2020-02-05 22:16:58 +00:00
|
|
|
// Copyright (c) 2020 Tailscale Inc & AUTHORS All rights reserved.
|
|
|
|
// Use of this source code is governed by a BSD-style
|
|
|
|
// license that can be found in the LICENSE file.
|
|
|
|
|
|
|
|
package ipn
|
|
|
|
|
|
|
|
import (
|
2020-11-02 16:33:34 +00:00
|
|
|
"errors"
|
|
|
|
"fmt"
|
|
|
|
"os"
|
2020-02-17 23:01:23 +00:00
|
|
|
"reflect"
|
2020-02-05 22:16:58 +00:00
|
|
|
"testing"
|
2020-11-02 16:33:34 +00:00
|
|
|
"time"
|
2020-02-05 22:16:58 +00:00
|
|
|
|
2020-02-18 03:33:01 +00:00
|
|
|
"github.com/tailscale/wireguard-go/wgcfg"
|
2020-02-05 22:16:58 +00:00
|
|
|
"tailscale.com/control/controlclient"
|
Add tstest.PanicOnLog(), and fix various problems detected by this.
If a test calls log.Printf, 'go test' horrifyingly rearranges the
output to no longer be in chronological order, which makes debugging
virtually impossible. Let's stop that from happening by making
log.Printf panic if called from any module, no matter how deep, during
tests.
This required us to change the default error handler in at least one
http.Server, as well as plumbing a bunch of logf functions around,
especially in magicsock and wgengine, but also in logtail and backoff.
To add insult to injury, 'go test' also rearranges the output when a
parent test has multiple sub-tests (all the sub-test's t.Logf is always
printed after all the parent tests t.Logf), so we need to screw around
with a special Logf that can point at the "current" t (current_t.Logf)
in some places. Probably our entire way of using subtests is wrong,
since 'go test' would probably like to run them all in parallel if you
called t.Parallel(), but it definitely can't because the're all
manipulating the shared state created by the parent test. They should
probably all be separate toplevel tests instead, with common
setup/teardown logic. But that's a job for another time.
Signed-off-by: Avery Pennarun <apenwarr@tailscale.com>
2020-05-14 02:59:54 +00:00
|
|
|
"tailscale.com/tstest"
|
2020-05-15 02:07:06 +00:00
|
|
|
"tailscale.com/wgengine/router"
|
2020-02-05 22:16:58 +00:00
|
|
|
)
|
|
|
|
|
2020-02-17 23:01:23 +00:00
|
|
|
func fieldsOf(t reflect.Type) (fields []string) {
|
|
|
|
for i := 0; i < t.NumField(); i++ {
|
|
|
|
fields = append(fields, t.Field(i).Name)
|
|
|
|
}
|
|
|
|
return
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestPrefsEqual(t *testing.T) {
|
Add tstest.PanicOnLog(), and fix various problems detected by this.
If a test calls log.Printf, 'go test' horrifyingly rearranges the
output to no longer be in chronological order, which makes debugging
virtually impossible. Let's stop that from happening by making
log.Printf panic if called from any module, no matter how deep, during
tests.
This required us to change the default error handler in at least one
http.Server, as well as plumbing a bunch of logf functions around,
especially in magicsock and wgengine, but also in logtail and backoff.
To add insult to injury, 'go test' also rearranges the output when a
parent test has multiple sub-tests (all the sub-test's t.Logf is always
printed after all the parent tests t.Logf), so we need to screw around
with a special Logf that can point at the "current" t (current_t.Logf)
in some places. Probably our entire way of using subtests is wrong,
since 'go test' would probably like to run them all in parallel if you
called t.Parallel(), but it definitely can't because the're all
manipulating the shared state created by the parent test. They should
probably all be separate toplevel tests instead, with common
setup/teardown logic. But that's a job for another time.
Signed-off-by: Avery Pennarun <apenwarr@tailscale.com>
2020-05-14 02:59:54 +00:00
|
|
|
tstest.PanicOnLog()
|
|
|
|
|
ipn, ipnserver, cmd/tailscale: add "server mode" support on Windows
This partially (but not yet fully) migrates Windows to tailscaled's
StateStore storage system.
This adds a new bool Pref, ForceDaemon, defined as:
// ForceDaemon specifies whether a platform that normally
// operates in "client mode" (that is, requires an active user
// logged in with the GUI app running) should keep running after the
// GUI ends and/or the user logs out.
//
// The only current applicable platform is Windows. This
// forced Windows to go into "server mode" where Tailscale is
// running even with no users logged in. This might also be
// used for macOS in the future. This setting has no effect
// for Linux/etc, which always operate in daemon mode.
Then, when ForceDaemon becomes true, we now write use the StateStore
to track which user started it in server mode, and store their prefs
under that key.
The ipnserver validates the connections/identities and informs that
LocalBackend which userid is currently in charge.
The GUI can then enable/disable server mode at runtime, without using
the CLI.
But the "tailscale up" CLI was also fixed, so Windows users can use
authkeys or ACL tags, etc.
Updates #275
2020-10-12 21:28:21 +00:00
|
|
|
prefsHandles := []string{"ControlURL", "RouteAll", "AllowSingleHosts", "CorpDNS", "WantRunning", "ShieldsUp", "AdvertiseTags", "Hostname", "OSVersion", "DeviceModel", "NotepadURLs", "ForceDaemon", "AdvertiseRoutes", "NoSNAT", "NetfilterMode", "Persist"}
|
2020-02-17 23:01:23 +00:00
|
|
|
if have := fieldsOf(reflect.TypeOf(Prefs{})); !reflect.DeepEqual(have, prefsHandles) {
|
|
|
|
t.Errorf("Prefs.Equal check might be out of sync\nfields: %q\nhandled: %q\n",
|
|
|
|
have, prefsHandles)
|
|
|
|
}
|
|
|
|
|
2020-02-18 03:33:01 +00:00
|
|
|
nets := func(strs ...string) (ns []wgcfg.CIDR) {
|
2020-02-17 23:01:23 +00:00
|
|
|
for _, s := range strs {
|
2020-02-18 03:33:01 +00:00
|
|
|
n, err := wgcfg.ParseCIDR(s)
|
2020-02-17 23:01:23 +00:00
|
|
|
if err != nil {
|
|
|
|
panic(err)
|
|
|
|
}
|
2020-03-17 03:27:00 +00:00
|
|
|
ns = append(ns, n)
|
2020-02-17 23:01:23 +00:00
|
|
|
}
|
|
|
|
return ns
|
|
|
|
}
|
|
|
|
tests := []struct {
|
|
|
|
a, b *Prefs
|
|
|
|
want bool
|
|
|
|
}{
|
|
|
|
{
|
|
|
|
&Prefs{},
|
|
|
|
nil,
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
nil,
|
|
|
|
&Prefs{},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{},
|
|
|
|
&Prefs{},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-02-19 05:03:22 +00:00
|
|
|
{
|
|
|
|
&Prefs{ControlURL: "https://login.tailscale.com"},
|
|
|
|
&Prefs{ControlURL: "https://login.private.co"},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{ControlURL: "https://login.tailscale.com"},
|
|
|
|
&Prefs{ControlURL: "https://login.tailscale.com"},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-02-17 23:01:23 +00:00
|
|
|
{
|
|
|
|
&Prefs{RouteAll: true},
|
|
|
|
&Prefs{RouteAll: false},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{RouteAll: true},
|
|
|
|
&Prefs{RouteAll: true},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
&Prefs{AllowSingleHosts: true},
|
|
|
|
&Prefs{AllowSingleHosts: false},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{AllowSingleHosts: true},
|
|
|
|
&Prefs{AllowSingleHosts: true},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
&Prefs{CorpDNS: true},
|
|
|
|
&Prefs{CorpDNS: false},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{CorpDNS: true},
|
|
|
|
&Prefs{CorpDNS: true},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
&Prefs{WantRunning: true},
|
|
|
|
&Prefs{WantRunning: false},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{WantRunning: true},
|
|
|
|
&Prefs{WantRunning: true},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-05-11 20:16:52 +00:00
|
|
|
{
|
|
|
|
&Prefs{NoSNAT: true},
|
|
|
|
&Prefs{NoSNAT: false},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{NoSNAT: true},
|
|
|
|
&Prefs{NoSNAT: true},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-06-02 16:12:05 +00:00
|
|
|
{
|
|
|
|
&Prefs{Hostname: "android-host01"},
|
|
|
|
&Prefs{Hostname: "android-host02"},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{Hostname: ""},
|
|
|
|
&Prefs{Hostname: ""},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-02-17 23:01:23 +00:00
|
|
|
{
|
|
|
|
&Prefs{NotepadURLs: true},
|
|
|
|
&Prefs{NotepadURLs: false},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{NotepadURLs: true},
|
|
|
|
&Prefs{NotepadURLs: true},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
2020-04-29 06:37:35 +00:00
|
|
|
&Prefs{ShieldsUp: true},
|
|
|
|
&Prefs{ShieldsUp: false},
|
2020-02-17 23:01:23 +00:00
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
2020-04-29 06:37:35 +00:00
|
|
|
&Prefs{ShieldsUp: true},
|
|
|
|
&Prefs{ShieldsUp: true},
|
2020-02-17 23:01:23 +00:00
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
|
|
|
{
|
|
|
|
&Prefs{AdvertiseRoutes: nil},
|
2020-02-18 03:33:01 +00:00
|
|
|
&Prefs{AdvertiseRoutes: []wgcfg.CIDR{}},
|
2020-02-17 23:01:23 +00:00
|
|
|
true,
|
|
|
|
},
|
|
|
|
{
|
2020-02-18 03:33:01 +00:00
|
|
|
&Prefs{AdvertiseRoutes: []wgcfg.CIDR{}},
|
|
|
|
&Prefs{AdvertiseRoutes: []wgcfg.CIDR{}},
|
2020-02-17 23:01:23 +00:00
|
|
|
true,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{AdvertiseRoutes: nets("192.168.0.0/24", "10.1.0.0/16")},
|
|
|
|
&Prefs{AdvertiseRoutes: nets("192.168.1.0/24", "10.2.0.0/16")},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{AdvertiseRoutes: nets("192.168.0.0/24", "10.1.0.0/16")},
|
|
|
|
&Prefs{AdvertiseRoutes: nets("192.168.0.0/24", "10.2.0.0/16")},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{AdvertiseRoutes: nets("192.168.0.0/24", "10.1.0.0/16")},
|
|
|
|
&Prefs{AdvertiseRoutes: nets("192.168.0.0/24", "10.1.0.0/16")},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-05-13 22:35:22 +00:00
|
|
|
{
|
2020-05-15 02:07:06 +00:00
|
|
|
&Prefs{NetfilterMode: router.NetfilterOff},
|
|
|
|
&Prefs{NetfilterMode: router.NetfilterOn},
|
2020-05-13 22:35:22 +00:00
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
2020-05-15 02:07:06 +00:00
|
|
|
&Prefs{NetfilterMode: router.NetfilterOn},
|
|
|
|
&Prefs{NetfilterMode: router.NetfilterOn},
|
2020-05-13 22:35:22 +00:00
|
|
|
true,
|
|
|
|
},
|
|
|
|
|
2020-02-17 23:01:23 +00:00
|
|
|
{
|
|
|
|
&Prefs{Persist: &controlclient.Persist{}},
|
|
|
|
&Prefs{Persist: &controlclient.Persist{LoginName: "dave"}},
|
|
|
|
false,
|
|
|
|
},
|
|
|
|
{
|
|
|
|
&Prefs{Persist: &controlclient.Persist{LoginName: "dave"}},
|
|
|
|
&Prefs{Persist: &controlclient.Persist{LoginName: "dave"}},
|
|
|
|
true,
|
|
|
|
},
|
|
|
|
}
|
|
|
|
for i, tt := range tests {
|
|
|
|
got := tt.a.Equals(tt.b)
|
|
|
|
if got != tt.want {
|
|
|
|
t.Errorf("%d. Equal = %v; want %v", i, got, tt.want)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
2020-02-05 22:16:58 +00:00
|
|
|
func checkPrefs(t *testing.T, p Prefs) {
|
|
|
|
var err error
|
2020-02-20 19:07:00 +00:00
|
|
|
var p2, p2c *Prefs
|
|
|
|
var p2b *Prefs
|
2020-02-05 22:16:58 +00:00
|
|
|
|
|
|
|
pp := p.Pretty()
|
|
|
|
if pp == "" {
|
|
|
|
t.Fatalf("default p.Pretty() failed\n")
|
|
|
|
}
|
|
|
|
t.Logf("\npp: %#v\n", pp)
|
|
|
|
b := p.ToBytes()
|
|
|
|
if len(b) == 0 {
|
|
|
|
t.Fatalf("default p.ToBytes() failed\n")
|
|
|
|
}
|
2020-02-11 07:28:44 +00:00
|
|
|
if !p.Equals(&p) {
|
2020-02-05 22:16:58 +00:00
|
|
|
t.Fatalf("p != p\n")
|
|
|
|
}
|
2020-02-27 20:20:29 +00:00
|
|
|
p2 = p.Clone()
|
2020-02-05 22:16:58 +00:00
|
|
|
p2.RouteAll = true
|
2020-02-20 19:07:00 +00:00
|
|
|
if p.Equals(p2) {
|
2020-02-05 22:16:58 +00:00
|
|
|
t.Fatalf("p == p2\n")
|
|
|
|
}
|
|
|
|
p2b, err = PrefsFromBytes(p2.ToBytes(), false)
|
|
|
|
if err != nil {
|
|
|
|
t.Fatalf("PrefsFromBytes(p2) failed\n")
|
|
|
|
}
|
|
|
|
p2p := p2.Pretty()
|
|
|
|
p2bp := p2b.Pretty()
|
|
|
|
t.Logf("\np2p: %#v\np2bp: %#v\n", p2p, p2bp)
|
|
|
|
if p2p != p2bp {
|
|
|
|
t.Fatalf("p2p != p2bp\n%#v\n%#v\n", p2p, p2bp)
|
|
|
|
}
|
2020-02-20 19:07:00 +00:00
|
|
|
if !p2.Equals(p2b) {
|
2020-02-05 22:16:58 +00:00
|
|
|
t.Fatalf("p2 != p2b\n%#v\n%#v\n", p2, p2b)
|
|
|
|
}
|
2020-02-27 20:20:29 +00:00
|
|
|
p2c = p2.Clone()
|
2020-02-20 19:07:00 +00:00
|
|
|
if !p2b.Equals(p2c) {
|
2020-02-05 22:16:58 +00:00
|
|
|
t.Fatalf("p2b != p2c\n")
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestBasicPrefs(t *testing.T) {
|
Add tstest.PanicOnLog(), and fix various problems detected by this.
If a test calls log.Printf, 'go test' horrifyingly rearranges the
output to no longer be in chronological order, which makes debugging
virtually impossible. Let's stop that from happening by making
log.Printf panic if called from any module, no matter how deep, during
tests.
This required us to change the default error handler in at least one
http.Server, as well as plumbing a bunch of logf functions around,
especially in magicsock and wgengine, but also in logtail and backoff.
To add insult to injury, 'go test' also rearranges the output when a
parent test has multiple sub-tests (all the sub-test's t.Logf is always
printed after all the parent tests t.Logf), so we need to screw around
with a special Logf that can point at the "current" t (current_t.Logf)
in some places. Probably our entire way of using subtests is wrong,
since 'go test' would probably like to run them all in parallel if you
called t.Parallel(), but it definitely can't because the're all
manipulating the shared state created by the parent test. They should
probably all be separate toplevel tests instead, with common
setup/teardown logic. But that's a job for another time.
Signed-off-by: Avery Pennarun <apenwarr@tailscale.com>
2020-05-14 02:59:54 +00:00
|
|
|
tstest.PanicOnLog()
|
|
|
|
|
2020-02-19 05:03:22 +00:00
|
|
|
p := Prefs{
|
|
|
|
ControlURL: "https://login.tailscale.com",
|
|
|
|
}
|
2020-02-05 22:16:58 +00:00
|
|
|
checkPrefs(t, p)
|
|
|
|
}
|
|
|
|
|
|
|
|
func TestPrefsPersist(t *testing.T) {
|
Add tstest.PanicOnLog(), and fix various problems detected by this.
If a test calls log.Printf, 'go test' horrifyingly rearranges the
output to no longer be in chronological order, which makes debugging
virtually impossible. Let's stop that from happening by making
log.Printf panic if called from any module, no matter how deep, during
tests.
This required us to change the default error handler in at least one
http.Server, as well as plumbing a bunch of logf functions around,
especially in magicsock and wgengine, but also in logtail and backoff.
To add insult to injury, 'go test' also rearranges the output when a
parent test has multiple sub-tests (all the sub-test's t.Logf is always
printed after all the parent tests t.Logf), so we need to screw around
with a special Logf that can point at the "current" t (current_t.Logf)
in some places. Probably our entire way of using subtests is wrong,
since 'go test' would probably like to run them all in parallel if you
called t.Parallel(), but it definitely can't because the're all
manipulating the shared state created by the parent test. They should
probably all be separate toplevel tests instead, with common
setup/teardown logic. But that's a job for another time.
Signed-off-by: Avery Pennarun <apenwarr@tailscale.com>
2020-05-14 02:59:54 +00:00
|
|
|
tstest.PanicOnLog()
|
|
|
|
|
2020-02-05 22:16:58 +00:00
|
|
|
c := controlclient.Persist{
|
|
|
|
LoginName: "test@example.com",
|
|
|
|
}
|
|
|
|
p := Prefs{
|
2020-02-19 05:03:22 +00:00
|
|
|
ControlURL: "https://login.tailscale.com",
|
|
|
|
CorpDNS: true,
|
|
|
|
Persist: &c,
|
2020-02-05 22:16:58 +00:00
|
|
|
}
|
|
|
|
checkPrefs(t, p)
|
|
|
|
}
|
ipn, ipnserver, cmd/tailscale: add "server mode" support on Windows
This partially (but not yet fully) migrates Windows to tailscaled's
StateStore storage system.
This adds a new bool Pref, ForceDaemon, defined as:
// ForceDaemon specifies whether a platform that normally
// operates in "client mode" (that is, requires an active user
// logged in with the GUI app running) should keep running after the
// GUI ends and/or the user logs out.
//
// The only current applicable platform is Windows. This
// forced Windows to go into "server mode" where Tailscale is
// running even with no users logged in. This might also be
// used for macOS in the future. This setting has no effect
// for Linux/etc, which always operate in daemon mode.
Then, when ForceDaemon becomes true, we now write use the StateStore
to track which user started it in server mode, and store their prefs
under that key.
The ipnserver validates the connections/identities and informs that
LocalBackend which userid is currently in charge.
The GUI can then enable/disable server mode at runtime, without using
the CLI.
But the "tailscale up" CLI was also fixed, so Windows users can use
authkeys or ACL tags, etc.
Updates #275
2020-10-12 21:28:21 +00:00
|
|
|
|
|
|
|
func TestPrefsPretty(t *testing.T) {
|
|
|
|
tests := []struct {
|
|
|
|
p Prefs
|
|
|
|
os string
|
|
|
|
want string
|
|
|
|
}{
|
|
|
|
{
|
|
|
|
Prefs{},
|
|
|
|
"linux",
|
|
|
|
"Prefs{ra=false mesh=false dns=false want=false routes=[] nf=off Persist=nil}",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Prefs{},
|
|
|
|
"windows",
|
|
|
|
"Prefs{ra=false mesh=false dns=false want=false Persist=nil}",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Prefs{ShieldsUp: true},
|
|
|
|
"windows",
|
|
|
|
"Prefs{ra=false mesh=false dns=false want=false shields=true Persist=nil}",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Prefs{AllowSingleHosts: true},
|
|
|
|
"windows",
|
|
|
|
"Prefs{ra=false dns=false want=false Persist=nil}",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Prefs{
|
|
|
|
NotepadURLs: true,
|
|
|
|
AllowSingleHosts: true,
|
|
|
|
},
|
|
|
|
"windows",
|
|
|
|
"Prefs{ra=false dns=false want=false notepad=true Persist=nil}",
|
|
|
|
},
|
|
|
|
{
|
|
|
|
Prefs{
|
|
|
|
AllowSingleHosts: true,
|
|
|
|
WantRunning: true,
|
|
|
|
ForceDaemon: true, // server mode
|
|
|
|
},
|
|
|
|
"windows",
|
|
|
|
"Prefs{ra=false dns=false want=true server=true Persist=nil}",
|
|
|
|
},
|
|
|
|
}
|
|
|
|
for i, tt := range tests {
|
|
|
|
got := tt.p.pretty(tt.os)
|
|
|
|
if got != tt.want {
|
|
|
|
t.Errorf("%d. wrong String:\n got: %s\nwant: %s\n", i, got, tt.want)
|
|
|
|
}
|
|
|
|
}
|
|
|
|
}
|
2020-11-02 16:33:34 +00:00
|
|
|
|
|
|
|
func TestLoadPrefsNotExist(t *testing.T) {
|
|
|
|
bogusFile := fmt.Sprintf("/tmp/not-exist-%d", time.Now().UnixNano())
|
|
|
|
|
|
|
|
p, err := LoadPrefs(bogusFile)
|
|
|
|
if errors.Is(err, os.ErrNotExist) {
|
|
|
|
// expected.
|
|
|
|
return
|
|
|
|
}
|
|
|
|
t.Fatalf("unexpected prefs=%#v, err=%v", p, err)
|
|
|
|
}
|