Brad Fitzpatrick and Brad Fitzpatrick
090033ede5
cmd/derper: fix data race & server panic in manual cert mode
...
(Thanks for debugging, Roland!)
Fixes #4082
Change-Id: I400a64001c3c58899bb570b759b08e745abc0be1
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-10 15:14:09 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
c8dd39fcbc
.github/workflows: use a matrix for staticcheck GOOS/GOARCHes
...
Change-Id: Ic4eda169729117afc4031bbefbe265195b38c19b
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-10 09:48:44 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
4ee64681ad
tailcfg, control/controlclient: make Debug settings sticky in a map session [capver 37]
...
Fixes #4843
Change-Id: I3accfd91be474ac745cb47f5d6e866c37d5c5d2d
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-09 14:36:09 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
8e821d7aa8
types/opt: support an explicit "unset" value for Bool
...
Updates #4843
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-09 13:34:56 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
ec9d13bce5
hostinfo, net/netcheck: use CutPrefix
...
Updates #5309
Change-Id: I37e594cfd245784bf810c493de68a66d3ff20677
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-05 15:17:44 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
01e8ef7293
util/strs: add new package for string utility funcs
...
Updates #5309
Change-Id: I677cc6e01050b6e10d8d6907d961b11c7a787a05
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-05 15:06:08 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
18109c63b0
net/socks5: use new Go 1.19 binary.AppendByteOrder.AppendUintX
...
Updates #4872
Change-Id: I43db63d2ba237324bc1cd87d4261197f14cb1088
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-05 08:30:48 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
4950fe60bd
syncs, all: move to using Go's new atomic types instead of ours
...
Fixes #5185
Change-Id: I850dd532559af78c3895e2924f8237ccc328449d
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-04 07:47:59 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
5381437664
logtail, net/portmapper, wgengine/magicsock: use fmt.Appendf
...
Fixes #5206
Change-Id: I490bb92e774ce7c044040537e2cd864fcf1dbe5a
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-03 21:35:51 -07:00
9e5954c598
control/controlclient: fix crash in tests elsewhere when GetNLPublicKey is nil
...
4001d0bf25 caused tests in another repo to fail with a crash, calling
a nil func. This might not be the right fix, but fixes the build.
Change-Id: I67263f883c298f307abdd22bc2a30b3393f062e6
Co-authored-by: Maisem Ali <maisem@tailscale.com >
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-03 16:39:06 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
5f6abcfa6f
all: migrate code from netaddr.FromStdAddr to Go 1.18
...
With caveat https://github.com/golang/go/issues/53607#issuecomment-1203466984
that then requires a new wrapper. But a simpler one at least.
Updates #5162
Change-Id: I0a5265065bfcd7f21e8dd65b2bd74cae90d76090
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-02 22:25:07 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
7c7e23d87a
control/controlclient, tailcfg: add 6 more patchable Node fields [capver 36]
...
Change-Id: Iae997a9a98a5dd841bc41fa91227d5a7dd476a25
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-02 21:14:00 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
8725b14056
all: migrate more code code to net/netip directly
...
Instead of going through the tailscale.com/net/netaddr transitional
wrappers.
Updates #5162
Change-Id: I3dafd1c2effa1a6caa9b7151ecf6edd1a3fda3dd
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-02 13:59:57 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
e1309e1323
all: require Go 1.19
...
Updates #5210
Change-Id: I2e950b4776636b4ea89b6566b60e4a87596a3a43
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-02 11:49:01 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
fb82299f5a
wgengine/magicsock: avoid RebindingUDPConn mutex in common read/write case
...
Change-Id: I209fac567326f2e926bace2582dbc67a8bc94c78
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-02 11:27:10 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
116f55ff66
all: gofmt for Go 1.19
...
Updates #5210
Change-Id: Ib02cd5e43d0a8db60c1f09755a8ac7b140b670be
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-02 10:08:05 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
5d0e3d379c
go.mod: bump gvisor
...
For https://github.com/google/gvisor/pull/7850 to quiet macOS warnings.
Updates #5240
Change-Id: Iaa7abab20485c8ff40e5c9b16013aef4fd297a64
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-08-01 16:48:27 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
357fd85ecf
go.toolchain.rev: bump tailscale.go1.19 commit
...
for mutex slow path metrics: https://github.com/tailscale/go/pull/33
(a maybe temporary experiment)
Change-Id: Idba1ef866e2e1764728bdd869c25becccc1051b0
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-31 22:10:31 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
acc3b7f259
go.mod: bump inet.af/wf, tidy
...
This removes inet.af/netaddr from go.{mod,sum}.
Updates #5162
Change-Id: I7121e9fbb96d036cf188c51f0b53731570252d69
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-28 14:50:50 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
f541e00db2
go.toolchain.rev: bump for VERSION file
...
Updates #5210
Change-Id: Ib6db8b010a6a9369a3eda8a86a49e538e376aff6
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-28 14:29:15 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
eae003e56f
ipn/ipnlocal: blend existing host SSH keys + newly-generated types as needed
...
If the host only has RSA, use its RSA + generate ecdsa + ed25519, etc.
Perhaps fixes https://twitter.com/colek42c/status/1550554439299244032 and
something else that was reported.
Change-Id: I88dc475c8e3d95b6f25288ff7664b8e72655fd16
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-28 11:42:58 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
e5176f572e
go.toolchain.rev: switch to Go 1.19rc2+
...
Switch to Go 1.19rc2 in prep for the Go 1.19 GA release on Tuesday.
(We won't be using any Go 1.19 features until then.)
Updates #5210
Change-Id: I94fa0ae8f5645fb7579429668f3970c18d1796d8
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-28 11:28:21 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
48e73e147a
logtail,logpolicy: tweak minor cosmetic things
...
Just reading the code again in prep for some alloc reductions.
Change-Id: I065226ea794b7ec7144c2b15942d35131c9313a8
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-27 21:13:46 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
97b8c4fa1b
ipn/store/awsstore: add "ts_omit_aws" build tag to reduce binary size
...
Drops tailscaled from 23M to 21M.
Change-Id: I731c542d03113ac94abb695e3c8fcacbc5542712
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-27 14:19:33 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
0a6aa75a2d
cmd/tailscaled: add opt-in support for linking CLI into daemon
...
Doesn't help much, though.
$ go install --tags=ts_include_cli ./cmd/tailscaled/
$ ls -lh ~/go/bin/tailscaled
-rwxr-xr-x 2 bradfitz bradfitz 34M Jul 27 11:00 /home/bradfitz/go/bin/tailscaled
$ go install --tags= ./cmd/tailscaled/
$ ls -lh ~/go/bin/tailscaled
-rwxr-xr-x 1 bradfitz bradfitz 23M Jul 27 11:00 /home/bradfitz/go/bin/tailscaled
$ ls -lh ~/go/bin/tailscale
-rwxr-xr-x 1 bradfitz bradfitz 13M Jul 25 21:30 /home/bradfitz/go/bin/tailscale
Fixes #2233
Change-Id: I46bae91bb38eb47a76251c1b5c1e9e455fc234b6
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-27 11:15:52 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
04cf46a762
util/deephash: fix unexported time.Time hashing
...
Updates tailscale/corp#6311
Change-Id: I33cd7e4040966261c2f2eb3d32f29936aeb7f632
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-27 09:28:23 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
7c671b0220
.github/workflows: add gofmt (goimports) check
...
Change-Id: Iceb3182827b9c65f28f0351e0e254abe4a95e4de
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-26 09:46:06 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
dd3e91b678
go.mod: tidy, remove inet.af/netaddr
...
It was actually unused earlier, but I had a test program
in my git workdir, keeping go mod tidy from cleaning it.
(more CI needed, perhaps)
Updates #5162
Change-Id: I9047a9aaa6fde7736d6ef516dc3bb652d06fe921
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-25 22:08:20 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
a12aad6b47
all: convert more code to use net/netip directly
...
perl -i -npe 's,netaddr.IPPrefixFrom,netip.PrefixFrom,' $(git grep -l -F netaddr.)
perl -i -npe 's,netaddr.IPPortFrom,netip.AddrPortFrom,' $(git grep -l -F netaddr. )
perl -i -npe 's,netaddr.IPPrefix,netip.Prefix,g' $(git grep -l -F netaddr. )
perl -i -npe 's,netaddr.IPPort,netip.AddrPort,g' $(git grep -l -F netaddr. )
perl -i -npe 's,netaddr.IP\b,netip.Addr,g' $(git grep -l -F netaddr. )
perl -i -npe 's,netaddr.IPv6Raw\b,netip.AddrFrom16,g' $(git grep -l -F netaddr. )
goimports -w .
Then delete some stuff from the net/netaddr shim package which is no
longer neeed.
Updates #5162
Change-Id: Ia7a86893fe21c7e3ee1ec823e8aba288d4566cd8
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-25 21:53:49 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
6a396731eb
all: use various net/netip parse funcs directly
...
Mechanical change with perl+goimports.
Changed {Must,}Parse{IP,IPPrefix,IPPort} to their netip variants, then
goimports -d .
Finally, removed the net/netaddr wrappers, to prevent future use.
Updates #5162
Change-Id: I59c0e38b5fbca5a935d701645789cddf3d7863ad
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-25 21:12:28 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
730ca4203c
cmd/tsshd: add a package line to appease gofmt
...
Change-Id: I2fbbe983186169ddf1995d2f51c7b5a6164a0904
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-25 20:52:04 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
7eaf5e509f
net/netaddr: start migrating to net/netip via new netaddr adapter package
...
Updates #5162
Change-Id: Id7bdec303b25471f69d542f8ce43805328d56c12
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-25 16:20:43 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
2024008667
types/key: add MachinePrecomputedSharedKey.Open
...
Follow-up to cfdb862673
Updates tailscale/corp#1709
Change-Id: I7af931a2cb55f9006e1029381663ac21d1794242
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-22 12:05:29 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
ba91f57ddd
ipn/ipnlocal: ignore empty SSH host key files
...
Change-Id: I332b0d7d01386111d0af4adf98c96c04d3d12fbb
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-22 10:52:04 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
227c6b2a53
ipn/ipnlocal: flesh out error on ssh host key parse error
...
Change-Id: Iedd2d3898befa536181036b9e9dea59bc777a440
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-22 08:09:59 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
43f3a969ca
types/views: add SliceContains, View.ContainsFunc, View.IndexFunc
...
We were starting to write these elsewhere as little unexported copies
in misc places.
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-21 08:28:43 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
d8cb5aae17
tailcfg, control/controlclient: add tailcfg.PeersChangedPatch [capver 33]
...
This adds a lighter mechanism for endpoint updates from control.
Change-Id: If169c26becb76d683e9877dc48cfb35f90cc5f24
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-20 15:05:56 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
b7f1fe7b0d
tailcfg: remove old DNS fields
...
The control plane server doesn't send these to modern clients so we
don't need them in the tree. The server has its own serialization code
to generate legacy MapResponses when needed.
Change-Id: Idd1e5d96ddf9d4306f2da550d20b77f0c252817a
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-19 21:23:12 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
9bd3b5b89c
types/key: add ControlPrivate.Shared wrapper too
...
Follow-up to cfdb862673 .
Change-Id: Iab610d761f1e6d88e8bcb584d9c02cafe48fc377
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-19 14:49:01 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
cfdb862673
types/key: add naclbox shared key wrapper type + Seal method
...
So the control plane can stop doing precomputations on each naclbox
message.
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-19 14:18:12 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
2a22ea3e83
util/deephash: generate type-specific hasher funcs
...
name old time/op new time/op delta
Hash-8 71.1µs ± 2% 71.5µs ± 1% ~ (p=0.114 n=9+8)
HashPacketFilter-8 8.39µs ± 1% 4.83µs ± 2% -42.38% (p=0.000 n=8+9)
HashMapAcyclic-8 56.2µs ± 1% 56.9µs ± 2% +1.17% (p=0.035 n=10+9)
TailcfgNode-8 6.49µs ± 2% 3.54µs ± 1% -45.37% (p=0.000 n=9+9)
HashArray-8 729ns ± 2% 566ns ± 3% -22.30% (p=0.000 n=10+10)
name old alloc/op new alloc/op delta
Hash-8 24.0B ± 0% 24.0B ± 0% ~ (all equal)
HashPacketFilter-8 24.0B ± 0% 24.0B ± 0% ~ (all equal)
HashMapAcyclic-8 0.00B 0.00B ~ (all equal)
TailcfgNode-8 0.00B 0.00B ~ (all equal)
HashArray-8 0.00B 0.00B ~ (all equal)
name old allocs/op new allocs/op delta
Hash-8 1.00 ± 0% 1.00 ± 0% ~ (all equal)
HashPacketFilter-8 1.00 ± 0% 1.00 ± 0% ~ (all equal)
HashMapAcyclic-8 0.00 0.00 ~ (all equal)
TailcfgNode-8 0.00 0.00 ~ (all equal)
HashArray-8 0.00 0.00 ~ (all equal)
Change-Id: I34c4e786e748fe60280646d40cc63a2adb2ea6fe
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-19 11:33:13 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
2491fe1afe
tailcfg: add missing omitempty annotation to PopBrowserURL
...
Change-Id: I8e752afd5bf009c17aae1b53650479b37c3232bd
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-19 09:25:06 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
469c30c33b
ipn/localapi: define a cert dir for Synology DSM6
...
Fixes #4060
Change-Id: I5f145d4f56f6edb14825268e858d419c55918673
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-18 09:51:24 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
0d52674a84
net/tstun: diagnose /dev/net/tun fd leak, give better failure message
...
Updates #5029
Change-Id: Ibee5e0c9076fe764eb5d856d5ef8b09f4d0e2921
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-16 14:21:56 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
931f18b575
derp: add missing docs on clientInfo.Version
...
It's not the Tailscale version.
Change-Id: Icfbd5ff36300b2125b19cd2fa6caa22876965317
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-15 12:00:19 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
7fb6781bda
go.toolchain.rev: bump for Go 1.18.4 + runtime timer spin
...
See https://github.com/tailscale/go/pull/32
Updates #4760
Updates #5030 ?
Updates #4891 ?
Change-Id: I066aafddc09fade30a5f3fdee23e6bd200eda9fa
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-13 20:56:59 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
505ca2750d
cmd/tailscaled: fix Windows "Allow local LAN access" regression
...
3f686688a6 regressed the Windows beFirewallKillswitch code,
preventing the /firewall subprocess from running.
Fixes tailscale/corp#6063
Change-Id: Ibd105759e5fecfeffc54f587f8ddcd0f1cbc4dca
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-13 08:01:32 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
c93fd0d22b
go.mod: bump wireguard-go to set CLOEXEC on tun/netlink fds
...
To get:
https://github.com/WireGuard/wireguard-go/commit/c31a7b1ab47807f01613a571cc480f79d5fb4181
Diff:
https://github.com/WireGuard/wireguard-go/compare/95b48cdb3961..c31a7b1ab47807f01613a571cc480f79d5fb4181
Fixes #4992
Change-Id: I077586fefcde923a2721712dd54548f97d010f72
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-07-03 17:11:49 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
6b71568eb7
util/cloudenv: add Azure support & DNS IPs
...
And rewrite cloud detection to try to do only zero or one metadata
discovery request for all clouds, only doing a first (or second) as
confidence increases. Work remains for Windows, but a start.
And add Cloud to tailcfg.Hostinfo, which helped with testing using
"tailcfg debug hostinfo".
Updates #4983 (Linux only)
Updates #4984
Change-Id: Ib03337089122ce0cb38c34f724ba4b4812bc614e
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-30 17:03:46 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
aa37aece9c
ipn/ipnlocal, net/dns*, util/cloudenv: add AWS DNS support
...
And remove the GCP special-casing from ipn/ipnlocal; do it only in the
forwarder for *.internal.
Fixes #4980
Fixes #4981
Change-Id: I5c481e96d91f3d51d274a80fbd37c38f16dfa5cb
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-29 20:37:44 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
88c2afd1e3
ipn/ipnlocal, net/dns*, util/cloudenv: specialize DNS config on Google Cloud
...
This does three things:
* If you're on GCP, it adds a *.internal DNS split route to the
metadata server, so we never break GCP DNS names. This lets people
have some Tailscale nodes on GCP and some not (e.g. laptops at home)
without having to add a Tailnet-wide *.internal DNS route.
If you already have such a route, though, it won't overwrite it.
* If the 100.100.100.100 DNS forwarder has nowhere to forward to,
it forwards it to the GCP metadata IP, which forwards to 8.8.8.8.
This means there are never errNoUpstreams ("upstream nameservers not set")
errors on GCP due to e.g. mangled /etc/resolv.conf (GCP default VMs
don't have systemd-resolved, so it's likely a DNS supremacy fight)
* makes the DNS fallback mechanism use the GCP metadata IP as a
fallback before our hosted HTTP-based fallbacks
I created a default GCP VM from their web wizard. It has no
systemd-resolved.
I then made its /etc/resolv.conf be empty and deleted its GCP
hostnames in /etc/hosts.
I then logged in to a tailnet with no global DNS settings.
With this, tailscaled writes /etc/resolv.conf (direct mode, as no
systemd-resolved) and sets it to 100.100.100.100, which then has
regular DNS via the metadata IP and *.internal DNS via the metadata IP
as well. If the tailnet configures explicit DNS servers, those are used
instead, except for *.internal.
This also adds a new util/cloudenv package based on version/distro
where the cloud type is only detected once. We'll likely expand it in
the future for other clouds, doing variants of this change for other
popular cloud environments.
Fixes #4911
RELNOTES=Google Cloud DNS improvements
Change-Id: I19f3c2075983669b2b2c0f29a548da8de373c7cf
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-29 17:39:13 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
ef351ac0dd
Dockerfile: fix build
...
The Dockerfile directions said:
But that failed with:
Step 14/15 : FROM ghcr.io/tailscale/alpine-base:3.14
Head "https://ghcr.io/v2/tailscale/alpine-base/manifests/3.14 ": denied: denied
So I guess the Dockerfile.base part was undocumented. But it only had
one line anyway, so move it here to avoid the intermediate layer's
published permissions problem entirely.
Also optimize the cachability a bit while here.
Change-Id: I846ad59fe7e88e6126925689fae78bfb80c279f0
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-29 08:18:01 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
3b1f99ded1
ssh/tailssh: fix Tailscale SSH to Linux Arch machines
...
See https://github.com/tailscale/tailscale/issues/4924#issuecomment-1168201823
Arch uses a different login binary that makes the -h flag set the PAM
service to "remote". So if they don't have that configured, don't pass -h.
Thanks to @eddiezane for debugging!
Updates #4924
Change-Id: I8d33e0afb2dfb99517bcea2f9d5d0c6247519b3c
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-28 15:35:51 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
3ac8ab1791
tsnet: add Server.AuthKey field
...
... so callers can provide the AuthKey via mechanisms other than
environment variables which means multiple Servers can't be started
concurrently in the same process without coordination.
Change-Id: I7736ef4f59b7cc29637939e140e990613ce58e0d
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-27 21:57:57 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
35782f891d
util/deephash: add canMemHash func + typeInfo property
...
Currently unused. (breaking up a bigger change)
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-25 13:09:30 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
7b9a901489
util/deephash: add packet filter benchmark
...
(breaking up parts of another change)
This adds a PacketFilter hashing benchmark with an input that both
contains every possible field, but also is somewhat representative in
the shape of what real packet filters contain.
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-25 12:55:15 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
8c5c87be26
util/deephash: fix collisions between different types
...
Updates #4883
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-21 22:29:04 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
87a4c75fd4
control/controlclient, ipn/ipnlocal: remove Client.SetExpirySooner, fix race
...
Client.SetExpirySooner isn't part of the state machine. Remove it from
the Client interface.
And fix a use of LocalBackend.cc without acquiring the lock that
guards that field.
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-19 22:08:29 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
ef0d740270
control/controlclient: remove Client.SetStatusFunc
...
It can't change at runtime. Make it an option.
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-19 21:54:39 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
70a2797064
control/controlclient, ipn/ipnlocal: remove some Client methods
...
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-19 18:11:59 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
a1e429f7c3
control/controlclient, types/netmap: remove unused LocalPort field
...
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-19 17:22:00 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
526b0b6890
control/controlclient: start simplifying netmap fetch APIs
...
Step 1 of many, cleaning up the direct/auto client & restarting map
requests that leads to all the unnecessary map requests.
Updates tailscale/corp#5761
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-19 15:43:12 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
467eb2eca0
cmd/tailscale/cli, ipn/ipnlocal: give SSH tips when off/unconfigured
...
Updates #3802
Change-Id: I6b9a3175f68a6daa670f912561f2c2ececc07770
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-17 19:37:59 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
99ed54926b
tailcfg: define some Node.Capabilities about SSH, its config
...
Updates #3802
Change-Id: Icb4ccbc6bd1c6304013bfc553d04007844a5c0bf
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-17 12:14:50 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
13d0b8e6a4
control/controlclient, net/dnscache: use typed singleflight fork
...
Change-Id: I12be4c5a91ae3a812fe88d9b2d15526fdbb5a921
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-17 10:20:16 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
59ed846277
util/singleflight: add fork of singleflight with generics
...
Forked from golang.org/x/sync/singleflight at
the x/sync repo's commit 67f06af15bc961c363a7260195bcd53487529a21
Updates golang/go#53427
Change-Id: Iec2b47b7777940017bb9b3db9bd7d93ba4a2e394
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-17 10:20:16 -07:00
757ecf7e80
util/deephash: fix map hashing when key & element have the same type
...
Regression from 09afb8e35b , in which the
same reflect.Value scratch value was being used as the map iterator
copy destination.
Also: make nil and empty maps hash differently, add test.
Fixes #4871
Co-authored-by: Josh Bleecher Snyder <josharian@gmail.com >
Change-Id: I67f42524bc81f694c1b7259d6682200125ea4a66
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-16 22:29:47 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
22c544bca7
go.mod: bump go4.org/unsafe/assume-no-moving-gc for Go 1.19beta1
...
Otherwise we crash at startup with Go 1.19beta1.
Updates #4872
Change-Id: I371df4146735f7e066efd2edd48c1a305906c13d
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-16 20:40:22 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
f31588786f
util/deephash: don't track cycles on non-recursive types
...
name old time/op new time/op delta
Hash-8 67.3µs ±20% 76.5µs ±16% ~ (p=0.143 n=10+10)
HashMapAcyclic-8 63.0µs ± 2% 56.3µs ± 1% -10.65% (p=0.000 n=10+8)
TailcfgNode-8 9.18µs ± 2% 6.52µs ± 3% -28.96% (p=0.000 n=9+10)
HashArray-8 732ns ± 3% 709ns ± 1% -3.21% (p=0.000 n=10+10)
name old alloc/op new alloc/op delta
Hash-8 24.0B ± 0% 24.0B ± 0% ~ (all equal)
HashMapAcyclic-8 0.00B 0.00B ~ (all equal)
TailcfgNode-8 0.00B 0.00B ~ (all equal)
HashArray-8 0.00B 0.00B ~ (all equal)
name old allocs/op new allocs/op delta
Hash-8 1.00 ± 0% 1.00 ± 0% ~ (all equal)
HashMapAcyclic-8 0.00 0.00 ~ (all equal)
TailcfgNode-8 0.00 0.00 ~ (all equal)
HashArray-8 0.00 0.00 ~ (all equal)
Change-Id: I28642050d837dff66b2db54b2b0e6d272a930be8
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-16 18:39:10 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
36ea837736
util/deephash: fix map hashing to actually hash elements
...
Fixes #4868
Change-Id: I574fd139cb7f7033dd93527344e6aa0e625477c7
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-16 11:32:12 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
4005134263
tailcfg: clarify some of the MapRequest variants
...
Change-Id: Ia09bd69856e372c3a6b64cda7ddb34029b32a11b
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-14 13:08:55 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
d3643fa151
cmd/tailscale: add 'debug ts2021' Noise connectivity subcommand
...
Updates #3488
Change-Id: I9272e68f66c4cf36fb98dd1248a74d3817447690
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-08 09:07:05 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
db83926121
go.toolchain.rev: bump Go to 1.18.3 (+ Tailscale patches)
...
See https://github.com/tailscale/go/commits/04d67b90d8cfd6f822664220f79e0e69cacb6b5c
Diff:
https://github.com/tailscale/go/compare/bb6009ec7cd24dbcf2a32034893c9cfbc1f8c36b..04d67b90d8cfd6f822664220f79e0e69cacb6b5c
Change-Id: Ic0abd3058f3696c3f8007e1004ab4bf377c5323c
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-06 15:46:28 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
4007601f73
cmd/controlclient: wire up PingRequest peerapi pings too
...
Updates tailscale/corp#754
Change-Id: I61ac3fc44783b54bd02455bcb0baf19159b7a9d2
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-06 13:41:34 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
0d972678e7
cmd/tailscale/cli: disable 'tailscale ssh' on sandboxed macOS
...
Updates #3802
Updates #4518
Fixes #4628
Change-Id: I194d2cc30fc8e38b66d4910787efbce14317b0ff
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-06 08:54:38 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
0df3b76c25
tsweb: fix Port80Handler redirect to https with FQDN unset
...
Fixes the current http://pkgs.tailscale.com/ redirect to https:///
as that server doesn't configure the Port80Handler.FQDN field.
Change-Id: Iff56e6127a46c306ca97738d91b217bcab32a582
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-05 13:01:30 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
fbc079d82d
ipn/ipnlocal: prevent attempting to run SSH on Synology for now
...
On DSM7 as a non-root user it'll run into problems.
And we haven't tested on DSM6, even though it might work, but I doubt
it.
Updates #3802
Updates tailscale/corp#5468
Change-Id: I75729042e4788f03f9eb82057482a44b319f04f3
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-03 13:50:33 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
2bac8b6013
Revert "cmd/tailscale/cli: disallow --ssh on Synology"
...
This reverts commit 03e3e6abcd
in favor of #4785 .
Change-Id: Ied65914106917c4cb8d15d6ad5e093a6299d1d48
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-03 13:49:42 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
a9b4bf1535
ipn/ipnserver, cmd/tailscaled: fix peerapi on Windows
...
We weren't wiring up netstack.Impl to the LocalBackend in some cases
on Windows. This fixes Windows 7 when run as a service.
Updates #4750 (fixes after pull in to corp repo)
Change-Id: I9ce51b797710f2bedfa90545776b7628c7528e99
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-03 12:24:47 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
69b535c01f
wgengine/netstack: replace a 1500 with a const + doc
...
Per post-submit code review feedback of 1336fb740b from @maisem.
Change-Id: Ic5c16306cbdee1029518448642304981f77ea1fd
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-02 08:24:35 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
e428bba7a3
ssh/tailssh: add metrics
...
Updates #3802
Change-Id: Ic9a4b8c51cff6dfe148a1c78bc0e5074195b7f80
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-02 08:18:53 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
1336fb740b
wgengine/netstack: make netstack MTU be 1280 also
...
Updates #3878
Change-Id: I1850085b32c8a40d85607b4ad433622c97d96a8d
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-06-01 12:16:41 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
4d85cf586b
cmd/tailscale, ipn/ipnlocal: add "peerapi" ping type
...
For debugging when stuff like #4750 isn't working.
RELNOTE=tailscale ping -peerapi
Change-Id: I9c52c90fb046e3ab7d2b121387073319fbf27b99
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-28 13:47:12 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
02e580c1d2
logtail: use http.NewRequestWithContext
...
Saves some allocs. Not hot, but because we can now.
And a const instead of a var.
Change-Id: Ieb2b64534ed38051c36b2c0aa2e82739d9d0e015
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-27 16:33:43 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
c81be7b899
control/controlclient: avoid Noise protocol for js/wasm for now
...
Updates #3157
Change-Id: I04accc09783a68257d28cadde5818bf0724a8013
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-20 12:09:09 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
cc91a05686
ipn/ipnserver: fix build on js/wasm
...
Broken by 3dedcd1640 but we don't have CI coverage yet.
Updates #3157
Change-Id: Ie8e95ebd36264887fdeed16fc9f25a857d48124b
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-19 15:01:27 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
48d43134d7
cmd/tsshd: delete, leaving only forwarding docs
...
Updates #3802
Change-Id: I89d4d3d68d64af9bc7288a149b4b34f61884f5f4
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-16 11:52:44 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
da601c23e1
ipn/ipnlocal: add missing place where we set the SSH atomic
...
This fixes the "tailscale up --authkey=... --ssh" path (or any "up"
path that used Start instead of EditPrefs) which wasn't setting the
bit.
Updates #3802
Change-Id: Ifca532ec58296fedcedb5582312dfee884367ed7
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-14 12:47:28 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
4c75605e23
go.toolchain.rev: bump Tailscale Go toolchain
...
For https://github.com/tailscale/go/commit/bb6009ec7cd24dbcf2a32034893c9cfbc1f8c36b
(The cherry-picked fix for golang/go#51776 )
Change-Id: Ib4a67c0f82256c62989fbba2cc9c15b728313ebd
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-10 05:31:13 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
35111061e9
wgengine/netstack, ipn/ipnlocal: serve http://100.100.100.100/
...
For future stuff.
Change-Id: I64615b8b2ab50b57e4eef1ca66fa72e3458cb4a9
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-06 07:51:28 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
c4f06ef7be
client/tailscale: fix ExpandSNIName on non-default LocalClient
...
It was using a mix.
Found by @maisem.
Change-Id: Ieb79d78608474ac13c2f44e0f3d8997a5665eb13
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-05 12:22:38 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
46cb9d98a3
api.md: update GET tailnet key detail docs to show preauthorized, tags
...
Fixes #4571
Change-Id: If81471d0d8cb2f659736991ad8612aed2efc174e
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-05 12:09:28 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
c1445155ef
ssh/tailssh: handle Control-C during hold-and-delegate prompt
...
Fixes #4549
Change-Id: Iafc61af5e08cd03564d39cf667e940b2417714cc
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-05 11:47:08 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
2d1849a7b9
tsweb: remove JSONHandlerFunc
...
It's unused and we've decided it's not what we want.
Change-Id: I425a0104e8869630b498a0adfd0f455876d6f92b
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-04 11:52:07 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
3e1f2d01f7
ipn/ipnlocal: move Ping method from IPN bus to LocalBackend (HTTP)
...
Change-Id: I61759f1dae8d9d446353db54c8b1e13bfffb3287
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-03 15:59:19 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
66f9292835
client/tailscale: update Client API a bit
...
Change-Id: I81aa29a8b042a247eac1941038f5d90259569941
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-03 11:30:57 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
512573598a
tailcfg: remove some documented DebugFlags that no longer exist
...
Update tailscale/corp#5007
Change-Id: I3ce5b1c4cd367bae769a5f5a301925a2dac1b3a6
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-05-03 08:28:41 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
a54671529b
client/tailscale: move API client for the control admin API
...
This was work done Nov-Dec 2020 by @c22wen and @chungdaniel.
This is just moving it to another repo.
Co-Authored-By: Christina Wen <37028905+c22wen@users.noreply.github.com >
Co-Authored-By: Christina Wen <christina@tailscale.com >
Co-Authored-By: Daniel Chung <chungdaniel@users.noreply.github.com >
Co-Authored-By: Daniel Chung <daniel@tailscale.com >
Change-Id: I6da3b05b972b54771f796b5be82de5aa463635ca
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-04-30 09:05:26 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
e3619b890c
client/tailscale: rename tailscale.go -> localclient.go
...
In prep for other stuff.
Change-Id: I82c24946d062d668cab48ca6749776b6ae7025ac
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-04-29 19:50:40 -07:00
Brad Fitzpatrick and Brad Fitzpatrick
87ba528ae0
client/tailscale: move/copy all package funcs to new LocalClient type
...
Remove all global variables, and clean up tsnet and cmd/tailscale's usage.
This is in prep for using this package for the web API too (it has the
best package name).
RELNOTE=tailscale.com/client/tailscale package refactored w/ LocalClient type
Change-Id: Iba9f162fff0c520a09d1d4bd8862f5c5acc9d7cd
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com >
2022-04-29 13:57:52 -07:00