v0.1.0
Pre-release
Pre-release
What's Changed
- docs: say which sibling repos exist, and how to land a change by @aswinsam in #3
- feat(store): PostgreSQL access, self-applying schema, honest readiness by @aswinsam in #4
- feat(enroll): device identity, one-time tokens, proof of possession by @aswinsam in #5
- feat(api): enrolment over HTTP, and
meshp joinby @aswinsam in #6 - feat(session): the device control channel by @aswinsam in #7
- feat(agentapi): a local socket, and join behind the daemon by @aswinsam in #8
- feat(session): state deltas, a push that happens, and a bounded change log by @aswinsam in #9
- ci: build the container image, and prove it starts by @aswinsam in #10
- deps: Bump alpine from 3.21 to 3.24 in /deploy/docker by @dependabot[bot] in #1
- feat(wgplan): decide what a WireGuard interface should look like by @aswinsam in #11
- feat(wglink): create real WireGuard interfaces, and move a packet by @aswinsam in #12
- feat(meshpd): the daemon brings up a real tunnel, and keeps it up by @aswinsam in #13
- fix(wgplan): a peer's endpoint is evidence, not drift by @aswinsam in #14
- feat(meshpd): remember the port an interface settled on by @aswinsam in #15
- docs: decide how relayed traffic reaches a relay (ADR-0016) by @aswinsam in #16
- feat(relayproto): the framing a relay forwards by by @aswinsam in #17
- feat(relay): the forwarding core, and what it refuses to do by @aswinsam in #18
- feat(relaytoken): the capability a relay checks, which it cannot mint by @aswinsam in #19
- feat(meshp-relay): a relay that listens, and does so on several ports by @aswinsam in #20
- fix(relay): report an IPv4 peer as IPv4 by @aswinsam in #21
- feat(relayclient): the agent's side of the relay protocol by @aswinsam in #22
- feat(session): agents ask for relay credentials (ADR-0017) by @aswinsam in #23
- feat(wgplan): a relayed peer, and why it cannot be inferred by @aswinsam in #24
- feat(relayforward): carry packets between the kernel and a relay by @aswinsam in #25
- feat(session): tell agents which relay to use, and lower the MTU for it by @aswinsam in #26
- feat(relay): carry a peer's traffic through a relay, end to end by @aswinsam in #27
- feat(revoke): take a device out of a network, and mean it by @aswinsam in #28
- feat(acl): the policy language, and compiling it to a device's filter by @aswinsam in #29
- feat(acl): store a policy, and deliver the filter it compiles to by @aswinsam in #30
- feat(acl): enforce policy with nftables by @aswinsam in #31
- feat(tls): serve the control plane over TLS, and refuse plaintext to anywhere else by @aswinsam in #32
- feat(routes): route groups, their advertisers, and networks without psql by @aswinsam in #33
- feat(routes): select advertisers and tell devices who carries a prefix by @aswinsam in #34
- feat(routes): carry an assigned prefix on the peer that advertises it by @aswinsam in #35
- feat(routes): tell an advertiser what it carries by @aswinsam in #36
- feat(routes): forward into a carried prefix, and rewrite the source by @aswinsam in #37
- test(routes): prove a packet crosses into a carried LAN by @aswinsam in #38
- feat(routes): let client reports drive advertiser health by @aswinsam in #39
- feat(routes): decide when to leave an advertiser and when to come back by @aswinsam in #40
- feat(routes): fail over from an advertiser that has gone silent by @aswinsam in #41
- feat(routes): tell the control plane what this device observed by @aswinsam in #42
- test(e2e): stand up a route group against a real kernel by @aswinsam in #43
- test(e2e): two live agents, one per network namespace by @aswinsam in #44
- chore: add NOTICE and canonicalise authorship by @aswinsam in #45
- chore: move to Go 1.26.6, from one file by @aswinsam in #46
- fix(health): a client's verdict is authoritative on arrival by @aswinsam in #47
- test(e2e): a client fails over from a dead gateway on its own by @aswinsam in #48
- docs(adr-0009): the commercial layer is operated, never distributed by @aswinsam in #49
- docs(adr-0018): a mechanism is not done until something running reaches it by @aswinsam in #50
- feat(egress): the fail-closed kill switch, before anything claims a route by @aswinsam in #51
- feat(egress): reclaim a lock left behind by a dead agent by @aswinsam in #52
- feat(egress): work out what must never go through the tunnel by @aswinsam in #53
- docs(adr-0019): egress is routing, overlapping prefixes are addressing by @aswinsam in #54
- feat(egress): route a full tunnel without capturing its own packets by @aswinsam in #55
- feat(egress): claim the default route, behind the lock by @aswinsam in #56
- feat(egress): fail closed unless somebody says otherwise by @aswinsam in #57
- test(egress): kill the agent and prove the traffic stays blocked by @aswinsam in #58
- feat(egress): refuse plaintext DNS outside the tunnel by @aswinsam in #59
- feat(cli): meshp doctor explains a machine that is refusing traffic by @aswinsam in #60
- feat(release): an install path that is not "build it yourself" by @aswinsam in #61
- docs: stop pointing at a deployment guide that does not exist by @aswinsam in #69
- feat(routes): refuse a prefix two customer networks both claim by @aswinsam in #70
- feat(api): somewhere for an administrator to opt out of fail-closed by @aswinsam in #71
- feat(routes): the failover policy an administrator writes now reaches the agent by @aswinsam in #72
- feat(routes): probe through the advertiser, not just its handshake by @aswinsam in #73
- docs: guides for self-hosters, and the bugs that writing them found by @aswinsam in #74
- docs: ADR-0021, names resolve on the device, from desired state by @aswinsam in #79
- docs: ADR-0020 allocates mapped ranges server-side, and both ADRs are accepted by @aswinsam in #80
- feat(dns): a device resolves its networks' names, from state it already holds by @aswinsam in #81
- feat(dns): a device gets a name that is unique in the network it answers from by @aswinsam in #82
- fix(dns): the resolver binds before the daemon carries on by @aswinsam in #83
- feat(dns): point this machine's resolver at meshp for the names meshp owns by @aswinsam in #84
- fix(dns): a port free in one protocol is not free in the other by @aswinsam in #85
- chore: ignore what an assistant derives from this repository by @aswinsam in #86
- test(dns): a name resolves on the machine holding it by @aswinsam in #87
- feat(nftables): two customers on the same prefix, told apart by @aswinsam in #88
- fix(forwarding): an advertiser that carries nothing stops looking healthy by @aswinsam in #90
- feat(prefixmap): the control plane can choose where a colliding prefix is reached by @aswinsam in #91
- feat(routes): a colliding prefix reaches the device with somewhere to reach it by @aswinsam in #92
- feat(tunnel): a technician reaches both customers on 192.168.1.0/24 by @aswinsam in #93
- test(e2e): a lock that does not block is not a lock that went away by @aswinsam in #94
- fix(nftables): each membership translates in a table of its own by @aswinsam in #95
- ci: Bump actions/upload-artifact from 4.6.2 to 7.0.1 by @dependabot[bot] in #99
- ci: Bump actions/download-artifact from 4.3.0 to 8.0.1 by @aswinsam in #102
- ci: one pull request for CodeQL, and majors on their own by @aswinsam in #101
- ci: Bump the codeql group with 3 updates by @dependabot[bot] in #103
- fix(state): a collision created in one network reaches the other by @aswinsam in #104
- fix(forwarding): carry a prefix past a firewall meshp does not own by @aswinsam in #105
- docs: a security policy the README can point at by @aswinsam in #106
- docs: add top-level CONTRIBUTING.md by @Abhishek4512009 in #75
- docs: point contributors at the toolchain file, not the language version by @aswinsam in #107
- docs(adr): decide the topology view before building it by @aswinsam in #109
- docs: the status section describes the project as it is by @aswinsam in #110
New Contributors
- @aswinsam made their first contribution in #3
- @dependabot[bot] made their first contribution in #1
- @Abhishek4512009 made their first contribution in #75
Full Changelog: https://github.com/meshpnet/meshp/commits/v0.1.0