TestNATPing called SetMasqueradeAddresses on the test control server and then immediately read both nodes' status, expecting the new masqueraded peer addresses to already be there. But the change reaches the nodes asynchronously via their streaming map responses, so under load the status check ran before the new map response arrived and the test failed with "n1 sees n2 as 100.64.0.2; want 100.64.2.1" and the like. This was the dominant failure mode on the flakes dashboard (11 of the 18 most recent CI failures) and the only one found in a six hour Antithesis run (run 30b4de27d89d8d7a651e7b43b3f1ec3f-61-9, 54 failures in 16,599 runs). Wait for each node's status to report the expected peer address instead. Also retry the "tailscale ping" invocations, since a ping can fail transiently right after a map response changes a peer's addresses and before the engine is reconfigured; the second most common failure mode was pings exiting with status 1. Failed pings now include the CLI output in the error rather than a bare exit status. Locally, flakestress (32 workers) reproduced the failure in 29 of 210 runs before this change (13.8%) and in 0 of 1,173 runs after. The remaining Windows-only failure mode on the dashboard, TempDir cleanup failing because tailscaled.exe is still open, is a harness-wide issue that affects every integration test and is not specific to this test. Fixes #12169 Updates tailscale/corp#47865 Change-Id: I7c3e2b8a5d914f0e6a2b1c9d8e7f6a5b4c3d2e1f Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Tailscale
Private WireGuard® networks made easy
Overview
This repository contains the majority of Tailscale's open source code.
Notably, it includes the tailscaled daemon and
the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows,
macOS, and to varying degrees
on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's
code, but this repo doesn't contain the mobile GUI code.
Other Tailscale repos of note:
- the Android app is at https://github.com/tailscale/tailscale-android
- the Synology package is at https://github.com/tailscale/tailscale-synology
- the QNAP package is at https://github.com/tailscale/tailscale-qpkg
- the Chocolatey packaging is at https://github.com/tailscale/tailscale-chocolatey
For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.
Using
We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.
Other clients
The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.
Building
We always require the latest Go release, currently Go 1.27. (While we build releases with our Go fork, its use is not required.)
go install tailscale.com/cmd/tailscale{,d}
If you're packaging Tailscale for distribution, use build_dist.sh
instead, to burn commit IDs and version info into the binaries:
./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled
If your distro has conventions that preclude the use of
build_dist.sh, please do the equivalent of what it does in your
distro's way, so that bug reports contain useful version information.
Bugs
Please file any issues about this code or the hosted service on the issue tracker.
Contributing
PRs welcome! But please file bugs. Commit messages should reference bugs.
We require Developer Certificate of
Origin
Signed-off-by lines in commits.
See commit-messages.md (or skim git log) for our commit message style.
About Us
Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:
- https://github.com/tailscale/tailscale/graphs/contributors
- https://github.com/tailscale/tailscale-android/graphs/contributors
Legal
WireGuard is a registered trademark of Jason A. Donenfeld.