mirror of
https://github.com/tailscale/tailscale.git
synced 2026-10-02 16:34:54 -04:00
This is the output of the new misc/bumpdeps tool (#21325) run with --exclude-newer-than-days=7, which asks proxy.golang.org for the newest version of every direct dependency, ignoring releases younger than a week in favor of the newest older one, and runs a single go get. gvisor tracks its "go" branch, wireguard-go its "tailscale" branch, and golang-x-crypto its "main" branch (the proxy's @latest for it is a stray v0.91.0 tag from 2024 that predates our acme fork changes). Indirect deps only moved as far as MVS pulled them. The week-long cooldown held back gvisor, the gokrazy modules, chromedp/cdproto, and hashicorp/raft-boltdb/v2, whose only newer versions are days old; they'll come along next time. Several upstream changes needed small fixes: nfpm's PrepareForPackager takes a modification time now (a zero time keeps the old behavior of using the source file's mtime), esbuild's ServeOptions.Port became an int while ServeResult.Host became a Hosts slice, client-go's EventRecorder.Eventf is now recognized by vet as a printf wrapper (so the k8s-operator calls that passed a preformatted message switch to Event), google/nftables v0.3.0 reads back the kernel's NF_NAT_RANGE_PROTO_SPECIFIED flag into a new expr.NAT.Specified field (so the port map DNAT rule now sets it too or findRule never matches the rule it just added), and staticcheck v0.8.1 knows encoding/json/v2's embed tag option, so the two SA5008 suppressions for it are gone. Two tests assumed old library behavior. client-go's fake clientset now replays existing objects when a watch starts, as a real apiserver does, so the k8s-proxy config test must tolerate the loader ignoring that no-op event before the real reload arrives. fyne.io/systray moved its dbusmenu object path and answers the first GetLayout with depth 1, so the systray test now finds the menu via the item's Menu property and polls until the submenu entries appear. Then make tidy, make updatedeps, and make kube-generate-all (the controller-gen bump to v0.22.0 changes doc strings, stops listing top-level metadata as required, and crd-ref-docs now marks optional fields). Updates #8043 Signed-off-by: Brad Fitzpatrick <bradfitz@tailscale.com> Change-Id: I3f9a2c6e8b1d4705a9e2c7b8d1f4e6a0c2b5d8e3
176 lines
6.7 KiB
Nix
176 lines
6.7 KiB
Nix
# flake.nix describes a Nix source repository that provides
|
|
# development builds of Tailscale and the fork of the Go compiler
|
|
# toolchain that Tailscale maintains. It also provides a development
|
|
# environment for working on tailscale, for use with "nix develop".
|
|
#
|
|
# For more information about this and why this file is useful, see:
|
|
# https://wiki.nixos.org/wiki/Flakes
|
|
#
|
|
# Also look into direnv: https://direnv.net/, this can make it so that you can
|
|
# automatically get your environment set up when you change folders into the
|
|
# project.
|
|
#
|
|
# WARNING: currently, the packages provided by this flake are brittle,
|
|
# and importing this flake into your own Nix configs is likely to
|
|
# leave you with broken builds periodically.
|
|
#
|
|
# The issue is that building Tailscale binaries uses the buildGoModule
|
|
# helper from nixpkgs. This helper demands to know the content hash of
|
|
# all of the Go dependencies of this repo, in the form of a Nix SRI
|
|
# hash. This hash isn't automatically kept in sync with changes made
|
|
# to go.mod yet, and so every time we update go.mod while hacking on
|
|
# Tailscale, this flake ends up with a broken build due to hash
|
|
# mismatches.
|
|
#
|
|
# Right now, this flake is intended for use by Tailscale developers,
|
|
# who are aware of this mismatch and willing to live with it. At some
|
|
# point, we'll add automation to keep the hashes more in sync, at
|
|
# which point this caveat should go away.
|
|
#
|
|
# See https://github.com/tailscale/tailscale/issues/6845 for tracking
|
|
# how to fix this mismatch.
|
|
{
|
|
inputs = {
|
|
nixpkgs.url = "github:NixOS/nixpkgs/nixpkgs-unstable";
|
|
systems.url = "github:nix-systems/default";
|
|
# Used by shell.nix as a compat shim.
|
|
flake-compat = {
|
|
url = "github:edolstra/flake-compat";
|
|
flake = false;
|
|
};
|
|
};
|
|
|
|
outputs = {
|
|
self,
|
|
nixpkgs,
|
|
systems,
|
|
flake-compat,
|
|
}: let
|
|
goVersion = nixpkgs.lib.fileContents ./go.toolchain.version;
|
|
toolChainRev = nixpkgs.lib.fileContents ./go.toolchain.rev;
|
|
flakeHashes = builtins.fromJSON (builtins.readFile ./flakehashes.json);
|
|
gitHash = flakeHashes.toolchain.sri;
|
|
eachSystem = f:
|
|
nixpkgs.lib.genAttrs (import systems) (system:
|
|
f (import nixpkgs {
|
|
system = system;
|
|
overlays = [
|
|
(final: prev: {
|
|
go_1_27 = prev.go_1_27.overrideAttrs (old: {
|
|
version = goVersion;
|
|
src = prev.fetchFromGitHub {
|
|
owner = "tailscale";
|
|
repo = "go";
|
|
rev = toolChainRev;
|
|
sha256 = gitHash;
|
|
};
|
|
# The Tailscale Go fork carries a placeholder in
|
|
# src/runtime/debug/mod.go that must be replaced with
|
|
# the actual toolchain git rev at build time. Without
|
|
# this, binaries report an empty tailscale.toolchain.rev
|
|
# and the runtime assertion in
|
|
# assert_ts_toolchain_match.go panics.
|
|
postPatch =
|
|
(old.postPatch or "")
|
|
+ ''
|
|
substituteInPlace src/runtime/debug/mod.go \
|
|
--replace-fail "TAILSCALE_GIT_REV_TO_BE_REPLACED_AT_BUILD_TIME" "${toolChainRev}"
|
|
'';
|
|
});
|
|
})
|
|
];
|
|
}));
|
|
tailscaleRev = self.rev or "";
|
|
in {
|
|
# tailscale takes a nixpkgs package set, and builds Tailscale from
|
|
# the same commit as this flake. IOW, it provides "tailscale built
|
|
# from HEAD", where HEAD is "whatever commit you imported the
|
|
# flake at".
|
|
#
|
|
# This is currently unfortunately brittle, because we have to
|
|
# specify vendorHash, and that sha changes any time we alter
|
|
# go.mod. We don't want to force a nix dependency on everyone
|
|
# hacking on Tailscale, so this flake is likely to have broken
|
|
# builds periodically until someone comes through and manually
|
|
# fixes them up. I sure wish there was a way to express "please
|
|
# just trust the local go.mod, vendorHash has no benefit here",
|
|
# but alas.
|
|
#
|
|
# So really, this flake is for tailscale devs to dogfood with, if
|
|
# you're an end user you should be prepared for this flake to not
|
|
# build periodically.
|
|
packages = eachSystem (pkgs: rec {
|
|
default = pkgs.buildGo127Module {
|
|
name = "tailscale";
|
|
pname = "tailscale";
|
|
src = ./.;
|
|
vendorHash = flakeHashes.vendor.sri;
|
|
nativeBuildInputs = [pkgs.makeWrapper pkgs.installShellFiles];
|
|
ldflags = ["-X tailscale.com/version.gitCommitStamp=${tailscaleRev}"];
|
|
env.CGO_ENABLED = 0;
|
|
subPackages = [
|
|
"cmd/tailscale"
|
|
"cmd/tailscaled"
|
|
"cmd/tsidp"
|
|
];
|
|
doCheck = false;
|
|
|
|
# NOTE: We strip the ${PORT} and $FLAGS because they are unset in the
|
|
# environment and cause issues (specifically the unset PORT). At some
|
|
# point, there should be a NixOS module that allows configuration of these
|
|
# things, but for now, we hardcode the default of port 41641 (taken from
|
|
# ./cmd/tailscaled/tailscaled.defaults).
|
|
postInstall =
|
|
pkgs.lib.optionalString pkgs.stdenv.isLinux ''
|
|
wrapProgram $out/bin/tailscaled --prefix PATH : ${pkgs.lib.makeBinPath [pkgs.iproute2 pkgs.iptables pkgs.getent pkgs.shadow]}
|
|
wrapProgram $out/bin/tailscale --suffix PATH : ${pkgs.lib.makeBinPath [pkgs.procps]}
|
|
|
|
sed -i \
|
|
-e "s#/usr/sbin#$out/bin#" \
|
|
-e "/^EnvironmentFile/d" \
|
|
-e 's/''${PORT}/41641/' \
|
|
-e 's/$FLAGS//' \
|
|
./cmd/tailscaled/tailscaled.service
|
|
|
|
install -D -m0444 -t $out/lib/systemd/system ./cmd/tailscaled/tailscaled.service
|
|
''
|
|
+ pkgs.lib.optionalString (pkgs.stdenv.buildPlatform.canExecute pkgs.stdenv.hostPlatform) ''
|
|
installShellCompletion --cmd tailscale \
|
|
--bash <($out/bin/tailscale completion bash) \
|
|
--fish <($out/bin/tailscale completion fish) \
|
|
--zsh <($out/bin/tailscale completion zsh)
|
|
'';
|
|
};
|
|
tailscale = default;
|
|
});
|
|
|
|
devShells = eachSystem (pkgs: {
|
|
default = pkgs.mkShell {
|
|
packages = with pkgs; [
|
|
curl
|
|
git
|
|
gopls
|
|
gotools
|
|
graphviz
|
|
perl
|
|
go_1_27
|
|
yarn
|
|
|
|
# qemu and e2fsprogs are needed for natlab
|
|
qemu
|
|
e2fsprogs
|
|
|
|
# mtools (mcopy) and dtc are needed by the `tsapp-qemu-pi`
|
|
# Makefile target that boots the Tailscale appliance under qemu.
|
|
mtools
|
|
dtc
|
|
|
|
# awscli2 is used by gokrazy/build.go to import and register the
|
|
# Tailscale appliance AMI.
|
|
awscli2.out
|
|
];
|
|
};
|
|
});
|
|
};
|
|
}
|
|
# nix-direnv cache busting line: sha256-aUbAZpPW0yrNVaDn4NRM4OSw521EIcD5nudXo5pTWpY= |