Android doesn't have /etc/resolv.conf. This causes problems for people running GOOS=linux binaries (or GOOS=android binaries without cgo, so they don't use Android's bionic libc) in Termux, adb shell, etc. (Go binaries built with cgo use bionic on Android: golang/go#10714) 16 years ago when I was on the Android team I added a system-wide DNS cache (dnsproxyd) and made bionic query that, so each Android app wasn't doing its own DNS resolution. That interface was never meant to be stable, and I thought that code would be surely dead by now 16 years later, but apparently it lives on, and is more stable now: both empirically (time, ossification?), and because of how Android's split system updates work nowadays, the dnsproxyd lives on the other side of bionic, so they seem to keep it pretty stable. The old bionic<->dnsproxyd APIs I added 16 years ago are still there, but 8 years ago it got some additional APIs to query by a DNS packet instead. So use it! If we find ourselves on Android and without libc access (and because we don't want to pull in ebitengine/purego with all its side effects), just query the DNS server like bionic does. This can be disabled in Linux binaries with ts_omit_androiddns. Old links: LineageOS/android_system_netd@007e987fee https://android.googlesource.com/platform/system/netd/+/007e987fee7e815e0c4bc820f434a632b7a69a9d ("DNS proxy thread in netd.") aosp-mirror/platform_bionic@a1dbf0b453 https://android.googlesource.com/platform/bionic/+/a1dbf0b453801620565e5911f354f82706b0200d ("DNS proxy: the start. proxies getaddrinfo calls.") Back then I found it cleaner to proxy at the getaddrinfo level rather than speak in terms of DNS packets. The raw-packet resnsend command I use here came eight years later, added in November 2018 for Android 10's android_res_nsend NDK API: LineageOS/android_system_netd@c0c818f448 https://android.googlesource.com/platform/system/netd/+/c0c818f448efa90ab1f9b1733fb86c5e22fb894c ("Add resNetworkSend cmd in DnsProxyListener") Android 10 (codename Q, API level 29, released September 2019) is therefore the minimum OS version for this to work. I verified this against the DnsResolver module on an Android 13 emulator with SELinux enforcing, from the shell UID, with both a pure Go GOOS=android binary and a static GOOS=linux binary: raw queries, NXDOMAIN handling, the runtime Android detection, and a tailcat binary reaching DERP with lookups visible in the daemon's logcat output, some served from my 2010 DNS cache. Updates #21129 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> Change-Id: I0d63763e255a077e4e5745b3e64ba0d78dab6d69 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Tailscale
Private WireGuard® networks made easy
Overview
This repository contains the majority of Tailscale's open source code.
Notably, it includes the tailscaled daemon and
the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows,
macOS, and to varying degrees
on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's
code, but this repo doesn't contain the mobile GUI code.
Other Tailscale repos of note:
- the Android app is at https://github.com/tailscale/tailscale-android
- the Synology package is at https://github.com/tailscale/tailscale-synology
- the QNAP package is at https://github.com/tailscale/tailscale-qpkg
- the Chocolatey packaging is at https://github.com/tailscale/tailscale-chocolatey
For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.
Using
We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.
Other clients
The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.
Building
We always require the latest Go release, currently Go 1.27. (While we build releases with our Go fork, its use is not required.)
go install tailscale.com/cmd/tailscale{,d}
If you're packaging Tailscale for distribution, use build_dist.sh
instead, to burn commit IDs and version info into the binaries:
./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled
If your distro has conventions that preclude the use of
build_dist.sh, please do the equivalent of what it does in your
distro's way, so that bug reports contain useful version information.
Bugs
Please file any issues about this code or the hosted service on the issue tracker.
Contributing
PRs welcome! But please file bugs. Commit messages should reference bugs.
We require Developer Certificate of
Origin
Signed-off-by lines in commits.
See commit-messages.md (or skim git log) for our commit message style.
About Us
Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:
- https://github.com/tailscale/tailscale/graphs/contributors
- https://github.com/tailscale/tailscale-android/graphs/contributors
Legal
WireGuard is a registered trademark of Jason A. Donenfeld.