invalidateAutogroupSelfCache derived the owning user from node.User().ID(), dereferencing the User association view. The NodeStore stores nodes by value with User as a *User pointer, and not every write path hydrates that association, so a non-tagged node could reach SetNodes with UserID set but User nil. UserView.ID() then dereferenced a nil *User and panicked on /machine/map whenever an autogroup:self policy was active and a node restarted tailscaled. Group affected nodes by node.TypedUserID(), which reads the UserID field directly. UserID is the authoritative ownership field for non-tagged nodes, so this needs no hydrated association and fixes every .User().ID() site in the function. |
||
|---|---|---|
| .. | ||
| matcher | ||
| policyutil | ||
| v2 | ||
| pm.go | ||
| policy.go | ||
| policy_autoapprove_test.go | ||
| policy_route_approval_test.go | ||
| policy_test.go | ||
| route_approval_test.go | ||