Files
tailscale/tstest/natlab
Brendan Creane 2d4379386a net/dns: don't take over DNS when the OS has no upstream resolvers (#20794)
On backends that can't do OS-level split DNS, Tailscale forwards the default
route to the system's own resolvers, which it reads out of the OS config. At
boot that config may not be populated yet, because NetworkManager or
systemd-resolved haven't run, and Tailscale took over regardless: it pointed
the OS at 100.100.100.100 but compiled an empty "." route, so every
non-Tailscale name failed to resolve for the rest of the process's life.

Fail compileConfig instead, which leaves the OS resolvers in place, and
retry the last config with a bounded backoff until resolvers appear. A
health warning explains why MagicDNS is inactive in the meantime.

Sandboxed macOS and iOS are exempt. There the network extension reapplies
the config itself when the OS nameservers change, and quad-100 as the
primary resolver is what keeps tailnet names resolving while the base config
is still empty. Dropping the exemption is tracked in tailscale/corp#48962.

This also changes the outcome on an openresolv host with no snippets
registered. Since the fix for #20825, openresolv reports an empty base config
there and tailscaled took over with no upstream, so every public name got
SERVFAIL. Such a host now keeps its resolv.conf and shows the health warning
instead. TestOpenresolvDNS checks that outcome.

TestSplitDNSEmptyBaseConfig covers the boot race end to end in natlab: it
empties resolv.conf on a guest using the "direct" backend, checks that
tailscaled leaves it alone, then adds a resolver and checks that both tailnet
and public names resolve.

Fixes #20341

Signed-off-by: Brendan Creane <bcreane@gmail.com>
2026-09-27 10:20:42 -07:00
..

natlab

Virtual network lab for integration tests. Tracking issue: https://github.com/tailscale/tailscale/issues/13038

Use the run-natlab-tests GitHub label on PRs to run these tests.

Prerequisites

  • qemu-system-x86_64 and qemu-img. On Debian/Ubuntu: apt install qemu-system-x86 qemu-utils
  • A built gokrazy natlabapp image (auto-built on first run via make -C gokrazy natlab)

KVM is used automatically on Linux when /dev/kvm is readable+writable. Add yourself to the kvm group to avoid QEMU falling back to software emulation.

Running locally

go test ./tstest/natlab/vmtest/ --run-vm-tests -v -timeout=15

go test's default timeout (10 min) is likely not enough to cover the whole package. You may need to raise it further or disable the timeout entirely (-timeout=0) when running the full suite.

Alternatively, select individual tests with the usual -run.