You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/wgengine
Brad Fitzpatrick 9bb601ebe8 ipn/ipnlocal, wgengine/netstack: use netstack for peerapi server
We're finding a bunch of host operating systems/firewalls interact poorly
with peerapi. We either get ICMP errors from the host or users need to run
commands to allow the peerapi port:

https://github.com/tailscale/tailscale/issues/3842#issuecomment-1025133727

... even though the peerapi should be an internal implementation detail.

Rather than fight the host OS & firewalls, this change handles the
server side of peerapi entirely in netstack (except on iOS), so it
never makes its way to the host OS where it might be messed with. Two
main downsides are:

1) netstack isn't as fast, but we don't really need speed for peerapi.
   And actually, with fewer trips to/from the kernel, we might
   actually make up for some of the netstack performance loss by
   staying in userspace.

2) tcpdump / Wireshark etc packet captures will no longer see the peerapi
   traffic. Oh well. Crawshaw's been wanting to add packet capture server
   support to tailscaled, so we'll probably do that sooner now.

   A future change might also then use peerapi for the client-side
   (except on iOS).

Updates #3842 (probably fixes, as well as many exit node issues I bet)

Change-Id: Ibc25edbb895dc083d1f07bd3cab614134705aa39
Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
(cherry picked from commit bd90781b34) + edits
(and cherry picked part of commit f3c0023add)
4 years ago
..
bench types/netmap: use key.NodePublic instead of tailcfg.NodeKey. 4 years ago
filter wgengine/filter: let unknown IPProto match if IP okay & match allows all ports 4 years ago
magicsock wgengine/magicsock: fix deadlock on shutdown 4 years ago
monitor support running in a FreeBSD jail 4 years ago
netstack ipn/ipnlocal, wgengine/netstack: use netstack for peerapi server 4 years ago
router wgengine/router{windows}: return the output from the firewallTweaker 4 years ago
wgcfg wgengine/wgcfg: recover from mismatched PublicKey/Endpoints 4 years ago
wglog wgengine/wgcfg: convert to use new node key type. 4 years ago
winnet all: gofmt -w -s (simplify) tests 4 years ago
mem_ios.go go.mod: upgrade wireguard-windows, de-fork wireguard-go 5 years ago
pendopen.go net/socks5/tssocks, wgengine: permit SOCKS through subnet routers/exit nodes 4 years ago
userspace.go ipnlocal, net/{dns,tsaddr,tstun}, wgengine: support MagicDNS on IPv6 4 years ago
userspace_ext_test.go go.mod: upgrade wireguard-windows, de-fork wireguard-go 5 years ago
userspace_test.go all: gofmt -w -s (simplify) tests 4 years ago
watchdog.go net/socks5/tssocks, wgengine: permit SOCKS through subnet routers/exit nodes 4 years ago
watchdog_test.go all: close fake userspace engines when tests complete 4 years ago
wgengine.go net/socks5/tssocks, wgengine: permit SOCKS through subnet routers/exit nodes 4 years ago