Skip to content

v0.1.0

Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 20 Aug 08:33
· 87 commits to main since this release
06ac3b2

What's Changed

  • docs: say which sibling repos exist, and how to land a change by @aswinsam in #3
  • feat(store): PostgreSQL access, self-applying schema, honest readiness by @aswinsam in #4
  • feat(enroll): device identity, one-time tokens, proof of possession by @aswinsam in #5
  • feat(api): enrolment over HTTP, and meshp join by @aswinsam in #6
  • feat(session): the device control channel by @aswinsam in #7
  • feat(agentapi): a local socket, and join behind the daemon by @aswinsam in #8
  • feat(session): state deltas, a push that happens, and a bounded change log by @aswinsam in #9
  • ci: build the container image, and prove it starts by @aswinsam in #10
  • deps: Bump alpine from 3.21 to 3.24 in /deploy/docker by @dependabot[bot] in #1
  • feat(wgplan): decide what a WireGuard interface should look like by @aswinsam in #11
  • feat(wglink): create real WireGuard interfaces, and move a packet by @aswinsam in #12
  • feat(meshpd): the daemon brings up a real tunnel, and keeps it up by @aswinsam in #13
  • fix(wgplan): a peer's endpoint is evidence, not drift by @aswinsam in #14
  • feat(meshpd): remember the port an interface settled on by @aswinsam in #15
  • docs: decide how relayed traffic reaches a relay (ADR-0016) by @aswinsam in #16
  • feat(relayproto): the framing a relay forwards by by @aswinsam in #17
  • feat(relay): the forwarding core, and what it refuses to do by @aswinsam in #18
  • feat(relaytoken): the capability a relay checks, which it cannot mint by @aswinsam in #19
  • feat(meshp-relay): a relay that listens, and does so on several ports by @aswinsam in #20
  • fix(relay): report an IPv4 peer as IPv4 by @aswinsam in #21
  • feat(relayclient): the agent's side of the relay protocol by @aswinsam in #22
  • feat(session): agents ask for relay credentials (ADR-0017) by @aswinsam in #23
  • feat(wgplan): a relayed peer, and why it cannot be inferred by @aswinsam in #24
  • feat(relayforward): carry packets between the kernel and a relay by @aswinsam in #25
  • feat(session): tell agents which relay to use, and lower the MTU for it by @aswinsam in #26
  • feat(relay): carry a peer's traffic through a relay, end to end by @aswinsam in #27
  • feat(revoke): take a device out of a network, and mean it by @aswinsam in #28
  • feat(acl): the policy language, and compiling it to a device's filter by @aswinsam in #29
  • feat(acl): store a policy, and deliver the filter it compiles to by @aswinsam in #30
  • feat(acl): enforce policy with nftables by @aswinsam in #31
  • feat(tls): serve the control plane over TLS, and refuse plaintext to anywhere else by @aswinsam in #32
  • feat(routes): route groups, their advertisers, and networks without psql by @aswinsam in #33
  • feat(routes): select advertisers and tell devices who carries a prefix by @aswinsam in #34
  • feat(routes): carry an assigned prefix on the peer that advertises it by @aswinsam in #35
  • feat(routes): tell an advertiser what it carries by @aswinsam in #36
  • feat(routes): forward into a carried prefix, and rewrite the source by @aswinsam in #37
  • test(routes): prove a packet crosses into a carried LAN by @aswinsam in #38
  • feat(routes): let client reports drive advertiser health by @aswinsam in #39
  • feat(routes): decide when to leave an advertiser and when to come back by @aswinsam in #40
  • feat(routes): fail over from an advertiser that has gone silent by @aswinsam in #41
  • feat(routes): tell the control plane what this device observed by @aswinsam in #42
  • test(e2e): stand up a route group against a real kernel by @aswinsam in #43
  • test(e2e): two live agents, one per network namespace by @aswinsam in #44
  • chore: add NOTICE and canonicalise authorship by @aswinsam in #45
  • chore: move to Go 1.26.6, from one file by @aswinsam in #46
  • fix(health): a client's verdict is authoritative on arrival by @aswinsam in #47
  • test(e2e): a client fails over from a dead gateway on its own by @aswinsam in #48
  • docs(adr-0009): the commercial layer is operated, never distributed by @aswinsam in #49
  • docs(adr-0018): a mechanism is not done until something running reaches it by @aswinsam in #50
  • feat(egress): the fail-closed kill switch, before anything claims a route by @aswinsam in #51
  • feat(egress): reclaim a lock left behind by a dead agent by @aswinsam in #52
  • feat(egress): work out what must never go through the tunnel by @aswinsam in #53
  • docs(adr-0019): egress is routing, overlapping prefixes are addressing by @aswinsam in #54
  • feat(egress): route a full tunnel without capturing its own packets by @aswinsam in #55
  • feat(egress): claim the default route, behind the lock by @aswinsam in #56
  • feat(egress): fail closed unless somebody says otherwise by @aswinsam in #57
  • test(egress): kill the agent and prove the traffic stays blocked by @aswinsam in #58
  • feat(egress): refuse plaintext DNS outside the tunnel by @aswinsam in #59
  • feat(cli): meshp doctor explains a machine that is refusing traffic by @aswinsam in #60
  • feat(release): an install path that is not "build it yourself" by @aswinsam in #61
  • docs: stop pointing at a deployment guide that does not exist by @aswinsam in #69
  • feat(routes): refuse a prefix two customer networks both claim by @aswinsam in #70
  • feat(api): somewhere for an administrator to opt out of fail-closed by @aswinsam in #71
  • feat(routes): the failover policy an administrator writes now reaches the agent by @aswinsam in #72
  • feat(routes): probe through the advertiser, not just its handshake by @aswinsam in #73
  • docs: guides for self-hosters, and the bugs that writing them found by @aswinsam in #74
  • docs: ADR-0021, names resolve on the device, from desired state by @aswinsam in #79
  • docs: ADR-0020 allocates mapped ranges server-side, and both ADRs are accepted by @aswinsam in #80
  • feat(dns): a device resolves its networks' names, from state it already holds by @aswinsam in #81
  • feat(dns): a device gets a name that is unique in the network it answers from by @aswinsam in #82
  • fix(dns): the resolver binds before the daemon carries on by @aswinsam in #83
  • feat(dns): point this machine's resolver at meshp for the names meshp owns by @aswinsam in #84
  • fix(dns): a port free in one protocol is not free in the other by @aswinsam in #85
  • chore: ignore what an assistant derives from this repository by @aswinsam in #86
  • test(dns): a name resolves on the machine holding it by @aswinsam in #87
  • feat(nftables): two customers on the same prefix, told apart by @aswinsam in #88
  • fix(forwarding): an advertiser that carries nothing stops looking healthy by @aswinsam in #90
  • feat(prefixmap): the control plane can choose where a colliding prefix is reached by @aswinsam in #91
  • feat(routes): a colliding prefix reaches the device with somewhere to reach it by @aswinsam in #92
  • feat(tunnel): a technician reaches both customers on 192.168.1.0/24 by @aswinsam in #93
  • test(e2e): a lock that does not block is not a lock that went away by @aswinsam in #94
  • fix(nftables): each membership translates in a table of its own by @aswinsam in #95
  • ci: Bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #99
  • ci: Bump actions/download-artifact from 4.3.0 to 8.0.1 by @aswinsam in #102
  • ci: one pull request for CodeQL, and majors on their own by @aswinsam in #101
  • ci: Bump the codeql group with 3 updates by @dependabot[bot] in #103
  • fix(state): a collision created in one network reaches the other by @aswinsam in #104
  • fix(forwarding): carry a prefix past a firewall meshp does not own by @aswinsam in #105
  • docs: a security policy the README can point at by @aswinsam in #106
  • docs: add top-level CONTRIBUTING.md by @Abhishek4512009 in #75
  • docs: point contributors at the toolchain file, not the language version by @aswinsam in #107
  • docs(adr): decide the topology view before building it by @aswinsam in #109
  • docs: the status section describes the project as it is by @aswinsam in #110

New Contributors

Full Changelog: https://github.com/meshpnet/meshp/commits/v0.1.0