feature/conn25: unmap addresses in TransitIPRequest

Unmap both transit and destination IPs in
TransitIPRequest to prevent unpredictable mappings.

Fixes https://github.com/tailscale/corp/issues/48781

Change-Id: I5aea2bf4e5ff5240c66f20c71cfa1ceba1722622
Signed-off-by: Mazdak Nasab <mazdak.nasab@gmail.com>
This commit is contained in:
Mazdak Nasab committed 2026-09-28 11:11:52 -07:00
1 parent 8a119e1ec0
commit ecedffff5b
2 files changed
+24

No files matched your search

+6
View File
@@ -588,6 +588,12 @@ func (c *Conn25) handleConnectorTransitIPRequest(n tailcfg.NodeView, peerCaps ta
seen := map[netip.Addr]bool{}
for _, each := range ctipr.TransitIPs {
// Canonicalize IPv4-in-IPv6 addresses, so that duplicate detection and
// the keys we store in the connector's map match the unmapped form the
// datapath produces when it parses packets.
each.TransitIP = each.TransitIP.Unmap()
each.DestinationIP = each.DestinationIP.Unmap()
if seen[each.TransitIP] {
resp.TransitIPs = append(resp.TransitIPs, TransitIPResponse{
Code: DuplicateTransitIP,
+18
View File
@@ -78,6 +78,9 @@ func TestHandleConnectorTransitIPRequest(t *testing.T) {
tipV4Outside := netip.MustParseAddr("192.0.2.1")
tipV6Outside := netip.MustParseAddr("2001:db8::1")
// tipV4_1 written in its IPv4-in-IPv6 form; the same address as tipV4_1.
tipV4_1In6 := netip.MustParseAddr("::ffff:169.254.0.1")
// Destination IPs
dipV4_1 := netip.MustParseAddr("10.0.0.1")
dipV4_2 := netip.MustParseAddr("10.0.0.2")
@@ -429,6 +432,21 @@ func TestHandleConnectorTransitIPRequest(t *testing.T) {
{{pipV4_2, tipV4Outside, netip.Addr{}}, {pipV4_2, tipV4_2, dipV4_2}},
},
},
// Single peer, a transit IP in its IPv4-in-IPv6 form is canonicalized
// and stored unmapped.
{
name: "one-peer-tip-4in6",
ctipReqPeers: []tailcfg.NodeView{peerV4Only},
ctipReqs: []ConnectorTransitIPRequest{
{TransitIPs: []TransitIPRequest{{TransitIP: tipV4_1In6, DestinationIP: dipV4_1, App: appName}}},
},
wants: []ConnectorTransitIPResponse{
{TransitIPs: []TransitIPResponse{{Code: OK, Message: ""}}},
},
wantLookups: [][][]netip.Addr{
{{pipV4_2, tipV4_1, dipV4_1}, {pipV4_2, tipV4_1In6, netip.Addr{}}},
},
},
}
for _, tt := range tests {