Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
326 commits
Select commit Hold shift + click to select a range
32d3a6e
build with go1.23 (#1198)
wadey Mar 6, 2025
750e4a8
Bump the golang-x-dependencies group across 1 directory with 5 update…
dependabot[bot] Mar 6, 2025
9feda81
bump go.mod to go1.23 (#1342)
wadey Mar 6, 2025
8a090e5
Bump github.com/gaissmai/bart from 0.13.0 to 0.18.1 (#1341)
dependabot[bot] Mar 6, 2025
13799f4
Bump the golang-x-dependencies group with 5 updates (#1339)
dependabot[bot] Mar 6, 2025
775c6bc
Bump google.golang.org/protobuf (#1344)
dependabot[bot] Mar 6, 2025
c46ef43
smoke-test-extra: cleanup ncat references (#1343)
wadey Mar 6, 2025
c58e223
Bump github.com/prometheus/client_golang from 1.20.4 to 1.21.1 (#1340)
dependabot[bot] Mar 7, 2025
f8734ff
Improve logging when handshaking with an invalid cert (#1345)
nbrownus Mar 7, 2025
096179a
Bump github.com/miekg/dns from 1.1.62 to 1.1.63 (#1346)
dependabot[bot] Mar 7, 2025
f7540ad
Remove commented out metadata.go (#1320)
jasikpark Mar 7, 2025
94e89a1
smoke-tests: guess the lighthouse container IP better (#1347)
wadey Mar 10, 2025
612637f
Fix `testifylint` lint errors (#1321)
jasikpark Mar 10, 2025
088af8e
Enable running testifylint in CI (#1350)
jasikpark Mar 10, 2025
2fb018c
Fixed homebrew formula path (#1219)
sashazykov Mar 12, 2025
1d3c853
add so_mark sockopt support (#1331)
jampe Mar 12, 2025
50473bd
Update example config to listen on `::` by default (#1351)
jasikpark Mar 13, 2025
3de36c9
build with go1.24 (#1338)
wadey Mar 14, 2025
f86953c
Implement ECMP for unsafe_routes (#1332)
dioss-Machiel Mar 24, 2025
4444ed1
Add `certVersion` field to logs when logging the cert name in handsha…
jasikpark Mar 25, 2025
75faa5f
Bump golang.org/x/net in the golang-x-dependencies group (#1370)
dependabot[bot] Mar 31, 2025
879852c
upgrade to yaml.v3 (#1148)
wadey Mar 31, 2025
36bc9dd
fix parseUnsafeRoutes for yaml.v3 (#1371)
wadey Apr 1, 2025
d2adebf
Bump golangci/golangci-lint-action from 6 to 7 (#1361)
dependabot[bot] Apr 1, 2025
e136d1d
Update example config with default_local_cidr_any changes (#1373)
johnmaguire Apr 1, 2025
58ead41
Bump github.com/gaissmai/bart from 0.18.1 to 0.20.1 (#1369)
dependabot[bot] Apr 1, 2025
e4bae15
Bump google.golang.org/protobuf in the protobuf-dependencies group (#…
dependabot[bot] Apr 1, 2025
d99fd60
Bump Apple-Actions/import-codesign-certs from 3 to 5 (#1364)
dependabot[bot] Apr 1, 2025
e2d6f4e
Bump github.com/miekg/dns from 1.1.63 to 1.1.64 (#1363)
dependabot[bot] Apr 1, 2025
f5d096d
move to golang.org/x/term (#1372)
wadey Apr 2, 2025
e83a1c6
Update config.go (#1353)
odaysec Apr 3, 2025
d4a7df3
Rename pki.default_version to pki.initiating_version (#1381)
johnmaguire Apr 7, 2025
c7fb3ad
Bump the golang-x-dependencies group with 4 updates (#1382)
dependabot[bot] Apr 8, 2025
18279ed
Bump github.com/miekg/dns from 1.1.64 to 1.1.65 (#1384)
dependabot[bot] Apr 8, 2025
459cb38
Bump github.com/gaissmai/bart from 0.20.1 to 0.20.4 (#1391)
dependabot[bot] Apr 16, 2025
e49f279
Bump golang.org/x/net in the golang-x-dependencies group (#1392)
dependabot[bot] Apr 17, 2025
4eb056a
Bump github.com/prometheus/client_golang from 1.21.1 to 1.22.0 (#1393)
dependabot[bot] Apr 17, 2025
b8ea55e
optimize usage of bart (#1395)
wadey Apr 18, 2025
2dc30fc
Support 32-bit machines in crypto test (#1394)
johnmaguire Apr 21, 2025
e5ce896
add netlink options (#1326)
nikitos Apr 21, 2025
15b5a43
Update issue and PR templates (#1376)
johnmaguire Apr 21, 2025
8536c57
Allow configuration of logger and build version in gvisor service lib…
maggie44 Apr 21, 2025
83ff246
Mention CA expiration in the README (#1378)
johnmaguire Apr 28, 2025
92a9248
Minor fixes to Readme shell snippets (#1389)
andygeorge May 2, 2025
061e733
Fix slack invitation link in issue template (#1406)
IanVS May 13, 2025
442a528
Fix off by one error in IPv6 packet parser (#1419)
brad-defined Jun 11, 2025
d34c2b8
Bump golangci/golangci-lint-action from 7 to 8 (#1400)
dependabot[bot] Jul 2, 2025
882edf1
Bump github.com/vishvananda/netlink from 1.3.0 to 1.3.1 (#1407)
dependabot[bot] Jul 2, 2025
e4b7dbc
Bump dario.cat/mergo from 1.0.1 to 1.0.2 (#1408)
dependabot[bot] Jul 2, 2025
b158eb0
Use a list for relay IPs instead of a map (#1423)
brad-defined Jul 2, 2025
94142ad
Fix relay migration panic by covering every possible relay state (#1414)
brad-defined Jul 2, 2025
b3a1f7b
Disable UDP receive error returns due to ICMP messages on Windows. (#…
brad-defined Jul 2, 2025
c242064
Darwin udp fix (#1428)
nbrownus Jul 2, 2025
5262382
Drop inactive tunnels (#1427)
nbrownus Jul 3, 2025
91eff03
Update slack OSS invite link (#1435)
brad-defined Jul 15, 2025
7da7968
fix lighthouse.calculated_remotes parsing (#1438)
wadey Jul 29, 2025
5cff83b
netlink: ignore route updates with no destination (#1437)
wadey Aug 25, 2025
4bea299
don't send recv errors for packets outside the connection window anym…
JackDoan Sep 3, 2025
932e329
Don't delete static host mappings for non-primary IPs (#1464)
JackDoan Sep 4, 2025
768325c
cert-v2 chores (#1466)
JackDoan Sep 5, 2025
73cfa7b
add firewall tests for ipv6 (#1451)
wadey Sep 8, 2025
65cc253
prevent linux from assigning ipv6 link-local addresses (#1476)
JackDoan Sep 9, 2025
8196c22
store lighthouses as a slice (#1473)
JackDoan Sep 10, 2025
5cccd39
update RemoteList.vpnAddrs when we complete a handshake (#1467)
JackDoan Sep 10, 2025
4cdeb28
Set CKA_VALUE_LEN attribute in DeriveNoise (#1482)
HenryGrahamRivian Sep 25, 2025
1ea5f77
update to go 1.25, use the cool new ECDSA key marshalling functions (…
JackDoan Sep 29, 2025
f1e992f
don't require a detailsVpnAddr in a HostUpdateNotification (#1472)
JackDoan Sep 29, 2025
071589f
Bump actions/setup-go from 5 to 6 (#1469)
dependabot[bot] Oct 2, 2025
8824eea
helper functions to more correctly marshal curve 25519 public keys (#…
JackDoan Oct 2, 2025
b1f53d8
Support IPv6 tunneling in FreeBSD (#1399)
sl274 Oct 3, 2025
fb7f0c3
Use x/net/route to manage routes directly (#1488)
nbrownus Oct 3, 2025
eb89839
Support for multi proto tun device on NetBSD (#1492)
nbrownus Oct 8, 2025
634181b
Fix incorrect CIDR construction in hostmap (#1493)
nbdd0121 Oct 8, 2025
45c1d3e
Support for multi proto tun device on OpenBSD (#1495)
nbrownus Oct 8, 2025
b126d88
Bump github.com/gaissmai/bart from 0.20.4 to 0.25.0 (#1471)
dependabot[bot] Oct 13, 2025
2b0aa74
Bump github.com/prometheus/client_golang from 1.22.0 to 1.23.2 (#1470)
dependabot[bot] Oct 13, 2025
ad6d3e6
Bump the golang-x-dependencies group across 1 directory with 5 update…
dependabot[bot] Oct 13, 2025
2710f2a
Bump github.com/kardianos/service from 1.2.2 to 1.2.4 (#1433)
dependabot[bot] Oct 13, 2025
fa8c013
Bump github.com/miekg/dns from 1.1.65 to 1.1.68 (#1444)
dependabot[bot] Oct 13, 2025
7701472
fix make bench (#1510)
JackDoan Oct 21, 2025
01909f4
try to make certificate addition/removal reloadable in some cases (#1…
JackDoan Nov 4, 2025
0f305d5
don't block startup on failure to configure SSH (#1520)
JackDoan Nov 5, 2025
97b3972
honor remote_allow_list in hole punch response (#1186)
wadey Nov 10, 2025
48f1ae9
switch to go.yaml.in/yaml (#1478)
wadey Nov 12, 2025
52f1908
Don't log every blocklisted fingerprint (#1525)
nbrownus Nov 12, 2025
17101d4
Bump golangci/golangci-lint-action from 8 to 9 (#1523)
dependabot[bot] Nov 12, 2025
a941b65
Bump actions/upload-artifact from 4 to 5 (#1515)
dependabot[bot] Nov 12, 2025
b348ee7
Bump actions/download-artifact from 4 to 6 (#1516)
dependabot[bot] Nov 12, 2025
3670e24
Bump actions/checkout from 4 to 5 (#1450)
dependabot[bot] Nov 12, 2025
3d94dfe
Bump the golang-x-dependencies group across 1 directory with 5 update…
dependabot[bot] Nov 12, 2025
6a8a299
Bump google.golang.org/protobuf in the protobuf-dependencies group (#…
dependabot[bot] Nov 12, 2025
a89f951
Firewall types and cross-stack subnet stuff (#1509)
JackDoan Nov 12, 2025
4400124
Bump github.com/gaissmai/bart from 0.25.0 to 0.26.0 (#1508)
dependabot[bot] Nov 13, 2025
36c890e
populate default Build version if missing (#1386)
wadey Nov 14, 2025
4df8bcb
nebula-cert: support reading CA passphrase from env (#1421)
halmartin Nov 17, 2025
27ea667
add more tests around bits counters (#1441)
wadey Nov 18, 2025
584c266
Bump golang.org/x/net in the golang-x-dependencies group (#1530)
dependabot[bot] Nov 19, 2025
99faab5
Fix a potential bug with udp ipv4 only on darwin (#1532)
nbrownus Nov 19, 2025
297767b
warn user if they configure a firewall rule that will allow way more …
JackDoan Nov 19, 2025
7aff313
Relax the restriction on routines from the config (#1531)
nbrownus Nov 19, 2025
a5ee928
Bump golang.org/x/crypto in the golang-x-dependencies group (#1536)
dependabot[bot] Nov 19, 2025
12cf348
feat: support via gateway for v6 multihop for v4 routes (#1521)
6ixfalls Nov 20, 2025
83ae807
No need to clear counter 0 (#1537)
nbrownus Nov 20, 2025
6d7cf61
improve nebula-cert sign version auto-select (#1535)
JackDoan Nov 20, 2025
64f202f
Make 0.0.0.0/0 and ::/0 not mean any address family, add any for that…
nbrownus Nov 21, 2025
56067af
Stab at better logging when a relay is being used (#1533)
nbrownus Dec 3, 2025
59e24b9
v1.10.0 (#1534)
nbrownus Dec 4, 2025
14a1af1
Bump Apple-Actions/import-codesign-certs from 5 to 6 (#1549)
dependabot[bot] Dec 10, 2025
48406f8
Bump the golang-x-dependencies group with 3 updates (#1550)
dependabot[bot] Dec 10, 2025
cba294f
Bump actions/checkout from 5 to 6 (#1541)
dependabot[bot] Dec 10, 2025
2d16940
Slight improvement to hot path benchmark, add a relay hot path benchm…
nbrownus Dec 10, 2025
3ec527e
cert.MarshalSigningPublicKeyToPEM should emit the 'ECDSA' variant of …
JackDoan Dec 10, 2025
2f71d6b
Ensure pubkey coherency when rehydrating a handshake cert (#1566)
brad-defined Jan 9, 2026
69259e6
Quietly log error on UDP_NETRESET ioctl on Windows. (#1453) (#1568)
nbrownus Jan 9, 2026
d7a3f01
Bump the golang-x-dependencies group across 1 directory with 4 update…
dependabot[bot] Jan 12, 2026
9933970
Bump actions/upload-artifact from 5 to 6 (#1558)
dependabot[bot] Jan 12, 2026
1b2d639
Bump actions/download-artifact from 6 to 7 (#1557)
dependabot[bot] Jan 12, 2026
a4a6143
Bump google.golang.org/protobuf in the protobuf-dependencies group (#…
dependabot[bot] Jan 12, 2026
523209e
Bump github.com/miekg/dns from 1.1.68 to 1.1.69 (#1561)
dependabot[bot] Jan 12, 2026
1283ff0
Add option to control accepting recv_error (#1569)
nbrownus Jan 13, 2026
88379b8
Bump golang.org/x/net in the golang-x-dependencies group (#1571)
dependabot[bot] Jan 13, 2026
ac3bd9c
Avoid losing system originated unsafe routes on reload (#1573)
nbrownus Jan 15, 2026
72a4000
v1.10.1 (#1575)
nbrownus Jan 16, 2026
bf49e78
Bump github.com/sirupsen/logrus from 1.9.3 to 1.9.4 (#1581)
dependabot[bot] Jan 20, 2026
e5f60fa
chore: fix some typos in comments (#1582)
zhetaicheleba Jan 20, 2026
e1e92f0
initialize routesFromSystem (#1580)
wadey Jan 20, 2026
0b02d98
v1.10.2 (#1584)
wadey Jan 21, 2026
02d8bca
Remove lighthouse goroutine leaks in lighthouse_test.go (#1589)
jasikpark Jan 28, 2026
42bee7c
Report if Nebula start fails because of tun device name (#1588)
JackDoan Jan 28, 2026
f573e8a
Merge commit from fork
JackDoan Feb 6, 2026
353ad1f
firewall: icmp no longer requires a port spec (#1609)
JackDoan Feb 13, 2026
e8bb874
smoke-extra: try AMD-V workaround (#1610)
wadey Feb 13, 2026
422fc2a
go fix (#1608)
wadey Feb 17, 2026
51308b8
connection-track ICMP traffic (#1602)
JackDoan Feb 19, 2026
7760cce
fix logging copy pasta (#1621)
jrwren Mar 6, 2026
1aa1a04
#ECCN:Open Source in CODEOWNERS (#1632)
jrwren Mar 16, 2026
9f1aef5
Fix dissector logic (#1626)
johnmaguire Mar 23, 2026
91d1f46
properly handle closetunnel packets (#1638)
JackDoan Mar 25, 2026
951d368
Add a small link to DN Managed Nebula (#1641)
johnmaguire Mar 30, 2026
f858795
add sshd.sandbox_dir config option (#1622)
jrwren Apr 3, 2026
6727113
gh workflow release: protect from ref_name attack (#1650)
jrwren Apr 6, 2026
0ad5c77
Refactor CA pool handling to use streaming (#1644)
johnmaguire Apr 13, 2026
3fae693
Additional e2e tests to assert current handshake behavior (#1653)
nbrownus Apr 14, 2026
b319423
udp_linux: wrap socket operations with syscall.RawConn for clean tear…
JackDoan Apr 14, 2026
a5e81ef
Try rsync from somewhere else (#1655)
nbrownus Apr 15, 2026
24c9c70
Bump github.com/miekg/dns from 1.1.70 to 1.1.72 (#1587)
dependabot[bot] Apr 15, 2026
f77fe74
Bump github.com/miekg/pkcs11 (#1586)
dependabot[bot] Apr 15, 2026
36ab1db
Bump the golang-x-dependencies group across 1 directory with 5 update…
dependabot[bot] Apr 15, 2026
72c04b9
Bump golang.zx2c4.com/wireguard/windows in the zx2c4-dependencies gro…
dependabot[bot] Apr 15, 2026
49e3c46
Try the hot new DefinedNet openbsd78 box (#1657)
nbrownus Apr 17, 2026
e80b983
Remove more os.Exit calls and give a more reliable wait for stop func…
JackDoan Apr 20, 2026
3d34cc9
Try to make smoke less flakey (#1663)
nbrownus Apr 20, 2026
8c71f2f
FreeBSD tun needs to be non blocking as well (#1666)
nbrownus Apr 21, 2026
2f4532f
No more dns globals, proper cleanup on shutdown (#1667)
nbrownus Apr 21, 2026
8c50fc3
Plug the conntrack cache ticker leak and nebula-service log.Fatal cal…
nbrownus Apr 21, 2026
32a7c04
Return NODATA instead of NXDOMAIN for missing record types (#1668)
johnmaguire Apr 21, 2026
e753e6e
Immediate Lighthouse update after reconfig/reconnect (#1645)
johnmaguire Apr 21, 2026
2a1cc62
fix: guard QueryCert against panic on short/empty QNAME (#1635)
gnesher Apr 22, 2026
5f00ab4
Fix e2e tests writing after the tester tun is closed causing a panic …
nbrownus Apr 22, 2026
db9218b
Another shot at the flakey smoke test (#1688)
nbrownus Apr 23, 2026
db85d61
SSH handshake in goroutine and defer close (#1640)
brad-defined Apr 23, 2026
5f890db
noise: only type-assert once (#1691)
JackDoan Apr 24, 2026
d0f02ba
Switch to slog, remove logrus (#1672)
nbrownus Apr 27, 2026
1ab1f71
Make stats a server we can reconfigure and start/stop (#1670)
nbrownus Apr 27, 2026
9ec8cf1
Handshake state machine (#1656)
nbrownus May 1, 2026
f141ceb
Run e2e tests in parallel, include a goroutine leak detector test (#1…
nbrownus May 1, 2026
33c2d72
Reduce HandshakeManager complexity a little bit (#1701)
nbrownus May 1, 2026
b7e9939
More stable e2e test harness, better for benchmarking (#1702)
nbrownus May 4, 2026
ff91c37
switch Bits to a packed u64 (#1705)
JackDoan May 6, 2026
4fb5cdb
refactor readOutsidePackets (#1642)
wadey May 6, 2026
213dd46
Stop leaking goroutines past Control.Stop, consolidate punching in Pu…
nbrownus May 6, 2026
a82a8dc
don't panic on bad ed25519 key lengths (#1601)
JackDoan May 6, 2026
eaf756e
Bump Apple-Actions/import-codesign-certs from 6 to 7 (#1697)
dependabot[bot] May 6, 2026
76e82a5
Bump golang.org/x/net (#1664)
dependabot[bot] May 6, 2026
dd2ac5d
Bump docker/login-action from 3 to 4 (#1628)
dependabot[bot] May 6, 2026
dd3a7ad
Bump docker/setup-buildx-action from 3 to 4 (#1627)
dependabot[bot] May 6, 2026
23c67bd
Bump actions/upload-artifact from 6 to 7 (#1618)
dependabot[bot] May 6, 2026
83809a5
Bump actions/download-artifact from 7 to 8 (#1617)
dependabot[bot] May 6, 2026
cba9ea5
Bump github.com/gaissmai/bart from 0.26.0 to 0.26.1 (#1604)
dependabot[bot] May 6, 2026
5f920fd
Remove the global noiseEndianness var (#1707)
nbrownus May 6, 2026
1ada3d4
Use DefinedNets fancy new netbsd10 vagrant box for smokes (#1711)
nbrownus May 7, 2026
c82db21
Change windows unsafe routes to link routes, fix sshd reload bug (#1709)
nbrownus May 7, 2026
696903d
Add a way to set the network type on windows + tests (#1710)
nbrownus May 8, 2026
398d67e
Windows code signing (#1718)
nbrownus May 8, 2026
110ea8f
Bump the golang-x-dependencies group with 4 updates (#1721)
dependabot[bot] May 15, 2026
6c7ebb0
Reset static host list addresses on change (#1713)
nbrownus May 15, 2026
3c121e7
Allow for `-` to stand in for stdin/out (#1714)
nbrownus May 15, 2026
99c5854
Prime some critical stats before the first scrape (#1715)
nbrownus May 15, 2026
625f58b
Record my local details in the dns server if enabled (#1716)
nbrownus May 15, 2026
ffd5249
Search for config.yaml/yml in both service and cli mode (#1717)
nbrownus May 15, 2026
0d23377
Fix flakey cert tests (#1728)
nbrownus May 18, 2026
04dea41
Make firewall reload when unsafe networks in the cert changes (#1719)
nbrownus May 18, 2026
074a123
Reject port numbers outside [0, 65535] in firewall rule parsing (#1724)
randomizedcoder May 18, 2026
0c1ad9b
Parallelize the tests a bit more (#1730)
nbrownus May 19, 2026
72bad16
Bump github.com/gaissmai/bart from 0.26.1 to 0.27.1 (#1732)
dependabot[bot] May 22, 2026
873f94f
Reduce relay log spam (#1733)
nbrownus May 22, 2026
3a95495
Fix duplicate log fields which slog duplicates (#1734)
nbrownus May 22, 2026
b041f30
Bump the golang-x-dependencies group with 3 updates (#1742)
dependabot[bot] Jun 3, 2026
e6032f8
correctly record window counters for relayed packets in a tunnel (#1751)
JackDoan Jun 9, 2026
eaad489
udp_darwin: don't call the EncReader on a UDP error (#1755)
JackDoan Jun 10, 2026
3db406b
fix a race in RelayState.CopyRelayIps (#1753)
JackDoan Jun 10, 2026
e028e6b
disallow negative stats intervals (#1754)
JackDoan Jun 10, 2026
a690c90
improve rejection of malformed handshakes (#1756)
JackDoan Jun 10, 2026
2e9117d
fix tunnels that could permanently escape connection-manager monitori…
JackDoan Jun 10, 2026
36b3839
Bump the golang-x-dependencies group with 4 updates (#1750)
dependabot[bot] Jun 15, 2026
ef95b25
Bump github.com/gaissmai/bart from 0.27.1 to 0.28.0 (#1743)
dependabot[bot] Jun 15, 2026
b7d83b0
Bump golang.org/x/net in the golang-x-dependencies group (#1763)
dependabot[bot] Jun 15, 2026
ab539f8
Add smoke test for ipv6 (#1764)
wadey Jun 16, 2026
16b302c
Relay log fix (#1765)
JackDoan Jun 16, 2026
e4cc80a
add IPv6 reject packet generation (#1766)
wadey Jun 16, 2026
fe1c568
add IPv6 support to CreateICMPEchoResponse (#1767)
wadey Jun 16, 2026
7d3166a
cleanup ipv6 iputil helpers / skip reject for ICMP error packets and …
wadey Jun 16, 2026
184cdc8
Add OCI image labels with version info (#1772)
johnmaguire Jun 23, 2026
58ab725
Bump actions/checkout from 6 to 7 (#1771)
dependabot[bot] Jun 29, 2026
02471b4
wireshark: fix Lua 5.4 bitwise operation (#1776)
zorvios Jul 1, 2026
6afca0f
correctly handle a test packet with a payload longer than the header …
JackDoan Jul 3, 2026
95d98b1
firewall: move conntrack check after cert+IP verification (#1779)
JackDoan Jul 7, 2026
6aa3363
Add explicit unmarshaller for signing and key agreement public keys (…
nbrownus Jul 7, 2026
0a95391
Make HostInfo.remote atomic to fix torn reads on the send path (#1773)
johnmaguire Jul 7, 2026
abfeb50
iputil: fix infinite loop in ipv6FindUpperProtocol from uint8 extensi…
nbrownus Jul 7, 2026
647775d
Bump golang.zx2c4.com/wireguard/windows (#1665)
dependabot[bot] Jul 7, 2026
19ad3bb
correctly discard nil proto addresses (#1785)
JackDoan Jul 7, 2026
32149f3
Bump github.com/kardianos/service from 1.2.4 to 1.3.0 (#1782)
dependabot[bot] Jul 7, 2026
942ee52
lighthouse: unmap 4-in-6 addresses in protoV6AddrPortToNetAddrPort so…
nbrownus Jul 7, 2026
7bd0bc2
sshd: guard trustedKeys/trustedCAs with a mutex to fix a concurrent m…
nbrownus Jul 7, 2026
e5c0fda
Darwin and openbsd in line with the other bsds for tun support (#1703)
nbrownus Jul 7, 2026
1e66c0d
hostmap: unlink a multi-vpnAddr hostinfo from the shared chain exactl…
nbrownus Jul 7, 2026
c1eea11
fix firewall port/proto bypass in parseV6 from uint8 extension-header…
nbrownus Jul 8, 2026
384610f
hostmap: replace the shared next/prev hostinfo chain with independent…
nbrownus Jul 9, 2026
1b84bd0
Remove dev fmt.Println (#1793)
nbrownus Jul 9, 2026
5ecdd4e
Fix e2e test races when looking at hostmap counts (#1795)
nbrownus Jul 9, 2026
ab736e4
Make Control safe to stop and wait on from any lifecycle state (#1794)
nbrownus Jul 10, 2026
8673386
don't make new relay state on a just-discarded tunnel (#1796)
JackDoan Jul 10, 2026
861d3aa
correct directionality of firewall.inbound_action and firewall.outbou…
JackDoan Jul 13, 2026
6c3972f
code-sign: default the S3 key-prefix to the calling repo (#1799)
nbrownus Jul 13, 2026
e290a68
Fix relay re-establishment for handshake on Disestablised entry (#1805)
johnmaguire Jul 17, 2026
147c202
Swap back to a blocking udp socket, test `shutdown(2)` (#1806)
nbrownus Jul 17, 2026
3615a79
add locks around replay window updates (#1802)
JackDoan Jul 20, 2026
a99699e
before removing a pending hostinfo in handshake_manager, make sure it…
JackDoan Jul 21, 2026
58f3b6f
Document rootless Nebula in example service script (#1814)
johnmaguire Jul 21, 2026
a60350e
Bump actions/setup-go from 6 to 7 (#1807)
dependabot[bot] Jul 22, 2026
94ac6db
Bump the golang-x-dependencies group across 1 directory with 5 update…
dependabot[bot] Jul 22, 2026
c2fbe21
Fix a test race, make dns server reload/restart safer (#1815)
nbrownus Jul 22, 2026
7902ce6
Rebind for MacOS (#1816)
nbrownus Jul 23, 2026
15f0f0d
Be less verbose with handshake send errors (#1810)
nbrownus Jul 23, 2026
f8775bb
Use go 1.26 (latest 1.26.5) (#1818)
nbrownus Jul 23, 2026
1617897
v1.11.0 changelog (#1792)
nbrownus Jul 23, 2026
72bf111
Add an e2e Drop exit type and a roaming recovery measurement (#1819)
nbrownus Jul 23, 2026
6d124d0
Tolerate ErrDumpInterrupted when listing tun addresses (#1835)
johnmaguire Jul 31, 2026
19a2397
Merge remote-tracking branch 'slack/master' into master
matt-defined Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
22 changes: 15 additions & 7 deletions .github/ISSUE_TEMPLATE/config.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,21 @@
blank_issues_enabled: true
contact_links:
- name: 💨 Performance Issues
url: https://github.com/slackhq/nebula/discussions/new/choose
about: 'We ask that you create a discussion instead of an issue for performance-related questions. This allows us to have a more open conversation about the issue and helps us to better understand the problem.'

- name: 📄 Documentation Issues
url: https://github.com/definednet/nebula-docs
about: "If you've found an issue with the website documentation, please file it in the nebula-docs repository."

- name: 📱 Mobile Nebula Issues
url: https://github.com/definednet/mobile_nebula
about: "If you're using the mobile Nebula app and have found an issue, please file it in the mobile_nebula repository."

- name: 📘 Documentation
url: https://nebula.defined.net/docs/
about: Review documentation.
about: 'The documentation is the best place to start if you are new to Nebula.'

- name: 💁 Support/Chat
url: https://join.slack.com/t/nebulaoss/shared_invite/enQtOTA5MDI4NDg3MTg4LTkwY2EwNTI4NzQyMzc0M2ZlODBjNWI3NTY1MzhiOThiMmZlZjVkMTI0NGY4YTMyNjUwMWEyNzNkZTJmYzQxOGU
about: 'This issue tracker is not for support questions. Join us on Slack for assistance!'

- name: 📱 Mobile Nebula
url: https://github.com/definednet/mobile_nebula
about: 'This issue tracker is not for mobile support. Try the Mobile Nebula repo instead!'
url: https://join.slack.com/t/nebulaoss/shared_invite/zt-39pk4xopc-CUKlGcb5Z39dQ0cK1v7ehA
about: 'For faster support, join us on Slack for assistance!'
116 changes: 116 additions & 0 deletions .github/actions/code-sign/action.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,116 @@
name: Code-sign Windows binaries
description: >
Sign every .exe under a given path in place via the DefinedNet code-signer
Lambda. If `role` or `bucket` is empty, logs a notice and skips signing so
forks and dev branches without AWS access still produce usable builds.

inputs:
path:
description: "Directory whose .exe files should be signed in place"
required: true
role:
description: "IAM role ARN to assume via OIDC; empty disables signing"
required: false
default: ""
bucket:
description: "S3 staging bucket the code-signer Lambda reads from; empty disables signing"
required: false
default: ""
region:
description: "AWS region for the role and Lambda"
required: false
default: "us-east-2"
function-name:
description: "Code-signer Lambda function name"
required: false
default: "code-signer"
key-prefix:
description: "S3 key prefix to write under; defaults to code-signing/<owner>/<repo> of the calling repo"
required: false
default: ""

runs:
using: composite
steps:
- name: Skip notice
if: inputs.role == '' || inputs.bucket == ''
shell: sh
run: echo "::notice::code-signer role or bucket not set; skipping code signing."

- name: Configure AWS credentials
if: inputs.role != '' && inputs.bucket != ''
uses: aws-actions/configure-aws-credentials@v6
with:
role-to-assume: ${{ inputs.role }}
aws-region: ${{ inputs.region }}
# Default is 12 retries to ride out IAM trust-policy propagation; once
# the role is stable we want a real misconfiguration to fail fast.
retry-max-attempts: 5

- name: Sign .exe files
if: inputs.role != '' && inputs.bucket != ''
shell: sh
env:
SIGN_PATH: ${{ inputs.path }}
BUCKET: ${{ inputs.bucket }}
FUNCTION_NAME: ${{ inputs.function-name }}
KEY_PREFIX: ${{ inputs.key-prefix }}
run: |
set -eu
# Default the prefix to this repo so the S3 key attributes the sign correctly.
# nebula-nightly runs this same action but writes under its own repo's prefix.
KEY_PREFIX="${KEY_PREFIX:-code-signing/$GITHUB_REPOSITORY}"
RUN="${GITHUB_RUN_ID}-${GITHUB_RUN_ATTEMPT}"

find "$SIGN_PATH" -name '*.exe' -print | while read -r path
do
rel=${path#"$SIGN_PATH"/}
file=$(basename "$path")
name=${file%.exe}
prefix="${KEY_PREFIX}/${RUN}"
src="${prefix}/unsigned/${rel}"
dst="${prefix}/signed/${rel}"

echo "::group::Sign ${rel}"
echo "Uploading unsigned to s3://${BUCKET}/${src}"
aws s3 cp --no-progress "$path" "s3://${BUCKET}/${src}" >/dev/null

echo "Invoking ${FUNCTION_NAME} Lambda"
payload=$(jq -nc \
--arg s "$src" \
--arg d "$dst" \
--arg p "$name" \
'{source_key: $s, dest_key: $d, program_name: $p}')
meta=$(aws lambda invoke \
--function-name "$FUNCTION_NAME" \
--cli-binary-format raw-in-base64-out \
--payload "$payload" \
--output json \
/tmp/sign-resp.json)
if echo "$meta" | jq -e '.FunctionError != null' >/dev/null
then
echo "::endgroup::"
echo "::error::code-signer Lambda failed for ${rel}"
cat /tmp/sign-resp.json >&2
exit 1
fi

echo "Downloading signed back to ${path}"
aws s3 cp --no-progress "s3://${BUCKET}/${dst}" "$path" >/dev/null

aws s3 rm "s3://${BUCKET}/${src}" >/dev/null 2>&1 || true
aws s3 rm "s3://${BUCKET}/${dst}" >/dev/null 2>&1 || true

# Sanity-check the bytes we got back actually carry an Authenticode
# signature that this machine can validate end to end.
status=$(powershell -NoProfile -Command "(Get-AuthenticodeSignature -FilePath '$path').Status" | tr -d '\r')
if [ "$status" != "Valid" ]
then
echo "::endgroup::"
echo "::error::${rel} signature status: ${status} (expected Valid)"
exit 1
fi

echo "Signed ${rel} (sha256=$(jq -r '.sha256' /tmp/sign-resp.json), status=${status})"
echo "::endgroup::"
done
11 changes: 11 additions & 0 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
<!--
Thank you for taking the time to submit a pull request!

Please be sure to provide a clear description of what you're trying to achieve with the change.

- If you're submitting a new feature, please explain how to use it and document any new config options in the example config.
- If you're submitting a bugfix, please link the related issue or describe the circumstances surrounding the issue.
- If you're changing a default, explain why you believe the new default is appropriate for most users.

P.S. If you're only updating the README or other docs, please file a pull request here instead: https://github.com/DefinedNet/nebula-docs
-->
34 changes: 0 additions & 34 deletions .github/workflows/gofmt.yml

This file was deleted.

96 changes: 78 additions & 18 deletions .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -10,11 +10,11 @@ jobs:
name: Build Linux/BSD All
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- uses: actions/setup-go@v5
- uses: actions/setup-go@v7
with:
go-version-file: 'go.mod'
go-version: '1.26'
check-latest: true

- name: Build
Expand All @@ -24,20 +24,23 @@ jobs:
mv build/*.tar.gz release

- name: Upload artifacts
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v7
with:
name: linux-latest
path: release

build-windows:
name: Build Windows
runs-on: windows-latest
permissions:
id-token: write
contents: read
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- uses: actions/setup-go@v5
- uses: actions/setup-go@v7
with:
go-version-file: 'go.mod'
go-version: '1.26'
check-latest: true

- name: Build
Expand All @@ -54,8 +57,15 @@ jobs:
mkdir build\dist\windows
mv dist\windows\wintun build\dist\windows\

- name: Code-sign
uses: ./.github/actions/code-sign
with:
path: build
role: ${{ secrets.DEFINED_CODE_SIGNER_ROLE }}
bucket: ${{ secrets.DEFINED_CODE_SIGNER_BUCKET }}

- name: Upload artifacts
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v7
with:
name: windows-latest
path: build
Expand All @@ -64,18 +74,18 @@ jobs:
name: Build Universal Darwin
env:
HAS_SIGNING_CREDS: ${{ secrets.AC_USERNAME != '' }}
runs-on: macos-11
runs-on: macos-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- uses: actions/setup-go@v5
- uses: actions/setup-go@v7
with:
go-version-file: 'go.mod'
go-version: '1.26'
check-latest: true

- name: Import certificates
if: env.HAS_SIGNING_CREDS == 'true'
uses: Apple-Actions/import-codesign-certs@v2
uses: Apple-Actions/import-codesign-certs@v7
with:
p12-file-base64: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_P12_BASE64 }}
p12-password: ${{ secrets.APPLE_DEVELOPER_CERTIFICATE_PASSWORD }}
Expand Down Expand Up @@ -104,20 +114,69 @@ jobs:
fi

- name: Upload artifacts
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v7
with:
name: darwin-latest
path: ./release/*

build-docker:
name: Create and Upload Docker Images
# Technically we only need build-linux to succeed, but if any platforms fail we'll
# want to investigate and restart the build
needs: [build-linux, build-darwin, build-windows]
runs-on: ubuntu-latest
env:
HAS_DOCKER_CREDS: ${{ vars.DOCKERHUB_USERNAME != '' && secrets.DOCKERHUB_TOKEN != '' }}
# XXX It's not possible to write a conditional here, so instead we do it on every step
#if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
steps:
# Be sure to checkout the code before downloading artifacts, or they will
# be overwritten
- name: Checkout code
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
uses: actions/checkout@v7

- name: Download artifacts
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
uses: actions/download-artifact@v8
with:
name: linux-latest
path: artifacts

- name: Login to Docker Hub
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
uses: docker/login-action@v4
with:
username: ${{ vars.DOCKERHUB_USERNAME }}
password: ${{ secrets.DOCKERHUB_TOKEN }}

- name: Set up Docker Buildx
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
uses: docker/setup-buildx-action@v4

- name: Build and push images
if: ${{ env.HAS_DOCKER_CREDS == 'true' }}
env:
DOCKER_IMAGE_REPO: ${{ vars.DOCKER_IMAGE_REPO || 'nebulaoss/nebula' }}
DOCKER_IMAGE_TAG: ${{ vars.DOCKER_IMAGE_TAG || 'latest' }}
run: |
mkdir -p build/linux-{amd64,arm64}
tar -zxvf artifacts/nebula-linux-amd64.tar.gz -C build/linux-amd64/
tar -zxvf artifacts/nebula-linux-arm64.tar.gz -C build/linux-arm64/
docker buildx build . --push -f docker/Dockerfile --platform linux/amd64,linux/arm64 \
--build-arg VERSION="${GITHUB_REF#refs/tags/v}" \
--build-arg REVISION="${GITHUB_SHA}" \
--tag "${DOCKER_IMAGE_REPO}:${DOCKER_IMAGE_TAG}" --tag "${DOCKER_IMAGE_REPO}:${GITHUB_REF#refs/tags/v}"

release:
name: Create and Upload Release
needs: [build-linux, build-darwin, build-windows]
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: actions/checkout@v7

- name: Download artifacts
uses: actions/download-artifact@v3
uses: actions/download-artifact@v8
with:
path: artifacts

Expand Down Expand Up @@ -163,10 +222,11 @@ jobs:
id: create_release
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REF_NAME: ${{ github.ref_name }}
run: |
cd artifacts
gh release create \
--verify-tag \
--title "Release ${{ github.ref_name }}" \
"${{ github.ref_name }}" \
--title "Release ${GITHUB_REF_NAME}" \
"${GITHUB_REF_NAME}" \
SHASUM256.txt *-latest/*.zip *-latest/*.tar.gz
Loading