headscale/hscontrol/policy/v2
Kristoffer Dalby 835b7eb960 policy: autogroup:internet does not generate packet filters
According to Tailscale SaaS behavior, autogroup:internet is handled
by exit node routing via AllowedIPs, not by packet filtering. ACL
rules with autogroup:internet as destination should produce no
filter rules for any node.

Previously, Headscale expanded autogroup:internet to public CIDR
ranges and distributed filters to exit nodes (because 0.0.0.0/0
"covers" internet destinations). This was incorrect.

Add detection for AutoGroupInternet in filter compilation to skip
filter generation for this autogroup. Update test expectations
accordingly.
2026-02-05 19:29:16 +01:00
..
filter.go policy: autogroup:internet does not generate packet filters 2026-02-05 19:29:16 +01:00
filter_test.go policy: fix wildcard DstPorts format and proto:icmp handling 2026-02-05 19:29:16 +01:00
policy.go policy/v2: add IsTagged() guards to prevent panics on tagged nodes 2026-02-03 16:53:15 +01:00
policy_test.go policy/v2: add test for issue #2990 same-user tagged device 2026-02-03 16:53:15 +01:00
tailscale_compat_test.go policy: fix wildcard DstPorts format and proto:icmp handling 2026-02-05 19:29:16 +01:00
tailscale_routes_compat_test.go policy: autogroup:internet does not generate packet filters 2026-02-05 19:29:16 +01:00
types.go policy: fix wildcard DstPorts format and proto:icmp handling 2026-02-05 19:29:16 +01:00
types_test.go policy: use CGNAT/ULA ranges for wildcard resolution 2026-02-05 19:29:16 +01:00
utils.go modernize: run gopls modernize to bring up to 1.25 (#2920) 2025-12-01 19:40:25 +01:00
utils_test.go integration: replace time.Sleep with assert.EventuallyWithT (#2680) 2025-07-10 23:38:55 +02:00