headscale/hscontrol
Kristoffer Dalby e5fcd01ee6 policy/v2: match via-grant destinations by prefix overlap
slices.Contains required exact equality between grant dst and the
advertised subnet route. Any non-identical pair was rejected, so a
via grant with broader (or narrower) dst emitted no filter rule and
added no route to the viewer's AllowedIPs. Tailscale SaaS uses
containment in either direction.

Switch to slices.ContainsFunc(routes, dst.Overlaps) for filter rule
emission (keep dst literal in DstPorts), and append overlapping
advertised routes to ViaRoutesForPeer.Include / Exclude. Rewrite the
multi-router HA election and regular-grant overlap detection to key
off the matched routes rather than the dst. Resolve *Host aliases to
*Prefix once in compileOneViaGrant and at the top of ViaRoutesForPeer
so the switch arms reach them.

Fixes #3267
2026-05-18 14:02:00 +02:00
..
assets assets: fix logo alignment and error icon centering 2026-04-13 17:23:47 +01:00
capver capver: regenerate for tailscale v1.96 2026-04-08 13:00:22 +01:00
db db: remove unused SetApprovedRoutes and SetTags helpers 2026-05-15 11:21:58 +02:00
derp all: fix golangci-lint issues (#3064) 2026-02-06 21:45:32 +01:00
dns Fix typo in comment about fsnotify behavior 2026-02-27 15:23:06 +01:00
mapper types/node, mapper: strip own IPv4 from emission when node has disable-ipv4 cap 2026-05-13 14:22:30 +02:00
policy policy/v2: match via-grant destinations by prefix overlap 2026-05-18 14:02:00 +02:00
servertest types: persist Node JSON slices via named IsZero types 2026-05-15 11:21:58 +02:00
state state: add regression test for Node slice persistence 2026-05-15 11:21:58 +02:00
templates all: rephrase prose to fit codebase voice 2026-04-29 16:22:19 +01:00
types types: persist Node JSON slices via named IsZero types 2026-05-15 11:21:58 +02:00
util hscontrol: route hostname handling through dnsname and NodeStore 2026-04-18 15:12:21 +01:00
app.go app: add security headers middleware 2026-04-17 16:31:49 +01:00
app_test.go app: add security headers middleware 2026-04-17 16:31:49 +01:00
auth.go hscontrol: preserve nil expiry on tailscaled restart 2026-05-13 17:06:16 +02:00
auth_tags_test.go hscontrol: preserve nil expiry on tailscaled restart 2026-05-13 17:06:16 +02:00
auth_test.go state: avoid nil deref in registration handlers when old user is missing 2026-05-06 07:23:02 +01:00
debug.go debug: explain URLIsNoise choice in ping callback 2026-04-17 16:31:49 +01:00
grpcv1.go policy/v2: evaluate the tests block on user-initiated writes 2026-05-12 11:54:54 +01:00
grpcv1_test.go all: rephrase prose to fit codebase voice 2026-04-29 16:22:19 +01:00
handlers.go oidc: render HTML error pages for browser-facing failures 2026-04-13 17:23:47 +01:00
handlers_test.go oidc: render HTML error pages for browser-facing failures 2026-04-13 17:23:47 +01:00
metrics.go all: fix golangci-lint issues (#3064) 2026-02-06 21:45:32 +01:00
noise.go noise: reject non-HEAD on PingResponseHandler 2026-04-17 16:31:49 +01:00
noise_test.go policy/v2: align SSH check action with SaaS wire format 2026-04-17 16:31:49 +01:00
oidc.go oidc: render HTML error pages for browser-facing failures 2026-04-13 17:23:47 +01:00
oidc_confirm_test.go oidc: add confirmation page for node registration 2026-04-10 14:09:57 +01:00
oidc_template_test.go oidc: render HTML error pages for browser-facing failures 2026-04-13 17:23:47 +01:00
oidc_test.go oidc: make email verification configurable 2025-12-18 11:42:32 +00:00
platform_config.go all: fix golangci-lint issues (#3064) 2026-02-06 21:45:32 +01:00
poll.go types: add node.expiry config, deprecate oidc.expiry 2026-04-08 13:00:22 +01:00
poll_test.go poll: fix poll test linter violations 2026-03-12 01:27:34 -07:00
tailsql.go all: fix golangci-lint issues (#3064) 2026-02-06 21:45:32 +01:00
templates_consistency_test.go Update links to Tailscale documentation 2026-04-18 09:33:41 +02:00