You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/linuxfw
Irbe Krumina 90c4067010
util/linuxfw: add container-friendly IPv6 NAT check (#11353)
Remove IPv6 NAT check when routing is being set up
using nftables.
This is unnecessary as support for nftables was
added after support for IPv6.
https://tldp.org/HOWTO/Linux+IPv6-HOWTO/ch18s04.html
https://wiki.nftables.org/wiki-nftables/index.php/Building_and_installing_nftables_from_sources

Additionally, run an extra check for IPv6 NAT support
when the routing is set up with iptables.
This is because the earlier checks rely on
being able to use modprobe and on /proc/net/ip6_tables_names
being populated on start - these conditions are usually not
true in container environments.

Updates tailscale/tailscale#11344

Signed-off-by: Irbe Krumina <irbe@tailscale.com>
2 years ago
..
linuxfwtest util/linuxfw: initial implementation of package 3 years ago
detector.go linuxfw,wgengine/route,ipn: add c2n and nodeattrs to control linux netfilter 2 years ago
fake.go util/linuxfw: move fake runner into pkg 2 years ago
helpers.go all: cleanup unused code, part 2 (#10670) 2 years ago
iptables.go util/linuxfw: move detection logic 2 years ago
iptables_runner.go util/linuxfw: add container-friendly IPv6 NAT check (#11353) 2 years ago
iptables_runner_test.go util/linuxfw: move fake runner into pkg 2 years ago
linuxfw.go util/linuxfw: add container-friendly IPv6 NAT check (#11353) 2 years ago
linuxfw_unsupported.go all: cleanup unused code, part 2 (#10670) 2 years ago
nftables.go util/cmpx: delete now that we're using Go 1.22 2 years ago
nftables_runner.go util/linuxfw: add container-friendly IPv6 NAT check (#11353) 2 years ago
nftables_runner_test.go util/linuxfw: add missing error checks in tests 2 years ago
nftables_types.go util/linuxfw: add new arch build constraints 2 years ago