Skip to content

Releases: slackhq/nebula

Release v1.11.1

Choose a tag to compare

@github-actions github-actions released this 21 Aug 19:34
v1.11.1
992e36b

See the v1.11.1 milestone for a complete list of changes.

Changed

  • IPv6 packets whose next header is a protocol Nebula does not parse (SCTP, GRE, IP-in-IP, etc.) are now
    classified as that protocol with no ports, closing a firewall bypass where a crafted payload could steer
    the classifier into reading one as TCP/UDP and matching a TCP/UDP rule. These packets are now matched as
    their true protocol, so only a proto: any rule allows them. If you carry one of these protocols over the
    overlay, confirm a proto: any rule covers it before upgrading, it may have been passing only through this
    bypass. (#1840)
  • Drop the dependency on github.com/cyberdelia/go-metrics-graphite, which has been unmaintained for over ten
    years, by inlining the small amount of code Nebula used. (#1832)

Fixed

  • The ICMPv6 type was read from the wrong byte when classifying IPv6 packets, so the echo identifier used
    for conntrack was never picked up. (#1840)
  • Enforce outbound message counter limits so a tunnel is rehandshaked before the counter can wrap, preventing
    nonce reuse. This is unreachable in practice, but is enforced as a defense-in-depth measure. (#1841)
  • Prevent nebula-cert ca from running out of memory on 32bit systems when generating encrypted private keys. (#1834)
  • Tolerate ErrDumpInterrupted when listing tun addresses on Linux, so a transient interrupted netlink dump
    no longer aborts startup. (#1835)

Release v1.11.0

Choose a tag to compare

@github-actions github-actions released this 23 Jul 18:24
v1.11.0
1617897

See the v1.11.0 milestone for a complete list of changes.

Breaking

  • Logging has switched from logrus to Go's structured slog. Log output changes: levels are upper case
    (level=INFO), trace prints as level=DEBUG-4, timestamps are always RFC3339Nano and logging.timestamp_format
    is ignored, and some messages were reworded. Review any log parsing before upgrading. This is also an API break
    for embedders, as constructors now take a *slog.Logger. (#1672, #1734, #1621)
  • firewall.inbound_action and firewall.outbound_action (used to set reject vs. drop policy) were each being
    applied to the opposite direction, that is now corrected. This only affects how blocked packets are answered, not
    which packets the firewall allows or denies. If you set either of these you are getting the behavior of the other
    one today and likely want to swap them before upgrading. (#1798)
  • On Windows, Nebula now installs WFP PERMIT filters for the nebula adapter and the listener port by default. WFP
    sits below Windows Defender Firewall, so any WDF inbound rules you rely on for either will no longer apply. Set
    tun.windows_bypass_wdf and listen.windows_bypass_wdf to false to leave WDF in charge. (#1710)
  • On Windows, the nebula device is now set to the private network category instead of whatever Windows decided,
    which is usually Public. This makes the host firewall less restrictive on the overlay. Set
    tun.network_category to unset to keep the old behavior. (#1710)
  • Reject packets for non-TCP now use ICMP code 13, communication administratively prohibited, instead of code 3,
    port unreachable. Anything keying off the old code needs updating. (#1766, #1768)
  • The SSH debug server's profiling commands are now confined to sshd.sandbox_dir, which defaults to
    $TMP/nebula-debug. Relative paths resolve inside it and absolute paths outside it are rejected, so anything
    scripting start-cpu-profile, save-heap-profile, or save-mutex-profile with a path elsewhere needs the
    directory set. The directory is not created for you. (#1622)

Added

  • Sign the Windows release binaries. (#1718)
  • Generate IPv6 reject packets, matching the existing IPv4 behavior. (#1766, #1767, #1768)
  • Accept - in nebula-cert to read from stdin or write to stdout. (#1714)
  • Search for both config.yml and config.yaml in service and command line modes. (#1717)
  • Add version labels to the Docker/OCI images. (#1772)
  • Rebind the listener and re-query lighthouses on macOS when the underlay network changes, so devices moving
    between wifi and wired or between networks recover without waiting for dead tunnel detection. Controlled by
    listen.rebind_on_network_change (default true, not reloadable). (#1816)

Changed

  • Reload the firewall when the unsafe networks in the certificate change. (#1719)
  • Reconfigure, start, and stop the stats listener on a config reload instead of requiring a restart. (#1670)
  • Update a static host's addresses when they change on reload. (#1713)
  • Don't require a port on ICMP firewall rules. (#1609)
  • Connection track ICMP traffic. (#1602)
  • Return NODATA instead of NXDOMAIN from the DNS server for a name that exists but has no record of the
    requested type, so clients that query AAAA first (busybox/Alpine) fall through to A. (#1668)
  • Record the local host's details in the DNS server. (#1716)
  • Install Windows unsafe routes as link routes. (#1709)
  • Reduce relay handshake log spam, and only log a handshake send error at error level when the remote list
    changes. (#1733, #1765, #1810)
  • Start, stop, and reload subsystems (DNS, stats, conntrack, ssh, punchy) cleanly without leaking goroutines. (#1640, #1654, #1661, #1667, #1669, #1708, #1806, #1815)
  • Control is now safe to stop and wait on from any lifecycle state, and a new Control.Wait blocks until nebula
    has fully stopped and returns the first fatal reader error. Failed starts release the udp sockets and tun fd
    instead of leaking them. (#1794)
  • Trigger an immediate lighthouse update when reconnecting to or adding a lighthouse instead of waiting for the next update tick. (#1645)
  • Bring the Darwin and OpenBSD tun implementations in line with the other BSDs. (#1703)
  • Update to build against go v1.26. (#1818)
  • Various dependency updates. (#1586, #1587, #1604, #1617, #1618, #1627, #1628, #1629, #1652, #1664, #1665, #1697, #1721, #1732, #1742, #1743, #1750, #1763, #1771, #1782, #1800, #1807)

Fixed

  • Fix a data race on a host's remote address that could send packets to the wrong address during a roam. (#1773)
  • Fix tunnels that could permanently escape connection manager monitoring. (#1752)
  • Fix a crash when reloading the SSH server's trusted keys. (#1787)
  • Fix hostmap corruption when a host has multiple overlay addresses. Each address now gets its own list instead of
    a single shared chain, which also fixes two latent bugs on the add and makePrimary paths. (#1788, #1790)
  • Apply remote_allow_list IPv4 rules to 4-in-6 mapped addresses. (#1786)
  • Don't panic in the DNS server on a short or empty query name. (#1635)
  • Advance the replay window on relayed packets so a relay drops replayed frames instead of re-forwarding them. (#1751)
  • Fix a race in relay state handling. (#1753)
  • Lock replay window updates so concurrent readers can't corrupt it. (#1802)
  • Reject malformed handshakes more reliably, including invalid ed25519 key lengths. (#1601, #1756)
  • Properly handle closetunnel packets. (#1638)
  • Fix an IPv6 extension-header length overflow that could make the firewall parse the wrong protocol and ports. (#1789)
  • Fix relay re-establishment when a handshake arrives over a relay entry that a one-sided teardown left
    Disestablished, which silently dropped every send until dead tunnel detection forced a re-handshake. (#1805)
  • Don't build new relay state on a tunnel that was just discarded. (#1796)
  • Don't delete the wrong pending hostinfo in the handshake manager. (#1811)
  • Don't call the packet reader after a UDP error on Darwin. (#1755)
  • Open the FreeBSD tun device non blocking. (#1666)

Release v1.10.3

Choose a tag to compare

@github-actions github-actions released this 06 Feb 19:38
v1.10.3
f573e8a

Security

  • Fix an issue where blocklist bypass is possible when using curve P256 since the signature can have 2 valid representations.
    Both fingerprint representations will be tested against the blocklist.
    Any newly issued P256 based certificates will have their signature clamped to the low-s form.
    Nebula will assert the low-s signature form when validating certificates in a future version. GHSA-69x3-g4r3-p962

Changed

  • Improve error reporting if nebula fails to start due to a tun device naming issue. (#1588)

Release v1.10.2

Choose a tag to compare

@github-actions github-actions released this 21 Jan 17:52
v1.10.2
0b02d98

Fixed

  • Fix panic when using use_system_route_table that was introduced in v1.10.1. (#1580)

Changed

  • Fix some typos in comments. (#1582)
  • Dependency updates. (#1581)

Release v1.10.1

Choose a tag to compare

@github-actions github-actions released this 16 Jan 15:44
v1.10.1
72a4000

See the v1.10.1 milestone for a complete list of changes.

Fixed

  • Fix a bug where an unsafe route derived from the system route table could be lost on a config reload. (#1573)
  • Fix the PEM banner for ECDSA P256 public keys. (#1552)
  • Fix a regression on Windows from 1.9.x where nebula could fall back to a less performant UDP listener if
    non-critical ioctls failed. (#1568)
  • Fix a bug in handshake processing when a peer sends an unexpected public key. (#1566)

Added

  • Add a config option to control accepting recv_error packets which defaults to always. (#1569)

Changed

Release v1.10.0

Choose a tag to compare

@github-actions github-actions released this 04 Dec 19:53
v1.10.0
59e24b9

See the v1.10.0 milestone for a complete list of changes.

NOTE: If you use unsafe_routes, please read the note in the Changed section about default_local_cidr_any. You may need to update your firewall rules in order to maintain connectivity.

Added

Changed

  • NOTE: default_local_cidr_any now defaults to false, meaning that any firewall rule
    intended to target an unsafe_routes entry must explicitly declare it via the
    local_cidr field. This is almost always the intended behavior. This flag is
    deprecated and will be removed in a future release. (#1373)
  • Improve logging when a relay is in use on an inbound packet. (#1533)
  • Avoid fatal errors if rountines is > 1 on systems that don't support more than 1 routine. (#1531)
  • Log a warning if a firewall rule contains an any that negates a more restrictive filter. (#1513)
  • Accept encrypted CA passphrase from an environment variable. (#1421)
  • Allow handshaking with any trusted remote. (#1509)
  • Log only the count of blocklisted certificate fingerprints instead of the entire list. (#1525)
  • Don't fatal when the ssh server is unable to be configured successfully. (#1520)
  • Update to build against go v1.25. (#1483)
  • Allow projects using nebula as a library with userspace networking to configure the logger and build version. (#1239)
  • Upgrade to yaml.v3. (#1148, #1371, #1438, #1478)

Fixed

  • Fix a potential bug with udp ipv4 only on darwin. (#1532)
  • Improve lost packet statistics. (#1441, #1537)
  • Honor remote_allow_list in hole punch response. (#1186)
  • Fix a panic when tun.use_system_route_table is true and a route lacks a destination. (#1437)
  • Fix an issue when tun.use_system_route_table: true could result in heavy CPU utilization when many thousands of routes
    are present. (#1326)
  • Fix tests for 32 bit machines. (#1394)
  • Fix a possible 32bit integer underflow in config handling. (#1353)
  • Fix moving a udp address from one vpn address to another in the static_host_map
    which could cause rapid re-handshaking with an incorrect remote. (#1259)
  • Improve smoke tests in environments where the docker network is not the default. (#1347)

Release v1.9.7

Choose a tag to compare

@github-actions github-actions released this 10 Oct 15:50
v1.9.7
7c3f533

Security

  • Fix an issue where Nebula could incorrectly accept and process a packet from an erroneous source IP when the sender's
    certificate is configured with unsafe_routes (cert v1/v2) or multiple IPs (cert v2). (#1494)

Changed

  • Disable sending recv_error messages when a packet is received outside the allowable counter window. (#1459)
  • Improve error messages and remove some unnecessary fatal conditions in the Windows and generic udp listener. (#1453)

Release v1.9.6

Choose a tag to compare

@github-actions github-actions released this 18 Jul 12:55
v1.9.6
105e0ec

Added

  • Support dropping inactive tunnels. This is disabled by default in this release but can be enabled with tunnels.drop_inactive. See example config for more details. (#1413)

Fixed

  • Fix Darwin freeze due to presence of some Network Extensions (#1426)
  • Ensure the same relay tunnel is always used when multiple relay tunnels are present (#1422)
  • Fix Windows freeze due to ICMP error handling (#1412)
  • Fix relay migration panic (#1403)

Release v1.9.5

Choose a tag to compare

@github-actions github-actions released this 06 Dec 14:59
v1.9.5
b55b901

Added

  • Gracefully ignore v2 certificates. (#1282)

Fixed

  • Fix relays that refuse to re-establish after one of the remote tunnel pairs breaks. (#1277)

Release v1.9.4

Choose a tag to compare

@github-actions github-actions released this 09 Sep 18:20
v1.9.4
ab81b62

Added

  • Support UDP dialing with gVisor. (#1181)

Changed

Fixed

  • Fix a bug on big endian hosts, like mips. (#1194)
  • Fix a rare panic if a local index collision happens. (#1191)
  • Fix integer wraparound in the calculation of handshake timeouts on 32-bit targets. (#1185)