David Anderson and Dave Anderson
fad21af01c
tailcfg: add DNS routes and advanced resolver config.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-08 15:29:08 -07:00
David Anderson
6def647514
net/dns/resolver: don't avoid tailscale routes for DNS forwarding.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-08 12:20:42 -07:00
David Anderson and Dave Anderson
4a64d2a603
net/dns: some post-review cleanups.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson and Dave Anderson
720c1ad0f0
net/dns: insert OS base config when emulating split DNS.
...
Part of #953 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson and Dave Anderson
e560be6443
net/dns: sort matchDomains to avoid test flake.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson and Dave Anderson
68f76e9aa1
net/dns: add GetBaseConfig to OSConfigurator interface.
...
Part of #953 , required to make split DNS work on more basic
platforms.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson and Dave Anderson
fe9cd61d71
net/dns: add tests for DNS config generation.
...
Part of #953 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson and Dave Anderson
0ba6d03768
net/dns/resolver: add a test helper to get at the resolver config.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson and Dave Anderson
da4cc8bbb4
net/dns: handle all possible translations of high-level DNS config.
...
With this change, all OSes can sort-of do split DNS, except that the
default upstream is hardcoded to 8.8.8.8 pending further plumbing.
Additionally, Windows 8-10 can do split DNS fully correctly, without
the 8.8.8.8 hack.
Part of #953 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-07 15:40:31 -07:00
David Anderson
e0e677a8f6
net/dns: split out search domains and match domains in OSConfig.
...
It seems that all the setups that support split DNS understand
this distinction, and it's an important one when translating
high-level configuration.
Part of #953 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-06 15:27:09 -07:00
David Anderson
a8dcda9c9a
net/dns: start of compat hacks for Windows 7.
...
Correctly reports that Win7 cannot do split DNS, and has a helper to
discover the "base" resolvers for the system.
Part of #953
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-06 15:27:09 -07:00
David Anderson and Dave Anderson
3e915ac783
net/dns: implement OS-level split DNS for Windows.
...
Part of #953 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 22:53:10 -07:00
David Anderson and Dave Anderson
c16a926bf2
net/dns: set OSConfig.Primary.
...
OS implementations are going to support split DNS soon.
Until they're all in place, hardcode Primary=true to get
the old behavior.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 22:53:10 -07:00
David Anderson and Dave Anderson
bc4381447f
net/tstun: return the real interface name at device creation.
...
This is usually the same as the requested interface, but on some
unixes can vary based on device number allocation, and on Windows
it's the GUID instead of the pretty name, since everything relating
to configuration wants the GUID.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 22:53:10 -07:00
David Anderson
de6dc4c510
net/dns: add a Primary field to OSConfig.
...
Currently ignored.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 13:05:47 -07:00
David Anderson and Dave Anderson
b2a597b288
net/dns: rename Set to SetDNS in OSConfigurator.
...
wgengine/router.CallbackRouter needs to support both the Router
and OSConfigurator interfaces, so the setters can't both be called
Set.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson and Dave Anderson
7d84ee6c98
net/dns: unify the OS manager and internal resolver.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson and Dave Anderson
1bf91c8123
net/dns/resolver: remove unused err return value.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson and Dave Anderson
6a206fd0fb
net/dns: rename impl to os.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson and Dave Anderson
c4530971db
net/dns/resolver: remove leftover debug print.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson and Dave Anderson
f007a9dd6b
health: add DNS subsystem and plumb errors in.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson and Dave Anderson
4c61ebacf4
wgengine: move DNS configuration out of wgengine/router.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-05 10:55:35 -07:00
David Anderson
748670f1e9
net/dns: fix typo in docstring.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 18:44:02 -07:00
David Anderson
27a1a2976a
wgengine/router: add a CallbackRouter shim.
...
The shim implements both network and DNS configurators,
and feeds both into a single callback that receives
both configs.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 18:43:24 -07:00
David Anderson
f89dc1c903
ipn/ipnlocal: don't install any magicdns names if not proxying.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 14:24:47 -07:00
David Anderson
a39d2403bc
net/dns: disable NetworkManager and resolved configurators temporarily.
...
They need some rework to do the right thing, in the meantime the direct
and resolvconf managers will work out.
The resolved implementation was never selected due to control-side settings.
The networkmanager implementation mostly doesn't get selected due to
unforeseen interactions with `resolvconf` on many platforms.
Both implementations also need rework to support the various routing modes
they're capable of.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 02:41:33 -07:00
David Anderson
befd8e4e68
net/dns: replace managerImpl with OSConfigurator in code.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 02:34:40 -07:00
David Anderson
077d4dc8c7
net/dns: add an OSConfigurator interface.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 01:49:17 -07:00
David Anderson and Dave Anderson
6ad44f9fdf
wgengine: take in dns.Config, split out to resolver.Config and dns.OSConfig.
...
Stepping stone towards having the DNS package handle the config splitting.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 00:59:44 -07:00
David Anderson and Dave Anderson
2edb57dbf1
net/dns: add new Config that captures tailscale+OS DNS config.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 00:59:44 -07:00
David Anderson and Dave Anderson
8af9d770cf
net/dns: rename Config to OSConfig.
...
Making way for a new higher level config struct.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-02 00:59:44 -07:00
David Anderson
fcfc0d3a08
net/dns: remove ManagerConfig, pass relevant args directly.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 23:26:52 -07:00
David Anderson
0ca04f1e01
net/dns: put noop.go back, limit with build tags for staticcheck.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 23:14:13 -07:00
David Anderson
95470c3448
net/dns: remove Cleanup manager parameter.
...
It's only use to skip some optional initialization during cleanup,
but that work is very minor anyway, and about to change drastically.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 23:06:56 -07:00
David Anderson
cf361bb9b1
net/dns: remove PerDomain from Config.
...
It's currently unused, and no longer makes sense with the upcoming
DNS infrastructure. Keep it in tailcfg for now, since we need protocol
compat for a bit longer.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 22:55:44 -07:00
David Anderson
f77ba75d6c
wgengine/router: move DNS cleanup into the DNS package.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 22:35:34 -07:00
David Anderson
15875ccc63
wgengine/router: don't store unused tunname on windows.
2021-04-01 22:28:24 -07:00
David Anderson
9f105d3968
net/dns/resolver: teach the forwarder to do per-domain routing.
...
Given a DNS route map, the forwarder selects the right set of
upstreams for a given name.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 19:42:48 -07:00
David Anderson
90f82b6946
net/dns/resolver: add live reconfig, plumb through to ipnlocal.
...
The resolver still only supports a single upstream config, and
ipn/wgengine still have to split up the DNS config, but this moves
closer to unifying the DNS configs.
As a handy side-effect of the refactor, IPv6 MagicDNS records exist
now.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-04-01 01:44:03 -07:00
David Anderson
caeafc4a32
net/dns/resolver: fix package docstring.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:42:28 -07:00
David Anderson
dbe4f6f42d
net/dns/resolver: unexport Resolve and ResolveReverse.
...
They're only used internally and in tests, and have surprising
semantics in that they only resolve MagicDNS names, not upstream
resolver queries.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:35:26 -07:00
David Anderson
cdeb8d6816
net/dns/resolver: fix staticcheck error.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:19:09 -07:00
David Anderson
f185d62dc8
net/dns/resolver: unexport Packet, only use it internally.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:12:31 -07:00
David Anderson
5fb9e00ecf
net/dns/resolver: remove Start method, fully spin up in New instead.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:12:31 -07:00
David Anderson
075fb93e69
net/dns/resolver: remove the Config struct.
...
In preparation for reintroducing a runtime reconfig Config struct.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:12:31 -07:00
David Anderson
bc81dd4690
net/dns/resolver: rename ResolverConfig to just Config.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:12:31 -07:00
David Anderson
d99f5b1596
net/dns/resolver: factor the resolver out into a sub-package.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-31 23:12:30 -07:00
David Anderson
07bf4eb685
wgengine: rename Fake to RespondToPing.
...
"Fake" doesn't mean a lot any more, given that many components
of the engine can be faked out, including in valid production
configurations like userspace-networking.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-28 21:45:02 -07:00
David Anderson
0fb738760f
wgengine: make Tun optional again, default to fake.
...
This makes setup more explicit in prod codepaths, without
requiring a bunch of arguments or helpers for tests and
userspace mode.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-28 21:45:02 -07:00
David Anderson
95ca86c048
go.mod: update to new wireguard-go version.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-28 19:05:55 -07:00
David Anderson
93a4aa697c
wgengine: default Router to a no-op router.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-28 18:59:48 -07:00
David Anderson
440effb21a
wgengine: remove Config.TUN argument.
2021-03-28 18:45:17 -07:00
David Anderson
2df8adef9d
wgengine: make the tun.Device required at construction.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-27 00:33:09 -07:00
David Anderson
25e0bb0a4e
net/tstun: rename wrap_windows.go to tun_windows.go.
...
The code has nothing to do with wrapping, it's windows-specific
driver initialization code.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 23:17:59 -07:00
David Anderson
22d53fe784
net/tstun: document exported function.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 23:17:01 -07:00
David Anderson
016de16b2e
net/tstun: rename TUN to Wrapper.
...
The tstun packagen contains both constructors for generic tun
Devices, and a wrapper that provides additional functionality.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 23:15:22 -07:00
David Anderson
82ab7972f4
net/tstun: rename NewFakeTUN to NewFake.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 22:46:47 -07:00
David Anderson and Dave Anderson
588b70f468
net/tstun: merge in wgengine/tstun.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 22:31:54 -07:00
David Anderson and Dave Anderson
018200aeba
net/tstun: rename from net/tun.
...
We depend on wireguard-go/tun, identical leaf packages can be
confusing in code.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 22:31:54 -07:00
David Anderson and Dave Anderson
2b4bfeda1a
wgengine: pass in an explicit router.Router, rather than a generator.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 22:01:55 -07:00
David Anderson and Dave Anderson
9ea5cbf81f
cmd/tailscaled: readd tun.Diagnose call, mistakenly lost during refactor.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 22:01:55 -07:00
David Anderson and Dave Anderson
44d9929208
wgengine: remove Config.TUNName, require caller to create device.
...
Also factors out device creation and associated OS workarounds to
net/tun.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 21:08:11 -07:00
David Anderson and Dave Anderson
0a84aaca0a
wgengine/router: remove unused wireguard *Device argument.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-26 19:43:13 -07:00
David Anderson
672731ac6f
many: gofmt.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-25 17:41:51 -07:00
David Anderson
6521f02ff6
Move DNS flush logic to net/dns.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-25 17:40:52 -07:00
David Anderson and Dave Anderson
9f7f2af008
wgengine/router/dns: move to net/dns.
...
Preparation for merging the APIs and whatnot.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-25 16:25:30 -07:00
David Anderson and Dave Anderson
8432999835
Move wgengine/tsdns to net/dns.
...
Straight move+fixup, no other changes. In prep for merging with
wgengine/router/dns.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-25 16:25:30 -07:00
David Anderson and Dave Anderson
8c0a0450d9
ipn/ipnlocal: allow client access to exit node's public IPs.
...
"public IP" is defined as an IP address configured on the exit node
itself that isn't in the list of forbidden ranges (RFC1918, CGNAT,
Tailscale).
Fixes #1522 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-19 11:54:15 -07:00
David Anderson and Dave Anderson
6fb5d4080c
net/portmapper: silently handle PCP NOT_AUTHORIZED responses.
...
Fixes #1525 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-17 19:44:35 -07:00
David Anderson
4543e4202f
VERSION.txt: this is 1.7.0.
2021-03-16 19:04:55 -07:00
David Anderson
6f48a8422a
version: remove version-info.sh when cleaning.
2021-03-16 16:38:19 -07:00
David Anderson
84aba349d9
Revert "wgengine/netstack: update gvisor to remove 64-bit only limitation"
...
Breaks our corp repo due to gRPC dependency hell.
This reverts commit d42f8b7f9a .
2021-03-16 15:36:06 -07:00
David Anderson
380a3526f6
cmd/tailscale/cli: warn if using subnet routing on BSD
...
Fixes #1475 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-15 17:25:59 -07:00
David Anderson
1bc3c03562
control/controlclient: allow for an unset linkMon.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-11 21:21:15 -08:00
David Anderson
fa6110e47b
wgengine/router: don't touch interface routes
...
Developed by a cast of dozens.
Fixes #1448
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-11 21:09:25 -08:00
David Anderson and Dave Anderson
0b66cfe1e0
control/controlclient: report broken IP forwarding more precisely.
...
IP forwarding is not required when advertising a machine's local IPs
over Tailscale.
Fixes #1435 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-11 10:49:57 -08:00
David Anderson
bf0740b011
Merge branch 'main' of github.com:tailscale/tailscale into danderson/filter-privacy
2021-03-09 16:33:55 -08:00
David Anderson and Dave Anderson
a7f12a110a
wgengine/filter: only log packets to/from non-default routes.
...
Fixes tailscale/corp#1429 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-09 16:28:43 -08:00
David Anderson
d79a2f3809
wgengine/filter: only log packets to/from non-default routes.
...
Fixes tailscale/corp#1429 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-09 16:24:09 -08:00
David Anderson and Dave Anderson
63a9adeb6c
portlist: collect IPv6 listening sockets on linux.
...
This is important because some of those v6 sockets are actually
dual-stacked sockets, so this is our only chance of discovering
some services.
Fixes #1443 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-04 13:52:56 -08:00
David Anderson and Dave Anderson
ad6edf5ecd
portlist: report a better process name for .Net on linux.
...
Fixes #1440 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-03 22:30:27 -08:00
David Anderson
2e347d1e10
tailcfg: tweak documentation for map version 11
...
version: bump date.
2021-03-03 15:06:35 -08:00
David Anderson
ea49b1e811
tailcfg: bump map request version for v6 + default routes.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-03 12:01:15 -08:00
David Anderson and Dave Anderson
1cb0ffc3ff
wgengine/router: make windows gracefully handle disabled IPv4 or IPv6.
...
This is necessary because either protocol can be disabled globally by a
Windows registry policy, at which point trying to touch that address
family results in "Element not found" errors. This change skips programming
address families that Windows tell us are unavailable.
Fixes #1396 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-03 11:48:17 -08:00
David Anderson
8d77dfdacb
wgengine/router: add a dummy IPv6 address if needed for default routing.
...
Fixes #1339
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-02 19:32:04 -08:00
David Anderson and Dave Anderson
793cb131f0
wgengine/router: toggle killswitch when using default routes on windows.
...
Fixes #1398 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-01 19:37:22 -08:00
David Anderson and Dave Anderson
ac3de93d5c
tempfork/wireguard-windows/firewall: add.
...
This is a fork of wireguard-windows's firewall package, with
the firewall rules adjusted to better line up with tailscale's
needs.
The package was taken from commit 3cc76ed5f222ec82748ef3bd8c41d4b059e28cdb
in our fork of wireguard-go.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-01 19:37:22 -08:00
David Anderson and Dave Anderson
f647e3daaf
ipn/ipnlocal: transform default routes into "all but LAN" routes.
...
Fixes #1177 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-03-01 18:47:43 -08:00
David Anderson
360095cd34
ipn: add tests for exit node pretty printing.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-24 21:18:35 -08:00
David Anderson
8ee1cb6156
ipn/ipnlocal: mark findExitNodeID as requiring mutex.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-24 21:18:33 -08:00
David Anderson and Dave Anderson
54d7070121
wgengine/router: correctly read IPv6 routes when diffing.
...
Fixes #1185 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-24 20:41:56 -08:00
David Anderson and Dave Anderson
abfd73f569
ipn: print currently selected exit route in Prefs.String().
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-24 20:41:56 -08:00
David Anderson and Dave Anderson
2404c0ffad
ipn/ipnlocal: only filter out default routes when computing the local wg config.
...
UIs need to see the full unedited netmap in order to know what exit nodes they
can offer to the user.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-24 20:41:56 -08:00
David Anderson
ebf3f2fd9f
cmd/tailscale/cli: add CLI option to offer an exit node to the tailnet.
...
Finishes up linux part of #1154 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-24 11:34:06 -08:00
David Anderson and Brad Fitzpatrick
d038a5295d
wgengine/wglog: drop 1/s "interface is up" messages.
...
Fixes #1388 .
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-23 09:01:58 -08:00
David Anderson
6e42430ad8
wgengine/monitor: don't log any single-IP routes added to the tailscale table.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-22 20:21:51 -08:00
David Anderson
df5adb2e23
wgengine/monitor: on linux, also monitor for IPv6 changes.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-22 19:38:07 -08:00
David Anderson and Dave Anderson
b83c273737
wgengine/filter: use IPSet for localNets instead of prefixes.
...
Part of #1177 , preparing for doing fancier set operations on
the allowed local nets.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-22 14:51:22 -08:00
David Anderson
e86b39b73f
ipn/ipnlocal: don't short-circuit default route filtering.
...
If no exit node is specified, the filter must still run to remove
offered default routes from all peers.
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-05 20:33:18 -08:00
David Anderson and Dave Anderson
a046b48593
cmd/tailscale/cli: display currently active exit node in tailscale status.
...
Signed-off-by: David Anderson <danderson@tailscale.com >
2021-02-05 14:53:17 -08:00