Commit Graph

72 Commits

Author SHA256 Message Date
4fc563b752 Accepting request 1252354 from network:vpn
- add patch fix-CVE-2025-22869.patch, fixes bsc#1239353 (forwarded request 1252353 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1252354
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=26
2025-03-12 19:13:52 +00:00
Richard Rahl
e301c435ed - add patch fix-CVE-2025-22869.patch, fixes bsc#1239353
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=71
2025-03-12 09:22:16 +00:00
cc303292a9 Accepting request 1250085 from network:vpn
- update to 1.80.3:
  * appc: fix a deadlock in route advertisements
  * client/web: fix CSRF handler order in web UI (forwarded request 1250084 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1250085
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=25
2025-03-04 17:33:44 +00:00
Richard Rahl
91a96b1ce6 - update to 1.80.3:
* appc: fix a deadlock in route advertisements
  * client/web: fix CSRF handler order in web UI

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=69
2025-03-04 13:49:59 +00:00
786d0d5383 Accepting request 1245709 from network:vpn
- update to 1.80.2:
  * Use ip:country as a geolocation device posture attribute (generally available). (forwarded request 1245700 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1245709
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=24
2025-02-13 17:47:55 +00:00
Richard Rahl
66c1141099 - update to 1.80.2:
* Use ip:country as a geolocation device posture attribute (generally available).

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=67
2025-02-13 15:36:34 +00:00
c81f735328 Accepting request 1244263 from network:vpn
- update to 1.80.1:
  * net/netmon: add extra panic guard around ParseRIB (forwarded request 1244262 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1244263
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=23
2025-02-09 19:01:34 +00:00
Richard Rahl
82875da72a - update to 1.80.1:
* net/netmon: add extra panic guard around ParseRIB

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=65
2025-02-07 19:13:40 +00:00
b055a4dece Accepting request 1241760 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1241760
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=22
2025-02-03 20:42:23 +00:00
Richard Rahl
aa509b69e0 - update to 1.80.0:
* Hostname system policy is added for overriding the device hostname
    configured by the operating system, using an MDM solution.
  * Web interface displays a Login button instead of the Reauthenticate button
    when adding a new device to your tailnet.
  * Tailscale Funnel configuration on devices displays errors when incoming
    connections are not permitted and connections are disallowed.
  * Connections to a custom coordination server that does not support HTTPS
    will no longer fail when a custom port number is specified.
  * TLS certificate requests from Let’s Encrypt include the device's DNS name
    in the CSR’s SAN extension and set the Common Name field.
  * Tailscale Funnel disabled on a device no longer displays enabled in the
    admin console.
  * GitHub username change automatically updates tailnet name
  * 4via6 subnet routers GA
  * Auto approvers GA
  * Node attributes GA
  * Download invoices GA
  * Fast user switching GA
  * Configuration log streaming integration with S3 buckets GA
  * Network flow log streaming integration with S3 buckets GA
  * NextDNS profiles per device GA
  * GitHub secret scanning
- remove fix-CVE-2024-45337.patch, as it's now included

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=63
2025-01-31 17:27:15 +00:00
938c433b47 Accepting request 1231944 from network:vpn
- add patch fix-CVE-2024-45337.patch, to circumevent a possibility
  of exploiting the golang-x-crypto security hole. (fix #1234506) (forwarded request 1231943 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1231944
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=21
2024-12-18 20:09:08 +00:00
Richard Rahl
a1960b58af - add patch fix-CVE-2024-45337.patch, to circumevent a possibility
of exploiting the golang-x-crypto security hole. (fix #1234506)

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=61
2024-12-18 17:43:39 +00:00
263e5eef59 Accepting request 1230718 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1230718
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=20
2024-12-13 21:38:17 +00:00
Richard Rahl
2b5ad6f362 Accepting request 1230717 from home:rrahl0
- update to 1.78.3:
  * cmd/containerboot: fix nil pointer exception
  * hostinfo: fix testing in container

OBS-URL: https://build.opensuse.org/request/show/1230717
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=59
2024-12-13 06:21:17 +00:00
9d3afc6a46 Accepting request 1228636 from network:vpn
(forwarded request 1228635 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1228636
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=19
2024-12-06 13:26:06 +00:00
Richard Rahl
c22a0bd619 OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=57 2024-12-06 01:25:57 +00:00
Richard Rahl
f85219504a - update to 1.78.1:
* health: fix TestHealthMetric

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=56
2024-12-06 01:23:23 +00:00
Richard Rahl
d6af84c7b6 - update to 1.78.0:
* Client metrics have been added, to provide insights into Tailscale client
    behavior, health, and performance.
  * tailscale metrics command has been added, to expose and collect client
    metrics for use with third-party monitoring systems.
  * tailscale syspolicy command has been added, to list system policies, reload
    system policies, or view errors related to the system policies configured
    on the device.
  * Tailscale system policies are applied immediately when pushed via mobile
    device management (MDM) or Group Policy, without requiring a client restart.
  * Tailscale SSH session recording detects the disappearance of the recorder
    node sooner. This fix addresses a security vulnerability described
    in TS-2024-013.
  * New scopes for OAuth clients have been added with more granular permissions.
    Existing OAuth clients using the previous set of scopes, and keys generated
    using these clients, are still valid.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=55
2024-12-05 22:13:03 +00:00
6cfd54f698 Accepting request 1222620 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1222620
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=18
2024-11-08 11:01:03 +00:00
Richard Rahl
36177afc8e - update to 1.76.6:
* Logging for when clients move home DERP regions is improved.
  * Tailscale clients no longer move their home DERP server prematurely in 
    response to unusual latency at very specific times.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=53
2024-11-08 03:52:44 +00:00
67362537a0 Accepting request 1218078 from network:vpn
- update to 1.76.3:
  * no relevant changelog
- update to 1.76.2:
  * no relevant changelog
- switch over to the new %{default_fw_backend} macro
- create old init file only for < leap 16

OBS-URL: https://build.opensuse.org/request/show/1218078
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=17
2024-10-25 17:19:32 +00:00
Richard Rahl
ad6ad67137 - update to 1.76.3:
* no relevant changelog
- update to 1.76.2:
  * no relevant changelog
- switch over to the new %{default_fw_backend} macro
- create old init file only for < leap 16

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=51
2024-10-24 15:01:48 +00:00
2c42f71626 Accepting request 1208651 from network:vpn
- update to 1.76.1:
  * tailscale netcheck CLI command no longer crashes when performing diagnostics
    on networks lacking UDP connectivity.
  * Improperly formatted SERVFAIL responses no longer cause DNS timeouts when using an exit node.
  * dbus login sessions no longer fail on systems where /bin/login is missing. (forwarded request 1208650 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1208651
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=16
2024-10-17 16:41:04 +00:00
Richard Rahl
e211ce0614 - update to 1.76.1:
* tailscale netcheck CLI command no longer crashes when performing diagnostics
    on networks lacking UDP connectivity.
  * Improperly formatted SERVFAIL responses no longer cause DNS timeouts when using an exit node.
  * dbus login sessions no longer fail on systems where /bin/login is missing.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=49
2024-10-17 14:19:57 +00:00
d4132497a4 Accepting request 1208074 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1208074
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=15
2024-10-15 13:02:21 +00:00
Richard Rahl
8e754bbadc require a fw backend
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=47
2024-10-15 09:09:37 +00:00
aaa9f77fac Accepting request 1207052 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1207052
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=14
2024-10-11 15:03:00 +00:00
Richard Rahl
52790f3e74 - update to 1.76.0:
* Clients lacking UDP connectivity no longer skip performing fallback latency
    measurements with DERP servers.
  * Warnings no longer display unnecessarily.
  * Tailscale connectivity on in-flight internet on airplanes (such as Alaska Airlines) no longer fails.
  * Service-related processes no longer run unnecessarily when services are disabled on the tailnet.
  * Error messages include explanations in addition to the HTTP status code.
  * Tailscale SSH supports sending environment variables to hosts. It's also possible to specify
    permitted environment variables using the acceptEnv field.
  * Tailscale SSH no longer breaks some terminal applications by omitting pixel width and height when
    resizing the application window.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=45
2024-10-11 06:11:52 +00:00
d7157acdb9 Accepting request 1202314 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1202314
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=13
2024-09-23 13:19:17 +00:00
Richard Rahl
29c031e93c Fix to zsh completions file path
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=43
2024-09-21 06:46:14 +00:00
4648ba845d Accepting request 1201856 from network:vpn
(forwarded request 1201855 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1201856
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=12
2024-09-19 19:17:13 +00:00
Richard Rahl
4de2c08f5a OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=41 2024-09-18 19:48:04 +00:00
Richard Rahl
789db47c2a - update to 1.74.1:
* wgengine/magicsock: disable raw disco by default; add envknob to enable

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=40
2024-09-18 19:45:04 +00:00
cf7e451ca1 Accepting request 1200808 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1200808
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=11
2024-09-15 10:35:41 +00:00
Richard Rahl
45a8d4c807 - update to 1.74.0
* AuthKey system policy can be used to authenticate a device with Tailscale using an MDM solution.
  * tailscale dns CLI command is added for accessing Tailscale DNS settings and status.
  * Tailnet Lock long rotation signatures are truncated automatically to avoid excessive growth.
  * Log In option in the client works as expected.
  * TCP generic receive offload (GRO) support is added for improved userspace mode throughput.
  * TCP generic segmentation offload (GSO) is re-introduced for supporting improved userspace mode throughput.
    This was initially introduced in Tailscale v1.72.0 and then rolled back in v1.72.1.
  * Device posture integration with CrowdStrike Falcon can now use MAC addresses to match devices that lack serial numbers.
    When Falcon integration is configured, Device Identity Collection will automatically collect MAC addresses.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=38
2024-09-13 11:05:19 +00:00
d967e912f2 Accepting request 1195619 from network:vpn
- update to 1.72.1:
  * DNS over TCP failures when querying the Tailscale-internal resolver are fixed. (forwarded request 1195618 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1195619
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=10
2024-08-23 20:26:49 +00:00
Richard Rahl
03d95338db - update to 1.72.1:
* DNS over TCP failures when querying the Tailscale-internal resolver are fixed.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=36
2024-08-22 22:14:21 +00:00
2a2c5d5d46 Accepting request 1195170 from network:vpn
- Update to version 1.72.0:
  * posture: deduplicate MAC addresses before returning them
  * health/dns: reduce severity of DNS unavailable warning
  * safeweb: add Server.Close method
  * go.mod.sri: update SRI hash for go.mod changes
  * go.{mod,sum}: migrate from nhooyr.io/websocket to github.com/coder/websocket
  * cmd/viewer: add support for map-like container types
- update golang(API) to 1.23
- export version variables, to circumvent a bug (forwarded request 1195168 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1195170
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=9
2024-08-22 16:13:25 +00:00
Richard Rahl
9793d04207 - Update to version 1.72.0:
* posture: deduplicate MAC addresses before returning them
  * health/dns: reduce severity of DNS unavailable warning
  * safeweb: add Server.Close method
  * go.mod.sri: update SRI hash for go.mod changes
  * go.{mod,sum}: migrate from nhooyr.io/websocket to github.com/coder/websocket
  * cmd/viewer: add support for map-like container types
- update golang(API) to 1.23
- export version variables, to circumvent a bug

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=34
2024-08-21 16:33:03 +00:00
a5412847f3 Accepting request 1188315 from network:vpn
- update to 1.70.0:
  * New: Restrict recommended and automatically selected exit nodes using the
    new AllowedSuggestedExitNodes system policy. Applies only to platforms that
    support system policies.
  * Changed: Improved NAT traversal for some uncommon scenarios.
  * Changed: Optimized sending firewall rules to clients more efficiently.
  * Fixed: Exit node suggestion CLI command now prints the hostname.
  * Fixed: Taildrive share paths configured through the CLI resolve relative
    to where you run the tailscale command. (forwarded request 1188314 from rrahl0)

OBS-URL: https://build.opensuse.org/request/show/1188315
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=8
2024-07-19 13:26:59 +00:00
Richard Rahl
ccc2356f80 - update to 1.70.0:
* New: Restrict recommended and automatically selected exit nodes using the
    new AllowedSuggestedExitNodes system policy. Applies only to platforms that
    support system policies.
  * Changed: Improved NAT traversal for some uncommon scenarios.
  * Changed: Optimized sending firewall rules to clients more efficiently.
  * Fixed: Exit node suggestion CLI command now prints the hostname.
  * Fixed: Taildrive share paths configured through the CLI resolve relative
    to where you run the tailscale command.

OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=32
2024-07-18 06:39:12 +00:00
673644643e Accepting request 1185700 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1185700
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=7
2024-07-05 17:50:21 +00:00
Richard Rahl
ee6befb779 Accepting request 1185699 from home:rrahl0:upgrades
- update to 1.68.2:
  * Fixed: Tailnet lock validation of rotation signatures now permits multiple nodes
    signed by the same pre-signed reusable auth key.

OBS-URL: https://build.opensuse.org/request/show/1185699
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=30
2024-07-05 00:17:07 +00:00
9ba05860f4 Accepting request 1181177 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1181177
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=6
2024-06-17 17:30:02 +00:00
Richard Rahl
2b8a3a8246 Accepting request 1181176 from home:rrahl0:upgrades
- update to 1.68.1:
  * Fixed: 4via6 subnet router advertisement works as expected.
  * Fixed: Tailscale SSH access to Security-Enhanced Linux (SELinux) machines works as expected.
- update to 1.68.0:
  * New: Auto-updates are allowed in containers, but ignore the tailnet-wide default
  * New: Apply auto-updates even if the node is down or disconnected from the coordination server.
  * New: tailscale lock status now prints the node's signature.

OBS-URL: https://build.opensuse.org/request/show/1181176
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=28
2024-06-16 14:02:30 +00:00
9d187e3f86 Accepting request 1175719 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1175719
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=5
2024-05-22 19:32:10 +00:00
Richard Rahl
7e88365b18 Accepting request 1175718 from home:rrahl0:upgrades
- update to 1.66.4:
  * Fixed: Restored UDP connectivity through Mullvad exit nodes
  * Stateful filtering is now off by default
- update to 1.66.3:
  * Login URLs did not always appear in the console when running tailscale up
  * Starting with v1.66, the Kubernetes operator must always run the same or later version
    as the proxies it manages.
  * Expose cloud services on cluster network to the tailnet, using Kubernetes ExternalName Services
  * Expose tailnet services that use Tailscale HTTPS to cluster workloads
  * Cluster workloads can now refer to Tailscale Ingress resources by their MagicDNS names
  * Configure environment variables for Tailscale Kubernetes operator proxies using ProxyClass CRD
  * Expose tailscaled metrics endpoint for Tailscale Kubernetes operator proxies through ProxyClass CRD
  * Configure labels for the Kubernetes operator Pods with Helm chart values
  * Configure affinity rules for Kubernetes operator proxy Pods with ProxyClass
  * Kubernetes operator proxy init container no longer attempts to enable IPv6 forwarding on systems
    that don't have IPv6 module loaded
  * Tailscale containers running on Kubernetes no longer error if an empty Kubernetes Secret is
    pre-created for the tailscaled state
  * Improved the ambiguous error messages when Tailscale running on Kubernetes does not have the right
    permissions to perform actions against the tailscaled state Secret

OBS-URL: https://build.opensuse.org/request/show/1175718
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=26
2024-05-22 08:53:26 +00:00
3af4b2639c Accepting request 1173205 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1173205
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=4
2024-05-11 16:21:13 +00:00
Richard Rahl
f80c1963ae Accepting request 1173203 from home:rrahl0:upgrades
- update to 1.66.1:
  * Resolved issues with nftables rules for stateful filtering,
    introduced in v1.66.0.
  * tailscale set command flags --netfilter-mode, --snat-subnet-routes,
     and --stateful-filtering are added.
- update to 1.66.0:
  * Implemented client-side quarantining for shared-in exit nodes,
    as a mitigation for a security vulnerability described in TS-2024-005.
  * Use the --stateful-filtering flag for the tailscale up to enable stateful filtering for
    subnet routers and exit nodes, as a mitigation for a security vulnerability described
    in TS-2024-005. 
  * Added tab completions
  * Use the tailscale exit-node suggest command to automatically pick an available exit node
    that is likely to perform best.
  * Site-to-site networking now also requires --stateful-filtering=false in addition to
    --snat-subnet-routes=false on new subnet routers. Existing subnet routers with --snat-subnet-routes=false
    will default to --stateful-filtering=false.
- update to 1.64.2:
  * nothing relevant for linux
- update to 1.64.1:
  * nothing relevant for linux
- update to 1.64.0:
  * New: tailscale configure kubeconfig now respects KUBECONFIG environment variable.
  * Fixed: tailscale configure kubeconfig now works with partially empty kubeconfig.
  * Fixed: MSS clamping for Kubernetes operator proxies using nftables.
  * Fixed: Containers on hosts with partial support for ip6tables no longer crash.
- turn of changelog generation
- add completions for bash

OBS-URL: https://build.opensuse.org/request/show/1173203
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=24
2024-05-10 15:52:27 +00:00
4de44add30 Accepting request 1163652 from network:vpn
OBS-URL: https://build.opensuse.org/request/show/1163652
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/tailscale?expand=0&rev=3
2024-04-02 14:41:14 +00:00