You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/tailcfg
Andrew Lytvynov 728622665f
1.48 cherry-picks for nftables (#8989)
* wgengine/router: fall back and set iptables as default again

Due to the conflict between our nftables implementation and ufw, which is a common utility used
on linux. We now want to take a step back to prevent regression. This will give us more chance to
let users to test our nftables support and heuristic.

Updates: #391
Signed-off-by: KevinLiang10 <kevinliang@tailscale.com>
(cherry picked from commit 93cab56277)

* util/linuxfw: reorganize nftables rules to allow it to work with ufw

This commit tries to mimic the way iptables-nft work with the filewall rules. We
follow the convention of using tables like filter, nat and the conventional
chains, to make our nftables implementation work with ufw.

Updates: #391

Signed-off-by: KevinLiang10 <kevinliang@tailscale.com>
(cherry picked from commit b040094b90)

* tailcfg: update docs on NetInfo.FirewallMode

Updates #391

Change-Id: Ifef196b31dd145f424fb0c0d0bb04565cc22c717
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
(cherry picked from commit 282dad1b62)

---------

Co-authored-by: KevinLiang10 <kevinliang@tailscale.com>
Co-authored-by: Brad Fitzpatrick <bradfitz@tailscale.com>
9 months ago
..
c2ntypes.go all: update copyright and license headers 1 year ago
derpmap.go net/netcheck, tailcfg: add DERPHomeParams and use it 11 months ago
tailcfg.go 1.48 cherry-picks for nftables (#8989) 9 months ago
tailcfg_clone.go tailcfg: Add FirewallMode to NetInfo to record wether host using iptables or nftables 10 months ago
tailcfg_export_test.go all: update copyright and license headers 1 year ago
tailcfg_test.go tailcfg: Add FirewallMode to NetInfo to record wether host using iptables or nftables 10 months ago
tailcfg_view.go tailcfg: Add FirewallMode to NetInfo to record wether host using iptables or nftables 10 months ago
tka.go tailcfg: add RPC structs for /tka/affected-sigs 1 year ago