mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-09 20:01:54 -04:00
On backends that can't do OS-level split DNS, Tailscale forwards the default route to the system's own resolvers, which it reads out of the OS config. At boot that config may not be populated yet, because NetworkManager or systemd-resolved haven't run, and Tailscale took over regardless: it pointed the OS at 100.100.100.100 but compiled an empty "." route, so every non-Tailscale name failed to resolve for the rest of the process's life. Fail compileConfig instead, which leaves the OS resolvers in place, and retry the last config with a bounded backoff until resolvers appear. A health warning explains why MagicDNS is inactive in the meantime. Sandboxed macOS and iOS are exempt. There the network extension reapplies the config itself when the OS nameservers change, and quad-100 as the primary resolver is what keeps tailnet names resolving while the base config is still empty. Dropping the exemption is tracked in tailscale/corp#48962. This also changes the outcome on an openresolv host with no snippets registered. Since the fix for #20825, openresolv reports an empty base config there and tailscaled took over with no upstream, so every public name got SERVFAIL. Such a host now keeps its resolv.conf and shows the health warning instead. TestOpenresolvDNS checks that outcome. TestSplitDNSEmptyBaseConfig covers the boot race end to end in natlab: it empties resolv.conf on a guest using the "direct" backend, checks that tailscaled leaves it alone, then adds a resolver and checks that both tailnet and public names resolve. Fixes #20341 Signed-off-by: Brendan Creane <bcreane@gmail.com>
natlab
Virtual network lab for integration tests. Tracking issue: https://github.com/tailscale/tailscale/issues/13038
Use the run-natlab-tests GitHub label on PRs to run these tests.
Prerequisites
qemu-system-x86_64andqemu-img. On Debian/Ubuntu:apt install qemu-system-x86 qemu-utils- A built gokrazy natlabapp image (auto-built on first run via
make -C gokrazy natlab)
KVM is used automatically on Linux when /dev/kvm is readable+writable. Add
yourself to the kvm group to avoid QEMU falling back to software emulation.
Running locally
go test ./tstest/natlab/vmtest/ --run-vm-tests -v -timeout=15
go test's default timeout (10 min) is likely not enough to cover the whole
package. You may need to raise it further or disable the timeout entirely
(-timeout=0) when running the full suite.
Alternatively, select individual tests with the usual -run.