You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/net
Brad Fitzpatrick 58abae1f83 net/dns/{publicdns,resolver}: add NextDNS DoH support
NextDNS is unique in that users create accounts and then get
user-specific DNS IPs & DoH URLs.

For DoH, the customer ID is in the URL path.

For IPv6, the IP address includes the customer ID in the lower bits.

For IPv4, there's a fragile "IP linking" mechanism to associate your
public IPv4 with an assigned NextDNS IPv4 and that tuple maps to your
customer ID.

We don't use the IP linking mechanism.

Instead, NextDNS is DoH-only. Which means using NextDNS necessarily
shunts all DNS traffic through 100.100.100.100 (programming the OS to
use 100.100.100.100 as the global resolver) because operating systems
can't usually do DoH themselves.

Once it's in Tailscale's DoH client, we then connect out to the known
NextDNS IPv4/IPv6 anycast addresses.

If the control plane sends the client a NextDNS IPv6 address, we then
map it to the corresponding NextDNS DoH with the same client ID, and
we dial that DoH server using the combination of v4/v6 anycast IPs.

Updates #2452

Change-Id: I3439d798d21d5fc9df5a2701839910f5bef85463
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
2 years ago
..
dns net/dns/{publicdns,resolver}: add NextDNS DoH support 2 years ago
dnscache net/dnscache: use net/netip 2 years ago
dnsfallback net/dnsfallback: allow setting log function (#5550) 2 years ago
flowtrack all: convert more code to use net/netip directly 2 years ago
interfaces go.mod: bump wireguard/windows, which moves to using net/netip 2 years ago
netaddr all: migrate code from netaddr.FromStdAddr to Go 1.18 2 years ago
netcheck net/stun: convert to use net/netip.AddrPort 2 years ago
neterror net/{neterror,dns/resolver}: move PacketWasTruncated to neterror from DNS code 3 years ago
netknob all: disable TCP keep-alives on iOS/Android 3 years ago
netns syncs, all: move to using Go's new atomic types instead of ours 2 years ago
netstat all: migrate more code code to net/netip directly 2 years ago
nettest net/nettest: deflake TestPipeTimeout 3 years ago
netutil all: convert more code to use net/netip directly 2 years ago
packet all: migrate more code code to net/netip directly 2 years ago
ping net/netcheck: try ICMP if UDP is blocked (#5056) 2 years ago
portmapper syncs, all: move to using Go's new atomic types instead of ours 2 years ago
proxymux net/proxymux: add a listener mux that can run SOCKS and HTTP on a single socket. 3 years ago
socks5 net/socks5: use new Go 1.19 binary.AppendByteOrder.AppendUintX 2 years ago
speedtest all: fix spelling mistakes 3 years ago
stun net/stun: convert to use net/netip.AddrPort 2 years ago
tlsdial all: gofmt for Go 1.19 2 years ago
tsaddr all: migrate more code code to net/netip directly 2 years ago
tsdial all: use syncs.AtomicValue 2 years ago
tshttpproxy all: use syncs.AtomicValue 2 years ago
tstun all: use syncs.AtomicValue 2 years ago