跳到主内容
精选85Tailscale Changelog客户端

Tailscale v1.102.1:新增指标与CLI,修复安全漏洞

Tailscale v1.102.1

原文
推荐理由

Tailscale 重度用户注意:此版本修复了 TS-2026-010 安全漏洞,建议尽快升级;同时新增 Serve 指标和 CLI 命令,方便监控和运维。

All Platforms

  • New: tailscaled_serve_outbound_bytes_total and tailscaled_serve_inbound_bytes_total client metrics report bytes sent to and received from peers on Tailscale Serve connections for Tailscale Services.
  • New: The tailscale get CLI command returns the current node's preferences.
  • New: The tailscale whoami CLI command displays information about the current user and device.
  • New: The tailscale service list CLI command displays Tailscale Services visible to the current node.
  • Changed: Node additions and removals are processed in constant time, significantly reducing CPU usage on large tailnets. This currently applies to all platforms except Windows.
  • Changed: Tailscale Funnel domains use TLS-ALPN-01 for faster HTTPS certificate renewals.
  • Changed: Deprecated formats for 4via6 MagicDNS names are no longer available to use.
  • Changed: TLS certificates on idle servers proactively auto-renew in the absence of traffic. Warnings are issued when there is no valid cached certificate.
  • Fixed: Dials to dual-stack DNS names through an IPv4-only exit node connect to the correct address when using tailscaled in userspace mode.
  • Fixed: Certificate issuance for multiple domains runs in parallel. Provisioning multiple domains does not stall each certificate behind the previous one.
  • Fixed: Resolved an issue causing connectivity issues from the operating system waking from sleep in wireguard-go.
  • Fixed: A node's home DERP region is reported to the coordination server after a profile switch or login, allowing for peers to immediately connect to the node.
  • Fixed: A memory leak that occurred after a failed WireGuard handshake has been resolved.
  • Fixed: tailscale status --peers=false command shows the current device name in the output.
  • Fixed: Resolved an issue that prevented connectivity via Tailscale Peer Relays after a client restart.
  • Fixed: Tailscale SSH passes environment variables to child processes via inherited file descriptors. This fix addresses a security vulnerability described in TS-2026-010.

Linux

  • New: Assembly crypto routines for 32-bit ARM are available, improving performance on these platforms.
  • Changed: Userspace TUN optimizations improve throughput and performance.
  • Fixed: Resolved an issue impacting performance of UDP GSO on Linux v7.0.x through v7.1.4.

macOS

  • New: The Tailscale protocol handler supports deep-linking to devices, exit nodes, and settings panels in the application window.
  • Changed: The device list in the menu bar and Windowed UI loads more efficiently.
  • Changed: The client onboarding process is redesigned to match the style of the windowed UI.
  • Changed: Exit node names appear as subtitles in Shortcuts and can be used to filter the list of displayed exit nodes.
  • Changed: The connection toggle is disabled when Tailscale is controlled by VPN On Demand settings for the active network interface.
  • Fixed: Domain matching on-demand rules are evaluated in the correct order.
  • Fixed: A mismatch between the active exit node and the suggested exit node when using automatic exit node selection has been resolved.
  • Fixed: tailscale configure kubeconfig checks permissions on the $KUBECONFIG file before refusing to write to it when it's in a non-standard directory, fixing false rejections during Kubernetes API server access setup.

iOS

  • New: A new split-plane layout is used on iPad in both portrait and landscape orientation and on sufficiently wide iPhones in landscape.
  • New: The status widget supports toggling the active exit node inline.
  • Changed: Exit node names appear as subtitles in Shortcuts and can be used to filter the list of displayed exit nodes.
  • Changed: The connection toggle is disabled when Tailscale is controlled by VPN On Demand settings for the active network interface.
  • Fixed: Domain matching on-demand rules are evaluated in the correct order.
  • Fixed: A mismatch between the active exit node and the suggested exit node when using automatic exit node selection has been resolved.

tvOS

  • New: The Tailscale web client is supported for remote management of Apple TV devices.
  • Changed: The client onboarding process ensures the VPN configuration is approved and a login profile is added before using fast user switching.
  • Fixed: tvOS does not require a restart to use a custom coordination server defined in Settings.

Android

  • Changed: A single CGNAT route is created when no other interface is using CGNAT.
  • Fixed: TCP connections do not reset when VPN routing changes due to a netmap update.
  • Fixed: Health warnings are promptly cleared as soon as the underlying issue is resolved.

Synology

  • Changed: ARMv7 binaries with software floating point are produced for certain Synology NAS models, replacing older ARMv5 binaries.

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近