Files
tailscale/tsconst/windowsmode.go
T
Brad Fitzpatrick b4e3a5299c cmd/tailscaled, safesocket: add --windows-mode=dev
This adds a tailscaled string flag "--windows-mode" which accepts two
possible values: the empty string (default) to get the normal behavior
(tailscaled running as an admin, usually as a service), and "dev", to
make the safesocket named pipe path be at a location that regular
users (non-admins) can create.

It then modifies the safesocket client side (as used by the CLI) to
try the dev mode path too on failure.

This lets people work on tailscaled.exe+tailscale.exe in a terminal
easily during development, as either an admin or non-admin. (This
used to work prior to the move away from TCP localhost to named pipes
for safesocket on Windows)

Updates #2791

Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com>
Change-Id: I9c1e3a5b7d0f2a4c6e8b0d2f4a6c8e0b2d4f6a8c
2026-09-28 13:26:52 -07:00

28 lines
1.2 KiB
Go

// Copyright (c) Tailscale Inc & contributors
// SPDX-License-Identifier: BSD-3-Clause
package tsconst
// WindowsMode is how tailscaled is being run on Windows, as given by its
// --windows-mode flag. It decides where tailscaled listens for the CLI and
// GUI and who may connect.
type WindowsMode string
const (
// WindowsModeDefault is the default: tailscaled is the Tailscale service
// (running as LocalSystem), or an administrator running tailscaled.exe by
// hand in its place. It must listen on the default named pipe under
// \\.\pipe\ProtectedPrefix\Administrators\, which only administrators
// can create; that is what lets clients trust it. It serves every local
// user, with per-user access decided by tailscaled itself.
WindowsModeDefault WindowsMode = ""
// WindowsModeDev is a developer running tailscaled by hand, possibly
// without administrator rights. It listens by default on a per-user
// named pipe, \\.\pipe\tailscale-<SID>, which is created owned by and
// accessible to that user alone, and the CLI falls back to that pipe
// when the default one doesn't exist. Nothing about it is trusted by
// other users, and it can't serve them.
WindowsModeDev WindowsMode = "dev"
)