You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
 
 
 
 
Go to file
James Tucker 95034e15a7 cmd/natc: fix ip allocation runtime
Avoid the unbounded runtime during random allocation, if random
allocation fails after a first pass at random through the provided
ranges, pick the next free address by walking through the allocated set.

The new ipx utilities provide a bitset based allocation pool, good for
small to moderate ranges of IPv4 addresses as used in natc.

Updates #15367

Signed-off-by: James Tucker <james@tailscale.com>
8 months ago
.bencher bencher: add config to suppress failures on benchmark regressions. 4 years ago
.github .github/workflows/govulncheck.yml: send messages to another channel (#15295) 9 months ago
appc appc: fix a deadlock in route advertisements (#15031) 10 months ago
atomicfile atomicfile: use ReplaceFile on Windows so that attributes and ACLs are preserved 11 months ago
chirp all: update copyright and license headers 3 years ago
client client/systray: use ico image format for windows 8 months ago
clientupdate clientupdate: cache CanAutoUpdate, avoid log spam when false 8 months ago
cmd cmd/natc: fix ip allocation runtime 8 months ago
control control/controlhttp: quiet "forcing port 443" log spam 8 months ago
derp cmd/derper, derp/derphttp: support, generate self-signed IP address certs 9 months ago
disco net/udprelay: start of UDP relay server implementation (#15480) 8 months ago
docs ipn/ipnlocal,util/syspolicy,docs/windows/policy: implement the ReconnectAfter policy setting 9 months ago
doctor net/{interfaces,netmon}, all: merge net/interfaces package into net/netmon 2 years ago
drive cmd/viewer,all: consistently use "read-only" instead of "readonly" 11 months ago
envknob ipn/store/kubestore,kube,envknob,cmd/tailscaled/depaware.txt: allow kubestore read/write custom TLS secrets (#15307) 9 months ago
feature feature/capture: move packet capture to feature/*, out of iOS + CLI 10 months ago
gokrazy gokrazy/natlab: update gokrazy, wire up natlab tests to GitHub CI 9 months ago
health health: relax no-derp-home warnable to not fire if not in map poll 10 months ago
hostinfo feature/*: make Wake-on-LAN conditional, start supporting modular features 10 months ago
internal cmd/k8s-operator,internal/client/tailscale: use VIPService annotations for ownership tracking (#15356) 9 months ago
ipn ipn/ipnlocal: add debug logging to initPeerAPIListener 8 months ago
jsondb all: update copyright and license headers 3 years ago
k8s-operator cmd/k8s-operator,k8s-operator: enable HA Ingress again. (#15453) 8 months ago
kube ipn/store/kubestore,kube,envknob,cmd/tailscaled/depaware.txt: allow kubestore read/write custom TLS secrets (#15307) 9 months ago
licenses licenses: update license notices 9 months ago
log log/sockstatlog: don't block for more than 5s on shutdown 1 year ago
logpolicy logpolicy: expose MaxBufferSize and MaxUploadSize options (#14903) 10 months ago
logtail logpolicy: expose MaxBufferSize and MaxUploadSize options (#14903) 10 months ago
maths maths: add exponentially weighted moving average type 9 months ago
metrics metrics,syncs: add ShardedInt support to metrics.LabelMap 12 months ago
net net/udprelay: start of UDP relay server implementation (#15480) 8 months ago
omit cmd/tailscaled, ipn/conffile: support ec2 user-data config file 2 years ago
packages/deb go.mod: upgrade nfpm to v2 (#8786) 2 years ago
paths all: illumos/solaris userspace only support 11 months ago
portlist all: use Go 1.22 range-over-int 2 years ago
posture control/controlclient,posture,util/syspolicy: use predefined syspolicy keys instead of string literals 1 year ago
prober prober: add address family label for udp metrics (#15413) 8 months ago
proxymap ipnlocal,proxymap,wgengine/netstack: add optional WhoIs/proxymap debug 1 year ago
release release/dist: clamp min / max version for synology package centre (#13857) 1 year ago
safesocket safesocket: respect context timeout when sleeping for 250ms in retry loop 9 months ago
safeweb go.mod: bump gorilla/csrf for security fix (#14822) 10 months ago
scripts install.sh - fix DNF 5 detection on all locales (#15325) 8 months ago
sessionrecording sessionrecording: implement v2 recording endpoint support (#14105) 1 year ago
smallzstd all: use Go 1.22 range-over-int 2 years ago
ssh/tailssh ssh/tailssh: fix typo in forwardedEnviron method, add docs 9 months ago
syncs syncs: add ShardedInt expvar.Var type 12 months ago
tailcfg control/controlclient, ipn: add client audit logging (#14950) 9 months ago
taildrop taildrop: fix defer in loop (#13757) 1 year ago
tempfork tempfork/acme: pull in latest changes for Go 1.24 (#15062) 10 months ago
tka tka: truncate long rotation signature chains 1 year ago
tool tool/gocross: remove trimpath from test builds 1 year ago
tsconst cmd/tailscale/cli: support passing network lock keys via files 1 year ago
tsd cmd/tailscaled,ipn/{auditlog,ipnlocal},tsd: omit auditlog unless explicitly imported 8 months ago
tsnet tsnet: Default executable name on iOS 8 months ago
tstest cmd/vnet: add wsproxy mode 8 months ago
tstime all: use math/rand/v2 more 2 years ago
tsweb tsweb: split promvarz into an optional dependency 9 months ago
types all: statically enforce json/v2 interface satisfaction (#15154) 9 months ago
util util/eventbus: remove debug UI from iOS build 9 months ago
version safesocket, version: fix safesocket_darwin behavior for cmd/tailscale (#15275) 9 months ago
wf wf/firewall: allow link-local multicast for permitted local routes when the killswitch is on on Windows 1 year ago
wgengine wgengine: return explicit lo0 for loopback addrs on sandboxed macOS (#15493) 8 months ago
words words: append to the tail of the wordlists (#15278) 9 months ago
.gitattributes .: add .gitattributes entry to use Go hunk-header driver 4 years ago
.gitignore tstest/tailmac: add customized macOS virtualization tooling (#13146) 1 year ago
.golangci.yml .github: Bump golangci/golangci-lint-action from 6.3.1 to 6.5.0 (#15046) 9 months ago
ALPINE.txt Bump Alpine, link iptables back to legacy (#15428) 8 months ago
AUTHORS Move Linux client & common packages into a public repo. 6 years ago
CODEOWNERS CODEOWNERS: add the start of an owners file 2 years ago
CODE_OF_CONDUCT.md Add a code of conduct. 6 years ago
Dockerfile Bump Alpine, link iptables back to legacy (#15428) 8 months ago
Dockerfile.base Bump Alpine, link iptables back to legacy (#15428) 8 months ago
LICENSE all: update tools that manage copyright headers 3 years ago
Makefile go.mod: bump depaware, add --internal flag to stop hiding internal packages 10 months ago
PATENTS Move Linux client & common packages into a public repo. 6 years ago
README.md Update README to reference correct Commit Style URL 11 months ago
SECURITY.md Add a SECURITY.md for vulnerability reports. 6 years ago
VERSION.txt VERSION.txt: this is v1.83.0 (#15443) 8 months ago
api.md {api.md,publicapi}: remove old API docs (#13468) 1 year ago
assert_ts_toolchain_match.go tailscaleroot: panic if tailscale_go build tag but Go toolchain mismatch 1 year ago
build_dist.sh feature/capture: move packet capture to feature/*, out of iOS + CLI 10 months ago
build_docker.sh build_docker.sh: bump default base image (#15432) 8 months ago
flake.lock nix: update nix and use go 1.23 1 year ago
flake.nix gokrazy, various: use point versions of Go and update Nix deps 1 year ago
go.mod client/systray: use ico image format for windows 8 months ago
go.mod.sri go.mod.sri: update SRI hash for go.mod changes 1 year ago
go.sum client/systray: use ico image format for windows 8 months ago
go.toolchain.branch go.toolchain.branch: update to Go 1.24 (#15016) 10 months ago
go.toolchain.rev go.toolchain.rev: bump to go1.24.1 (#15209) 9 months ago
gomod_test.go go.mod: add test that replace directives aren't added in oss 2 years ago
header.txt cmd/k8s-operator: operator can create subnetrouter (#9505) 2 years ago
pkgdoc_test.go all: skip looking for package comments in .git/ repository (#15384) 9 months ago
pull-toolchain.sh pull-toolchain.sh: don't run update-flake.sh 3 years ago
shell.nix go.mod.sri: update SRI hash for go.mod changes 1 year ago
staticcheck.conf all: cleanup unused code, part 2 (#10670) 2 years ago
update-flake.sh Code Improvements (#11311) 2 years ago
version-embed.go Fix various linting, vet & static check issues 11 months ago
version_tailscale_test.go tailscaleroot: panic if tailscale_go build tag but Go toolchain mismatch 1 year ago
version_test.go go.mod,wgengine/netstack: bump gvisor 2 years ago

README.md

Tailscale

https://tailscale.com

Private WireGuard® networks made easy

Overview

This repository contains the majority of Tailscale's open source code. Notably, it includes the tailscaled daemon and the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows, macOS, and to varying degrees on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's code, but this repo doesn't contain the mobile GUI code.

Other Tailscale repos of note:

For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.

Using

We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.

Other clients

The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.

Building

We always require the latest Go release, currently Go 1.23. (While we build releases with our Go fork, its use is not required.)

go install tailscale.com/cmd/tailscale{,d}

If you're packaging Tailscale for distribution, use build_dist.sh instead, to burn commit IDs and version info into the binaries:

./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled

If your distro has conventions that preclude the use of build_dist.sh, please do the equivalent of what it does in your distro's way, so that bug reports contain useful version information.

Bugs

Please file any issues about this code or the hosted service on the issue tracker.

Contributing

PRs welcome! But please file bugs. Commit messages should reference bugs.

We require Developer Certificate of Origin Signed-off-by lines in commits.

See git log for our commit message style. It's basically the same as Go's style.

About Us

Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:

WireGuard is a registered trademark of Jason A. Donenfeld.