:linux goarch:amd64
Decode/tcp4-8 12.2ns ± 5% 29.7ns ± 2% +142.32% (p=0.008 n=5+5)
Decode/tcp6-8 12.6ns ± 3% 65.1ns ± 2% +418.47% (p=0.008 n=5+5)
Decode/udp4-8 11.8ns ± 3% 30.5ns ± 2% +157.94% (p=0.008 n=5+5)
Decode/udp6-8 27.1ns ± 1% 65.7ns ± 2% +142.36% (p=0.016 n=4+5)
Decode/icmp4-8 24.6ns ± 2% 30.5ns ± 2% +23.65% (p=0.016 n=4+5)
Decode/icmp6-8 22.9ns ±51% 65.5ns ± 2% +186.19% (p=0.008 n=5+5)
Decode/igmp-8 18.1ns ±44% 30.2ns ± 1% +66.89% (p=0.008 n=5+5)
Decode/unknown-8 20.8ns ± 1% 10.6ns ± 9% -49.11% (p=0.016 n=4+5)
pkg:tailscale.com/wgengine/filter goos:linux goarch:amd64
Filter/icmp4-8 30.5ns ± 1% 77.9ns ± 3% +155.01% (p=0.008 n=5+5)
Filter/tcp4_syn_in-8 43.7ns ± 3% 123.0ns ± 3% +181.72% (p=0.008 n=5+5)
Filter/tcp4_syn_out-8 24.5ns ± 2% 45.7ns ± 6% +86.22% (p=0.008 n=5+5)
Filter/udp4_in-8 64.8ns ± 1% 210.0ns ± 2% +223.87% (p=0.008 n=5+5)
Filter/udp4_out-8 119ns ± 0% 278ns ± 0% +133.78% (p=0.016 n=4+5)
Filter/icmp6-8 40.3ns ± 2% 204.4ns ± 4% +407.70% (p=0.008 n=5+5)
Filter/tcp6_syn_in-8 35.3ns ± 3% 199.2ns ± 2% +464.95% (p=0.008 n=5+5)
Filter/tcp6_syn_out-8 32.8ns ± 2% 81.0ns ± 2% +147.10% (p=0.008 n=5+5)
Filter/udp6_in-8 106ns ± 2% 290ns ± 2% +174.48% (p=0.008 n=5+5)
Filter/udp6_out-8 184ns ± 2% 314ns ± 3% +70.43% (p=0.016 n=4+5)
pkg:tailscale.com/wgengine/tstun goos:linux goarch:amd64
Write-8 9.02ns ± 3% 8.92ns ± 1% ~ (p=0.421 n=5+5)
name old alloc/op new alloc/op delta
pkg:tailscale.com/net/packet goos:linux goarch:amd64
Decode/tcp4-8 0.00B 0.00B ~ (all equal)
Decode/tcp6-8 0.00B 0.00B ~ (all equal)
Decode/udp4-8 0.00B 0.00B ~ (all equal)
Decode/udp6-8 0.00B 0.00B ~ (all equal)
Decode/icmp4-8 0.00B 0.00B ~ (all equal)
Decode/icmp6-8 0.00B 0.00B ~ (all equal)
Decode/igmp-8 0.00B 0.00B ~ (all equal)
Decode/unknown-8 0.00B 0.00B ~ (all equal)
pkg:tailscale.com/wgengine/filter goos:linux goarch:amd64
Filter/icmp4-8 0.00B 0.00B ~ (all equal)
Filter/tcp4_syn_in-8 0.00B 0.00B ~ (all equal)
Filter/tcp4_syn_out-8 0.00B 0.00B ~ (all equal)
Filter/udp4_in-8 0.00B 0.00B ~ (all equal)
Filter/udp4_out-8 16.0B ± 0% 64.0B ± 0% +300.00% (p=0.008 n=5+5)
Filter/icmp6-8 0.00B 0.00B ~ (all equal)
Filter/tcp6_syn_in-8 0.00B 0.00B ~ (all equal)
Filter/tcp6_syn_out-8 0.00B 0.00B ~ (all equal)
Filter/udp6_in-8 0.00B 0.00B ~ (all equal)
Filter/udp6_out-8 48.0B ± 0% 64.0B ± 0% +33.33% (p=0.008 n=5+5)
name old allocs/op new allocs/op delta
pkg:tailscale.com/net/packet goos:linux goarch:amd64
Decode/tcp4-8 0.00 0.00 ~ (all equal)
Decode/tcp6-8 0.00 0.00 ~ (all equal)
Decode/udp4-8 0.00 0.00 ~ (all equal)
Decode/udp6-8 0.00 0.00 ~ (all equal)
Decode/icmp4-8 0.00 0.00 ~ (all equal)
Decode/icmp6-8 0.00 0.00 ~ (all equal)
Decode/igmp-8 0.00 0.00 ~ (all equal)
Decode/unknown-8 0.00 0.00 ~ (all equal)
pkg:tailscale.com/wgengine/filter goos:linux goarch:amd64
Filter/icmp4-8 0.00 0.00 ~ (all equal)
Filter/tcp4_syn_in-8 0.00 0.00 ~ (all equal)
Filter/tcp4_syn_out-8 0.00 0.00 ~ (all equal)
Filter/udp4_in-8 0.00 0.00 ~ (all equal)
Filter/udp4_out-8 1.00 ± 0% 1.00 ± 0% ~ (all equal)
Filter/icmp6-8 0.00 0.00 ~ (all equal)
Filter/tcp6_syn_in-8 0.00 0.00 ~ (all equal)
Filter/tcp6_syn_out-8 0.00 0.00 ~ (all equal)
Filter/udp6_in-8 0.00 0.00 ~ (all equal)
Filter/udp6_out-8 1.00 ± 0% 1.00 ± 0% ~ (all equal)
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-22 14:44:36 -08:00
David Anderson
ca676ea645
tailcfg: introduce map version 8, for clients that support v6 node config.
...
For now, the server will only send v6 configuration to mapversion 8 clients
as part of an early-adopter program, while we verify that the functionality
is robust.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 18:28:27 -08:00
David Anderson
03a039d48d
go.mod: bump wireguard-go version.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 17:26:05 -08:00
David Anderson
f5e33ad761
go.mod: update inet.af/netaddr, go mod tidy.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 14:01:43 -08:00
David Anderson and Dave Anderson
89be4037bb
control/controlclient: report broken routing for v4 and v6.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 13:50:44 -08:00
David Anderson and Dave Anderson
baa7937998
net/interfaces: return IPv6 addresses from LocalAddresses.
...
In practice, we already provide IPv6 endpoint addresses via netcheck,
and that address is likely to match a local address anyway (i.e. no NAT66).
The comment at that piece of the code mentions needing to figure out a
good priority ordering, but that only applies to non-active-discovery
clients, who already don't do anything with IPv6 addresses.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 13:50:44 -08:00
David Anderson and Dave Anderson
294ceb513c
ipn, wgengine/magicsock: fix tailscale status display.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 13:50:44 -08:00
David Anderson and Dave Anderson
891110e64c
wgengine: expand lazy config to work with dual-stacked peers.
...
Lazy wg configuration now triggers if a peer has only endpoint
addresses (/32 for IPv4, /128 for IPv6). Subnet routers still
trigger eager configuration to avoid the need for a CIDR match
in the hot packet path.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 13:50:44 -08:00
David Anderson and Dave Anderson
aa353b8d0f
net/packet: add an IP6 constructor from a raw byte array.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-19 13:50:44 -08:00
David Anderson and Dave Anderson
c8c493f3d9
wgengine/magicsock: make ReceiveIPv4 a little easier to follow.
...
The previous code used a lot of whole-function variables and shared
behavior that only triggered based on prior action from a single codepath.
Instead of that, move the small amounts of "shared" code into each switch
case.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-18 01:15:53 -08:00
David Anderson and Dave Anderson
0ad109f63d
wgengine/magicsock: move legacy endpoint creation into legacy.go.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-18 01:15:53 -08:00
David Anderson and Dave Anderson
f873da5b16
wgengine/magicsock: move more legacy endpoint handling.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-18 01:15:53 -08:00
David Anderson and Dave Anderson
58fcd103c4
wgengine/magicsock: move legacy sending code to legacy.go.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-18 01:15:53 -08:00
David Anderson and Dave Anderson
65ae66260f
wgengine/magicsock: unexport AddrSet.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-18 01:15:53 -08:00
David Anderson and Dave Anderson
c9b9afd761
wgengine/magicsock: move most legacy nat traversal bits to another file.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-18 01:15:53 -08:00
David Anderson and Brad Fitzpatrick
554a20becb
wgengine/magicsock: only log about lazy config when actually doing lazy config.
...
Before, tailscaled would log every 10 seconds when the periodic noteRecvActivity
call happens. This is noisy, but worse it's misleading, because the message
suggests that the disco code is starting a lazy config run for a missing peer,
whereas in fact it's just an internal piece of keepalive logic.
With this change, we still log when going from 0->1 tunnel for the peer, but
not every 10s thereafter.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-17 12:11:36 -08:00
David Anderson
9cee0bfa8c
wgengine/magicsock: sprinkle more docstrings.
...
Magicsock is too damn big, but this might help me page it back
in faster next time.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-14 23:59:17 -08:00
David Anderson and Dave Anderson
57cd7738c2
tsweb: add an endpoint to manually trigger a GC.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-08 16:49:42 -08:00
David Anderson
be6fe393c5
wgengine: don't try pinging IPv6 addresses in legacy pinger.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-01 20:09:32 -08:00
David Anderson
dfbde3d3aa
ipn: pass through the prefix length from control.
...
Control sets this to /32 for IPv4 and /128 for IPv6.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-12-01 20:09:16 -08:00
David Anderson
4c8ccd6dd6
tailcfg: document new debug flag.
2020-12-01 18:17:09 -08:00
David Anderson
3c508a58cc
wgengine/filter: don't filter GCP DNS.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-16 14:08:27 -08:00
David Anderson
2eb474dd8d
wgengine/filter: add test cases for len(dsts) > 1.
...
While the code was correct, I broke it during a refactoring and
tests didn't detect it. This fixes that glitch.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-12 21:41:52 -08:00
David Anderson
ce45f4f3ff
wgengine/filter: inline ip6InList into match.
...
matchIPsOnly gets 5% slower when inlining, despite significantly reduced
memory ops and slightly tighter code.
Part of #19 .
Filter/tcp6_syn_in-8 45.5ns ± 1% 42.4ns ± 2% -6.86% (p=0.000 n=10+10)
Filter/udp6_in-8 107ns ± 2% 94ns ± 2% -11.50% (p=0.000 n=9+10)
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-12 21:41:47 -08:00
David Anderson
3fdae12f0c
wgengine/filter: eliminate unnecessary memory loads.
...
Doesn't materially affect benchmarks, but shrinks match6 by 30 instructions
and halves memory loads.
Part of #19 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-12 21:41:40 -08:00
David Anderson
5062131aad
wgengine/filter: treat * as both a v4 and v6 wildcard.
...
Part of #19 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-12 21:41:29 -08:00
David Anderson
2d604b3791
net/packet: represent IP6 as two uint64s.
...
For the operations we perform on these types (mostly net6.Contains),
this encoding is much faster.
Part of #19 .
name old time/op new time/op delta
Filter/icmp4-8 27.5ns ± 1% 28.0ns ± 2% +1.89% (p=0.016 n=5+5)
Filter/tcp4_syn_in-8 38.8ns ± 2% 38.3ns ± 1% -1.24% (p=0.024 n=5+5)
Filter/tcp4_syn_out-8 27.6ns ±12% 24.6ns ± 1% ~ (p=0.063 n=5+5)
Filter/udp4_in-8 71.5ns ± 5% 65.9ns ± 1% -7.94% (p=0.008 n=5+5)
Filter/udp4_out-8 132ns ±13% 119ns ± 1% -10.29% (p=0.008 n=5+5)
Filter/icmp6-8 169ns ±10% 54ns ± 1% -68.35% (p=0.008 n=5+5)
Filter/tcp6_syn_in-8 149ns ± 6% 43ns ± 1% -71.11% (p=0.008 n=5+5)
Filter/tcp6_syn_out-8 37.7ns ± 4% 24.3ns ± 3% -35.51% (p=0.008 n=5+5)
Filter/udp6_in-8 179ns ± 5% 103ns ± 1% -42.75% (p=0.008 n=5+5)
Filter/udp6_out-8 156ns ± 3% 191ns ± 1% +22.54% (p=0.008 n=5+5)
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-12 21:41:21 -08:00
David Anderson
04ff3c91ee
wgengine/filter: add full IPv6 support.
...
Part of #19 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-12 21:41:15 -08:00
David Anderson and Dave Anderson
a664aac877
wgengine/router: disable IPv6 if v6 policy routing is unavailable.
...
Fixes #895 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-11 15:31:15 -08:00
David Anderson
a38e28da07
net/packet: documentation pass.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 22:29:00 -08:00
David Anderson
c2cc3acbaf
net/packet: remove NewIP, offer only a netaddr constructor.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 22:03:47 -08:00
David Anderson
d7ee3096dd
net/packet: documentation cleanups.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 21:12:55 -08:00
David Anderson and Dave Anderson
9ef39af2f2
net/packet: fix panic on invalid IHL field.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 20:23:54 -08:00
David Anderson and Dave Anderson
22bf48f37c
net/packet: remove {get,put}{16,32} indirection to encoding/binary.
...
name old time/op new time/op delta
Decode/tcp4-8 28.8ns ± 2% 13.1ns ± 4% -54.44% (p=0.008 n=5+5)
Decode/tcp6-8 20.6ns ± 1% 12.6ns ± 2% -38.72% (p=0.008 n=5+5)
Decode/udp4-8 28.2ns ± 1% 12.1ns ± 4% -57.01% (p=0.008 n=5+5)
Decode/udp6-8 20.0ns ± 6% 12.1ns ± 2% -39.38% (p=0.008 n=5+5)
Decode/icmp4-8 21.7ns ± 2% 11.5ns ± 1% -47.01% (p=0.008 n=5+5)
Decode/icmp6-8 14.1ns ± 2% 11.8ns ± 4% -16.60% (p=0.008 n=5+5)
Decode/unknown-8 9.43ns ± 2% 9.30ns ± 3% ~ (p=0.222 n=5+5)
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 20:23:54 -08:00
David Anderson and Dave Anderson
55b1221db2
net/packet: support full IPv6 decoding.
...
The packet filter still rejects all IPv6, but decodes enough from v6
packets to do something smarter in a followup.
name time/op
Decode/tcp4-8 28.8ns ± 2%
Decode/tcp6-8 20.6ns ± 1%
Decode/udp4-8 28.2ns ± 1%
Decode/udp6-8 20.0ns ± 6%
Decode/icmp4-8 21.7ns ± 2%
Decode/icmp6-8 14.1ns ± 2%
Decode/unknown-8 9.43ns ± 2%
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 20:23:54 -08:00
David Anderson and Dave Anderson
89894c6930
net/packet: add IPv6 source and destination IPs to Parsed.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-10 20:23:54 -08:00
David Anderson
6e52633c53
net/packet: record allocations in benchmark.
2020-11-10 02:19:55 -08:00
David Anderson
093431f5dd
net/packet: s/ParsedPacket/Parsed/ to avoid package stuttering.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 23:52:54 -08:00
David Anderson
c48253e63b
wgengine/filter: add a method to run the packet filter without a packet.
...
The goal is to move some of the shenanigans we have elsewhere into the filter
package, so that all the weird things to do with poking at the filter is in
a single place, behind clean APIs.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 23:34:01 -08:00
David Anderson
7a54910990
wgengine/filter: remove helper vars, mark NewAllowAll test-only.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 22:02:37 -08:00
David Anderson and Dave Anderson
76d99cf01a
wgengine/filter: remove the Matches type.
...
It only served to obscure the underlying slice type without
adding much value.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 21:39:25 -08:00
David Anderson and Dave Anderson
b950bd60bf
wgengine/filter: add and clean up documentation.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 21:39:25 -08:00
David Anderson and Dave Anderson
a8589636a8
wgengine/filter: remove unused Clone methods.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 21:39:25 -08:00
David Anderson and Dave Anderson
b3634f020d
wgengine/filter: use netaddr types in public API.
...
We still use the packet.* alloc-free types in the data path, but
the compilation from netaddr to packet happens within the filter
package.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 21:39:25 -08:00
David Anderson
7988f75b87
tailscaled.service: also cleanup prior to starting.
...
Fixes #813 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 20:16:11 -08:00
David Anderson
427bf2134f
net/packet: rename from wgengine/packet.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 16:25:24 -08:00
David Anderson
19df6a2ee2
wgengine/packet: rename types to reflect their v4-only-ness, document.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 16:25:24 -08:00
David Anderson and Dave Anderson
ebd96bf4a9
wgengine/router/dns: use OpenKeyWait to set DNS configuration.
...
Fixes tailscale/corp#839 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-09 14:08:39 -08:00
David Anderson
ed17f5ddae
VERSION.txt: this is now 1.3.x.
2020-11-03 15:09:02 -08:00
David Anderson
39bbb86b09
build_dist: fix after version refactor.
2020-11-03 14:40:09 -08:00
David Anderson
de5da37a22
VERSION: rename to version.txt to work around macOS limitations.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-02 20:39:10 -08:00
David Anderson and Dave Anderson
65bad9a8bd
version: greatly simplify redo nonsense, now that we use VERSION.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-02 19:54:44 -08:00
David Anderson and Dave Anderson
437142daa5
version: calculate version info without using git tags.
...
This makes it easier to integrate this version math into a submodule-ful
world. We'll continue to have regular git tags that parallel the information
in VERSION, so that builds out of this repository behave the same.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-02 15:23:35 -08:00
David Anderson and Dave Anderson
710b105f38
version: use -g as the "other" suffix, so that git show works.
...
Fixes #880 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-11-02 13:12:34 -08:00
David Anderson
68ddf134d7
wgengine/router/dns: issue ipconfig /registerdns when applying DNS settings.
...
Amazingly, there doesn't seem to be a documented way of updating network
configuration programmatically in a way that Windows takes notice of.
The naturopathic remedy for this is to invoke ipconfig /registerdns, which
does a variety of harmless things and also invokes the private API that
tells windows to notice new adapter settings. This makes our DNS config
changes stick within a few seconds of us setting them.
If we're invoking a shell command anyway, why futz with the registry at
all? Because netsh has no command for changing the DNS suffix list, and
its commands for setting resolvers requires parsing its output and
keeping track of which server is in what index. Amazingly, twiddling
the registry directly is the less painful option.
Fixes #853 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-10-29 20:05:38 -07:00
David Anderson
09721fede8
version: fix documentation.
2020-10-28 16:29:26 -07:00
David Anderson and Dave Anderson
54e6c3a290
version: use OSS repo's version when building.
...
When building with redo, also include the git commit hash
from the proprietary repo, so that we have a precise commit
that identifies all build info (including Go toolchain version).
Add a top-level build script demonstrating to downstream distros
how to burn the right information into builds.
Adjust `tailscale version` to print commit hashes when available.
Fixes #841 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-10-28 16:17:21 -07:00
David Anderson
3d34128171
go.mod: update to new wireguard-go.
2020-10-26 19:23:01 +00:00
David Anderson and Dave Anderson
62d941dc26
tailcfg: add a DebugFlags field for experiments and debugging.
...
Also replaces the IPv6Overlay bool with use of DebugFlags, since
it's currently an experimental configuration.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-10-19 17:03:04 -07:00
David Anderson and Dave Anderson
ff0cf6340a
wgengine/router: fix configuration of loopback netfilter rules for v6.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-10-15 15:15:24 -07:00
David Anderson and Dave Anderson
5c35c35e7f
tsaddr: add helpers for the Tailscale IPv6 range, and 4to6 conversion.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-10-15 15:15:24 -07:00
David Anderson and Dave Anderson
c6dbd24f67
tailcfg: add a field to advertise support for IPv6 tailscale config.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-10-15 15:15:24 -07:00
David Anderson
c493e5804f
wgengine/router: make v6-ness configurable in test, for consistent results.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-09-28 23:47:05 +00:00
David Anderson and Dave Anderson
fddbcb0c7b
wgengine/router: support various degrees of broken IPv6.
...
Gracefully skips touching the v6 NAT table on systems that don't have
it, and doesn't configure IPv6 at all if IPv6 is globally disabled.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-09-24 18:37:00 -07:00
David Anderson and Dave Anderson
0d80904fc2
wgengine/router: set up basic IPv6 routing/firewalling.
...
Part of #19 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-09-24 18:37:00 -07:00
David Anderson
b7e0ff598a
wgengine: don't close tundev in NewUserspaceEngine.
...
newUserspaceEngineAdvanced closes the tun device on error already.
Fixes #783 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-09-23 19:55:34 +00:00
David Anderson and Dave Anderson
8f5b52e571
net/netns: add windows support.
...
Also remove rebinding logic from the windows router. Magicsock will
instead rebind based on link change signals.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-09-14 16:28:49 -07:00
David Anderson and Dave Anderson
37c19970b3
derp: add a debug option to verbosely log drops to a destination.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-08-12 15:27:01 -07:00
David Anderson
15949ad77d
derp: export the new expvar.
2020-08-11 19:59:08 +00:00
David Anderson
13661e195a
derp: rename "wireguard" packet type to "other".
...
Strictly speaking, we don't know that it's a wireguard packet, just that
it doesn't look like a disco packet.
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-08-11 19:30:39 +00:00
David Anderson
1b5b59231b
derp: break down received packets by kind (disco vs. wireguard).
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-08-11 19:16:28 +00:00
David Anderson
c2b63ba363
cmd/microproxy: add a quick hack for some malformed variables.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-08-11 17:22:45 +00:00
David Anderson and Dave Anderson
c3467fbadb
version: adjust to a pure semver version number, per bradfitz's proposal.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2020-08-03 12:49:42 -07:00