headscale/hscontrol/policy/v2
Kristoffer Dalby 8573ff9158 policy/v2: fix grant-only policies returning FilterAllowAll
compileFilterRules checked only pol.ACLs == nil to decide whether
to return FilterAllowAll (permit-any). Policies that use only Grants
(no ACLs) had nil ACLs, so the function short-circuited before
compiling any CapGrant rules. This meant cap/relay, cap/drive, and
any other App-based grant capabilities were silently ignored.

Check both ACLs and Grants are empty before returning FilterAllowAll.

Updates #2180
2026-04-01 14:10:42 +01:00
..
testdata policy/v2: add advertised routes to compat test topologies 2026-04-01 14:10:42 +01:00
filter.go policy/v2: fix grant-only policies returning FilterAllowAll 2026-04-01 14:10:42 +01:00
filter_test.go policy/v2: use bare IPs in autogroup:self DstPorts 2026-04-01 14:10:42 +01:00
main_test.go all: fix test flakiness and improve test infrastructure 2026-03-14 02:52:28 -07:00
policy.go policy/v2,state,mapper: implement per-viewer via route steering 2026-04-01 14:10:42 +01:00
policy_test.go all: upgrade to Go 1.26rc2 and modernize codebase 2026-02-08 12:35:23 +01:00
tailscale_acl_data_compat_test.go policy/v2: implement CapGrant compilation with companion capabilities 2026-04-01 14:10:42 +01:00
tailscale_grants_compat_test.go policy/v2: implement autogroup:danger-all support 2026-04-01 14:10:42 +01:00
tailscale_routes_data_compat_test.go policy/v2: convert routes compat tests to data-driven format with Tailscale SaaS captures 2026-04-01 14:10:42 +01:00
tailscale_ssh_data_compat_test.go policy/v2: add SSH compatibility testdata from Tailscale SaaS 2026-02-28 05:14:11 -08:00
types.go policy/v2: implement autogroup:danger-all support 2026-04-01 14:10:42 +01:00
types_test.go policy/v2: implement autogroup:danger-all support 2026-04-01 14:10:42 +01:00
utils.go policy/v2: exclude exit routes from ReduceFilterRules 2026-04-01 14:10:42 +01:00
utils_test.go policy/v2: exclude exit routes from ReduceFilterRules 2026-04-01 14:10:42 +01:00