headscale/hscontrol/policy/v2
Kristoffer Dalby dda35847b0 policy/v2: reorder ACL self grants to match Tailscale rule ordering
When an ACL has non-autogroup destinations (groups, users, tags, hosts)
alongside autogroup:self, emit non-self grants before self grants to
match Tailscale's filter rule ordering. ACLs with only autogroup
destinations (self + member) preserve the policy-defined order.

This fixes ACL-A17, ACL-SF07, and ACL-SF11 compat test failures.

Updates #2180
2026-04-01 14:10:42 +01:00
..
testdata policy/v2: add advertised routes to compat test topologies 2026-04-01 14:10:42 +01:00
filter.go policy/v2: use approved node routes in wildcard SrcIPs 2026-04-01 14:10:42 +01:00
filter_test.go policy/v2: use bare IPs in autogroup:self DstPorts 2026-04-01 14:10:42 +01:00
main_test.go all: fix test flakiness and improve test infrastructure 2026-03-14 02:52:28 -07:00
policy.go policy/v2: refactor alias resolution to use ResolvedAddresses 2026-04-01 14:10:42 +01:00
policy_test.go all: upgrade to Go 1.26rc2 and modernize codebase 2026-02-08 12:35:23 +01:00
tailscale_acl_data_compat_test.go policy/v2: use approved node routes in wildcard SrcIPs 2026-04-01 14:10:42 +01:00
tailscale_grants_compat_test.go policy/v2: exclude exit routes from ReduceFilterRules 2026-04-01 14:10:42 +01:00
tailscale_routes_data_compat_test.go policy/v2: convert routes compat tests to data-driven format with Tailscale SaaS captures 2026-04-01 14:10:42 +01:00
tailscale_ssh_data_compat_test.go policy/v2: add SSH compatibility testdata from Tailscale SaaS 2026-02-28 05:14:11 -08:00
types.go policy/v2: reorder ACL self grants to match Tailscale rule ordering 2026-04-01 14:10:42 +01:00
types_test.go policy/v2: exclude exit routes from ReduceFilterRules 2026-04-01 14:10:42 +01:00
utils.go policy/v2: exclude exit routes from ReduceFilterRules 2026-04-01 14:10:42 +01:00
utils_test.go policy/v2: exclude exit routes from ReduceFilterRules 2026-04-01 14:10:42 +01:00