Bugs found by running the real test suite after merging upstream:
- types/types_clone.go, types/types_view.go: extend the regeneration
guard struct literals to include the new Groups field, and add a
UserView.Groups() accessor. Generated files normally rebuilt via
cloner / viewer; touched by hand here pending make generate.
- db/db.go: the migration adding the groups column ran after
202505141324, which calls ListUsers() through the User struct that
now includes Groups. Move the column-add to 202505141323 so the
schema is in place before any migration loads users. Register the
new ID in the FK-disabled migration list.
- db/db.go: 202507021200 recreates all tables from inline SQL during
the SQLite schema migration; add groups to both the CREATE TABLE
users statement and the INSERT INTO users ... SELECT FROM users_old
so the column survives the recreation. Also fix a copy-paste bug
in the Rollback closure that referenced tx instead of db.
- db/schema.sql: add the groups column to the canonical schema so
squibble.Validate accepts databases produced by the new migration
chain. Verified against all 7 historical sqlite dumps in
hscontrol/db/testdata/sqlite.
- types/users_test.go: the casby-oidc-claim case now exercises group
storage; update the want to include the JSON-encoded groups column.
- integration/oidc_groups_test.go: replace the aspirational draft
(which referenced assertNoErr, scenario.usernames, hsic.WithTLS and
other symbols that do not exist) with a focused test that follows
the auth_oidc_test.go pattern. Verifies the groups column directly
via sqlite3 inside the headscale container since the gRPC User
message does not expose Groups.
Tagged nodes are owned by their tags, not a user. Previously
user_id was kept as "created by" tracking, but this prevents
deleting users whose nodes have all been tagged, and the
ON DELETE CASCADE FK would destroy the tagged nodes.
Add a migration that sets user_id = NULL on all existing tagged
nodes. Subsequent commits enforce this invariant at write time.
Updates #3077
Add a version check that runs before database migrations to ensure
users do not skip minor versions or downgrade. This protects database
migrations and allows future cleanup of old migration code.
Rules enforced:
- Same minor version: always allowed (patch changes either way)
- Single minor upgrade (e.g. 0.27 -> 0.28): allowed
- Multi-minor upgrade (e.g. 0.25 -> 0.28): blocked with guidance
- Any minor downgrade: blocked
- Major version change: blocked
- Dev builds: warn but allow, preserve stored version
The version is stored in a purpose-built database_versions table
after migrations succeed. The table is created with raw SQL before
gormigrate runs to avoid circular dependencies.
Updates #3058
This PR changes tags to be something that exists on nodes in addition to users, to being its own thing. It is part of moving our tags support towards the correct tailscale compatible implementation.
There are probably rough edges in this PR, but the intention is to get it in, and then start fixing bugs from 0.28.0 milestone (long standing tags issue) to discover what works and what doesnt.
Updates #2417Closes#2619