* WireGuard configuration that occurs automatically in the client, no longer
results in a panic
OBS-URL: https://build.opensuse.org/package/show/network:vpn/tailscale?expand=0&rev=112
678 lines
30 KiB
Plaintext
678 lines
30 KiB
Plaintext
-------------------------------------------------------------------
|
||
Wed Dec 17 13:24:06 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.92.3:
|
||
* WireGuard configuration that occurs automatically in the client, no longer
|
||
results in a panic
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Dec 12 14:21:14 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.92.2:
|
||
* cmd/derper: add GCP Certificate Manager support
|
||
|
||
-------------------------------------------------------------------
|
||
Sat Dec 6 11:39:58 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.92.1:
|
||
* fix LocalBackend deadlock when packet arrives during profile switch
|
||
* wgengine: fix TSMP/ICMP callback leak
|
||
- Update to version 1.92.0:
|
||
* no changelog provided
|
||
- Update to version 1.90.9:
|
||
* tailscaled no longer deadlocks during event bursts
|
||
* The client no longer hangs after wake up
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Nov 19 16:23:06 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.90.8:
|
||
* tka: move RemoveAll() to CompactableChonk
|
||
- Update to version 1.90.7:
|
||
* wgengine/magicsock: validate endpoint.derpAddr
|
||
* wgengine/magicsock: fix UDPRelayAllocReq/Resp deadlock
|
||
* net/udprelay: replace VNI pool with selection algorithm
|
||
* feature/relayserver,ipn/ipnlocal,net/udprelay: plumb DERPMap
|
||
* feature/relayserver: fix Shutdown() deadlock
|
||
* net/netmon: do not abandon a subscriber when exiting early
|
||
* tka: don't try to read AUMs which are partway through being written
|
||
* tka: rename a mutex to mu instead of single-letter l
|
||
* ipn/ipnlocal: use an in-memory TKA store if FS is unavailable
|
||
|
||
-------------------------------------------------------------------
|
||
Sun Nov 2 11:43:31 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.90.6:
|
||
* Routes no longer stall and fail to apply when updated repeatedly in a short
|
||
period of time
|
||
* Tailscale SSH no longer hangs for 10s when connecting to tsrecorder. This
|
||
affected tailnets that use Tailscale SSH recording
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Oct 29 09:50:22 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.90.4:
|
||
* deadlock issue no longer occurs in the client when checking
|
||
for the network to be available
|
||
* tailscaled no longer sporadically panics when a
|
||
Trusted Platform Module (TPM) device is present
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Oct 28 11:12:50 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.90.3:
|
||
* tailscaled shuts down as expected and without panic
|
||
* tailscaled starts up as expected in a no router configuration environment
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Oct 24 18:11:11 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Update to version 1.90.2:
|
||
* util/linuxfw: fix 32-bit arm regression with iptables
|
||
* health: compare warnable codes to avoid errors on release branch
|
||
* feature/tpm: check TPM family data for compatibility
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Oct 24 10:08:31 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- Upate to version 1.90.1:
|
||
* Clients can use configured DNS resolvers for all domains
|
||
* Node keys will be renewed seamlessly
|
||
* Unnecessary path discovery packets over DERP servers are suppressed
|
||
* Node key sealing is GA (generally available) and enabled by default
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Oct 1 11:55:52 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to version 1.88.3:
|
||
* cmd/tailscale/cli: add ts2021 debug flag to set a dial plan
|
||
* control/controlhttp: simplify, fix race dialing, remove priority concept
|
||
- update to version 1.88.2:
|
||
* k8s-operator: reset service status before append
|
||
- require the minimum go version directly, in comparison to using the golang(API)
|
||
symbol
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Sep 12 11:11:48 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to version 1.88.1:
|
||
* Tailscale CLI prompts users to confirm impactful actions
|
||
* Tailscale SSH works as expected when using an IP address instead of a
|
||
hostname and MagicDNS is disabled
|
||
* fixed: Taildrive sharing when su not present
|
||
* Taildrive files remain consistently accessible
|
||
* new: Tailscale tray GUI
|
||
* DERP IPs changed for Singapore and Tokyo
|
||
- remove fix-CVE-2025-58058.patch, fixed upstream
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Aug 29 12:57:59 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- add patch fix-CVE-2025-58058.patch, fixing bsc#1248920
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Aug 29 11:10:29 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to version 1.86.5:
|
||
* cmd/k8s-proxy,k8s-operator: fix serve config for userspace mode
|
||
- update to version 1.86.4:
|
||
* nothing of relevance
|
||
- update to version 1.86.3:
|
||
* nothing of relevance
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Jul 29 21:20:47 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to version 1.86.2:
|
||
* A deadlock issue that may have occurred in the client
|
||
* An occasional crash when establishing a new port mapping with a gateway or
|
||
firewall
|
||
|
||
-------------------------------------------------------------------
|
||
Sat Jul 26 16:23:38 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to version 1.86.0:
|
||
* tsStateEncrypted device posture attribute for checking whether the
|
||
Tailscale client state is encrypted at rest
|
||
* Cross-site request forgery (CSRF) issue that may have resulted in a log in
|
||
error when accessing the web interface
|
||
* Recommended exit node when the previously recommended exit node is offline
|
||
* tailscale up --exit-node=auto:any and tailscale set --exit-node=auto:any
|
||
CLI commands track the recommended exit node and automatically switches to
|
||
it when available exit nodes or network conditions change
|
||
* tailscaled CLI command flag --encrypt-state encrypts the node state file on
|
||
the disk using trusted platform module (TPM)
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Jun 26 17:29:44 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.84.3:
|
||
* ipn/ipnlocal: Update hostinfo to control on service config change
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Jun 10 15:36:55 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.84.2:
|
||
* Re-enable setting —accept-dns by using TS_EXTRA_ARGS. This issue resulted
|
||
from stricter CLI arguments parsing introduced in Tailscale v1.84.0
|
||
|
||
-------------------------------------------------------------------
|
||
Fri May 30 06:23:15 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.84.1:
|
||
* net/dns: cache dns.Config for reuse when compileConfig fails
|
||
|
||
-------------------------------------------------------------------
|
||
Thu May 22 08:27:09 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.84.0:
|
||
* The --reason flag is added to the tailscale down command
|
||
* ReconnectAfter policy setting, which configures the maximum period of time
|
||
between a user disconnecting Tailscale and the client automatically
|
||
reconnecting
|
||
* Tailscale CLI commands throw an error if multiple of the same flag are detected
|
||
* Network connectivity issues when creating a new profile or switching
|
||
profiles while using an exit node
|
||
* DNS-over-TCP fallback works correctly with upstream servers reachable only
|
||
via the tailnet
|
||
- remove fix-CVE-2025-22869.patch, as upstream updated their dependencies
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Apr 18 07:37:15 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.82.5:
|
||
* A panic issue related to CUBIC congestion control in userspace mode is resolved.
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Mar 27 19:50:58 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.82.0:
|
||
* DERP functionality within the client supports certificate pinning for
|
||
self-signed IP address certificates for those unable to use Let's Encrypt
|
||
or WebPKI certificates.
|
||
* Go is updated to version 1.24.1
|
||
* NAT traversal code uses the DERP connection that a packet arrived on as an
|
||
ultimate fallback route if no other information is available
|
||
* Captive portal detection reliability is improved on some in-flight Wi-Fi networks
|
||
* Port mapping success rate is improved
|
||
* Helsinki is added as a DERP region.
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Mar 12 09:07:49 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- add patch fix-CVE-2025-22869.patch, fixes bsc#1239353
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Mar 4 13:42:34 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.80.3:
|
||
* appc: fix a deadlock in route advertisements
|
||
* client/web: fix CSRF handler order in web UI
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Feb 13 14:30:28 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.80.2:
|
||
* Use ip:country as a geolocation device posture attribute (generally available).
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Feb 6 19:52:22 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.80.1:
|
||
* net/netmon: add extra panic guard around ParseRIB
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Jan 31 17:20:29 UTC 2025 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.80.0:
|
||
* Hostname system policy is added for overriding the device hostname
|
||
configured by the operating system, using an MDM solution.
|
||
* Web interface displays a Login button instead of the Reauthenticate button
|
||
when adding a new device to your tailnet.
|
||
* Tailscale Funnel configuration on devices displays errors when incoming
|
||
connections are not permitted and connections are disallowed.
|
||
* Connections to a custom coordination server that does not support HTTPS
|
||
will no longer fail when a custom port number is specified.
|
||
* TLS certificate requests from Let’s Encrypt include the device's DNS name
|
||
in the CSR’s SAN extension and set the Common Name field.
|
||
* Tailscale Funnel disabled on a device no longer displays enabled in the
|
||
admin console.
|
||
* GitHub username change automatically updates tailnet name
|
||
* 4via6 subnet routers GA
|
||
* Auto approvers GA
|
||
* Node attributes GA
|
||
* Download invoices GA
|
||
* Fast user switching GA
|
||
* Configuration log streaming integration with S3 buckets GA
|
||
* Network flow log streaming integration with S3 buckets GA
|
||
* NextDNS profiles per device GA
|
||
* GitHub secret scanning
|
||
- remove fix-CVE-2024-45337.patch, as it's now included
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Dec 18 17:33:23 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- add patch fix-CVE-2024-45337.patch, to circumevent a possibility
|
||
of exploiting the golang-x-crypto security hole. (fix #1234506)
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Dec 13 05:06:26 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.78.3:
|
||
* cmd/containerboot: fix nil pointer exception
|
||
* hostinfo: fix testing in container
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Dec 6 01:22:05 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.78.1:
|
||
* health: fix TestHealthMetric
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Dec 5 22:10:32 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.78.0:
|
||
* Client metrics have been added, to provide insights into Tailscale client
|
||
behavior, health, and performance.
|
||
* tailscale metrics command has been added, to expose and collect client
|
||
metrics for use with third-party monitoring systems.
|
||
* tailscale syspolicy command has been added, to list system policies, reload
|
||
system policies, or view errors related to the system policies configured
|
||
on the device.
|
||
* Tailscale system policies are applied immediately when pushed via mobile
|
||
device management (MDM) or Group Policy, without requiring a client restart.
|
||
* Tailscale SSH session recording detects the disappearance of the recorder
|
||
node sooner. This fix addresses a security vulnerability described
|
||
in TS-2024-013.
|
||
* New scopes for OAuth clients have been added with more granular permissions.
|
||
Existing OAuth clients using the previous set of scopes, and keys generated
|
||
using these clients, are still valid.
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Nov 8 03:46:50 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.76.6:
|
||
* Logging for when clients move home DERP regions is improved.
|
||
* Tailscale clients no longer move their home DERP server prematurely in
|
||
response to unusual latency at very specific times.
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Oct 22 18:34:42 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.76.3:
|
||
* no relevant changelog
|
||
- update to 1.76.2:
|
||
* no relevant changelog
|
||
- switch over to the new %{default_fw_backend} macro
|
||
- create old init file only for < leap 16
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Oct 16 20:40:31 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.76.1:
|
||
* tailscale netcheck CLI command no longer crashes when performing diagnostics
|
||
on networks lacking UDP connectivity.
|
||
* Improperly formatted SERVFAIL responses no longer cause DNS timeouts when using an exit node.
|
||
* dbus login sessions no longer fail on systems where /bin/login is missing.
|
||
|
||
-------------------------------------------------------------------
|
||
Mon Oct 14 13:06:13 UTC 2024 - Alexandre Vicenzi <alexandre.vicenzi@suse.com>
|
||
|
||
- Require a firewall backend (boo#1228829)
|
||
- Add simple test check to ensure binaries are working
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Oct 11 06:07:28 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.76.0:
|
||
* Clients lacking UDP connectivity no longer skip performing fallback latency
|
||
measurements with DERP servers.
|
||
* Warnings no longer display unnecessarily.
|
||
* Tailscale connectivity on in-flight internet on airplanes (such as Alaska Airlines) no longer fails.
|
||
* Service-related processes no longer run unnecessarily when services are disabled on the tailnet.
|
||
* Error messages include explanations in addition to the HTTP status code.
|
||
* Tailscale SSH supports sending environment variables to hosts. It's also possible to specify
|
||
permitted environment variables using the acceptEnv field.
|
||
* Tailscale SSH no longer breaks some terminal applications by omitting pixel width and height when
|
||
resizing the application window.
|
||
|
||
-------------------------------------------------------------------
|
||
Sat Sep 21 05:28:42 UTC 2024 - Eric Torres <eric.torres@its-et.me>
|
||
|
||
- Change path of zsh completion file to make zsh properly recognize completions
|
||
* /usr/share/zsh/site-functions/tailscale moved to /usr/share/zsh/site-functions/_tailscale
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Sep 18 19:10:19 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.74.1:
|
||
* wgengine/magicsock: disable raw disco by default; add envknob to enable
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Sep 13 10:48:17 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.74.0
|
||
* AuthKey system policy can be used to authenticate a device with Tailscale using an MDM solution.
|
||
* tailscale dns CLI command is added for accessing Tailscale DNS settings and status.
|
||
* Tailnet Lock long rotation signatures are truncated automatically to avoid excessive growth.
|
||
* Log In option in the client works as expected.
|
||
* TCP generic receive offload (GRO) support is added for improved userspace mode throughput.
|
||
* TCP generic segmentation offload (GSO) is re-introduced for supporting improved userspace mode throughput.
|
||
This was initially introduced in Tailscale v1.72.0 and then rolled back in v1.72.1.
|
||
* Device posture integration with CrowdStrike Falcon can now use MAC addresses to match devices that lack serial numbers.
|
||
When Falcon integration is configured, Device Identity Collection will automatically collect MAC addresses.
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Aug 22 22:08:51 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.72.1:
|
||
* DNS over TCP failures when querying the Tailscale-internal resolver are fixed.
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Aug 21 16:05:02 UTC 2024 - rrahl0@opensuse.org
|
||
|
||
- Update to version 1.72.0:
|
||
* posture: deduplicate MAC addresses before returning them
|
||
* health/dns: reduce severity of DNS unavailable warning
|
||
* safeweb: add Server.Close method
|
||
* go.mod.sri: update SRI hash for go.mod changes
|
||
* go.{mod,sum}: migrate from nhooyr.io/websocket to github.com/coder/websocket
|
||
* cmd/viewer: add support for map-like container types
|
||
- update golang(API) to 1.23
|
||
- export version variables, to circumvent a bug
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Jul 18 06:31:58 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.70.0:
|
||
* New: Restrict recommended and automatically selected exit nodes using the
|
||
new AllowedSuggestedExitNodes system policy. Applies only to platforms that
|
||
support system policies.
|
||
* Changed: Improved NAT traversal for some uncommon scenarios.
|
||
* Changed: Optimized sending firewall rules to clients more efficiently.
|
||
* Fixed: Exit node suggestion CLI command now prints the hostname.
|
||
* Fixed: Taildrive share paths configured through the CLI resolve relative
|
||
to where you run the tailscale command.
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Jul 2 20:35:35 UTC 2024 - Richard Rahl <rrahl0@opensuse.org>
|
||
|
||
- update to 1.68.2:
|
||
* Fixed: Tailnet lock validation of rotation signatures now permits multiple nodes
|
||
signed by the same pre-signed reusable auth key.
|
||
|
||
-------------------------------------------------------------------
|
||
Sun Jun 16 13:30:20 UTC 2024 - Richard Rahl <rrahl0@disroot.org>
|
||
|
||
- update to 1.68.1:
|
||
* Fixed: 4via6 subnet router advertisement works as expected.
|
||
* Fixed: Tailscale SSH access to Security-Enhanced Linux (SELinux) machines works as expected.
|
||
- update to 1.68.0:
|
||
* New: Auto-updates are allowed in containers, but ignore the tailnet-wide default
|
||
* New: Apply auto-updates even if the node is down or disconnected from the coordination server.
|
||
* New: tailscale lock status now prints the node's signature.
|
||
|
||
-------------------------------------------------------------------
|
||
Wed May 22 08:36:37 UTC 2024 - Richard Rahl <rrahl0@disroot.org>
|
||
|
||
- update to 1.66.4:
|
||
* Fixed: Restored UDP connectivity through Mullvad exit nodes
|
||
* Stateful filtering is now off by default
|
||
|
||
- update to 1.66.3:
|
||
* Login URLs did not always appear in the console when running tailscale up
|
||
* Starting with v1.66, the Kubernetes operator must always run the same or later version
|
||
as the proxies it manages.
|
||
* Expose cloud services on cluster network to the tailnet, using Kubernetes ExternalName Services
|
||
* Expose tailnet services that use Tailscale HTTPS to cluster workloads
|
||
* Cluster workloads can now refer to Tailscale Ingress resources by their MagicDNS names
|
||
* Configure environment variables for Tailscale Kubernetes operator proxies using ProxyClass CRD
|
||
* Expose tailscaled metrics endpoint for Tailscale Kubernetes operator proxies through ProxyClass CRD
|
||
* Configure labels for the Kubernetes operator Pods with Helm chart values
|
||
* Configure affinity rules for Kubernetes operator proxy Pods with ProxyClass
|
||
* Kubernetes operator proxy init container no longer attempts to enable IPv6 forwarding on systems
|
||
that don't have IPv6 module loaded
|
||
* Tailscale containers running on Kubernetes no longer error if an empty Kubernetes Secret is
|
||
pre-created for the tailscaled state
|
||
* Improved the ambiguous error messages when Tailscale running on Kubernetes does not have the right
|
||
permissions to perform actions against the tailscaled state Secret
|
||
|
||
-------------------------------------------------------------------
|
||
Fri May 10 15:16:33 UTC 2024 - Richard Rahl <rrahl0@disroot.org>
|
||
|
||
- update to 1.66.1:
|
||
* Resolved issues with nftables rules for stateful filtering,
|
||
introduced in v1.66.0.
|
||
* tailscale set command flags --netfilter-mode, --snat-subnet-routes,
|
||
and --stateful-filtering are added.
|
||
|
||
- update to 1.66.0:
|
||
* Implemented client-side quarantining for shared-in exit nodes,
|
||
as a mitigation for a security vulnerability described in TS-2024-005.
|
||
* Use the --stateful-filtering flag for the tailscale up to enable stateful filtering for
|
||
subnet routers and exit nodes, as a mitigation for a security vulnerability described
|
||
in TS-2024-005.
|
||
* Added tab completions
|
||
* Use the tailscale exit-node suggest command to automatically pick an available exit node
|
||
that is likely to perform best.
|
||
* Site-to-site networking now also requires --stateful-filtering=false in addition to
|
||
--snat-subnet-routes=false on new subnet routers. Existing subnet routers with --snat-subnet-routes=false
|
||
will default to --stateful-filtering=false.
|
||
|
||
- update to 1.64.2:
|
||
* nothing relevant for linux
|
||
|
||
- update to 1.64.1:
|
||
* nothing relevant for linux
|
||
|
||
- update to 1.64.0:
|
||
* New: tailscale configure kubeconfig now respects KUBECONFIG environment variable.
|
||
* Fixed: tailscale configure kubeconfig now works with partially empty kubeconfig.
|
||
* Fixed: MSS clamping for Kubernetes operator proxies using nftables.
|
||
* Fixed: Containers on hosts with partial support for ip6tables no longer crash.
|
||
|
||
- turn of changelog generation
|
||
- add completions for bash
|
||
|
||
-------------------------------------------------------------------
|
||
Sat Mar 30 08:28:56 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- update to 1.62.1:
|
||
* Send load balancing hint HTTP request header
|
||
* Fixed: Kubernetes operator proxies should not accept subnet routes
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Mar 14 03:13:54 UTC 2024 - rrahl0@proton.me
|
||
|
||
- update to 1.62.0:
|
||
* IPv6 support detection in a container environment is improved
|
||
* New: Web interface now uses ACL grants to manage access on tagged devices
|
||
* Tailscale SSH connections now disable unnecessary hostname canonicalization
|
||
* tailscale bugreport command for generating diagnostic logs now contain ethtool information
|
||
* Mullvad's family-friendly server is added to the list of well known DNS over HTTPS (DoH) servers
|
||
* DNS over HTTP requests now contain a timeout
|
||
* TCP forwarding attempts in userspace mode now have a per-client limit
|
||
* Endpoints with link-local IPv6 addresses is preferred over private addresses
|
||
* WireGuard logs are less verbose
|
||
* Go min. version 1.22.1
|
||
* DERP server region no longer changes if connectivity to the new DERP region is degraded
|
||
|
||
- update to 1.60.1:
|
||
* Exposing port 8080 to other devices on your tailnet works as expected
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Feb 20 22:10:41 UTC 2024 - Alexandre Vicenzi <alexandre.vicenzi@suse.com>
|
||
|
||
- Add disable-auto-update.patch to prevent auto updates and instead
|
||
ask users to use Zypper to update manually
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Feb 20 14:52:46 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- change to the non deprecated manualrun
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Feb 16 14:38:14 UTC 2024 - alexandre.vicenzi@suse.com
|
||
|
||
- Spec cleanup
|
||
* Use tar_scm to avoid commit hashes in the spec
|
||
* Use tailscale build scripts
|
||
* Drop ProtectClock fix for Leap, DeviceAllow fixes it
|
||
- Add build-verbose.patch to get go flags into build log
|
||
- Enable PrivateDevices but allow access to /dev/net/tun in tailscaled.service
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Feb 16 00:50:26 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- update to 1.60.0:
|
||
* minimum go version 1.22
|
||
* authentication: present users with a valid login page when
|
||
attempting to login even after leaving device unattended for several days
|
||
* networking: mute noisy peer mtu discovery errors
|
||
* networking: expose gVisor metrics in debug mode
|
||
* port mapper: support legacy "urn:dslforum-org" port mapping services
|
||
* port mapper: fix crash when no support mapping services found
|
||
* ssh: log warning when unable to find SSH host keys
|
||
* serve: improve error message when running as non-root
|
||
* Detect when Tailscale is running on Digital Ocean and automatically
|
||
use Digital Ocean's DNS resolvers
|
||
* enable app connectors to install routes for domains that resolve to CNAME
|
||
records
|
||
* support pre-configured routes from control server
|
||
* add new read-only mode
|
||
* tailscale status command: fix output formatting Tailnet
|
||
includes location-based exit nodes
|
||
* a new ProxyClass custom resource that allows to provide custom
|
||
configuration for cluster resources that the operator creates
|
||
* ACL tags for the operator can now be configured via Helm chart values
|
||
* routing to Ingress backends that require an exact path without a slash
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Feb 7 14:52:53 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- make rpm not overwrite /etc/default/taiscaled
|
||
- defattr everything to root
|
||
|
||
-------------------------------------------------------------------
|
||
Sat Feb 3 11:18:05 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- no stripping of binaries
|
||
- add commitID to binaries for upstream
|
||
- add directory for saved configs
|
||
|
||
-------------------------------------------------------------------
|
||
Tue Jan 23 23:54:36 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- switch services to manual
|
||
- update to version 1.58.2:
|
||
* Fixed: [App connectors][app-connectors] have improved scheduling
|
||
and merging of route changes under some conditions
|
||
* Fixed: Crash when performing UPnP portmapping on older routers
|
||
with no supported portmapping services
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Jan 19 08:06:27 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- update to version 1.58.0:
|
||
* portmap: check the epoch from NAT-PMP & PCP, establish new portmapping if it changes
|
||
* portmap: better handle multiple interfaces
|
||
* portmap: handle multiple UPnP discovery responses
|
||
* increase the number of 4via6 site IDs from 256 to 65,536
|
||
* taildrop: allow category Z unicode characters
|
||
* increased binary size with 1.56 is resolved in 1.58
|
||
* Reduce home DERP flapping when there's still an active connection
|
||
* device web ui: fixed issue when accessing shared devices
|
||
* device web ui: fixed login issue when accessed over https
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Jan 10 02:17:57 UTC 2024 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- fix an issue with Leap, where ProtectClock prevents to connect to
|
||
/dev/net/tun
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Dec 15 21:22:39 UTC 2023 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- update to version 1.56.1:
|
||
* Fixed: Web interface redirects to the correct self IP known by source peer
|
||
* Fixed: Usage of slices.Compact from app connector domains list
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Dec 15 13:48:28 UTC 2023 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- fix version output to what upstream expects
|
||
|
||
-------------------------------------------------------------------
|
||
Wed Dec 13 22:08:30 UTC 2023 - rrahl0@proton.me
|
||
|
||
- Update to version 1.56.0:
|
||
* improve responsiveness under load, especially with bidirectional traffic
|
||
* improve UPnP portmapping
|
||
* add tailscale whois subcommand to observe metadata associated with a Tailscale IP
|
||
* include tailnet name and profile ID in tailscale switch --list to disambiguate
|
||
profiles with common login names
|
||
* improve tailscale web interface for configuring some device settings such as exit nodes,
|
||
subnet routers, and Tailscale SSH
|
||
* improve containerboot to symlink its socket file if possible,
|
||
making the tailscale CLI work without --socket=/tmp/tailscale.sock
|
||
* add support in Kubernetes operator cluster egress for referring to a tailnet service
|
||
by its MagicDNS name
|
||
|
||
|
||
- Update to version 1.54.1:
|
||
* no relevant updates to the linux version
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Nov 24 21:59:11 UTC 2023 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- tailscale couldn't connect to /dev/net/tun
|
||
|
||
-------------------------------------------------------------------
|
||
Thu Nov 23 06:51:24 UTC 2023 - rrahl0@proton.me
|
||
|
||
- Update to version 1.54.0:
|
||
* improve throughput substantially for UDP packets over TUN device with recent Linux kernels
|
||
|
||
|
||
- Update to version 1.52.1:
|
||
* no linux improvements
|
||
|
||
- Update to version 1.52.0:
|
||
* tailscale set command flag --auto-update is added to opt in to automatic client updates
|
||
* tailscale serve and tailscale funnel commands are updated for improved usability
|
||
* tailscale update command for manual updates is now in beta
|
||
* Taildrop file transfer displays a progress meter
|
||
* nftables auto-detection is improved when TS_DEBUG_FIREWALL_MODE=auto is used
|
||
* DNS detection of NetworkManager with configured but absent systemd-resolved
|
||
* Taildrop now resumes file transfers after partial transfers are interrupted
|
||
* tailscale up command displays a message about client updates when newer versions are available
|
||
* tailscale status command displays a message about client updates when newer versions are available
|
||
* tailscale cert command renews in the background. The current certificate only displays if it has expired.
|
||
|
||
-------------------------------------------------------------------
|
||
Mon Oct 02 23:51:03 UTC 2023 - rrahl0@proton.me
|
||
|
||
- Update to version 1.50.1:
|
||
* fix bug where serve config could get wiped
|
||
* Funnel support for tsnet apps
|
||
* fix potential crash with UPnP
|
||
|
||
-------------------------------------------------------------------
|
||
Sat Sep 30 19:38:50 UTC 2023 - rrahl0@proton.me
|
||
|
||
- Update to version 1.50.0:
|
||
* Update tailscale{,d} licenses
|
||
* Update Quad9 addresses and references
|
||
* Adds support for Wikimedia DNS using DNS-over-HTTPS
|
||
|
||
- Update to version 1.48.1:
|
||
* no relevant updates
|
||
|
||
- Update to version 1.48.2:
|
||
* Improvements to Mullvad exit nodes
|
||
|
||
-------------------------------------------------------------------
|
||
Fri Aug 18 15:56:24 UTC 2023 - Richard Rahl <rrahl0@proton.me>
|
||
|
||
- Initial revision
|