When quad-100 must be installed as the OS primary resolver (Apple Mode B), its catch-all forwarders were blended from base-config nameserver IPs alone: non-standard ports, search domains, and DoH/DoT endpoints were lost, and a base read that returned no resolvers silently installed a catch-all with no forwarders at all, breaking all public DNS while reporting a healthy DNS configuration. Introduce OSConfig.Resolvers, which OSConfigurators able to recover the underlying resolver configuration at full fidelity populate for the DNS manager only: it never reaches the OS, and Equal ignores it so configuration application is unaffected. Blend it into the catch-all route verbatim, falling back to plain IP:53 resolvers derived from Nameservers. Teach the forwarder to dial arbitrary https:// resolvers instead of only well-known public providers: at their BootstrapResolution addresses when present, or at the URL's own host when that is an IP literal, so enterprise DoH endpoints recovered from the OS can be forwarded to over DoH rather than plaintext DNS. Reject an empty base config on Apple Mode B: keep the previous configuration, use the upstream empty-base health warning and medium severity, and let an extension-triggered recompile retry instead of installing a catch-all that cannot forward. Expose the same missing- resolver error to OS configurators so bridge-reported absence uses this warning too, while genuine configuration-read failures remain distinct. Extend the Apple mode tests with empty-base and full-fidelity blend coverage, and update the iOS primary-mode cases to model the real NetworkExtension base read (LAN resolvers and search domains) rather than the silently empty catch-all. RELNOTE: Fix silent public DNS breakage when Tailscale must be the system DNS resolver on Apple clients. Updates #20341 Updates tailscale/corp#45534 Updates tailscale/corp#48693 Change-Id: Ie7e277b0fd39d2b91b1e770f8f01d688e02b4d49 Signed-off-by: James Tucker <james@tailscale.com>
Tailscale
Private WireGuard® networks made easy
Overview
This repository contains the majority of Tailscale's open source code.
Notably, it includes the tailscaled daemon and
the tailscale CLI tool. The tailscaled daemon runs on Linux, Windows,
macOS, and to varying degrees
on FreeBSD and OpenBSD. The Tailscale iOS and Android apps use this repo's
code, but this repo doesn't contain the mobile GUI code.
Other Tailscale repos of note:
- the Android app is at https://github.com/tailscale/tailscale-android
- the Synology package is at https://github.com/tailscale/tailscale-synology
- the QNAP package is at https://github.com/tailscale/tailscale-qpkg
- the Chocolatey packaging is at https://github.com/tailscale/tailscale-chocolatey
For background on which parts of Tailscale are open source and why, see https://tailscale.com/opensource/.
Using
We serve packages for a variety of distros and platforms at https://pkgs.tailscale.com.
Other clients
The macOS, iOS, and Windows clients use the code in this repository but additionally include small GUI wrappers. The GUI wrappers on non-open source platforms are themselves not open source.
Building
We always require the latest Go release, currently Go 1.27. (While we build releases with our Go fork, its use is not required.)
go install tailscale.com/cmd/tailscale{,d}
If you're packaging Tailscale for distribution, use build_dist.sh
instead, to burn commit IDs and version info into the binaries:
./build_dist.sh tailscale.com/cmd/tailscale
./build_dist.sh tailscale.com/cmd/tailscaled
If your distro has conventions that preclude the use of
build_dist.sh, please do the equivalent of what it does in your
distro's way, so that bug reports contain useful version information.
Bugs
Please file any issues about this code or the hosted service on the issue tracker.
Contributing
PRs welcome! But please file bugs. Commit messages should reference bugs.
We require Developer Certificate of
Origin
Signed-off-by lines in commits.
See commit-messages.md (or skim git log) for our commit message style.
About Us
Tailscale is primarily developed by the people at https://github.com/orgs/tailscale/people. For other contributors, see:
- https://github.com/tailscale/tailscale/graphs/contributors
- https://github.com/tailscale/tailscale-android/graphs/contributors
Legal
WireGuard is a registered trademark of Jason A. Donenfeld.