You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
tailscale/util/linuxfw
Irbe Krumina 90c4067010
util/linuxfw: add container-friendly IPv6 NAT check (#11353)
Remove IPv6 NAT check when routing is being set up
using nftables.
This is unnecessary as support for nftables was
added after support for IPv6.
https://tldp.org/HOWTO/Linux+IPv6-HOWTO/ch18s04.html
https://wiki.nftables.org/wiki-nftables/index.php/Building_and_installing_nftables_from_sources

Additionally, run an extra check for IPv6 NAT support
when the routing is set up with iptables.
This is because the earlier checks rely on
being able to use modprobe and on /proc/net/ip6_tables_names
being populated on start - these conditions are usually not
true in container environments.

Updates tailscale/tailscale#11344

Signed-off-by: Irbe Krumina <irbe@tailscale.com>
3 months ago
..
linuxfwtest util/linuxfw: initial implementation of package 1 year ago
detector.go linuxfw,wgengine/route,ipn: add c2n and nodeattrs to control linux netfilter 7 months ago
fake.go util/linuxfw: move fake runner into pkg 8 months ago
helpers.go all: cleanup unused code, part 2 (#10670) 6 months ago
iptables.go util/linuxfw: move detection logic 8 months ago
iptables_runner.go util/linuxfw: add container-friendly IPv6 NAT check (#11353) 3 months ago
iptables_runner_test.go util/linuxfw: move fake runner into pkg 8 months ago
linuxfw.go util/linuxfw: add container-friendly IPv6 NAT check (#11353) 3 months ago
linuxfw_unsupported.go all: cleanup unused code, part 2 (#10670) 6 months ago
nftables.go util/cmpx: delete now that we're using Go 1.22 4 months ago
nftables_runner.go util/linuxfw: add container-friendly IPv6 NAT check (#11353) 3 months ago
nftables_runner_test.go util/linuxfw: add missing error checks in tests 8 months ago
nftables_types.go util/linuxfw: add new arch build constraints 12 months ago