You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Anton Tolchanov
db34cdcfe7
cmd/tailscale/cli: add a risk message about rp_filter
...
We already present a health warning about this, but it is easy to miss
on a server when blackholing traffic makes it unreachable.
In addition to a health warning, present a risk message when exit node
is enabled.
Example:
```
$ tailscale up --exit-node=lizard
The following issues on your machine will likely make usage of exit nodes impossible:
- interface "ens4" has strict reverse-path filtering enabled
- interface "tailscale0" has strict reverse-path filtering enabled
Please set rp_filter=2 instead of rp_filter=1; see https://github.com/tailscale/tailscale/issues/3310
To skip this warning, use --accept-risk=linux-strict-rp-filter
$
```
Updates #3310
Signed-off-by: Anton Tolchanov <anton@tailscale.com>
10 months ago
..
auditlog
ipn/ipnext: remove some interface indirection to add hooks
12 months ago
conffile
ipn/conffile: don't depend on hujson on iOS/Android
2 years ago
desktop
ipn/ipnext: remove some interface indirection to add hooks
12 months ago
ipnauth
control/controlclient, ipn: add client audit logging ( #14950 )
1 year ago
ipnext
ipn/ipnlocal: make GetExt work earlier, before extension init
11 months ago
ipnlocal
cmd/tailscale/cli: add a risk message about rp_filter
10 months ago
ipnserver
ipn/ipn{server,test}: extract the LocalAPI test client and server into ipntest
11 months ago
ipnstate
Revert "ipn/ipnstate: add home DERP to tailscale status JSON"
1 year ago
lapitest
ipn/ipn{server,test}: extract the LocalAPI test client and server into ipntest
11 months ago
localapi
cmd/tailscale/cli: add a risk message about rp_filter
10 months ago
policy
ipn,tailconfig: clean up unreleased and removed app connector service
2 years ago
store
ipn/store: remove a layer of indirection for registering stores ( #15986 )
11 months ago
backend.go
ipn: add watch opt to include actions in health messages
11 months ago
conf.go
ipn: ensure that conffile is source of truth for advertised services. ( #15361 )
1 year ago
doc.go
ipn: generate LoginProfileView and use it instead of *LoginProfile where appropriate
1 year ago
ipn_clone.go
cmd/tailscale,ipn: add relay-server-port "tailscale set" flag and Prefs field ( #15594 )
1 year ago
ipn_test.go
all: do not depend on the testing package
2 years ago
ipn_view.go
cmd/tailscale,ipn: add relay-server-port "tailscale set" flag and Prefs field ( #15594 )
1 year ago
prefs.go
ipn: set RouteAll=true by default for new accounts on iOS and Android ( #16110 )
11 months ago
prefs_test.go
cmd/tailscale,ipn: add relay-server-port "tailscale set" flag and Prefs field ( #15594 )
1 year ago
serve.go
tailcfg: add ServiceName
1 year ago
serve_test.go
ipn: [serve] warn that foreground funnel won't work if shields are up ( #14685 )
1 year ago
store.go
ipn: add comment about thread-safety to StateStore
2 years ago
store_test.go
ipn: avoid useless no-op WriteState calls
3 years ago