Commit Graph
13 Commits
Author SHA1 Message Date
John Maguire 8589b76e1f Do not warn about local address failures on every update
localAddrs runs inside every SendUpdate, which fires on lighthouse.interval
and again on every network change via RebindUDPServer. Logging the failure
there meant a persistent failure warned every interval for the life of the
process, once per failing interface.

collectLocalAddrs now returns its failures instead of logging them, which
keeps it stateless and lets the tests assert on errors rather than log
output. The lighthouse holds the previous error and warns only when it
changes, demoting repeats to Debug, matching how handshake_manager handles
repeated send failures.
2026-07-24 17:53:55 -04:00
John Maguire 28cff022ee Link an android binary in build-test-mobile
The package builds only compile, so a linker-only failure could not fail
CI. anet relies on //go:linkname, which the linker rejects on Go 1.23+
without -checklinkname=0, so linking cmd/nebula for android both covers
that regression and records the flag requirement.
2026-07-24 17:53:55 -04:00
John Maguire 8cbee0e965 Advertise underlay addresses on Android
On Android 11+ the app sandbox denies bind() on netlink_route_socket, so
the stdlib's net.Interfaces fails with EACCES. localAddrs discarded that
error and returned an empty slice, so the node advertised no underlay
addresses and peers could only ever reach it at the address a lighthouse
observed. A device on the same LAN as a peer was unreachable at its LAN
address.

Split interface enumeration behind a build-tagged seam and use
github.com/wlynxg/anet on Android, which reads RTM_GETADDR from an
unbound socket. Interface addresses have to come from anet as well, since
net.Interface.Addrs goes back through the same denied path. Every other
platform keeps the net package implementation.

Stop discarding the enumeration errors, which are exceptional now that
the sandbox case is handled.

anet needs -ldflags=-checklinkname=0 on Go 1.23+. Nebula ships no Android
binaries, so build-test-mobile is unaffected, but consumers linking
Android artifacts will need the flag.
2026-07-24 15:06:29 -04:00
John Maguire a3e6edf9c7 Use config.yml consistently (not config.yaml) (#789) 2022-12-19 11:45:15 -06:00
John Maguire ad7222509d Add a link to mobile nebula in the new issue form (#790) 2022-12-19 11:28:49 -06:00
John Maguire ec48298fe8 Update config to show aes cipher instead of chacha (#788) 2022-12-07 11:38:56 -06:00
John Maguire 85f5849d0b Fix a hang when shutting down Android (#772) 2022-11-11 10:18:43 -06:00
John Maguire a0b280621d Remove firewall.conntrack.max_connections from examples (#684) 2022-06-23 10:29:54 -05:00
John Maguire 0577c097fb Fix flaky test (#567) 2021-11-04 14:49:56 -05:00
John Maguire 34d002d695 Check CA cert and key match in nebula-cert sign (#503)
`func (nc *NebulaCertificate) VerifyPrivateKey(key []byte) error` would
previously return an error even if passed the correct private key for a
CA certificate `nc`.

That function has been updated to support CA certificates, and
nebula-cert now calls it before signing a new certificate. Previously,
it would perform all constraint checks against the CA certificate
provided, take a SHA256 fingerprint of the provided certificate, insert
it into the new node certificate, and then finally sign it with the
mismatching private key provided.
2021-10-01 12:43:33 -04:00
John Maguire 98c391396c Remove log when no handshake message is sent (#452) 2021-04-30 18:19:40 -05:00
John Maguire 20bef975cd Remove obsolete systemd unit settings (take 2) (#438) 2021-04-07 12:02:40 -05:00
John Maguire 2bce222550 List possible cipher options in example config (#385) 2021-02-19 21:46:42 -06:00