engine

package
v0.2.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 9, 2026 License: BSD-3-Clause Imports: 47 Imported by: 0

Documentation

Overview

Package engine drives tailscale.com's wgengine and magicsock from a static headwire configuration: no control plane, no LocalBackend. The config is translated once into a DERP map and a network map, per-peer config is served to the engine lazily, and endpoints are advertised to DERP-mode peers with disco call-me-maybe messages so both sides can upgrade from the relay to a direct path.

Index

Constants

View Source
const TUNName = "headwire0"

TUNName is the interface name in TUN mode. Darwin allocates the next utun.

Variables

This section is empty.

Functions

func MTU

func MTU(cfg *config.Config) int

MTU is the interface MTU: the configured one, else the engine's default.

func Routes

func Routes(cfg *config.Config) []netip.Prefix

Routes is what the host must route into the tunnel: each interface subnet and every peer's AllowedIPs. An embedder that owns the interface installs these itself.

Types

type Engine

type Engine struct {
	// contains filtered or unexported fields
}

Engine is a running headwire node.

func Start

func Start(cfg *config.Config, logf logger.Logf, opts Options) (_ *Engine, err error)

Start brings the node up. Close releases it.

func (*Engine) Close

func (e *Engine) Close()

Close tears the node down in reverse dependency order.

func (*Engine) NetworkChanged

func (e *Engine) NetworkChanged()

NetworkChanged tells the engine the host's interfaces changed, for hosts whose sandbox hides the route socket the monitor listens on.

func (*Engine) Ping

func (e *Engine) Ping(ip netip.Addr) (string, error)

Ping sends one disco ping to the peer owning ip and names the path that answered first: a direct ip:port, or relay:<id> when only the DERP region replied.

func (*Engine) Reload

func (e *Engine) Reload(cfg *config.Config) error

Reload applies a changed configuration to the running node: peer additions and updates preserve existing sessions. Source-permission revocations, including peer removal and ownership transfers, require restart, because the pinned engine can apply a stale lazy peer config after a sync. Only [Peer] sections and AllowIn may change. Other [Interface] and [DERPRegion] changes are refused and the old configuration stays live.

func (*Engine) Status

func (e *Engine) Status(field string) (string, error)

Status renders the node for `show`: the human-readable summary when field is empty, otherwise the tab-separated lines of that one field. Every field is reported even where the value is fixed (keepalive) or withheld (keys). Endpoints may name a relay, keys are redacted, listen-port reports the IPv4 socket only, and peer lifetimes are the backend's. The "ip [-1|-4|-6]" and "ping IP" requests share every host's transport.

type Options

type Options struct {
	// Netstack runs an in-process TCP/IP stack instead of a kernel TUN.
	// Netstack needs no privileges, TUN mode needs root.
	Netstack bool
	// TCPHandler serves inbound tunnel TCP flows addressed to the node
	// (netstack only).
	TCPHandler func(net.Conn)
	// Tun is a packet device the caller already owns, for embedders that
	// are handed one by the host: an Apple NetworkExtension provider gets a
	// utun descriptor it cannot ask the engine to create. The engine then
	// installs no OS router, because the host owns the interface address
	// and routes. Close takes the device down.
	Tun tun.Device
}

Options selects how the engine attaches to the network.

type ReloadApplyError

type ReloadApplyError struct{ Err error }

ReloadApplyError means publication has occurred and the engine must be closed. The caller must not continue serving or retry against partially applied state.

func (*ReloadApplyError) Error

func (e *ReloadApplyError) Error() string

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL